CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
more from Github RE: getting pwned by TeamPCP
πŸ‘1
A criminal complaint was unsealed in Alaska today charging a Canadian man with operating the KimWolf DDoS botnet. The U.S. complaint was unsealed following the defendant’s arrest in Canada by Canadian authorities.

On April 10, 2026, U.S. authorities criminally charged Jacob Butler, aka β€œDort,” 23, of Ottawa, with offenses related to the development & operation of the KimWolf botnet. KimWolf was a DDoS-for-hire service which infected over a million devices worldwide, including devices in Alaska.

For more info, read the press release at https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos
πŸ‘3❀1
Qilin ransomware group lists Semgrep, a software company whose mission is to β€œmake it expensive to exploit software.”
😁3
BravoX ransomware group has listed The Salvation Army, marking the third time in less than a year the organization has been named by a ransomware group. It was previously listed by the Interlock and Chaos ransomware groups. BravoX claims to have stolen 110 GB of data across 4,500 directories and 59,000 files.
πŸ‘€1
Genesis ransomware group has listed five new victims:
- A. Roettgers
- Cedar Street Capital
- Green Resource
- Wentworth
- Cavalier Flooring Systems Inc.

The organizations span multiple sectors, including fuel retail, private investment, agricultural supply distribution, home remodeling, and flooring and tile contracting.
Gunra ransomware group has added five new victims to its leak site: Star Empire Entertainment, Somafix, bkksky, Cablematic Dos Mil SLU, and Triotech. The group claims to have stolen 10 GB of data from SOMAFIX and 100 GB from Cablematic Dos Mil SLU.
Lapsus$ has listed INGKA Group (IKEA), claiming to have obtained approximately 180 GB of internal data. The group says the data includes global e-commerce architecture mapping, internal coworker platforms, supply chain logistics, cloud infrastructure, and AI/MLOps repositories.
πŸ‘1
BravoX ransomware group has listed AcademyHealth.

AcademyHealth is based in Washington, D.C. and focuses on advancing health services research and health policy.

The group claims to have obtained 975 GB of data.
πŸ‘1
A threat actor has allegedly posted 341K records from the Indonesian National Police Database also while claiming they arrested the wrong person?? lol no idea
❀1πŸ‘1
A threat actor has posted 421k customer records from the Saudi Arabian website of mrsool[.]co. Its kinda like some DoorDash/TaskRabbit platform.
πŸ‘1
A threat actor on Breached claims to be offering a β€œfull Grindr database” allegedly containing data on 15 million users. The listing appears questionable, with the actor pricing the alleged database at just $400.
🍌3πŸ‘€1
INC ransomware group lists Stuga Machinery Ltd, a company specializing in precision sawing and machining centers for the fenestration industry, primarily serving customers in the UK and Ireland.
πŸ‘€1
LockBit ransomware group lists Sierra Vista Hospital, a private behavioral health facility in Sacramento, California, offering psychiatric and chemical dependency treatment through inpatient and outpatient programs.
πŸ‘€1
LockBit lists Uni-China Group, a Hong Kong-based conglomerate with more than 25 years of history in retail, wholesale trade, logistics, cold storage, and market operations. The group claims to have stolen 170,656 files across 9,075 folders, totaling roughly 195 GB of data.
πŸ™1
Akira ransomware group lists three new victims on its DLS: Oaks Park, Kennon Worldwide, and T/CCI Manufacturing.

The group claims it will soon publish 10 GB of data from Oaks Park, 30 GB from Kennon Worldwide, and 35 GB from T/CCI Manufacturing. Alleged data includes employee information, payment details, contracts, NDAs, client information, financials, and confidential files.
πŸ‘2
Krybit ransomware group lists Shantou Huashan Electronic Devices Co., Ltd. (SHEDCL), a Chinese manufacturer of semiconductor devices and electronic components based in Shantou, Guangdong Province.

The company produces and distributes components including voltage regulators, transistors, Schottky diodes, wafers, capacitors, inductors, and resistors.
πŸ‘1
Akira ransomware group lists HRC Sicherheitsdienste, a family-owned security service provider with more than 45 years of experience.

The group claims it will soon publish 24 GB of corporate data, including employee information, German passports and IDs, credit cards, payment details, financials, agreements, contracts, and confidential documents.
πŸ‘1
Qilin ransomware group lists Isuzu Motors Thailand (isuzu-motors.co.th) as a victim.
πŸ‘1