πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.96K subscribers
1.23K photos
68 videos
1.09K links
Download Telegram
🚨 Healthcare sector database allegedly for sale on a cybercrime forum, 1.3M+ users claimed
β €
A cybercrime forum user is advertising what they claim is a database belonging to a healthcare sector company containing information on more than 1.3 million users worldwide. The seller claims the dataset contains customer and contact-related records.
β €
The advertised data includes:
β €
β€’ Names
β€’ Email addresses
β€’ Phone numbers
β€’ Mobile and home phone information
β€’ Physical addresses
β€’ Dates of birth
β€’ Gender information
β€’ Account identifiers
β€’ Contact records
β€’ Healthcare-related account fields
β€’ Medical record numbers
β€’ Customer service information
β€’ Communication preferences
β€’ Account activity data
β€’ Internal Salesforce-related fields
β€’ Additional profile and demographic information
β €
The seller claims the database contains a large number of structured records and is offering a single copy for $2,000.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€ΌοΈπŸ‡«πŸ‡· A forum post shares login credentials and access window details for the member portal of Ordre National Infirmiers, a French nursing professional order.

The post includes a username, password, and login time window.
🚨 Cryptocurrency wallet drainer source code allegedly advertised on a cybercrime forum for $6,500
β €
A cybercrime forum user is advertising what they claim is the source code for an all-in-one cryptocurrency wallet drainer and monitoring platform named Nexus Core Vortex. The seller claims the tool includes automated withdrawal capabilities, address monitoring and support for multiple blockchain networks.
β €
The advertised features include:
β €
β€’ Cryptocurrency wallet draining functionality
β€’ Automated monitoring of blockchain addresses
β€’ Seed phrase and private key processing
β€’ Automated withdrawal systems
β€’ Support for Bitcoin, Litecoin, Bitcoin Cash, Dogecoin and Zcash
β€’ EVM network support across multiple chains
β€’ Support for seed phrase formats including BIP39
β€’ Telegram notifications and management features
β€’ Transaction monitoring and logging
β€’ Proxy rotation support
β€’ Custom derivation rules
β€’ API access
β€’ Administrative dashboard
β€’ Internal portfolio tracking
β€’ Multi-network asset monitoring
β€’ Node management capabilities
β €
The seller claims the tool supports dozens of blockchain networks and can monitor generated wallet addresses for incoming transactions before automatically attempting withdrawals.
β €
The listing is priced at $6,500 and includes access to a claimed demonstration panel. The seller also advertises optional updates and additional support.
β €
The seller's claims and the capabilities, effectiveness and legitimacy of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀1
πŸš¨πŸ‡ΊπŸ‡Έ SteelSeries TeamCity environment allegedly breached, employee data and credentials claimed exposed
β €
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β €
The advertised data includes:
β €
β€’ Employee account information
β€’ User IDs
β€’ Names
β€’ Email addresses
β€’ Last login details
β€’ User roles
β€’ Azure signing keys
β€’ VCS credentials
β€’ SSH keys
β€’ SVN-related credentials
β €
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β €
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: https://github.com/toanln-cov/CVE-2026-76565

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≀ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

β€’ Reflected XSS through crafted GET parameters
β€’ Exploitation of vulnerable price filter inputs
β€’ Attribute-context injection caused by missing htmlspecialchars() encoding
β€’ No authentication requirement for exploitation
β€’ Affected versions: PhocaCart ≀ 6.1.7
β€’ Fixed version: PhocaCart 6.1.8

πŸ’₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
❀1
πŸš¨πŸ‡ΊπŸ‡Έ Access to major US technology company infrastructure allegedly offered for sale on cybercrime forum
β €
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β €
The advertised access includes:
β €
β€’ Corporate Git hosting with organization administrator rights
β€’ Claimed persistence access within company infrastructure
β€’ Private container registry credentials
β€’ Internal communication channels and webhooks
β€’ API keys for internal services
β€’ Access to a claimed vulnerability allowing credential retrieval
β €
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β €
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2
πŸš¨πŸ‡ΈπŸ‡¦ STC TV user database allegedly leaked on a cybercrime forum, 3M+ records claimed
β €
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β €
The advertised data includes:
β €
β€’ Full names
β€’ User points
β€’ Gender information
β€’ Mobile numbers
β€’ Email addresses
β€’ Dates of birth
β€’ Nationality information
β€’ Barcode-related data
β €
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β €
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hono: A small, simple, and ultrafast web framework built on Web Standards

GitHub: https://github.com/honojs/hono
πŸ”₯1
🚨 Desktop RAT with reverse shell and file management features advertised on a cybercrime forum
β €
An actor is advertising what they describe as a desktop remote access trojan (RAT) featuring remote control capabilities, reverse shell functionality and an integrated file explorer. The seller is offering a free trial period to selected forum members.
β €
The advertised features include:
β €
β€’ Desktop remote access capabilities
β€’ Reverse shell functionality
β€’ Interactive remote control
β€’ Screen streaming using H.264 encoding
β€’ Low-level screenshot capture methods
β€’ Multi-monitor support
β€’ Automatic quality adjustment based on network conditions
β€’ Bot information storage
β€’ System information tracking
β€’ Online/offline status monitoring
β€’ Privilege level detection
β€’ Remote file management
β€’ File upload and download capabilities
β€’ File search, deletion, renaming and creation
β€’ Customizable options and future feature additions
β €
The seller claims the tool was written in C++ and includes mechanisms intended to reduce detection. The listing advertises the software for $100 per week.
β €
The seller's claims and the capabilities, effectiveness and detection resistance of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A new clearnet/darknet dr*g shop being advertised.

My comment: Site is very buggy. Stay smart.

mydrugs[.]top - Name is based off the tv series: "How to Sell Drugs Online (Fast)" Good show btw.

Dark Web Onion: http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/

Lite version:
http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/lite/index.php

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/d593c18aefe1dcd0b2b6
😭1
πŸš¨πŸ‡ΊπŸ‡Έ Cybercrime forum user seeks US-based mules for KYC-related activity, $40K-$50K budget claimed
β €
An actor is seeking workers or mules from the United States for what they describe as KYC-related activity. The user claims they are looking for individuals who can provide access to KYC websites, obtain company documents, or create documents for account-related operations.
β €
The advertised request includes:
β €
β€’ US-based mules or workers
β€’ KYC platform accounts
β€’ Company documents or document creation
β€’ More than 50 accounts
β€’ Cryptocurrency payments
β €
The user claims they are willing to pay $40,000-$50,000 for the requested services and states they are only dealing through a middleman.
β €
The claims and the purpose, authenticity and scope of the requested activity have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· Banque Alimentaire du Bas-Rhin allegedly leaked on a cybercrime forum
β €
A threat actor claims to have leaked data belonging to Banque Alimentaire du Bas-Rhin, a French food bank organization based in Strasbourg. The post claims the leaked dataset contains approximately 10,073 lines in JSON format with a total size of 4.3 MB.
β €
The advertised data includes:
β €
β€’ Structured JSON records
β€’ Personal and organizational information
β€’ Internal database entries
β€’ Additional records from the claimed dataset
β €
The post includes sample data and a claimed proof of access, along with download links for the full dataset.
β €
Banque Alimentaire du Bas-Rhin is a nonprofit organization that supports food assistance programs and partner associations throughout the region.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2