πͺ That Dark Web Guy - Part 3 πͺ
βΌοΈ CYBERLEEK, Grand Theft Auto 6, Dark Web Onion: IOC: http://leekrdlpsy3xcxwcvfje7ovj34fo4y2xqaghdikhf3t7hatev346h6qd[.]onion/
Someone caught the "gamer" who went to Rockstar North's office on video and a direct look from his point of view.
π2
π¨πΊπΈ SteelSeries TeamCity environment allegedly breached, employee data and credentials claimed exposed
β
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β
The advertised data includes:
β
β’ Employee account information
β’ User IDs
β’ Names
β’ Email addresses
β’ Last login details
β’ User roles
β’ Azure signing keys
β’ VCS credentials
β’ SSH keys
β’ SVN-related credentials
β
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β
The advertised data includes:
β
β’ Employee account information
β’ User IDs
β’ Names
β’ Email addresses
β’ Last login details
β’ User roles
β’ Azure signing keys
β’ VCS credentials
β’ SSH keys
β’ SVN-related credentials
β
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart β€ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
β’ Reflected XSS through crafted GET parameters
β’ Exploitation of vulnerable price filter inputs
β’ Attribute-context injection caused by missing htmlspecialchars() encoding
β’ No authentication requirement for exploitation
β’ Affected versions: PhocaCart β€ 6.1.7
β’ Fixed version: PhocaCart 6.1.8
π₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart β€ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
β’ Reflected XSS through crafted GET parameters
β’ Exploitation of vulnerable price filter inputs
β’ Attribute-context injection caused by missing htmlspecialchars() encoding
β’ No authentication requirement for exploitation
β’ Affected versions: PhocaCart β€ 6.1.7
β’ Fixed version: PhocaCart 6.1.8
π₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
β€1
π¨πΊπΈ Access to major US technology company infrastructure allegedly offered for sale on cybercrime forum
β
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β
The advertised access includes:
β
β’ Corporate Git hosting with organization administrator rights
β’ Claimed persistence access within company infrastructure
β’ Private container registry credentials
β’ Internal communication channels and webhooks
β’ API keys for internal services
β’ Access to a claimed vulnerability allowing credential retrieval
β
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β
The advertised access includes:
β
β’ Corporate Git hosting with organization administrator rights
β’ Claimed persistence access within company infrastructure
β’ Private container registry credentials
β’ Internal communication channels and webhooks
β’ API keys for internal services
β’ Access to a claimed vulnerability allowing credential retrieval
β
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€2
π¨πΈπ¦ STC TV user database allegedly leaked on a cybercrime forum, 3M+ records claimed
β
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β
The advertised data includes:
β
β’ Full names
β’ User points
β’ Gender information
β’ Mobile numbers
β’ Email addresses
β’ Dates of birth
β’ Nationality information
β’ Barcode-related data
β
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β
The advertised data includes:
β
β’ Full names
β’ User points
β’ Gender information
β’ Mobile numbers
β’ Email addresses
β’ Dates of birth
β’ Nationality information
β’ Barcode-related data
β
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hono: A small, simple, and ultrafast web framework built on Web Standards
GitHub: https://github.com/honojs/hono
GitHub: https://github.com/honojs/hono
π₯1
π¨ Desktop RAT with reverse shell and file management features advertised on a cybercrime forum
β
An actor is advertising what they describe as a desktop remote access trojan (RAT) featuring remote control capabilities, reverse shell functionality and an integrated file explorer. The seller is offering a free trial period to selected forum members.
β
The advertised features include:
β
β’ Desktop remote access capabilities
β’ Reverse shell functionality
β’ Interactive remote control
β’ Screen streaming using H.264 encoding
β’ Low-level screenshot capture methods
β’ Multi-monitor support
β’ Automatic quality adjustment based on network conditions
β’ Bot information storage
β’ System information tracking
β’ Online/offline status monitoring
β’ Privilege level detection
β’ Remote file management
β’ File upload and download capabilities
β’ File search, deletion, renaming and creation
β’ Customizable options and future feature additions
β
The seller claims the tool was written in C++ and includes mechanisms intended to reduce detection. The listing advertises the software for $100 per week.
