‼️🇺🇸 U.S. Bank has been claimed a victim to LockBit Ransomware
🇺🇸 U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.
The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
🇺🇸 U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.
The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
😁2
🚨 Blue Screen of Death decoy tool for RMM and HVNC operations released on a cybercrime forum
⠀
A forum user has released source code for a Windows tool called "BEFORE GOP", designed to display a fake Blue Screen of Death while an operator allegedly continues working through RMM or HVNC sessions in the background.
⠀
The advertised features include:
⠀
• Full-screen Blue Screen of Death decoy
• Approximately 7 minutes of operating time behind the decoy
• Designed for RMM and HVNC operations
• ScreenConnect and Datto environments specifically referenced
• Use of alternate desktops for background activity
• Keyboard and mouse input restrictions
• Native Windows API functionality
• C++ and Qt-based interface
• Source code provided
• Precompiled version reportedly included
• Runtime scan result advertised as 0/21 detections
• Scan-time result advertised as 0/36 detections
⠀
The developer says the project was originally intended as a private component of a larger tool but was released separately due to binary size constraints. The listing also teases a separate "GOP Rootkit" for a future release.
⠀
The developer's claims and the capabilities and detection results of the tool have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user has released source code for a Windows tool called "BEFORE GOP", designed to display a fake Blue Screen of Death while an operator allegedly continues working through RMM or HVNC sessions in the background.
⠀
The advertised features include:
⠀
• Full-screen Blue Screen of Death decoy
• Approximately 7 minutes of operating time behind the decoy
• Designed for RMM and HVNC operations
• ScreenConnect and Datto environments specifically referenced
• Use of alternate desktops for background activity
• Keyboard and mouse input restrictions
• Native Windows API functionality
• C++ and Qt-based interface
• Source code provided
• Precompiled version reportedly included
• Runtime scan result advertised as 0/21 detections
• Scan-time result advertised as 0/36 detections
⠀
The developer says the project was originally intended as a private component of a larger tool but was released separately due to binary size constraints. The listing also teases a separate "GOP Rootkit" for a future release.
⠀
The developer's claims and the capabilities and detection results of the tool have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A threat actor is offering for sale a 27.2 GB full dataset dump allegedly from Mendine Pharmaceuticals for $10K, containing numerous SQL tables covering sales, vouchers, receivables, customer, and account data.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
🚨🇧🇴 Instituto Técnico Los Ángeles principal account and student database access advertised on a cybercrime forum
⠀
A forum user claims to be selling access to a principal-level account belonging to Instituto Técnico Los Ángeles in Bolivia, providing administrative control over the institution's student management system.
⠀
The advertised access reportedly includes:
⠀
• Principal-level administrative access
• Student database access
• Personal student information
• Academic records
• Ability to modify student information
• Ability to change grades
• Degree and certificate issuance functions
• Enrollment and registration management
• Teacher administration
• Course and program management
• Access to institutional documents and statistics
⠀
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
⠀
The seller states that the access will only remain available while the compromised account continues to work.
⠀
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user claims to be selling access to a principal-level account belonging to Instituto Técnico Los Ángeles in Bolivia, providing administrative control over the institution's student management system.
⠀
The advertised access reportedly includes:
⠀
• Principal-level administrative access
• Student database access
• Personal student information
• Academic records
• Ability to modify student information
• Ability to change grades
• Degree and certificate issuance functions
• Enrollment and registration management
• Teacher administration
• Course and program management
• Access to institutional documents and statistics
⠀
A screenshot provided as proof of access shows the institution's administrative dashboard and a grade certificate management interface containing student records.
⠀
The seller states that the access will only remain available while the compromised account continues to work.
⠀
The claims and the authenticity, availability and scope of the advertised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Link: https://darkwebinformer.com/developer-sought-on-a-breach-forum-to-build-a-mexican-kyc-bot-capturing-id-scans-and-face-biometrics/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
A member posting as Cookiegen131 is recruiting a developer to build a Telegram based identity verification system for a stated Mexican telecom project.
‼️ New Darknet Market: KONTOR Marketplace
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
Operator claims 400 buyers which I find hard to believe since this was just announced.
Dark Web: http://kontorvn7xkfebifxy7c5jgtjclur6twtiuivl34wodfam7wmrmw5cyd[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/f6fc6038002a27d9876b
‼️Unverified Claim... Possible Police Sting Operation
🚨🇷🇴 A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
⠀
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
⠀
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
⠀
The user claims:
⠀
• A QR code was included with the shipment
• The QR code directed to a Signal account called "Flavour Man"
• The Signal contact allegedly attempted to recruit them for dead drops
• A subsequent package was delivered to a parcel locker
• Police were allegedly positioned around the pickup location
• Officers reportedly remained near the location for two days
• The package was eventually returned after going uncollected
• No payment was ever requested for the shipment
• The Signal account subsequently went offline
• RomanianPowder is currently shown as being on "vacation"
⠀
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
⠀
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇷🇴 A Darknet user warns /u/RomanianPowder may be compromised in alleged Romanian police operation
Dread Thread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/1bab89f8a3a2065b0c6e
⠀
A darknet forum user is warning customers of RomanianPowder, claiming the vendor may have been infiltrated, arrested, or cooperating with Romanian authorities.
⠀
According to the warning, an order allegedly arrived with a QR code directing the buyer to a Signal contact. The contact reportedly attempted to recruit the customer for local dead drops before offering to send another order directly at a cheaper price.
⠀
The user claims:
⠀
• A QR code was included with the shipment
• The QR code directed to a Signal account called "Flavour Man"
• The Signal contact allegedly attempted to recruit them for dead drops
• A subsequent package was delivered to a parcel locker
• Police were allegedly positioned around the pickup location
• Officers reportedly remained near the location for two days
• The package was eventually returned after going uncollected
• No payment was ever requested for the shipment
• The Signal account subsequently went offline
• RomanianPowder is currently shown as being on "vacation"
⠀
The warning urges other Romanian customers not to scan QR codes or communicate with contacts associated with the deliveries.
⠀
These allegations are based on an individual forum user's account and have not been independently verified. There is currently no confirmation that RomanianPowder is compromised or involved in a law enforcement operation.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇧🇷 Quero Namoro allegedly breached, 19K Brazilian users and 5 GB website backup leaked on a cybercrime forum
⠀
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
⠀
The advertised data includes:
⠀
• Names
• Email addresses
• Password-related fields
• Telephone and mobile numbers
• Dates of birth
• Gender information
• Cities and states
• Professions
• Monthly income information
• Physical address fields
• Postal codes
• Usernames
• Account and profile information
• User photographs
• Registration and account activity metadata
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum user claims to have released a full website backup belonging to Quero Namoro, a Brazilian dating platform, containing information associated with approximately 19,000 users. The listing describes the complete backup as roughly 5 GB.
⠀
The advertised data includes:
⠀
• Names
• Email addresses
• Password-related fields
• Telephone and mobile numbers
• Dates of birth
• Gender information
• Cities and states
• Professions
• Monthly income information
• Physical address fields
• Postal codes
• Usernames
• Account and profile information
• User photographs
• Registration and account activity metadata
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ The IRS is warning cryptocurrency holders about fake, official-looking letters being mailed to victims and directing them to a fraudulent “Digital Asset Compliance Portal.”
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a “Digital Asset Compliance Portal” and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
The letters contain a QR code that leads to a fake IRS website designed to collect sensitive information, potentially including personal details, wallet information, exchange credentials, and other account data.
The IRS says it does not operate a “Digital Asset Compliance Portal” and did not send these letters.
Coinbase and DarkTower reportedly traced infrastructure linked to the campaign to a recently registered domain hosted in Romania.
If you receive one of these letters, do not scan the QR code, visit the linked website, or provide any information.
🚨 Adornis GmbH source code allegedly leaked on a cybercrime forum
⠀
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
⠀
The allegedly leaked source code includes:
⠀
• Approximately 90 independent npm packages and modules
• TypeScript-based full-stack framework components
• Authentication and routing modules
• MongoDB integration
• BaseQL query layer
• MCP server functionality for AI agents
• AI and LLM integration modules
• CRM and CMS functionality
• Wiki, task and calendar modules
• Chat and collaboration features
• Expense reimbursement functionality
• Electronic signature support
• Survey and payment modules
• EBICS banking functionality
• Collaborative document editing
• TinyMCE and Monaco-based editing components
• Internationalization and translation support
• Caching and analytics modules
• Prometheus metrics integration
• Testing utilities
⠀
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
⠀
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have released the source code for Adornis Engine, an internal application framework associated with Adornis GmbH / NDI New Digital Intelligence. The project is described as a modular TypeScript monorepo used to build business web applications.
