π¨π·πΊ "Legal services" aimed at cybercrime forum members advertised with prices up to 50,000
β
An actor on a Russian-language cybercrime forum is advertising what they describe as a full range of legal services, promoting assistance with criminal, financial, military and civil legal matters while emphasizing confidentiality.
β
The advertised services include:
β
β’ Consultations across areas of Russian law
β’ Assessment of income sources and potential criminal or civil legal risks
β’ Criminal defense-related assistance
β’ Military law and deferment assistance
β’ Help obtaining military documentation
β’ Contracts, claims and other legal documents
β’ Debt and microfinance-related disputes
β’ Challenges involving restrictions on leaving the country
β’ Assistance with restrictions under Russian 115-FZ and 161-FZ
β’ Preparation of legal agreements
β’ Analysis of complex or unusual legal situations
β
The actor claims to have formal legal education and practical experience, and states that they have received reviews on other underground forums.
β
The listing displays a price range of 1,500 to 50,000, although the currency is not specified, with prospective clients directed to contact the seller privately.
β
The advertised qualifications, services and claims have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An actor on a Russian-language cybercrime forum is advertising what they describe as a full range of legal services, promoting assistance with criminal, financial, military and civil legal matters while emphasizing confidentiality.
β
The advertised services include:
β
β’ Consultations across areas of Russian law
β’ Assessment of income sources and potential criminal or civil legal risks
β’ Criminal defense-related assistance
β’ Military law and deferment assistance
β’ Help obtaining military documentation
β’ Contracts, claims and other legal documents
β’ Debt and microfinance-related disputes
β’ Challenges involving restrictions on leaving the country
β’ Assistance with restrictions under Russian 115-FZ and 161-FZ
β’ Preparation of legal agreements
β’ Analysis of complex or unusual legal situations
β
The actor claims to have formal legal education and practical experience, and states that they have received reviews on other underground forums.
β
The listing displays a price range of 1,500 to 50,000, although the currency is not specified, with prospective clients directed to contact the seller privately.
β
The advertised qualifications, services and claims have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
I guess TeamPCP forgot about the extended look of GTA 6 today.
π7
π¨πΊπΈ Initial Access: US AI Company
A threat actor is advertising access to an unnamed U.S. artificial intelligence/fintech company reportedly generating $11M in revenue.
The advertised access includes Slack, Auth0, GCP, MongoDB, Azure, SendGrid, and Grok. Payment is requested in XMR.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising access to an unnamed U.S. artificial intelligence/fintech company reportedly generating $11M in revenue.
The advertised access includes Slack, Auth0, GCP, MongoDB, Azure, SendGrid, and Grok. Payment is requested in XMR.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
βΌοΈ Allure Darknet Market launches 1.5
Dark Web: http://allureg32wdtbv7yzcybds6iakavl3dd6z2aten3l26xpsmeo7dq47id[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3e4cf9f309984f61f924
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
Dark Web: http://allureg32wdtbv7yzcybds6iakavl3dd6z2aten3l26xpsmeo7dq47id[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3e4cf9f309984f61f924
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
πͺ That Dark Web Guy - Part 3 πͺ
βΌοΈ Allure Darknet Market launches 1.5 Dark Web: http://allureg32wdtbv7yzcybds6iakavl3dd6z2aten3l26xpsmeo7dq47id[.]onion Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3e4cf9f309984f61f924 ______________β¦
Mirror: http://c5lpbpiufttwjm4daqb6kiyaspwbyedgnshhayhomksf65ebp2ckaeqd[.]onion
Subdread: /d/allure
Subdread: /d/allure
β€1
βΌοΈ DarkForums is back up under the domain I discovered earlier today:
darkforums[.]as
https://x.com/DarkWebInformer/status/2093018895846162799?s=20
darkforums[.]as
https://x.com/DarkWebInformer/status/2093018895846162799?s=20
β€6π₯1π1
Brave added email aliases to their desktop browser
https://x.com/DarkWebInformer/status/2093129109106794603
https://x.com/DarkWebInformer/status/2093129109106794603
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
Brave added email aliases to their desktop browser
Email Aliases lets you create unique email addresses that automatically forward messages to your primary inbox.
