{"id":84954,"date":"2025-09-05T09:00:31","date_gmt":"2025-09-05T09:00:31","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=84954"},"modified":"2025-09-05T09:00:31","modified_gmt":"2025-09-05T09:00:31","slug":"threat-intelligence-researchers-uncover-a-massive-pirate-iptv-operation","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=84954","title":{"rendered":"Threat Intelligence Researchers \u201cUncover a Massive Pirate IPTV Operation\u201d"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/iptv-ff-s.png\" alt=\"iptv-ff-s\" width=\"300\" height=\"183\" class=\"alignright size-full wp-image-261981\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/iptv-ff-s.png 400w, https:\/\/torrentfreak.com\/images\/iptv-ff-s-300x183.png 300w, https:\/\/torrentfreak.com\/images\/iptv-ff-s-150x92.png 150w\" sizes=\"(max-width: 300px) 100vw, 300px\">Research and investigations concerning internet platforms can be incredibly time-consuming, despite most of the necessary tools being readily available to the public free of charge.<\/p>\n<p>Threat intelligence platform Silent Push combines the essence of these tools into a graphical interface that does much more than the sum of its parts. Historical data, for example, allows connections to be built in cases where evidence no longer exists on the \u2018live\u2019 web. Straightforward tasks such as WHOIS lookups, on the other hand, only rarely look this good.<\/p>\n<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/silent-push-whois.png\" alt=\"silent-push-whois\" width=\"670\" height=\"377\" class=\"aligncenter size-full wp-image-271651\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/silent-push-whois.png 670w, https:\/\/torrentfreak.com\/images\/silent-push-whois-300x169.png 300w, https:\/\/torrentfreak.com\/images\/silent-push-whois-600x338.png 600w, https:\/\/torrentfreak.com\/images\/silent-push-whois-150x84.png 150w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\"><\/center><\/p>\n<p>According to Silent Push researchers (SPR), the platform makes it easy to \u201cmap out the entire infrastructure supporting IPTV networks\u201d by \u201ccombining just a few technical fingerprints.\u201d The results of an investigation published today claim to identify a major IPTV network and an individual the researchers claim is closely involved.<\/p>\n<h2>A Domain Name Gets Things Rolling<\/h2>\n<p>SPR say their investigation began with a domain name \u2013 <em>premiumplustv[.]xyz<\/em> \u2013 which had been reported as hosting pirated content. Using the <a href=\"https:\/\/help.silentpush.com\/docs\/web-scanner\">Silent Push Web Scanner<\/a> they were then able to connect the service to 10,000 IP addresses and 1,100 domains, with one standing out in particular.<\/p>\n<p>\u201cThe <em>xuione[.]com<\/em> website, seen below, is a massive IPTV provider that appears to support numerous pirated content schemes \u2013 confirming the initial suspicions of our research partner,\u201d SPR write.<\/p>\n<p>\u201cFor several years, the <em>xuione[.]com<\/em> website listed details indicating the registrant was based in Herat, Afghanistan.\u201d<\/p>\n<p>Records were updated to remove references to Afghanistan in March 2025, but historical records are more difficult to change.<\/p>\n<h2>SPR Identify an Individual With Close Links to the Network<\/h2>\n<p>SPR\u2019s investigation led them to identify an individual that they believe is closely linked to the pirate IPTV network, who is also the \u201clikely\u201d operator of the pirate IPTV service at <em>jvtvlive[.]xyz<\/em>. <\/p>\n<p>That service allegedly exploits content from the world\u2019s leading entertainment and sports brands including <em>Prime Video, Bein Sports, Disney Plus, NPO Plus, Formula 1, HBO, Viaplay, Videoland, Discovery Channel, Ziggo Sports, Netflix, Apple TV, Hulu, NBA, RMC Sport, Premier League, Champions League, Sky Sports, NHL, WWE, and UFC.<\/em><\/p>\n<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/jvtvlive.png\" alt=\"jvtvlive\" width=\"670\" height=\"403\" class=\"aligncenter size-full wp-image-271653\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2025\/09\/jvtvlive.png 1458w, https:\/\/torrentfreak.com\/images\/jvtvlive-300x181.png 300w, https:\/\/torrentfreak.com\/images\/jvtvlive-600x361.png 600w, https:\/\/torrentfreak.com\/images\/jvtvlive-150x90.png 150w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\"><\/center><\/p>\n<p>While that individual may indeed be everything SPR say he is, an OPSEC note accompanying the investigation notes that the methods used by the team to enumerate the piracy network, and the process used to identify the individual (located in Herat, Afghanistan), \u201ccannot be shared publicly.\u201d <\/p>\n<p>We have no reason to doubt their findings, but there\u2019s no replacement for seeing the evidence first hand.<\/p>\n<h2>Evidence Mounts<\/h2>\n<p>Ultimately, however, SPR were able to link the domain <em>xuione[.]com<\/em> to an IP address \u2013 158.220.114[.]199 \u2013 used by many apparent IPTV-linked services [<a href=\"https:\/\/www.silentpush.com\/wp-content\/uploads\/iptv-image-13-sp-total-view-ip-158220114199.png\">here<\/a>] including <em>streamxpert[.]net, jvtvlive[.]xyz<\/em>, and <em>tiyanhost[.]com<\/em>.<\/p>\n<p><em>Tiyanhost[.]com<\/em> is the domain name of Tiyan Software Development, a business entity also based in Herat, Afghanistan. Public records show that the person identified by SPR shares the same name as the owner of that company. Sites with links to XuiOne display a WhatsApp number with an Afghan country code that perfectly matches a number directly linked to the same person, researchers say.<\/p>\n<p>Overall, that led to the researchers feeling \u201ccomfortable assessing his involvement\u201d in the pirate network\u2019s operations.<\/p>\n<h2>Food For Thought<\/h2>\n<p>Exactly what additional evidence was obtained by the researchers is unknown, but we assume that it\u2019s pretty compelling after naming the individual in public. It also seems reasonable to assume that information has been shared with anti-piracy companies and other interested parties in advance. If not, publication of the research is a pretty loud \u2018headsup\u2019 for those involved.<\/p>\n<p>Yet, as far as we know, the service remains active. Enforcement in Afghanistan may present more than a few stumbling blocks, but the country isn\u2019t known for cutting edge technical infrastructure. The service\u2019s infrastructure has a fairly significant European presence, but perhaps the time isn\u2019t quite right to do anything about it.<\/p>\n<p>Finally, online databases used for investigations aren\u2019t always accurate and at times can deliver the occasional curveball. All things considered, the existence of an $84 million turnover ad agency in the same Afghan town seems unusual. Even more so when allegedly operated by an individual with a familiar name, which some databases link to an even bigger operation in the Netherlands.<\/p>\n<p><em>Silent Push (Community Edition) is available for free <a href=\"https:\/\/www.silentpush.com\/community-edition\/\">here<\/a> (pdf). The investigation report is available <a href=\"https:\/\/www.silentpush.com\/blog\/iptv-piracy\/\">here<\/a><\/em><\/p>\n<p>From: <a href=\"https:\/\/torrentfreak.com\/\">TF<\/a>, for the latest news on copyright battles, piracy and more.<\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Research and investigations concerning internet platforms can be incredibly time-consuming, despite most of the necessary tools being readily available to the public free of charge. Threat intelligence platform Silent Push combines the essence of these tools into a graphical interface that does much more than the sum of its parts. Historical data, for example, allows [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":84955,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[308],"tags":[],"class_list":["post-84954","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-torrent"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/84954","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=84954"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/84954\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/84955"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=84954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=84954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=84954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}