π¨ New Dark Web Informer Blog Post!
Title: Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts
Link: https://darkwebinformer.com/threat-actor-selling-root-access-to-south-korean-government-server-with-lateral-movement-to-42-internal-hosts/
Title: Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts
Link: https://darkwebinformer.com/threat-actor-selling-root-access-to-south-korean-government-server-with-lateral-movement-to-42-internal-hosts/
Dark Web Informer
Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts
βΌοΈπ A threat actor is allegedly selling a bundle of 19 corporate accesses targeting companies across Spain, UK, Brazil, Guatemala, Mexico, and India.
The access reportedly includes GitLab/GitHub repos and tokens, SSO/IdP configurations (Okta, Azure AD, OpenAM), CI/CD secrets, Jira/Confluence admin, AWS Lambda with payment code, vulnerability data, Slack webhooks, and customer databases.
Targets range from large enterprises (β¬2Bββ¬38B revenue in retail, insurance, banking) to mid-sized firms (β¬15Mββ¬450M in IT, SaaS, fintech) and smaller cybersecurity companies. Available as a package or individually.
The access reportedly includes GitLab/GitHub repos and tokens, SSO/IdP configurations (Okta, Azure AD, OpenAM), CI/CD secrets, Jira/Confluence admin, AWS Lambda with payment code, vulnerability data, Slack webhooks, and customer databases.
Targets range from large enterprises (β¬2Bββ¬38B revenue in retail, insurance, banking) to mid-sized firms (β¬15Mββ¬450M in IT, SaaS, fintech) and smaller cybersecurity companies. Available as a package or individually.
βΌοΈ DOJ Press Release
βββββββββββββββββββββ
Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act Allegations
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
βββββββββββββββββββββ
Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act Allegations
Full Press Release β justice.gov
βββββββββββββββββββββ
π΅οΈ Dark Web Informer β’ DOJ Monitor
www.justice.gov
Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act
Aetna Inc., a national insurer incorporated under the laws of Pennsylvania, has agreed to pay $117,700,000 to resolve allegations that it violated the False Claims Act by submitting or failing to withdraw inaccurate and untruthful diagnosis codes for itsβ¦
π¨ New Dark Web Informer Blog Post!
Title: Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked
Link: https://darkwebinformer.com/viking-line-ferries-allegedly-breached-with-full-passenger-database-and-payment-data-leaked/
Title: Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked
Link: https://darkwebinformer.com/viking-line-ferries-allegedly-breached-with-full-passenger-database-and-payment-data-leaked/
Dark Web Informer
Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked
β οΈ FBI Watchdog - DNS Change (SOA) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: thesecure.biz
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 16:25:00 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: thesecure.biz
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 16:25:00 UTC
Previous Records:
edna.ns.cloudflare.com. dns.cloudflare.com. 2397922649 10000 2400 604800 1800
New Records:
edna.ns.cloudflare.com. dns.cloudflare.com. 2398729597 10000 2400 604800 1800
β οΈ FBI Watchdog - DNS Change (SOA) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: ps4pkg.com
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 17:13:40 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: ps4pkg.com
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 17:13:40 UTC
Previous Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398103745 10000 2400 604800 1800
New Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398734186 10000 2400 604800 1800
βΌοΈπΊπΈ Stryker is currently offline due to a wiper malware attack by Handala.
https://x.com/BleepinComputer/status/2031782605616492593
Edit: Flag was set to Israel, should have been USA
https://x.com/BleepinComputer/status/2031782605616492593
Edit: Flag was set to Israel, should have been USA
π₯2
Do you want me to delete the DOJ articles that are not cyber related when I see them? Currently all of the articles come in unfiltered rather than by keyword so nothing is missed.
Anonymous Poll
70%
Yes
18%
No
11%
Show Results
β οΈ FBI Watchdog - DNS Change (SOA) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: ps5pkg.net
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 19:17:07 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: ps5pkg.net
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 19:17:07 UTC
Previous Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398068487 10000 2400 604800 1800
New Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398741935 10000 2400 604800 1800
Cybersecurity Incident Disclosure
Wed, 11 Mar 2026 17:24:57 EDT
A cybersecurity incident has been disclosed by STRYKER CORP, Inc CIK: 0000310764, Ticker: $SYK.
View SEC Filing
Wed, 11 Mar 2026 17:24:57 EDT
A cybersecurity incident has been disclosed by STRYKER CORP, Inc CIK: 0000310764, Ticker: $SYK.
View SEC Filing
βΌοΈπ¦π· Arimex Importadora has been claimed a victim to Qilin Ransomware
Note: Qilin used the wrong logo screenshot, the samples provided show Arimex Importadora
Note: Qilin used the wrong logo screenshot, the samples provided show Arimex Importadora
β οΈ FBI Watchdog - DNS New Domain (A) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS New Domain (A)
Time Detected: 2026-03-11 22:11:12 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS New Domain (A)
Time Detected: 2026-03-11 22:11:12 UTC
Previous Records:
None
New Records:
104.21.89.31
172.67.136.145
β οΈ FBI Watchdog - DNS New Domain (AAAA) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS New Domain (AAAA)
Time Detected: 2026-03-11 22:11:13 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS New Domain (AAAA)
Time Detected: 2026-03-11 22:11:13 UTC
Previous Records:
None
New Records:
2606:4700:3034::6815:591f
2606:4700:3034::ac43:8891
β οΈ FBI Watchdog - DNS Seizure (NS) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS Seizure (NS)
Time Detected: 2026-03-11 22:11:20 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS Seizure (NS)
Time Detected: 2026-03-11 22:11:20 UTC
Previous Records:
Previously active
New Records:
ns1.fbi.seized.gov.
ns2.fbi.seized.gov.
β οΈ FBI Watchdog - DNS Seizure (SOA) β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS Seizure (SOA)
Time Detected: 2026-03-11 22:11:30 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: drifthub.cc
Record Type: DNS Seizure (SOA)
Time Detected: 2026-03-11 22:11:30 UTC
Previous Records:
Previously active
New Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2394338815 10000 2400 604800 1800
π¨ FBI Watchdog - SEIZURE ESCALATION ALERT π¨
π DarkWebInformer.com - Cyber Threat Intelligence
Domain:
Triggered By: HTTP Initial (this domain has been seized, this website has been seized, warrant issued)
Time Detected: 2026-03-11 22:11:55 UTC
π HTTP Fingerprint Changes:
π DNS Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain:
drifthub.ccTriggered By: HTTP Initial (this domain has been seized, this website has been seized, warrant issued)
Time Detected: 2026-03-11 22:11:55 UTC
π HTTP Fingerprint Changes:
Seizure keywords: this domain has been seized, this website has been seized, warrant issued, law enforcement operation, joint law enforcement operation
π DNS Records:
NS: ns1.fbi.seized.gov., ns2.fbi.seized.gov. β ns1.fbi.seized.gov., ns2.fbi.seized.gov.
SOA: ns1.fbi.seized.gov. dns.cloudflare.com. 2394338815 10000 2400 604800 1800 β ns1.fbi.seized.gov. dns.cloudflare.com. 2394338815 10000 2400 604800 1800