Dark Web Informer - Cyber Threat Intelligence
Open in Telegram
Discord Channel: discord.gg/gDHTYz5N9D Website: darkwebinformer.com Subscribe by Crypto: darkwebinformer.com/crypto-payments Advertise: darkwebinformer.com/advertising Canary: darkwebinformer.com/canary
Show moreNo data
Subscribers
+1524 hours
+1107 days
+49930 days
Posts Archive
š”Ransomware Attack Update for the 11th of August 2025
https://darkwebinformer.com/ransomware-attack-update-for-the-11th-of-august-2025/
+1
šØAlleged Sale of C2 Framework with Full EDR Bypass
⢠Industry: N/A
⢠Threat Actor: bryanross
⢠Network: Clearnet, Dark Web
⢠Price: $500
⢠Details: Threat actor is offering a custom-built C2 framework and obfuscated payload designed to bypass all major EDR and antivirus solutions on Windows 10/11 and Linux. Features include behavioral and signature detection evasion, in-memory execution, process masquerading, encrypted communications, and multi-OS agent deployment. Capabilities extend to post-exploitation actions such as keylogging, credential theft (Mimikatz), remote shell access, file transfer, process injection, SOCKS proxying, persistence mechanisms, and lateral movement.
+1
šØAlleged Sale of Wacapew Crypter Malware Tool
⢠Industry: N/A
⢠Threat Actor: Wacapew
⢠Network: Clearnet, Dark Web
⢠Price: $60
⢠Details: Threat actor is promoting the āWacapew Crypter,ā a manual crypting tool designed to bypass Windows Defender and SmartScreen on Windows 7ā11 systems. The tool is written in low-level NASM and C, offering 0ā3 detections at runtime and scan time, and claims to produce unique builds for each use.
+1
šØAlleged Sale of Wacapew Crypter Malware Tool
⢠Industry: N/A
⢠Threat Actor: Wacapew
⢠Network: Clearnet, Dark Web
⢠Price: $60
⢠Details: Threat actor is promoting the āWacapew Crypter,ā a manual crypting tool designed to bypass Windows Defender and SmartScreen on Windows 7ā11 systems. The tool is written in low-level NASM and C, offering 0ā3 detections at runtime and scan time, and claims to produce unique builds for each use.
+1
šØš«š·Alleged data sale of French Swimming Federation (FFN) - Angers branch and FFN Bourgogne Franche Comte
Note: Both screenshots were captured by the feed before the site was closed.
Scattered Lapsus$ Hunters new channel: https://t.me/sp1d3rlapsushunters
The following PGP message has been signed by Shiny of Shinyhunters.
"It has come to my attention that both BreachForums and its official PGP key have been compromised"
Read on...
šØš¬š§Alleged Sale of UK Pensioners' Data with Bank and Monthly Income Information
⢠Industry: Financial Services
⢠Threat Actor: visionmoon
⢠Network: Clearnet, Dark Web
⢠Price: Negotiable (bulk rates for 1K / 5K / 10K records)
⢠Details: Threat actor claims to be selling fresh UK-based pensioners' data sourced in Q2 2025 from a financial CRM breach. Dataset allegedly includes full names, email addresses, active mobile numbers, postcodes/regions, age brackets (60+ subset), pensioner tags, bank account details, and monthly pension income estimates (Ā£700āĀ£20,000).
+1
šØPLAY Ransomware Claims 4 New Victims
šŗšøRite Track
šŗšøTravancore Analytics
šŗšøBluewater Yacht Sales
šŗšøThe Scharine Group
šØšŗšøRamar & Paradiso, PC has Fallen Victim to PEAR Ransomware
+1
šØšŗš¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO
šØšŗš¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO
šØAlleged Akira Ransomware Attacks, Multiple Victims Worldwide
⢠Woodside KC šŗšø ā Wellness & fitness center
⢠Bondtech šøšŖ ā Autoclave systems manufacturer
⢠Wytech Industries šŗšø ā Medical device component maker
⢠Sweetener Supply šŗšø ā Food ingredients supplier
⢠Aurora Air Products šŗšø ā Gas & chemical distributor
⢠Safti First šŗšø ā Safety glass manufacturer
⢠The Law Offices of Hicks & Demps šŗšø ā Law firm
⢠SPEEDLOGISTIK ā Logistics services
⢠TOP Ships š¬š· ā Shipping company
⢠Geotec š°š· ā Engineering & construction
⢠Sterling Card Solutions šŗšø ā Payment solutions
⢠TRS Industries ā Industrial products
⢠Microcosm š¬š§ ā Scientific equipment supplier
⢠GWU-Umwelttechnik GmbH š©šŖ ā Environmental engineering
⢠ESD Inc. šŗšø ā Mechanical & electronic systems
⢠Architectural DesignWest šŗšø ā Architecture firm
⢠Spring Footwear šŗšø ā Shoe manufacturer
⢠The Law Company ā Construction services
⢠Anderson Packaging ā Packaging solutions
⢠Atlas Transfer & Storage šŗšø ā Moving & storage
⢠Insero & Co. CPAs, LLP ā Accounting firm
šØš°šæAlleged Data Breach of Overclockers Online Store
⢠Industry: E-commerce
⢠Threat Actor: Dr0xKrueger
⢠Network: Clearnet, Dark Web
⢠Details: The threat actor claims to have leaked a CSV file allegedly containing 179,263 lines of data from the Overclockers online store in Kazakhstan.
šØSale of EVILATOR NetSupport Bundle Dropper and Loader
⢠Industry: Malware Development
⢠Threat Actor: Evilator
⢠Network: Clearnet, Dark Web
⢠Details: A threat actor is allegedly offering EVILATOR, a compiler that produces a dropper or loader for covert NetSupport RAT client installation. The tool includes options to disguise the process as another executable, glue any file type (e.g., PDF, DOCX, XLSX) into the build, customize icons, and enable self-deletion of the loader after a set delay. The seller claims it builds fully FUD (Fully Undetectable) on both runtime and scan-time tests. The service supports Russian and English interfaces.
š°Price: 3,000$/month
š°Test Price: 500$/week (first 5 customers, in exchange for a review)
šØš³š±AgroFair Benelux Falls Victim to Qilin Ransomware
https://darkwebinformer.com/agrofair-benelux-falls-victim-to-qilin-ransomware/
Samples:
š¼ Image 1: Shipping and customs documentation
š¼ Image 2: Pesticide test results spreadsheet
š¼ Image 3: Lab analysis images
š¼ Image 4: Internal scheduling spreadsheet
š¼ Image 5: Supplier contact list
š¼ Image 6: Supplier identification and data records
šØš±š°Ministry of Health Sri Lanka Data Sale, 398,769 Records Allegedly for Sale
https://darkwebinformer.com/ministry-of-health-sri-lanka-data-sale-398-769-records-allegedly-for-sale/
h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
GitHub: https://github.com/khast3x/h8mail
h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
GitHub: https://github.com/khast3x/h8mail
