π¨π²π½ Veracruz citizen assistance system database allegedly leaked
A forum actor claims to have leaked data from Veracruzβs Sistema Institucional de AtenciΓ³n Ciudadana, including registered user accounts and citizen reports submitted between 2024 and 2026.
The post advertises more than 170,000 reports containing names, email addresses, phone numbers, user roles, report identifiers, case statuses, assigned departments, submission methods, timestamps, internal user IDs, staff details, and descriptions of reported incidents.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked data from Veracruzβs Sistema Institucional de AtenciΓ³n Ciudadana, including registered user accounts and citizen reports submitted between 2024 and 2026.
The post advertises more than 170,000 reports containing names, email addresses, phone numbers, user roles, report identifiers, case statuses, assigned departments, submission methods, timestamps, internal user IDs, staff details, and descriptions of reported incidents.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π²π½ FUCAM cancer hospital patient records allegedly leaked
A forum actor claims to have leaked a database belonging to FundaciΓ³n de CΓ‘ncer de Mama, a Mexican healthcare organization specializing in breast cancer detection, diagnosis, and treatment. The post advertises more than 200,000 hospital and patient study records.
Published samples allegedly contain patient names, identification numbers, ages, dates of birth, examination and medical record identifiers, procedures, imaging modalities, service locations, appointment statuses, email addresses, phone numbers, internal usernames, system IP addresses, and other clinical and administrative data.
The actor also claims recent records, photographs, and hospital access are available upon request.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked a database belonging to FundaciΓ³n de CΓ‘ncer de Mama, a Mexican healthcare organization specializing in breast cancer detection, diagnosis, and treatment. The post advertises more than 200,000 hospital and patient study records.
Published samples allegedly contain patient names, identification numbers, ages, dates of birth, examination and medical record identifiers, procedures, imaging modalities, service locations, appointment statuses, email addresses, phone numbers, internal usernames, system IP addresses, and other clinical and administrative data.
The actor also claims recent records, photographs, and hospital access are available upon request.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
βΌοΈ New Dark Web Informer Blog Post!
Title: Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access
Link: https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access
Link: https://darkwebinformer.com/hungarian-state-treasury-allegedly-compromised-actor-claims-vcenter-and-identity-vault-access/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Hungarian State Treasury Allegedly Compromised, Actor Claims vCenter and Identity Vault Access
A threat actor posting as bytetobreach claims to have compromised the Magyar ΓllamkincstΓ‘r, Hungary's State Treasury, which administers state payments, pensions, family benefits, and EU funding.
π¨π²π½ Hospital MΓ©xico Americano patient database and CT scans allegedly leaked
A forum actor claims to have compromised Hospital MΓ©xico Americano and published a 9.1GB collection containing its patient database and medical imaging files, including CT scans.
The exposed data allegedly includes patient names, identifiers, sex, dates of birth, ages, study identifiers, accession numbers, examination descriptions, study timestamps, and associated diagnostic images.
A sample of the CT scan data was also posted.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have compromised Hospital MΓ©xico Americano and published a 9.1GB collection containing its patient database and medical imaging files, including CT scans.
The exposed data allegedly includes patient names, identifiers, sex, dates of birth, ages, study identifiers, accession numbers, examination descriptions, study timestamps, and associated diagnostic images.
A sample of the CT scan data was also posted.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
βΌοΈ New Dark Web Informer Blog Post!
Title: Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed Through HR Assessment Vendor
Link: https://darkwebinformer.com/baltas-online-allegedly-breached-750-turkish-companies-exposed-through-hr-assessment-vendor/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed Through HR Assessment Vendor
Link: https://darkwebinformer.com/baltas-online-allegedly-breached-750-turkish-companies-exposed-through-hr-assessment-vendor/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed Through HR Assessment Vendor
An actor posting as WInQ7wk9sA3a claims to have held root access for 47 days to Baltas Online, a Turkish HR and assessment firm, and exfiltrated a 500GB+ archive covering more than 750 corporate clients.
βΌοΈ New Dark Web Informer Blog Post!
Title: Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked With One-Week Ultimatum
Link: https://darkwebinformer.com/bacoor-city-government-allegedly-breached-57-000-business-permit-records-leaked-with-one-week-ultimatum/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked With One-Week Ultimatum
Link: https://darkwebinformer.com/bacoor-city-government-allegedly-breached-57-000-business-permit-records-leaked-with-one-week-ultimatum/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked With One-Week Ultimatum
An actor posting as dopePanda claims to have compromised the business permit database of the Bacoor City Government in Cavite, Philippines, releasing what they describe as more than 57,000 records covering permits, owner names, addresses, and phone numbers.
π¨π«π· Shokz customer records allegedly offered for sale
A forum actor claims to be selling 48,284 records associated with Shokz, a consumer electronics company known for its open-ear headphones. The listing is dated July 30, 2026, and appears to involve customers of the companyβs French online store.
The data allegedly includes first and last names, street addresses, cities, postal codes, countries, phone numbers, and email addresses.
The dataset is priced at $120, with the seller claiming it will only be sold once.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling 48,284 records associated with Shokz, a consumer electronics company known for its open-ear headphones. The listing is dated July 30, 2026, and appears to involve customers of the companyβs French online store.
The data allegedly includes first and last names, street addresses, cities, postal codes, countries, phone numbers, and email addresses.
The dataset is priced at $120, with the seller claiming it will only be sold once.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π΅π Cebu Pacific customer database allegedly offered for sale
A forum actor claims to be selling 2,539,804 records associated with Cebu Pacific, a Philippine low-cost airline. The listing states the data is dated July 17, 2026, and is being offered to a single buyer for $499.
The data allegedly includes customer and record identifiers, home addresses, cities, postal codes, countries, email addresses, phone and fax numbers, business numbers, SMS preference fields, and emergency contact names, relationships, area codes, and phone numbers.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling 2,539,804 records associated with Cebu Pacific, a Philippine low-cost airline. The listing states the data is dated July 17, 2026, and is being offered to a single buyer for $499.
The data allegedly includes customer and record identifiers, home addresses, cities, postal codes, countries, email addresses, phone and fax numbers, business numbers, SMS preference fields, and emergency contact names, relationships, area codes, and phone numbers.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π¨π¦ Qtrade Direct Investing customer records allegedly offered for sale
A forum actor claims to be selling 152,284 records associated with Qtrade Direct Investing, a Canadian online investment and brokerage platform. The listing states the data is dated July 25, 2026, and is being offered to a single buyer for $300.
The data allegedly includes email addresses, first and last names, home addresses, cities, provinces or states, postal codes, phone numbers, gender, lead-check information, and internal user-type classifications.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling 152,284 records associated with Qtrade Direct Investing, a Canadian online investment and brokerage platform. The listing states the data is dated July 25, 2026, and is being offered to a single buyer for $300.
The data allegedly includes email addresses, first and last names, home addresses, cities, provinces or states, postal codes, phone numbers, gender, lead-check information, and internal user-type classifications.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π«π· Linxea customer records allegedly offered for sale
A forum actor claims to be selling 384,804 records associated with Linxea, a French online savings, investment, and wealth management platform. The listing states the data is dated July 29, 2026, and is being offered to a single buyer for $380.
The data allegedly includes first and last names, full names, email addresses, street addresses, postal codes, cities, phone numbers, gender, dates of birth, anonymous account identifiers, and tax residency information.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling 384,804 records associated with Linxea, a French online savings, investment, and wealth management platform. The listing states the data is dated July 29, 2026, and is being offered to a single buyer for $380.
The data allegedly includes first and last names, full names, email addresses, street addresses, postal codes, cities, phone numbers, gender, dates of birth, anonymous account identifiers, and tax residency information.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨πΊπΈ Landa user records allegedly offered for sale
A forum actor claims to be selling 82,697 records associated with Landa, a US real estate investing platform. The listing states the data is dated July 27, 2026, and is being offered to a single buyer for $300.
The data allegedly includes names, email addresses, phone numbers, user identifiers, account verification status, verification codes, roles, currency and account-type fields, timestamps, categories, and card number fields.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling 82,697 records associated with Landa, a US real estate investing platform. The listing states the data is dated July 27, 2026, and is being offered to a single buyer for $300.
The data allegedly includes names, email addresses, phone numbers, user identifiers, account verification status, verification codes, roles, currency and account-type fields, timestamps, categories, and card number fields.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
βΌοΈ New Dark Web Informer Blog Post!
Title: Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals
Link: https://darkwebinformer.com/buyer-solicits-corporate-network-access-to-350m-western-firms-excluding-cis-schools-and-hospitals/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals
Link: https://darkwebinformer.com/buyer-solicits-corporate-network-access-to-350m-western-firms-excluding-cis-schools-and-hospitals/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals
A buyer posting as umbreon is advertising to purchase corporate network access on flat-rate terms, setting out unusually specific selection criteria.
π¨ A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
βΌοΈπ¬π§πΊπΈ DragonForce ransomware claims 2 victims
π¬π§ Lamont Pridmore - A UK-based chartered accountancy firm providing accounting, tax, audit, and business advisory services.
πΊπΈ Moore Bradley Myers (MBM Law) - A South Carolina law firm representing individuals, families, and businesses across a range of legal matters.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¬π§ Lamont Pridmore - A UK-based chartered accountancy firm providing accounting, tax, audit, and business advisory services.
πΊπΈ Moore Bradley Myers (MBM Law) - A South Carolina law firm representing individuals, families, and businesses across a range of legal matters.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
β€1
π¨πΊπΈ Genesis Ransomware claims an undisclosed healthcare company
A U.S.-based healthcare provider storing data from more than 20 medical facilities.
