πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.82K subscribers
1.1K photos
62 videos
980 links
Download Telegram
🚨STORM Windows info stealer advertised for $350 per month

A forum actor is advertising STORM, a Windows-based information stealer written in C++ and marketed with uniquely compiled builds, obfuscation, encrypted delivery, and a web-based control panel.

The listing claims the malware can extract browser data, passwords, cookies, cryptocurrency wallets, password manager data, messenger sessions, Discord tokens, files, screenshots, and detailed system information. It also includes a configurable loader capable of downloading and executing additional EXE, DLL, and PowerShell files.

The standard license is priced at $350 per month, while a team license with 100 user slots and 200 build slots costs $700 per month. The seller states that the malware will not target systems located in Russia or the CIS.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡Ί Bendigo Law Courts dataset allegedly leaked

A forum actor claims to have leaked more than 28,600 records allegedly obtained from Bendigo Law Courts, a multi-jurisdictional courthouse complex serving Bendigo and the Loddon-Mallee region in Victoria, Australia.

The dataset is described as containing court booking and hearing information across the Magistrates’ Court, Children’s Court, County Court, Supreme Court, Victorian Civil and Administrative Tribunal, and federal courts.

The allegedly exposed information includes case titles and numbers, hearing dates and times, courtrooms, divisions, participant names and email addresses, dates of birth, custody locations, agency details, notes, Webex meeting links, meeting numbers, passwords, host information, and PINs.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸ’₯ Discordo: A lightweight, secure, and feature-rich Discord terminal (TUI) client made in Go.

GitHub: https://github.com/ayn2op/discordo/
πŸ”₯2
🚨πŸ‡ͺπŸ‡Έ Spanish Football Federation coaching academy data allegedly exposed

A forum actor claims to have accessed data tied to the Royal Spanish Football Federation’s coaching academy after discovering an allegedly misconfigured Firebase Storage bucket and Realtime Database.

The listing says 504 files totaling 182MB were publicly downloadable without authentication, while 113,681 authentication user IDs could be enumerated from the database. The actor says exposed files were linked to 16 users.

The allegedly exposed material includes front and back scans of Spanish DNI identity cards, profile photographs, invoices, personal images, course materials, administrative documents, training slides, screenshots, and a video.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
😭2πŸ”₯1
‼️ CVE-2026-23744: MCPJam Inspector RCE Exploit

GitHub: https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit

Features:

β–ͺ️Multi-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads.
β–ͺ️Command Execution: Execute commands on the target system with output capture.
β–ͺ️Target Scanning: Scan multiple targets with configurable rate limiting.
β–ͺ️Session Management: Persistent session management for ongoing testing.
β–ͺ️Proxy Support: Integrate with proxies for anonymous or routed traffic.
β–ͺ️Target Fingerprinting: Identify target system characteristics.
β–ͺ️Auto-listener Setup: Automatically configure listeners for reverse shells.
β€ΌοΈπŸ‡ΊπŸ‡Έ DragonForce Ransomware names 4 victims

πŸ‡ΊπŸ‡Έ Heritage Mechanical LLC - Maryland-based mechanical contractor providing commercial plumbing, HVAC, and steamfitting services.

πŸ‡ΊπŸ‡Έ Stephens Precision - Vermont-based precision manufacturer specializing in machined assemblies, components, and tooling.

πŸ‡ΊπŸ‡Έ Shillen MacKall & Seldon - Law firm representing personal injury clients across Vermont, New Hampshire, and Florida.

πŸ‡ΊπŸ‡Έ Hughes Atwood & Mullaly PLLC - New Hampshire-based full-service law firm serving individuals, businesses, and institutions.
To those asking what happened to my GitHub... I simply just made everything private over a week ago. I'm no longer interested in using the application in general.

However, I will be using a different tool so you can still enjoy everything I've come out with. Probably will be done this weekend, I just need to find time.

Attaching a screenshot just to show nothing is gone.
❀3
β€ΌοΈπŸ‡ΏπŸ‡¦ RansomHouse names 1 new victim

πŸ‡ΏπŸ‡¦ Fidelity Services Group - South African integrated security provider offering guarding, cash management, fire protection, and related services.
This media is not supported in your browser
VIEW IN TELEGRAM
Microsoft fixed an Age of Empires RCE from yesterday’s Patch Tuesday (CVE-2026-50663). Here is an example of how it was done.

Credit: https://x.com/rdjgr/status/2077331427549421918
πŸ”₯2
πŸš¨πŸ‡«πŸ‡· DELKO customer dataset allegedly compromised

A forum actor claims to have compromised an internal appointment-booking tool belonging to DELKO, a French vehicle repair and maintenance chain operating more than 160 garages across France.

The actor says information belonging to 450,092 customers was scraped from the system. A sample containing customer and vehicle records was published with the post.

The allegedly exposed information includes customer IDs, names, email addresses, phone numbers, vehicle registration numbers, account creation dates, appointment dates, service types, transaction amounts, and detailed descriptions of vehicle repairs or maintenance.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡· Argentine government portal credentials allegedly listed for sale

A forum actor claims to be selling a bundle of working login credentials for 21 government platforms across Argentina.

The seller describes the accounts as active and verified, claiming they provide access to restricted dashboards, administrative panels, internal communications, documents, notifications, workflows, and record-management functions. The credentials are said to have remained active for at least 30 days.

The advertised platforms include judicial, tax, vehicle registration, municipal, human resources, social security, and other government services.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 DarkMatter ransomware operation advertises affiliate program

A forum actor is advertising DarkMatter (not to be confused with one of the world's largest darknet markets), a newly introduced ransomware operation targeting small, medium, and large enterprises while claiming to exclude healthcare organizations and entities located in the CIS region.

The listing says CIS-based affiliates must pay a $250 entry fee, while non-CIS affiliates are charged $500 in Bitcoin or Monero. The operators are seeking a limited number of Russian-speaking partners and claim average affiliate payouts of approximately $70,000.

The advertised Windows ransomware supports multithreaded encryption, Active Directory integration, network propagation, credential dumping, security-tool disruption, event-log clearing, virtual machine detection, ESXi targeting, encrypted TOR-based victim portals, and configurable ransom notes. The operators also claim to provide custom builds, dedicated infrastructure, encrypted communications, and real-time reporting.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing