More shiity OpSec...
🚨 Investigators may have left the Coldcard Wave 1 hacker with nowhere to hide
The attacker behind the largest wave of the Coldcard Bitcoin theft allegedly used a paid account at a major blockchain data provider while preparing and carrying out the drains.
Block investigators found that the provider’s internal logs closely matched the number, timing, and sequence of queries associated with the theft. Information connected to the account was then provided to law enforcement.
Wave 1 drained 1,082.65 BTC from vulnerable wallets in just 41 minutes. The stolen Bitcoin remains largely unmoved.
Galaxy Research’s Alex Thorn says the Wave 1 attacker’s identity “may be known to law enforcement,” although the FBI has not publicly confirmed identifying, arresting, or charging anyone.
The theft exploited weak wallet seeds generated by affected Coldcard firmware after a 2021 random-number generation flaw reduced their effective entropy.
Multiple attack waves have since pushed confirmed losses beyond 1,700 BTC.
The blockchain may be public, but apparently the hacker’s API bill was too.
Source: https://bitcoinmagazine.com/technical/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi
🚨 Investigators may have left the Coldcard Wave 1 hacker with nowhere to hide
The attacker behind the largest wave of the Coldcard Bitcoin theft allegedly used a paid account at a major blockchain data provider while preparing and carrying out the drains.
Block investigators found that the provider’s internal logs closely matched the number, timing, and sequence of queries associated with the theft. Information connected to the account was then provided to law enforcement.
Wave 1 drained 1,082.65 BTC from vulnerable wallets in just 41 minutes. The stolen Bitcoin remains largely unmoved.
Galaxy Research’s Alex Thorn says the Wave 1 attacker’s identity “may be known to law enforcement,” although the FBI has not publicly confirmed identifying, arresting, or charging anyone.
The theft exploited weak wallet seeds generated by affected Coldcard firmware after a 2021 random-number generation flaw reduced their effective entropy.
Multiple attack waves have since pushed confirmed losses beyond 1,700 BTC.
The blockchain may be public, but apparently the hacker’s API bill was too.
Source: https://bitcoinmagazine.com/technical/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi
Bitcoin Magazine
The Coldcard Hacker Left A Paper Trail That May Already Be In Law Enforcement Hands
Shared GPG keys, matching patterns, and a bug that produced exactly the outcome Coinkite once warned about. The public record is thin—but not empty.
😁1😈1
‼️🇺🇸 U.S. Bank has been claimed a victim to LockBit Ransomware
🇺🇸 U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.
The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
🇺🇸 U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.
The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
😁2
🚨 Blue Screen of Death decoy tool for RMM and HVNC operations released on a cybercrime forum
⠀
A forum user has released source code for a Windows tool called "BEFORE GOP", designed to display a fake Blue Screen of Death while an operator allegedly continues working through RMM or HVNC sessions in the background.
⠀
The advertised features include:
⠀
• Full-screen Blue Screen of Death decoy
• Approximately 7 minutes of operating time behind the decoy
• Designed for RMM and HVNC operations
• ScreenConnect and Datto environments specifically referenced
• Use of alternate desktops for background activity
• Keyboard and mouse input restrictions
• Native Windows API functionality
• C++ and Qt-based interface
• Source code provided
• Precompiled version reportedly included
• Runtime scan result advertised as 0/21 detections
• Scan-time result advertised as 0/36 detections
⠀
The developer says the project was originally intended as a private component of a larger tool but was released separately due to binary size constraints. The listing also teases a separate "GOP Rootkit" for a future release.
⠀
The developer's claims and the capabilities and detection results of the tool have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user has released source code for a Windows tool called "BEFORE GOP", designed to display a fake Blue Screen of Death while an operator allegedly continues working through RMM or HVNC sessions in the background.
⠀
The advertised features include:
⠀
• Full-screen Blue Screen of Death decoy
• Approximately 7 minutes of operating time behind the decoy
• Designed for RMM and HVNC operations
• ScreenConnect and Datto environments specifically referenced
• Use of alternate desktops for background activity
• Keyboard and mouse input restrictions
• Native Windows API functionality
• C++ and Qt-based interface
• Source code provided
• Precompiled version reportedly included
• Runtime scan result advertised as 0/21 detections
• Scan-time result advertised as 0/36 detections
⠀
The developer says the project was originally intended as a private component of a larger tool but was released separately due to binary size constraints. The listing also teases a separate "GOP Rootkit" for a future release.
⠀
The developer's claims and the capabilities and detection results of the tool have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A threat actor is offering for sale a 27.2 GB full dataset dump allegedly from Mendine Pharmaceuticals for $10K, containing numerous SQL tables covering sales, vouchers, receivables, customer, and account data.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇧🇴 Instituto Técnico Los Ángeles principal account and student database access advertised on a cybercrime forum
⠀
A forum user claims to be selling access to a principal-level account belonging to Instituto Técnico Los Ángeles in Bolivia, providing administrative control over the institution's student management system.
⠀
The advertised access reportedly includes:
⠀
• Principal-level administrative access
• Student database access
• Personal student information
• Academic records
• Ability to modify student information
• Ability to change grades
• Degree and certificate issuance functions
• Enrollment and registration management
• Teacher administration
• Course and program management
• Access to institutional documents and statistics
⠀
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
⠀
The seller states that the access will only remain available while the compromised account continues to work.
⠀
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user claims to be selling access to a principal-level account belonging to Instituto Técnico Los Ángeles in Bolivia, providing administrative control over the institution's student management system.
⠀
The advertised access reportedly includes:
⠀
• Principal-level administrative access
• Student database access
• Personal student information
• Academic records
• Ability to modify student information
• Ability to change grades
• Degree and certificate issuance functions
• Enrollment and registration management
• Teacher administration
• Course and program management
• Access to institutional documents and statistics
⠀
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
⠀
The seller states that the access will only remain available while the compromised account continues to work.
⠀
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
A member posting as Cookiegen131 is recruiting a developer to build a Telegram based identity verification system for a stated Mexican telecom project.
‼️ New Darknet Market: KONTOR Marketplace
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
‼️Unverified Claim... Possible Police Sting Operation
🚨🇷🇴 A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
⠀
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
⠀
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
⠀
The user claims:
⠀
• A QR code was included with the shipment
• The QR code directed to a Signal account called "Flavour Man"
• The Signal contact allegedly attempted to recruit them for dead drops
• A subsequent package was delivered to a parcel locker
• Police were allegedly positioned around the pickup location
• Officers reportedly remained near the location for two days
• The package was eventually returned after going uncollected
• No payment was ever requested for the shipment
• The Signal account subsequently went offline
• RomanianPowder is currently shown as being on "vacation"
⠀
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
⠀
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇷🇴 A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
⠀
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
⠀
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
⠀
The user claims:
⠀
• A QR code was included with the shipment
• The QR code directed to a Signal account called "Flavour Man"
• The Signal contact allegedly attempted to recruit them for dead drops
• A subsequent package was delivered to a parcel locker
• Police were allegedly positioned around the pickup location
• Officers reportedly remained near the location for two days
• The package was eventually returned after going uncollected
• No payment was ever requested for the shipment
• The Signal account subsequently went offline
• RomanianPowder is currently shown as being on "vacation"
⠀
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
⠀
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Quero Namoro allegedly breached, 19K Brazilian users and 5 GB website backup leaked on a cybercrime forum
⠀
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
⠀
The advertised data includes:
⠀
• Names
• Email addresses
• Password-related fields
• Telephone and mobile numbers
• Dates of birth
• Gender information
• Cities and states
• Professions
• Monthly income information
• Physical address fields
• Postal codes
• Usernames
• Account and profile information
• User photographs
• Registration and account activity metadata
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
⠀
The advertised data includes:
⠀
• Names
• Email addresses
• Password-related fields
• Telephone and mobile numbers
• Dates of birth
• Gender information
• Cities and states
• Professions
• Monthly income information
• Physical address fields
• Postal codes
• Usernames
• Account and profile information
• User photographs
• Registration and account activity metadata
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ The IRS is warning cryptocurrency holders about fake, official-looking letters being mailed to victims and directing them to a fraudulent “Digital Asset Compliance Portal.”
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a “Digital Asset Compliance Portal” and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a “Digital Asset Compliance Portal” and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
🚨 Adornis GmbH source code allegedly leaked on a cybercrime forum
⠀
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
⠀
The allegedly leaked source code includes:
⠀
• Approximately 90 independent npm packages and modules
• TypeScript-based full-stack framework components
• Authentication and routing modules
• MongoDB integration
• BaseQL query layer
• MCP server functionality for AI agents
• AI and LLM integration modules
• CRM and CMS functionality
• Wiki, task and calendar modules
• Chat and collaboration features
• Expense reimbursement functionality
• Electronic signature support
• Survey and payment modules
• EBICS banking functionality
• Collaborative document editing
• TinyMCE and Monaco-based editing components
• Internationalization and translation support
• Caching and analytics modules
• Prometheus metrics integration
• Testing utilities
⠀
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
⠀
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
⠀
The allegedly leaked source code includes:
⠀
• Approximately 90 independent npm packages and modules
• TypeScript-based full-stack framework components
• Authentication and routing modules
• MongoDB integration
• BaseQL query layer
• MCP server functionality for AI agents
• AI and LLM integration modules
• CRM and CMS functionality
• Wiki, task and calendar modules
• Chat and collaboration features
• Expense reimbursement functionality
• Electronic signature support
• Survey and payment modules
• EBICS banking functionality
• Collaborative document editing
• TinyMCE and Monaco-based editing components
• Internationalization and translation support
• Caching and analytics modules
• Prometheus metrics integration
• Testing utilities
⠀
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
⠀
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇳 University of Delhi database allegedly breached and advertised for sale on a cybercrime forum
⠀
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
⠀
The exposed sample includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Student or applicant identifiers
• Application and approval status
• Departments
• Academic programs and qualifications
• Registration or enrollment references
• Timestamps
• Profile and document image filenames
• University-hosted file and image references
⠀
The listing includes sample records associated with multiple university departments and academic programs.
⠀
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
⠀
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
⠀
The exposed sample includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Student or applicant identifiers
• Application and approval status
• Departments
• Academic programs and qualifications
• Registration or enrollment references
• Timestamps
• Profile and document image filenames
• University-hosted file and image references
⠀
The listing includes sample records associated with multiple university departments and academic programs.
⠀
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
‼️ New Dark Web Informer Blog Post!
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
A forum user posting as Satanic is selling what they describe as the full database of Wrappiness.co, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains.
🚨🇹🇭🇮🇳🇸🇪🇫🇷🇺🇸 Five corporate network accesses advertised on a cybercrime forum
⠀
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
⠀
The advertised accesses include:
⠀
🇹🇭 Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
⠀
🇮🇳 India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
⠀
🇸🇪 Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
⠀
🇫🇷 France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
⠀
🇺🇸 United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
⠀
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
⠀
The advertised accesses include:
⠀
🇹🇭 Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
⠀
🇮🇳 India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
⠀
🇸🇪 Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
⠀
🇫🇷 France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
⠀
🇺🇸 United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
⠀
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing