πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.28K subscribers
779 photos
36 videos
721 links
Download Telegram
‼️ A forum actor advertises the sale of RDP and VPN access, offering to use a guarantor (escrow) for the transaction.

No specific victim organization or details are provided.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
β€ΌοΈπŸ‡ΊπŸ‡Έ A forum actor is offering for sale super_admin-level SSH access to a FortiGate device belonging to an unnamed US retail company with reported revenue of $453.5 million, covering 378 hosts.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
🚨 WP-Admin, cPanel, Plesk and WHM administrative access advertised for sale on a cybercrime forum
β €
A forum seller is advertising compromised administrative access to websites and hosting control panels, claiming the credentials are valid and provide full administrator privileges.
β €
The advertised access includes:
β €
β€’ WordPress administrator accounts with plugin installation privileges
β€’ cPanel accounts with verified panel access and no 2FA
β€’ Plesk accounts with verified panel access and no 2FA
β€’ WHM accounts with verified panel access and no 2FA
β€’ Login credentials included with each access
β €
Pricing is advertised at $1 per WordPress admin, $3 per cPanel account, $3 per Plesk account and $25 per WHM account. The listing requires a $200 minimum purchase, with escrow available at the buyer's expense.
β €
The seller states that website characteristics, domains and SEO metrics have not been pre-screened.
β €
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 EliteCrypt malware crypter and loader advertised on a cybercrime forum with Windows security bypass claims
β €
A forum seller is advertising EliteCrypt, a malware crypter and loader service designed to conceal malicious payloads and bypass Windows security controls during both scan-time and runtime execution.
β €
The advertised features include:
β €
β€’ Windows Defender 10/11 bypass
β€’ Microsoft SmartScreen bypass
β€’ Chrome security bypass claims
β€’ UAC bypass
β€’ Scan-time and runtime evasion
β€’ Support for stealers, RATs and cryptocurrency miners
β€’ Compatibility with Vidar, WebRAT, DCRat, HVNC, Stealc and other payloads
β€’ Native x64, x86 and .NET support
β€’ C-based loader stub
β€’ Unique builds rather than a shared static stub
β€’ DLL sideloading functionality
β€’ .LNK payload delivery
β€’ Ability to disguise .LNK loaders as PDF, DOCX, TXT and XLSX files
β €
Pricing is advertised at $37 for the standard crypt, $75 for DLL sideloading and $80 for the .LNK loader.
β €
The seller's claims and the capabilities of the tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1😁1
🚨 Bugatti Cloud credential log distribution service advertised on a cybercrime forum
β €
A forum user is promoting Bugatti Cloud, a service distributing credential logs and other compromised data. The operator claims the project has attracted more than 2,000 users and has published over 1 million logs since launching.
β €
The advertised features include:
β €
β€’ More than 1 million previously published logs
β€’ 10+ GB of new material reportedly added each week
β€’ Logs collected from multiple sources
β€’ SEO-related logs
β€’ YouTube-related logs
β€’ Cryptocurrency exchange-related logs
β€’ Access to downloadable log archives
β€’ Extended exports and "HQ combo" datasets
β€’ Community access and active support
β€’ Private access through Bugatti Private Cloud
β€’ Exclusive material reportedly added every 2 days
β€’ Personalized support and potential collaboration opportunities
β €
The operator's claims and the authenticity, source and scope of the advertised logs have not been independently verified.
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Kriminal AI: "The AI That Answers Everything"

https://kriminal[.]ai
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
❀4πŸ”₯2
XSS is having domain problems again. 🀑
😭4
The fake X account claiming to be the Grand Theft Auto 6 leakers was just suspended by X.

x.com/cyberleek_ar_io
😭2❀1
πŸš¨πŸ‡«πŸ‡· Alaxione allegedly breached, 6.8M patient records and 10.1M appointment records advertised on a cybercrime forum
β €
A forum actor claims to have breached Alaxione, a French e-health company, and extracted approximately 12.8 GB of data spanning more than 18 million records. The listing claims the compromised data includes 6,835,489 patient/user records and 10,145,988 appointment records.
β €
The advertised data includes:
β €
β€’ First and last names
β€’ Email and billing email addresses
β€’ Phone and fax numbers
β€’ Dates of birth
β€’ Gender information
β€’ Physical addresses and postal codes
β€’ Cities and professions
β€’ Account identifiers and user roles
β€’ Healthcare practitioner information
β€’ Insurance and healthcare-related fields
β€’ Appointment dates and times
β€’ Patient and practitioner identifiers
β€’ Appointment locations and statuses
β€’ Appointment reasons and results
β€’ Waiting-time information
β€’ Discussion and messaging records
β€’ Internal application and account metadata
β €
The listing also references two discussion datasets containing approximately 144,310 and 129,729 records, along with additional practitioner-related information. Samples from multiple datasets were published directly in the thread.
β €
The data is being offered for $5,000 without exclusivity, with a higher price requested for an exclusive sale.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸ”₯1
More shiity OpSec...

🚨 Investigators may have left the Coldcard Wave 1 hacker with nowhere to hide

The attacker behind the largest wave of the Coldcard Bitcoin theft allegedly used a paid account at a major blockchain data provider while preparing and carrying out the drains.

Block investigators found that the provider’s internal logs closely matched the number, timing, and sequence of queries associated with the theft. Information connected to the account was then provided to law enforcement.

Wave 1 drained 1,082.65 BTC from vulnerable wallets in just 41 minutes. The stolen Bitcoin remains largely unmoved.

Galaxy Research’s Alex Thorn says the Wave 1 attacker’s identity β€œmay be known to law enforcement,” although the FBI has not publicly confirmed identifying, arresting, or charging anyone.

The theft exploited weak wallet seeds generated by affected Coldcard firmware after a 2021 random-number generation flaw reduced their effective entropy.

Multiple attack waves have since pushed confirmed losses beyond 1,700 BTC.

The blockchain may be public, but apparently the hacker’s API bill was too.

Source: https://bitcoinmagazine.com/technical/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi
😁1😈1
‼️ ShinyHunters claims an unknown victim named Cyrus******
‼️ New Ransomware Group: DYSPHOR1A

Clearnet: https://normalhunters0x[.]surge[.]sh

Dark Web: http://y3maveiwszbnrziufbbberx74cvrdcsf72nxzuqxzv7ppdmmqzffazid[.]onion
β€ΌοΈπŸ‡ΊπŸ‡Έ U.S. Bank has been claimed a victim to LockBit Ransomware

πŸ‡ΊπŸ‡Έ U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.

The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
😁2
🚨 Blue Screen of Death decoy tool for RMM and HVNC operations released on a cybercrime forum
β €
A forum user has released source code for a Windows tool called "BEFORE GOP", designed to display a fake Blue Screen of Death while an operator allegedly continues working through RMM or HVNC sessions in the background.
β €
The advertised features include:
β €
β€’ Full-screen Blue Screen of Death decoy
β€’ Approximately 7 minutes of operating time behind the decoy
β€’ Designed for RMM and HVNC operations
β€’ ScreenConnect and Datto environments specifically referenced
β€’ Use of alternate desktops for background activity
β€’ Keyboard and mouse input restrictions
β€’ Native Windows API functionality
β€’ C++ and Qt-based interface
β€’ Source code provided
β€’ Precompiled version reportedly included
β€’ Runtime scan result advertised as 0/21 detections
β€’ Scan-time result advertised as 0/36 detections
β €
The developer says the project was originally intended as a private component of a larger tool but was released separately due to binary size constraints. The listing also teases a separate "GOP Rootkit" for a future release.
β €
The developer's claims and the capabilities and detection results of the tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A threat actor is offering for sale a 27.2 GB full dataset dump allegedly from Mendine Pharmaceuticals for $10K, containing numerous SQL tables covering sales, vouchers, receivables, customer, and account data.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
πŸš¨πŸ‡§πŸ‡΄ Instituto TΓ©cnico Los Ángeles principal account and student database access advertised on a cybercrime forum
β €
A forum user claims to be selling access to a principal-level account belonging to Instituto Técnico Los Ángeles in Bolivia, providing administrative control over the institution's student management system.
β €
The advertised access reportedly includes:
β €
β€’ Principal-level administrative access
β€’ Student database access
β€’ Personal student information
β€’ Academic records
β€’ Ability to modify student information
β€’ Ability to change grades
β€’ Degree and certificate issuance functions
β€’ Enrollment and registration management
β€’ Teacher administration
β€’ Course and program management
β€’ Access to institutional documents and statistics
β €
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
β €
The seller states that the access will only remain available while the compromised account continues to work.
β €
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Darknet Market: KONTOR Marketplace

Operator claims 400 buyers which I find hard to believe since this was just announced.

Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b