CTI Updates
236 subscribers
161 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
weird takedown thingy posted on the Kairos ransomware groups DLS page. Claimed by the "SBU Cyber Department" ?

nerqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad[.]onion
๐Ÿ‘2
Akira ransomware group lists Minnesota Health Insurance Network, a provider of individual and family plans, group and small business coverage, Medicare, dental and vision insurance, and short-term health insurance.
๐Ÿ‘3
Insomnia ransomware group lists United Medical Doctors (UMD), an independent multi-specialty medical-surgical group with 70+ Southern California locations and 40+ specialties focused on patient care, outpatient surgery, and clinical research.
๐Ÿ‘€3
The Qilin ransomware group lists 7 new victims

ยฐ,ยธ Higashiyama Industries Co.,Ltd.
ยฐ,ยธ Guerin Glass
ยฐ,ยธ TIS
ยฐ,ยธ Sonn Law Group
ยฐ,ยธ Autogalerie Heister
ยฐ,ยธ Saam Towage
ยฐ,ยธ Nan Lui Enterprises
๐Ÿ”ฅ2๐Ÿ‘1
XSS forum is down atm
๐Ÿ˜ข2
OGUser.com is having some downtime atm
๐Ÿ‘2๐Ÿ‘1
The average HackForums post
๐Ÿ˜ญ3๐Ÿ™ˆ2
CoinbaseCartel ransomware group lists Carterโ€™s, Ralph Lauren, and Helzberg as victims.

Carterโ€™s is a childrenโ€™s clothing retailer, Ralph Lauren is a fashion and apparel brand, and Helzberg is a jewelry retailer specializing in diamonds and gold.
๐Ÿณ3๐Ÿ‘€2๐Ÿ’ฏ1
the 0APT ransomware silly willy who got busted for posting fake victims and being a larp has came back with a post extorting another ransomware group, Krybit, and threatening to expose who they are if they do not pay
๐Ÿคฃ5๐Ÿ˜2
Ryan LLC has been removed from the ShinyHunters DLS
๐Ÿ‘1
PEAR ransomware group lists Colorado-based Colorado Pulmonary Intensivists (CPI / UCHealth), claiming to have stolen 2.3 TB of data. The group says the haul includes financials, HR files, provider and vendor data, patient PII/PHI, email correspondence, and cloud-stored data.
๐Ÿณ1๐Ÿ‘€1
Vect ransomware group mentions Airbnb and Booking.com
โค2๐Ÿ‘€2๐Ÿณ1
Krybit ransomware group responds to 0APTs claim of hacking them
Cognizant listed by the Coinbasecartel ransomware group this morning
๐Ÿ‘€2
The financial fraud website Altenens is offline atm
๐Ÿ‘1
Vect / TeamPCP added two new victims from their Trivy/LiteLLM campaign.

S&P Global and Guesty
๐Ÿ‘2
XSS is derped atm
๐Ÿ‘€2๐Ÿ‘1
Pitney Bowes
7-11 (the gas station)
Medronic PLC
The Canada Life Assurance Company
Zara

All listed by ShinyHunters just now. Looks to be a continuation of their Salesforce pwnage
๐ŸŽ„3๐Ÿ‘€2
Carding forum Altenens is closed with a notice of

"forum is closed We will back soon please keep remember your ID and password of Altenens.is"
โค2
Citizens Bank & Frost Bank listed by the Everest ransomware group
๐Ÿ‘1