Email Aliases lets you create unique email addresses that automatically forward messages to your primary inbox.
Google Engineer Accused of Polymarket Insider Trading Says He Was Just Gambling
https://www.wired.com/story/google-engineer-accused-of-polymarket-insider-trading-says-he-was-just-gambling/
https://www.wired.com/story/google-engineer-accused-of-polymarket-insider-trading-says-he-was-just-gambling/
WIRED
Google Engineer Accused of Polymarket Insider Trading Says He Was Just Gambling
Michele Spagnuolo was arrested for alleged insider trading on Polymarket, but the Switzerland-based engineer says he was simply gamblingβactivity that is beyond the reach of US commodities law.
π1
Here is the Indictment against Ruben Ian Thomson
https://www.courtlistener.com/docket/74707103/united-states-v-thomson/
https://www.courtlistener.com/docket/74707103/united-states-v-thomson/
π¨π«π· Actis Location dataset allegedly leaked on a cybercrime forum, 464GB and 666K+ files claimed
β
Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.
β
The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.
β
The advertised data includes:
β
β’ Email communications
β’ Employee and customer names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Cities, postal codes and countries
β’ CRM records
β’ Customer and company account information
β’ Internal reference numbers
β’ Rental and quotation documents
β’ Contract-related information
β’ Equipment and product details
β’ Pricing and payment-related information
β’ Rental dates and durations
β’ Additional internal business documents
β
The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.
β
The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.
β
The advertised data includes:
β
β’ Email communications
β’ Employee and customer names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Cities, postal codes and countries
β’ CRM records
β’ Customer and company account information
β’ Internal reference numbers
β’ Rental and quotation documents
β’ Contract-related information
β’ Equipment and product details
β’ Pricing and payment-related information
β’ Rental dates and durations
β’ Additional internal business documents
β
The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π©πͺ EggyWall advertises privacy-focused "bulletproof" VPS hosting with DDoS protection
EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.
The advertised features include:
β’ VPS hosting in Frankfurt, Germany
β’ NVMe SSD storage
β’ High-speed uplinks
β’ Full root access
β’ Free DDoS protection
β’ Layer 7 WAF protection
β’ Filtering against malicious HTTP traffic
β’ Full server control
β’ Privacy-focused hosting
β’ "Bulletproof" hosting
β’ Responsive support
The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."
No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.
The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.
The advertised features include:
β’ VPS hosting in Frankfurt, Germany
β’ NVMe SSD storage
β’ High-speed uplinks
β’ Full root access
β’ Free DDoS protection
β’ Layer 7 WAF protection
β’ Filtering against malicious HTTP traffic
β’ Full server control
β’ Privacy-focused hosting
β’ "Bulletproof" hosting
β’ Responsive support
The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."
No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.
The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΆπ¦ Qatar General Retirement & Social Insurance Authority allegedly breached, internal accounts and API tokens exposed
Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.
The advertised data includes:
β’ Internal and partner user accounts
β’ First and last names
β’ Email addresses
β’ User and partner account types
β’ Partner IDs
β’ Store IDs
β’ Account roles and permissions
β’ Account status information
β’ API names and environment identifiers
β’ API authentication tokens
β’ Token expiration dates
β’ Record creation and update timestamps
The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.
The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.
The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.
The advertised data includes:
β’ Internal and partner user accounts
β’ First and last names
β’ Email addresses
β’ User and partner account types
β’ Partner IDs
β’ Store IDs
β’ Account roles and permissions
β’ Account status information
β’ API names and environment identifiers
β’ API authentication tokens
β’ Token expiration dates
β’ Record creation and update timestamps
The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.
The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.