The claimed leak includes over 1 TB of healthcare and personal data, patient lists, clinic records, accounting and operational data, network user folders, and fileserver data.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A U.S.-based healthcare provider storing data from more than 20 medical facilities.
The claimed leak includes over 1 TB of healthcare and personal data, patient lists, clinic records, accounting and operational data, network user folders, and fileserver data.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨πΊπΈ Cl0p Ransomware claims a capital management company. They also announced new email addresses.
πΊπΈ Blue Vista Capital Management - A Chicago-based real estate investment firm providing equity and credit investment strategies across U.S. and Canadian property markets.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πΊπΈ Blue Vista Capital Management - A Chicago-based real estate investment firm providing equity and credit investment strategies across U.S. and Canadian property markets.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ Remus information-stealing malware offered as a service
A forum seller is advertising Remus, a malware-as-a-service stealer promoted with 24/7 support, an easy-to-use control panel, configurable builds, automated log processing, Telegram integration, and a claimed callback rate of up to 90%.
The seller claims Remus can collect:
β’ Data from 21 browsers, 16 cold wallets, and 38 applications
β’ Credentials, cookies, autofill data, browser history, saved notes, and payment card numbers with CVVs
β’ Cryptocurrency seed phrases, private keys, wallet files, and MetaMask data
β’ Data from 181 Chromium wallet extensions, 43 password managers, 11 note extensions, and 13 two-factor authentication extensions
β’ Data from 42 Mozilla wallet extensions, 22 password managers, and four authentication extensions
β’ Files from selected folders using configurable paths, masks, depth limits, exclusions, and maximum file sizes
The management panel reportedly includes:
β’ Full and incomplete log scoring with detailed statistics
β’ Search filters for cookies, passwords, browser history, and other collected data
β’ AND/OR search conditions and preconfigured filters for different targeting categories
β’ Instant browser-based log viewing without downloading the archive
β’ Unlimited log exports and simultaneous download tasks
β’ Per-build statistics pages and configurable collection rules
β’ Telegram alerts, bots, loaders, and callback notifications
β’ Support for operator-controlled collection servers deployed through Docker
The malware is reportedly written in C++ and uses:
β’ System calls and a custom communication protocol
β’ Encrypted configurations and encrypted data transmission
β’ Compressed logs, caching, backup servers, and microservice infrastructure
β’ Build obfuscation and a small executable footprint
β’ Claimed EDR bypass capabilities
β’ Claimed detection of virtual machines, honeypots, and dedicated analysis servers
β’ A claimed automated MetaMask wallet brute-force feature
Pricing is advertised at:
β’ Base: $250 per month
β’ Pro: $500 per month
β’ Enterprise: $1,000 per month
Higher-priced plans reportedly add more builds, filters, Telegram bots, loaders, concurrent exports, team accounts, worker dashboards, API access, granular permissions, and DLL, PowerShell, or in-memory execution options.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum seller is advertising Remus, a malware-as-a-service stealer promoted with 24/7 support, an easy-to-use control panel, configurable builds, automated log processing, Telegram integration, and a claimed callback rate of up to 90%.
The seller claims Remus can collect:
β’ Data from 21 browsers, 16 cold wallets, and 38 applications
β’ Credentials, cookies, autofill data, browser history, saved notes, and payment card numbers with CVVs
β’ Cryptocurrency seed phrases, private keys, wallet files, and MetaMask data
β’ Data from 181 Chromium wallet extensions, 43 password managers, 11 note extensions, and 13 two-factor authentication extensions
β’ Data from 42 Mozilla wallet extensions, 22 password managers, and four authentication extensions
β’ Files from selected folders using configurable paths, masks, depth limits, exclusions, and maximum file sizes
The management panel reportedly includes:
β’ Full and incomplete log scoring with detailed statistics
β’ Search filters for cookies, passwords, browser history, and other collected data
β’ AND/OR search conditions and preconfigured filters for different targeting categories
β’ Instant browser-based log viewing without downloading the archive
β’ Unlimited log exports and simultaneous download tasks
β’ Per-build statistics pages and configurable collection rules
β’ Telegram alerts, bots, loaders, and callback notifications
β’ Support for operator-controlled collection servers deployed through Docker
The malware is reportedly written in C++ and uses:
β’ System calls and a custom communication protocol
β’ Encrypted configurations and encrypted data transmission
β’ Compressed logs, caching, backup servers, and microservice infrastructure
β’ Build obfuscation and a small executable footprint
β’ Claimed EDR bypass capabilities
β’ Claimed detection of virtual machines, honeypots, and dedicated analysis servers
β’ A claimed automated MetaMask wallet brute-force feature
Pricing is advertised at:
β’ Base: $250 per month
β’ Pro: $500 per month
β’ Enterprise: $1,000 per month
Higher-priced plans reportedly add more builds, filters, Telegram bots, loaders, concurrent exports, team accounts, worker dashboards, API access, granular permissions, and DLL, PowerShell, or in-memory execution options.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
β€1