⠀
The allegedly leaked source code includes:
⠀
• Approximately 90 independent npm packages and modules
• TypeScript-based full-stack framework components
• Authentication and routing modules
• MongoDB integration
• BaseQL query layer
• MCP server functionality for AI agents
• AI and LLM integration modules
• CRM and CMS functionality
• Wiki, task and calendar modules
• Chat and collaboration features
• Expense reimbursement functionality
• Electronic signature support
• Survey and payment modules
• EBICS banking functionality
• Collaborative document editing
• TinyMCE and Monaco-based editing components
• Internationalization and translation support
• Caching and analytics modules
• Prometheus metrics integration
• Testing utilities
⠀
The listing describes Adornis Engine as an actively maintained internal framework used to rapidly build custom line-of-business applications.
⠀
The claims and the authenticity, source and completeness of the allegedly leaked code have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇳 University of Delhi database allegedly breached and advertised for sale on a cybercrime forum
⠀
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
⠀
The exposed sample includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Student or applicant identifiers
• Application and approval status
• Departments
• Academic programs and qualifications
• Registration or enrollment references
• Timestamps
• Profile and document image filenames
• University-hosted file and image references
⠀
The listing includes sample records associated with multiple university departments and academic programs.
⠀
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
⠀
A forum user claims that LidaBroker and DYSPHOR1A breached the University of Delhi and are now selling data allegedly obtained from university systems.
⠀
The exposed sample includes:
⠀
• Full names
• Email addresses
• Phone numbers
• Student or applicant identifiers
• Application and approval status
• Departments
• Academic programs and qualifications
• Registration or enrollment references
• Timestamps
• Profile and document image filenames
• University-hosted file and image references
⠀
The listing includes sample records associated with multiple university departments and academic programs.
⠀
The database is being advertised for $450, with the price stated as non-negotiable and middleman services accepted.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
DYSPHOR1A Ransomware:
https://x.com/DarkWebInformer/status/2090460630583017979
‼️ New Dark Web Informer Blog Post!
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
Link: https://darkwebinformer.com/wrappiness-customer-database-allegedly-offered-for-sale-with-3-million-order-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records
A forum user posting as Satanic is selling what they describe as the full database of Wrappiness.co, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains.
🚨🇹🇭🇮🇳🇸🇪🇫🇷🇺🇸 Five corporate network accesses advertised on a cybercrime forum
⠀
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
⠀
The advertised accesses include:
⠀
🇹🇭 Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
⠀
🇮🇳 India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
⠀
🇸🇪 Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
⠀
🇫🇷 France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
⠀
🇺🇸 United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
⠀
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum broker is advertising access to five organizations across Thailand, India, Sweden, France and the United States, spanning the education, software, food and beverage, and business services sectors.
⠀
The advertised accesses include:
⠀
🇹🇭 Thailand, Education: VPN access with Domain User privileges, approximately 250 hosts, 2,300 domain computers, 4 domain controllers, 5 MSSQL servers and Veeam infrastructure. Symantec, Trend Micro and Windows Defender are reportedly deployed. Revenue listed at approximately $6M.
⠀
🇮🇳 India, Education: VPN access with standard user privileges. Revenue listed at approximately $100M. Antivirus and EDR information is listed as unknown.
⠀
🇸🇪 Sweden, Software: Domain User access covering approximately 520 domain users, 350 domain computers, 3 domain controllers and an Entra ID environment. Windows Defender and Sophos Intercept X EDR are reportedly deployed. Revenue listed at approximately $25M.
⠀
🇫🇷 France, Food and Beverage: VPN access with user-level privileges, approximately 100 hosts and 2 domain controllers. Revenue listed at approximately $40M.
⠀
🇺🇸 United States, Business Services: VPN access with user-level privileges, approximately 120 hosts, 80 domain-joined machines, 4 domain controllers, 8 MSSQL servers and Veeam infrastructure. Revenue listed at approximately $10M.
⠀
The claims and the authenticity, availability and scope of the advertised corporate access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
Link: https://darkwebinformer.com/french-restaurant-platform-frenchinnov-allegedly-scraped-exposing-client-credentials-and-live-payment-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Restaurant Platform FrenchInnov Allegedly Scraped, Exposing Client Credentials and Live Payment Keys
A forum user posting as Alduin claims to have scraped the CRM behind frenchinnov.fr, a French platform that centralises restaurant operations including point of sale, stock, staff planning, loyalty and delivery platform integration.