The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πͺπΈ Dataset from unnamed Spanish company allegedly offered on a cybercrime forum, 7,222+ records claimed
β
An unnamed company in Spain is allegedly affected by a data exposure after a threat actor advertised what they claim is a complete dataset containing more than 7,222 plaintext records across multiple tables.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes
β’ Cities and municipalities
β’ Spanish identification numbers
β’ Customer-related records
β’ Contact information
β’ Commercial and billing-related tables
β’ Invoice-related records
β’ Additional internal business data
β
The actor published sample records from the alleged dataset along with a partial list of table names, including customer, contact, invoice and tax-related tables.
β
The company is not identified in the listing, and no public asking price is provided.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed company in Spain is allegedly affected by a data exposure after a threat actor advertised what they claim is a complete dataset containing more than 7,222 plaintext records across multiple tables.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes
β’ Cities and municipalities
β’ Spanish identification numbers
β’ Customer-related records
β’ Contact information
β’ Commercial and billing-related tables
β’ Invoice-related records
β’ Additional internal business data
β
The actor published sample records from the alleged dataset along with a partial list of table names, including customer, contact, invoice and tax-related tables.
β
The company is not identified in the listing, and no public asking price is provided.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπͺ VMware Horizon enterprise admin access to Swedish technology company allegedly offered for sale on a cybercrime forum
β
An unnamed technology/SaaS company in Sweden, reportedly generating $100 million to $250 million in revenue, is allegedly compromised after a threat actor advertised access to its environment through an underground marketplace.
β
The advertised access includes:
β
β’ VMware Horizon access
β’ Enterprise Administrator privileges
β’ Network of approximately 1,000 hosts
β’ No AV/EDR detected by the seller
β’ Technology/SaaS sector
β’ Sweden-based organization
β
The actor is asking for approximately 0.02254392 BTC, for the accesst.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed technology/SaaS company in Sweden, reportedly generating $100 million to $250 million in revenue, is allegedly compromised after a threat actor advertised access to its environment through an underground marketplace.
β
The advertised access includes:
β
β’ VMware Horizon access
β’ Enterprise Administrator privileges
β’ Network of approximately 1,000 hosts
β’ No AV/EDR detected by the seller
β’ Technology/SaaS sector
β’ Sweden-based organization
β
The actor is asking for approximately 0.02254392 BTC, for the accesst.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΊπΈ Grindr (again?) dataset allegedly offered for sale on a cybercrime forum, 28M user records claimed
β
Grindr, a location-based dating and social networking platform, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 28 million registered users.
β
The advertised data includes:
β
β’ Email addresses
β’ Account and profile IDs
β’ Dates of birth and ages
β’ Gender and pronoun information
β’ Cities, states and countries
β’ Account and verification status
β’ Device and app information
β’ Profile creation and activity timestamps
β’ Height, weight and body-type information
β’ Relationship and dating preferences
β’ Profile descriptions and interests
β’ Social media account information
β’ Subscription and account tier details
β’ Profile views and engagement metrics
β’ Health-related profile fields
β’ Additional highly sensitive profile information
β
The actor published sample records and a list of claimed dataset fields, and is offering the alleged material for $400.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Grindr, a location-based dating and social networking platform, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 28 million registered users.
β
The advertised data includes:
β
β’ Email addresses
β’ Account and profile IDs
β’ Dates of birth and ages
β’ Gender and pronoun information
β’ Cities, states and countries
β’ Account and verification status
β’ Device and app information
β’ Profile creation and activity timestamps
β’ Height, weight and body-type information
β’ Relationship and dating preferences
β’ Profile descriptions and interests
β’ Social media account information
β’ Subscription and account tier details
β’ Profile views and engagement metrics
β’ Health-related profile fields
β’ Additional highly sensitive profile information
β
The actor published sample records and a list of claimed dataset fields, and is offering the alleged material for $400.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π1
βΌοΈ New Dark Web Informer Blog Post!
Title: ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
Link: https://darkwebinformer.com/toxc2-sells-a-cross-platform-agent-that-runs-its-command-channel-over-tox/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
Link: https://darkwebinformer.com/toxc2-sells-a-cross-platform-agent-that-runs-its-command-channel-over-tox/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
A seller posting as Reze is advertising ToxC2, a command and control agent priced at 70 dollars for builds covering Windows, macOS and Linux.