en
Feedback
Dark Web Informer - Cyber Threat Intelligence

Dark Web Informer - Cyber Threat Intelligence

Open in Telegram
No data
Subscribers
+1524 hours
+1107 days
+49930 days
Posts Archive
🚨Alleged Sale of C2 Framework with Full EDR Bypass • Industry: N/A • Threat Actor: bryanross • Network: Clearnet, Dark Web •
+1
🚨Alleged Sale of C2 Framework with Full EDR Bypass • Industry: N/A • Threat Actor: bryanross • Network: Clearnet, Dark Web • Price: $500 • Details: Threat actor is offering a custom-built C2 framework and obfuscated payload designed to bypass all major EDR and antivirus solutions on Windows 10/11 and Linux. Features include behavioral and signature detection evasion, in-memory execution, process masquerading, encrypted communications, and multi-OS agent deployment. Capabilities extend to post-exploitation actions such as keylogging, credential theft (Mimikatz), remote shell access, file transfer, process injection, SOCKS proxying, persistence mechanisms, and lateral movement.

🚨Alleged Sale of Wacapew Crypter Malware Tool • Industry: N/A • Threat Actor: Wacapew • Network: Clearnet, Dark Web • Price:
+1
🚨Alleged Sale of Wacapew Crypter Malware Tool • Industry: N/A • Threat Actor: Wacapew • Network: Clearnet, Dark Web • Price: $60 • Details: Threat actor is promoting the ā€œWacapew Crypter,ā€ a manual crypting tool designed to bypass Windows Defender and SmartScreen on Windows 7–11 systems. The tool is written in low-level NASM and C, offering 0–3 detections at runtime and scan time, and claims to produce unique builds for each use.

🚨Alleged Sale of Wacapew Crypter Malware Tool • Industry: N/A • Threat Actor: Wacapew • Network: Clearnet, Dark Web • Price:
+1
🚨Alleged Sale of Wacapew Crypter Malware Tool • Industry: N/A • Threat Actor: Wacapew • Network: Clearnet, Dark Web • Price: $60 • Details: Threat actor is promoting the ā€œWacapew Crypter,ā€ a manual crypting tool designed to bypass Windows Defender and SmartScreen on Windows 7–11 systems. The tool is written in low-level NASM and C, offering 0–3 detections at runtime and scan time, and claims to produce unique builds for each use.

Feds playing games. It's back up.
Feds playing games. It's back up.

šŸšØšŸ‡«šŸ‡·Alleged data sale of French Swimming Federation (FFN) - Angers branch and FFN Bourgogne Franche Comte Note: Both screen
+1
šŸšØšŸ‡«šŸ‡·Alleged data sale of French Swimming Federation (FFN) - Angers branch and FFN Bourgogne Franche Comte Note: Both screenshots were captured by the feed before the site was closed.

BreachForums has been closed.
BreachForums has been closed.

Scattered Lapsus$ Hunters new channel: https://t.me/sp1d3rlapsushunters The following PGP message has been signed by Shiny of
Scattered Lapsus$ Hunters new channel: https://t.me/sp1d3rlapsushunters The following PGP message has been signed by Shiny of Shinyhunters. "It has come to my attention that both BreachForums and its official PGP key have been compromised" Read on...

šŸšØšŸ‡¬šŸ‡§Alleged Sale of UK Pensioners' Data with Bank and Monthly Income Information • Industry: Financial Services • Threat Ac
šŸšØšŸ‡¬šŸ‡§Alleged Sale of UK Pensioners' Data with Bank and Monthly Income Information • Industry: Financial Services • Threat Actor: visionmoon • Network: Clearnet, Dark Web • Price: Negotiable (bulk rates for 1K / 5K / 10K records) • Details: Threat actor claims to be selling fresh UK-based pensioners' data sourced in Q2 2025 from a financial CRM breach. Dataset allegedly includes full names, email addresses, active mobile numbers, postcodes/regions, age brackets (60+ subset), pensioner tags, bank account details, and monthly pension income estimates (Ā£700–£20,000).

🚨PLAY Ransomware Claims 4 New Victims šŸ‡ŗšŸ‡øRite Track šŸ‡ŗšŸ‡øTravancore Analytics šŸ‡ŗšŸ‡øBluewater Yacht Sales šŸ‡ŗšŸ‡øThe Scharine Gro
+1
🚨PLAY Ransomware Claims 4 New Victims šŸ‡ŗšŸ‡øRite Track šŸ‡ŗšŸ‡øTravancore Analytics šŸ‡ŗšŸ‡øBluewater Yacht Sales šŸ‡ŗšŸ‡øThe Scharine Group

šŸšØšŸ‡ŗšŸ‡øRamar & Paradiso, PC has Fallen Victim to PEAR Ransomware
šŸšØšŸ‡ŗšŸ‡øRamar & Paradiso, PC has Fallen Victim to PEAR Ransomware

šŸšØšŸ‡ŗšŸ‡¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO
+1
šŸšØšŸ‡ŗšŸ‡¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO

šŸšØšŸ‡ŗšŸ‡¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO
šŸšØšŸ‡ŗšŸ‡¦Z-ALLIANCE Targeted the Website of Help To Ukraine NGO

🚨Alleged Akira Ransomware Attacks, Multiple Victims Worldwide • Woodside KC šŸ‡ŗšŸ‡ø – Wellness & fitness center • Bondtech šŸ‡øšŸ‡Ŗ
🚨Alleged Akira Ransomware Attacks, Multiple Victims Worldwide • Woodside KC šŸ‡ŗšŸ‡ø – Wellness & fitness center • Bondtech šŸ‡øšŸ‡Ŗ – Autoclave systems manufacturer • Wytech Industries šŸ‡ŗšŸ‡ø – Medical device component maker • Sweetener Supply šŸ‡ŗšŸ‡ø – Food ingredients supplier • Aurora Air Products šŸ‡ŗšŸ‡ø – Gas & chemical distributor • Safti First šŸ‡ŗšŸ‡ø – Safety glass manufacturer • The Law Offices of Hicks & Demps šŸ‡ŗšŸ‡ø – Law firm • SPEEDLOGISTIK – Logistics services • TOP Ships šŸ‡¬šŸ‡· – Shipping company • Geotec šŸ‡°šŸ‡· – Engineering & construction • Sterling Card Solutions šŸ‡ŗšŸ‡ø – Payment solutions • TRS Industries – Industrial products • Microcosm šŸ‡¬šŸ‡§ – Scientific equipment supplier • GWU-Umwelttechnik GmbH šŸ‡©šŸ‡Ŗ – Environmental engineering • ESD Inc. šŸ‡ŗšŸ‡ø – Mechanical & electronic systems • Architectural DesignWest šŸ‡ŗšŸ‡ø – Architecture firm • Spring Footwear šŸ‡ŗšŸ‡ø – Shoe manufacturer • The Law Company – Construction services • Anderson Packaging – Packaging solutions • Atlas Transfer & Storage šŸ‡ŗšŸ‡ø – Moving & storage • Insero & Co. CPAs, LLP – Accounting firm

šŸšØšŸ‡°šŸ‡æAlleged Data Breach of Overclockers Online Store • Industry: E-commerce • Threat Actor: Dr0xKrueger • Network: Clearnet
šŸšØšŸ‡°šŸ‡æAlleged Data Breach of Overclockers Online Store • Industry: E-commerce • Threat Actor: Dr0xKrueger • Network: Clearnet, Dark Web • Details: The threat actor claims to have leaked a CSV file allegedly containing 179,263 lines of data from the Overclockers online store in Kazakhstan.

🚨Sale of EVILATOR NetSupport Bundle Dropper and Loader • Industry: Malware Development • Threat Actor: Evilator • Network: C
🚨Sale of EVILATOR NetSupport Bundle Dropper and Loader • Industry: Malware Development • Threat Actor: Evilator • Network: Clearnet, Dark Web • Details: A threat actor is allegedly offering EVILATOR, a compiler that produces a dropper or loader for covert NetSupport RAT client installation. The tool includes options to disguise the process as another executable, glue any file type (e.g., PDF, DOCX, XLSX) into the build, customize icons, and enable self-deletion of the loader after a set delay. The seller claims it builds fully FUD (Fully Undetectable) on both runtime and scan-time tests. The service supports Russian and English interfaces. šŸ’°Price: 3,000$/month šŸ’°Test Price: 500$/week (first 5 customers, in exchange for a review)

šŸšØšŸ‡³šŸ‡±AgroFair Benelux Falls Victim to Qilin Ransomware https://darkwebinformer.com/agrofair-benelux-falls-victim-to-qilin-ransomware/ Samples: šŸ–¼ Image 1: Shipping and customs documentation šŸ–¼ Image 2: Pesticide test results spreadsheet šŸ–¼ Image 3: Lab analysis images šŸ–¼ Image 4: Internal scheduling spreadsheet šŸ–¼ Image 5: Supplier contact list šŸ–¼ Image 6: Supplier identification and data records

šŸšØšŸ‡±šŸ‡°Ministry of Health Sri Lanka Data Sale, 398,769 Records Allegedly for Sale https://darkwebinformer.com/ministry-of-health-sri-lanka-data-sale-398-769-records-allegedly-for-sale/

h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email Gi
h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email GitHub: https://github.com/khast3x/h8mail

h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email Gi
h8mail: Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email GitHub: https://github.com/khast3x/h8mail