β
The seller's claims and the capabilities, effectiveness and detection resistance of the advertised tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An actor is advertising what they describe as a desktop remote access trojan (RAT) featuring remote control capabilities, reverse shell functionality and an integrated file explorer. The seller is offering a free trial period to selected forum members.
β
The advertised features include:
β
β’ Desktop remote access capabilities
β’ Reverse shell functionality
β’ Interactive remote control
β’ Screen streaming using H.264 encoding
β’ Low-level screenshot capture methods
β’ Multi-monitor support
β’ Automatic quality adjustment based on network conditions
β’ Bot information storage
β’ System information tracking
β’ Online/offline status monitoring
β’ Privilege level detection
β’ Remote file management
β’ File upload and download capabilities
β’ File search, deletion, renaming and creation
β’ Customizable options and future feature additions
β
The seller claims the tool was written in C++ and includes mechanisms intended to reduce detection. The listing advertises the software for $100 per week.
β
The seller's claims and the capabilities, effectiveness and detection resistance of the advertised tool have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ A new clearnet/darknet dr*g shop being advertised.
My comment: Site is very buggy. Stay smart.
mydrugs[.]top - Name is based off the tv series: "How to Sell Drugs Online (Fast)" Good show btw.
Dark Web Onion: http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/
Lite version:
http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/lite/index.php
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/d593c18aefe1dcd0b2b6
My comment: Site is very buggy. Stay smart.
mydrugs[.]top - Name is based off the tv series: "How to Sell Drugs Online (Fast)" Good show btw.
Dark Web Onion: http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/
Lite version:
http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/lite/index.php
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/d593c18aefe1dcd0b2b6
π1
πͺ That Dark Web Guy - Part 3 πͺ
βΌοΈ A new clearnet/darknet dr*g shop being advertised. My comment: Site is very buggy. Stay smart. mydrugs[.]top - Name is based off the tv series: "How to Sell Drugs Online (Fast)" Good show btw. Dark Web Onion: http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqβ¦
IMDb
How to Sell Drugs Online (Fast) (TV Series 2019β2025) β 7.7 | Comedy, Crime, Drama
30m | TV-MA
π3
π¨πΊπΈ Cybercrime forum user seeks US-based mules for KYC-related activity, $40K-$50K budget claimed
β
An actor is seeking workers or mules from the United States for what they describe as KYC-related activity. The user claims they are looking for individuals who can provide access to KYC websites, obtain company documents, or create documents for account-related operations.
β
The advertised request includes:
β
β’ US-based mules or workers
β’ KYC platform accounts
β’ Company documents or document creation
β’ More than 50 accounts
β’ Cryptocurrency payments
β
The user claims they are willing to pay $40,000-$50,000 for the requested services and states they are only dealing through a middleman.
β
The claims and the purpose, authenticity and scope of the requested activity have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An actor is seeking workers or mules from the United States for what they describe as KYC-related activity. The user claims they are looking for individuals who can provide access to KYC websites, obtain company documents, or create documents for account-related operations.
β
The advertised request includes:
β
β’ US-based mules or workers
β’ KYC platform accounts
β’ Company documents or document creation
β’ More than 50 accounts
β’ Cryptocurrency payments
β
The user claims they are willing to pay $40,000-$50,000 for the requested services and states they are only dealing through a middleman.
β
The claims and the purpose, authenticity and scope of the requested activity have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π«π· Banque Alimentaire du Bas-Rhin allegedly leaked on a cybercrime forum
β
A threat actor claims to have leaked data belonging to Banque Alimentaire du Bas-Rhin, a French food bank organization based in Strasbourg. The post claims the leaked dataset contains approximately 10,073 lines in JSON format with a total size of 4.3 MB.
β
The advertised data includes:
β
β’ Structured JSON records
β’ Personal and organizational information
β’ Internal database entries
β’ Additional records from the claimed dataset
β
The post includes sample data and a claimed proof of access, along with download links for the full dataset.
β
Banque Alimentaire du Bas-Rhin is a nonprofit organization that supports food assistance programs and partner associations throughout the region.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A threat actor claims to have leaked data belonging to Banque Alimentaire du Bas-Rhin, a French food bank organization based in Strasbourg. The post claims the leaked dataset contains approximately 10,073 lines in JSON format with a total size of 4.3 MB.
