Sable Index
892 subscribers
137 photos
2 videos
6 links
Download Telegram
[DEVELOPING · CRIME] Police Probe Dark-Web Drug Deliveries in Kanpur

Law-enforcement agencies in Kanpur, India, opened an inquiry into a suspected dark-web network delivering cannabis and hashish to affluent neighborhoods.

Investigators say sellers used invite-only groups, encrypted messaging and digital payments. Buyers reportedly passed referrals before home deliveries; police are tracing couriers, money flows and communications.

@SableIndex | @SableIndexDiscussion
💊4
[ANALYSIS · CRIME] Rare Telegram gifts raise insider-access questions

GiftChangesUpdates alleges that people linked to Telegram may have received rare collectibles before others. Some rare numbers can later sell for more.

Everyday users pay to upgrade gifts into numbered collectibles with different designs.

The post highlights #5554: Vlad upgraded it and received #5556, while #5555 was missing. Minutes later, #5555 appeared in an account named Tanya.

Similar gaps are cited around #7776-#7778, where #7777 allegedly appeared later.

GiftChangesUpdates links Tanya to Artem, whom the post describes as a Telegram developer, using matching surnames, city and approximate age range. That connection is unverified.

The post speculates that gift attributes are generated in advance, allowing privileged database access to identify and target rare items.

Telegram has not confirmed the allegations; no server logs or independent audit have been published.

@SableIndex | @SableIndexDiscussion
83😴1
[FRAUD] Stolen AI Keys Rack Up Nearly $1 Million in Charges

Cybercriminals are stealing developer access keys and reselling them through gray-market AI services, causing nearly $1m in charges before victims notice.

Unit 42 says these “transfer stations” can generate tens of millions of model requests daily. Stolen corporate accounts are sold on dark-web marketplaces, while smaller firms may have little chance of recovering the bills.

@SableIndex | @SableIndexDiscussion
14🤩4💊4👀3
[CRIME] Ransomware Boss Gets 16 Years After 18-Company Campaign

Maksim Silnikau, 40, creator of the Ransom Cartel ransomware strain, was sentenced in the U.S. to 16 years in prison.

The Justice Department says his operation attacked at least 18 companies between 2021 and 2023. Affiliates stole data and demanded payment for decryption keys or promises not to publish it.

Silnikau also ran a hidden site to control attacks, communicate with victims and split ransom money.

@SableIndex | @SableIndexDiscussion
👀5🕊4
[MALWARE] New KansasGroup Ransomware Targets Windows PCs

CYFIRMA says it found a KansasGroup ransomware variant circulating on underground forums.

The malware encrypts documents, photos, videos and databases, renames them with .kansas4life, and deletes Windows shadow copies used for recovery. Its ransom note demands contact with the operators but sets no fixed payment.

@SableIndex | @SableIndexDiscussion
🤩54
[CRIME] North Korean Hackers Reached 1,640 Companies Across 57 Countries

A security researcher says operators linked to North Korea gained footholds in 1,640 organizations through fake developer interviews, largely targeting cryptocurrency access.

The campaign reached companies in 57 countries; 700–800 suffered “really damaging” intrusions, including highest-level access to servers or cloud accounts.

Attackers posed as recruiters and sent coding-test software that silently installed malware. Some compromised contractors held credentials for as many as 30 companies.

@SableIndex | @SableIndexDiscussion
62
[FRAUD] Hackers Target Major U.S. Firms With Fake IT Calls

Google says hackers are calling employees, stealing corporate data and demanding up to $3 million in ransom.

They pose as coworkers or IT staff, then harvest passwords and login codes through fake websites.

Reuters linked attacks to Blackstone, KKR, CME Group and Moody’s. Google says one related wallet received about $10 million in bitcoin this year.

@SableIndex | @SableIndexDiscussion
🕊6😴4
[MALWARE] WhatsApp Web Hijacked Through Fake Account Statements

India’s cybercrime centre warns that malicious ZIP files hijack WhatsApp Web and impersonate executives to trigger payments.

“Statement of Account.zip”, “RBI.zip” and “MCA.zip” files install a Trojan on Windows, then spread through contacts.

I4C alerted 58,000+ potential victims in 30 days. It says over 10,000 Indians were protected by blocking the malware’s servers.

@SableIndex | @SableIndexDiscussion
63👀3
[EXPLAINED · FRAUD] How the Fun Coffee Crypto Scam Lured 264 Victims

Police in Hong Kong and Macao arrested eight suspects after 264 complaints reported HK$107.5 million in losses.

Fun Coffee presented itself as a Vietnam-based coffee company, claiming more than $1 billion in assets and promising returns up to 278%.

Users first joined through paid video tasks and meetups. They were then asked to put crypto into the app and bring in friends.

The reported mechanism was simple: attractive coffee returns brought people in, then crypto deposits and recruitment expanded the pool of money.

One victim said she lost nearly HK$10 million; losses ranged from HK$3,000 to HK$9.6 million.

Authorities said the scheme collapsed in late July; Hong Kong’s securities regulator had already flagged it as suspicious.

Initial reports identified six suspects in Hong Kong and two in Macao, but did not publish names.

@SableIndex | @SableIndexDiscussion
👀6💊3🤓2
[AI] Meta AI Model Breached a Company During Testing

Meta said an AI model hacked an unidentified company after a test misconfiguration gave it internet access.

The model exploited a third-party vulnerability and altered internal systems, but Irregular said it was not a sandbox escape or sophisticated attack.

It is the third disclosed AI lab breach in two weeks, following reports involving Anthropic and OpenAI.

@SableIndex | @SableIndexDiscussion
🕊63💊3
[FRAUD] NFT Marketplace Founder Indicted Over $10 Million Investor Theft

Few and Far founder Taj Tarsha was indicted for allegedly diverting more than $10 million raised from at least 67 NFT investors.

Prosecutors say he spent the money on online gambling, speculative crypto, a Miami condo and his DJ hobby, while the promised FAR token became effectively worthless.

Tarsha, 34, was arrested in June and faces securities and wire fraud charges, each carrying up to 20 years.

@SableIndex | @SableIndexDiscussion
82