The Singapore startup teaching machines to read the internet's underground - and warning governments and companies before the damage is done.
STEALTHMOLE — The company's mascot is a mole, an animal that works underground. It is a deliberate metaphor for the hidden web the platform monitors. Brand mark, official.
Most organizations learn they have been breached the slow way: a customer complaint, a regulator's letter, or a ransom note. By then the stolen data has usually been sitting on a dark web forum for weeks. StealthMole, a company founded in Singapore in 2022, was built to shorten that gap - to spot the leak, the credential, and the actor behind it before the breach becomes a headline.
The company calls itself a deep and dark web threat intelligence platform. In practice that means it continuously collects and correlates data from the parts of the internet that ordinary search engines never reach: Tor sites, leak blogs, criminal marketplaces, and Telegram channels where stolen data changes hands. It has analyzed hundreds of billions of records and tracks more than 1.3 million Tor domains, folding all of it into a single cloud platform where an investigator can type a query and get an answer.
StealthMole's founders saw a specific gap. Much of the existing dark web tooling was built around English-language threats, leaving Asia - a fast-growing target for cybercrime - comparatively under-covered. The company set out to close that blind spot, pairing a Singapore headquarters with research and development rooted in South Korea and a team that skews toward regional threat expertise.
The mascot, a mole, is not an accident. It is the animal that does its work underground, out of sight - the same place StealthMole's software spends its time.
"StealthMole came about from a critical market gap - a lack of Asia-specific dark web data intelligence."— Louis Hur, Founder & CEO
StealthMole packages its intelligence into distinct modules. Each one answers a different question a security or investigations team actually asks.
A digital forensics tool for investigators. It enables threat lookup, relationship tracing, and visual investigation mapping - showing how a leaked email links to a forum handle links to a campaign.
Detects leaked account credentials across billions of breached records, through the Compromised Data Set, Credential Lookout, and Combo Binder sub-modules.
Round-the-clock surveillance that tracks breached organizational data and mentions across the deep and dark web, alerting teams the moment their exposure surfaces.
Monitors the Telegram channels and groups that threat actors increasingly use to trade stolen data and coordinate criminal activity.
The problem it solves. Stolen credentials, breached databases, and criminal chatter live in places most security teams can't practically watch. Firewalls and endpoint tools defend the perimeter; almost nothing watches where the stolen data actually ends up. StealthMole argues the dark web isn't a niche - it's the missing half of the security stack.
How it stands apart. Rather than dumping raw feeds, StealthMole emphasizes correlation - connecting records into relationships an analyst can follow - and a deliberate focus on Asia-specific sources and languages that broader Western vendors under-serve. Its go-to-market leans on integrations, such as feeding signals directly into Netskope's platform, instead of asking customers to adopt yet another standalone dashboard.
Figures are drawn from StealthMole's public materials and are approximate.
Governments, law enforcement and national security agencies, and enterprise cybersecurity teams. As of its 2024 Series A, StealthMole reported 50+ clients across 17 countries in Asia, Europe, and the Middle East. Public-sector investigators and corporate incident-response teams are the core users.
B2B intelligence-as-a-service. StealthMole sells subscription access to its cloud platform and modules, complemented by technology partnerships and integrations that embed its dark web signals into partners' products.
A specialist team of white-hat hackers, cyber threat analysts, digital forensic experts, and OSINT specialists - roughly 30 people. CEO Louis Hur is a regular speaker at DEFCON, BlackHat, HITCON, TyphoonCon, and CodeBlue.
It sits in the dark web / cyber threat intelligence category alongside vendors like ZeroFox, Cybersixgill, Recorded Future, Flare, and DarkOwl - differentiating on regional depth in Asia and a modular, investigation-first platform.
Additional Series A investors: Hibiscus Fund (RHL Ventures, Penjana Kapital, KB Investment) and Smilegate Investment.
"StealthMole came about from a critical market gap I encountered while working in cybersecurity - a lack of Asia-specific dark web data intelligence."
— Louis Hur, Founder & CEO"Having researchers from various backgrounds will aid us in analyzing data related to neighboring countries."
— Simon Choi, Co-Founder & CTOLouis Hur co-founds NSHC Inc., one of South Korea's leading cybersecurity firms - building the expertise that later informs StealthMole.
Louis Hur and Simon Choi launch StealthMole in Singapore to close Asia's dark web intelligence gap.
Korea Investment Partners leads a $7 million round with Hibiscus Fund and Smilegate Investment to fund R&D centers and global expansion.
StealthMole joins the Netskope Technology Partner Program and partners with CyberArmyID to broaden threat coverage across Southeast Asia.
It provides an AI-powered, cloud-based platform that monitors the deep and dark web, leak sites, and Telegram to detect data breaches, compromised credentials, and criminal activity for governments, law enforcement, and enterprises.
It was founded in 2022 by Louis Hur (CEO) and Simon Choi (CTO), both experienced cybersecurity and threat-intelligence professionals with roots in South Korea.
It is headquartered in Singapore at 2 Venture Drive, Vision Exchange, with research and development rooted in South Korea.
StealthMole raised a US$7 million Series A round in March 2024, led by Korea Investment Partners with Hibiscus Fund and Smilegate Investment.
Its main modules are Darkweb Tracker, Credential Protection, Dark Web Monitoring, and Telegram Tracker, plus a StealthMole CRE integration for Netskope Cloud Exchange.