β
The advertised data includes:
β
β’ Structured JSON records
β’ Personal and organizational information
β’ Internal database entries
β’ Additional records from the claimed dataset
β
The post includes sample data and a claimed proof of access, along with download links for the full dataset.
β
Banque Alimentaire du Bas-Rhin is a nonprofit organization that supports food assistance programs and partner associations throughout the region.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β€2
π¨πΊπΈ Cornerstone Residential allegedly breached, SQL dump advertised on cybercrime forum
β
Cornerstone Residential, a Texas-based property management company, is allegedly the target of a claimed breach after a threat actor advertised what they describe as a full SQL database dump from the company.
β
The threat actor claims the leaked data includes:
β
β’ User preferences
β’ User roles
β’ Elementor API access tokens and secrets
β’ Administrator IP location information
β’ Additional database records
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Cornerstone Residential, a Texas-based property management company, is allegedly the target of a claimed breach after a threat actor advertised what they describe as a full SQL database dump from the company.
β
The threat actor claims the leaked data includes:
β
β’ User preferences
β’ User roles
β’ Elementor API access tokens and secrets
β’ Administrator IP location information
β’ Additional database records
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Electoral Roll Data on 13.7 Million Chileans Advertised as a Complete Database
Link: https://darkwebinformer.com/electoral-roll-data-on-13-7-million-chileans-advertised-as-a-complete-database/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Electoral Roll Data on 13.7 Million Chileans Advertised as a Complete Database
Link: https://darkwebinformer.com/electoral-roll-data-on-13-7-million-chileans-advertised-as-a-complete-database/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Electoral Roll Data on 13.7 Million Chileans Advertised as a Complete Database
A forum user posting as GordonFreeman is advertising what they describe as the complete electoral roll of Chile, listing 13,737,519 citizens and attributing it to SERVEL, the national electoral service.
βΌοΈ New Dark Web Informer Blog Post!
Title: Agence Vauban Client Accounts and Property Files Shared Free on a Forum
Link: https://darkwebinformer.com/agence-vauban-client-accounts-and-property-files-shared-free-on-a-forum/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Agence Vauban Client Accounts and Property Files Shared Free on a Forum
Link: https://darkwebinformer.com/agence-vauban-client-accounts-and-property-files-shared-free-on-a-forum/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Agence Vauban Client Accounts and Property Files Shared Free on a Forum
A forum user posting as sh444d0w has published what they describe as the database of Agence Vauban, a real estate agency working the Antibes and French Riviera market.
π¨ D*xbin source code allegedly offered for sale on a cybercrime forum
β
DF owner is advertising what they claim is the complete source code for D*xbin, a platform associated with the publication of personal information. The actor claims the code can be used to build a D*xbin/Vilebin-style platform or operate a similar paste site.
β
The advertised offering includes:
β
β’ Complete platform source code
β’ Updated version of the claimed Doxbin codebase
β’ Ability to create a clone-style platform
β’ Existing forum infrastructure components
β’ Custom deployment capabilities
β
The actor claims the source code is the same version currently used by D*xbin and states that some clone paste sites are already operating using the code.
β
The seller's claims and the authenticity, ownership and functionality of the advertised source code have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
DF owner is advertising what they claim is the complete source code for D*xbin, a platform associated with the publication of personal information. The actor claims the code can be used to build a D*xbin/Vilebin-style platform or operate a similar paste site.
β
The advertised offering includes:
β
β’ Complete platform source code
β’ Updated version of the claimed Doxbin codebase
β’ Ability to create a clone-style platform
β’ Existing forum infrastructure components
β’ Custom deployment capabilities
β
The actor claims the source code is the same version currently used by D*xbin and states that some clone paste sites are already operating using the code.
β
The seller's claims and the authenticity, ownership and functionality of the advertised source code have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs
Link: https://darkwebinformer.com/jce-records-on-7-1-million-dominicans-advertised-with-5-76-million-id-photographs/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs
Link: https://darkwebinformer.com/jce-records-on-7-1-million-dominicans-advertised-with-5-76-million-id-photographs/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs
A forum user posting as GordonFreeman claims to have breached the Junta Central Electoral, the Dominican Republic's central electoral board, and is publishing what they describe as 7,141,313 citizen records alongside 5,758,124 identity card photographs keyedβ¦