🔪 Slice For Life - Part 2 🔪
4.85K subscribers
1.13K photos
63 videos
1K links
Download Telegram
‼️🇦🇹🇹🇷🇨🇱 DireWolf Ransomware claims a well known video game publisher and 2 hospitals

🇦🇹 THQ Nordic - An Austrian video game publisher and developer based in Vienna, known for franchises including Darksiders, Destroy All Humans!, and SpongeBob SquarePants titles. The listing claims 335 GB of data.

🇹🇷 Erdem Hospital - A Turkish private healthcare provider operating hospitals and medical facilities offering a range of diagnostic, surgical, and specialist services. The listing claims 260 GB of data.

🇨🇱 Hospital Clínico Universidad de Chile - A major university teaching hospital in Santiago affiliated with the University of Chile, providing specialized medical care, education, and clinical research. The listing claims 240 GB of data.
🚨🇫🇷 Fédération Française de Tir access allegedly offered for sale on a cybercrime forum, data on up to 300K people claimed accessible

Fédération Française de Tir (FFTir), France’s national governing body for shooting sports, is allegedly affected by a security issue after a threat actor advertised access to its systems and claimed sensitive member information could potentially be retrieved.

The actor describes exploitation as high difficulty and claims to have identified a partial IDOR vulnerability, while the presence of SQL injection or other vulnerabilities remains unknown.

The allegedly accessible data includes:

• Shooting licence numbers
• Full names
• Email addresses
• Dates of birth
• Gender information
• Club identifiers
• Nationality information
• Disability-status fields
• Licence validity dates
• Account/activity status
• Association and departmental information
• Invoices
• Additional internal documents

The actor claims successful exploitation could expose information associated with approximately 300,000 people and published samples appearing to show member and licence-related records.

The listing makes clear that this is not a ready-to-download dataset and states that significant technical skill would be required to use the advertised access. No fixed price is provided, with the seller requesting offers privately.

The claims and the authenticity, scope and current validity of the alleged access and vulnerabilities have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Windows HVNC malware with source code advertised on a cybercrime forum for $3,000

A threat actor is advertising Windows HVNC, a hidden virtual network computing tool designed to provide covert remote control over compromised Windows endpoints while remaining largely invisible to the victim.

The advertised features include:

• Hidden background operation
• Remote mouse and keyboard control
• Multi-victim C2 management
• Automatic client reconnection
• Remote system information collection
• Application and process control
• Remote browser launching
• File Explorer access
• PowerShell execution
• Native C++ implementation
• Code obfuscation
• Full source code and compiled binary
• EDR/AV evasion claims
• Ongoing support

The seller claims the malware currently receives a 1/36 detection result when compiled from source and advertises a proof-of-concept involving operation alongside Carbon Black EDR.

The package is priced at $3,000 and is advertised as including the full source code, binary, one-time FUD service and support, with payment handled through forum escrow.

The seller's claims and the capabilities, stealth, detection rate and effectiveness of the advertised malware have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ Security researcher Nightmare Eclipse released another zero-day vulnerability.

"GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability"

GitHub: https://github.com/MSNightmare/PrettyPrague
3
‼️ This IP, looks like it is being used as a Darknet Market proxy for making scam market sites. Likely no association to any market below.

Nexus Market redirect: 72[.]56[.]108[.]250
Nexus Market redirect 2: 72[.]56[.]108[.]250:8002
Nexus Market redirect 3: 72[.]56[.]108[.]250:8003
Scam site: https://nexusb2l7hog66bnzz5msrz4m5qxj7jbi7aah3r65uzydy5mew2fu3id[.]online

Omega Market redirect: 72[.]56[.]108[.]250:8010
Mars Market redirect: 72[.]56[.]108[.]250:8008
Black Ops Market redirect: 72[.]56[.]108[.]250:8007
Prime Market redirect: 72[.]56[.]108[.]250:8009
Dark Matter redirect: 72[.]56[.]108[.]250:8005
🔥1🤔1
🚨🇻🇳 AB Beauty World dataset allegedly offered for sale on a cybercrime forum, 226K records claimed

AB Beauty World, a Vietnam-based cosmetics retailer operating online and through a network of physical stores, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 226,000 individuals.

The actor claims the retailer operates around 16-20 stores in Ho Chi Minh City and sells products from hundreds of domestic and international beauty brands.

The advertised data includes:

• Full names
• 226,000 unique phone numbers
• 72,000 unique email addresses
• Dates of birth
• Gender information
• Physical addresses
• Cities and regional information
• Customer IDs and account records
• Account creation dates
• Customer transaction-related fields
• Employee names
• Employee email addresses
• Employee phone numbers
• Internal employee identifiers
• Account activity and login-related fields

The listing includes samples of both alleged customer and employee records. The dataset is being offered for $250, with the seller stating that escrow is accepted.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇹🇭 Thailand Cyber Police admin access allegedly advertised on a cybercrime forum

Thailand Cyber Police, a Thai law enforcement organization focused on cybercrime investigations, is allegedly affected by a security compromise after a threat actor advertised administrator-level access to an internal web panel.

The advertised access allegedly includes:

• Live access to cybercrime reports
• Ability to communicate with victims
• Access to victim information
• Ability to close cybercrime reports
• Ability to create new user accounts
• Access to cybercrime investigation reports
• Ability to view case information
• Ability to manage case information
• Administrator-level privileges

The actor describes the access type as a web administration panel and is offering proof of access privately to interested parties.

No public asking price is provided in the listing.

The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Valley Health Team dataset allegedly offered for sale on a cybercrime forum, 3.28TB and 9M+ files claimed by Rhysida Ransomware

Valley Health Team, a California-based Federally Qualified Health Center providing healthcare services across the Central Valley, is allegedly affected by a major data exposure after a threat actor advertised what they claim is 3.28 TB of internal data spanning 9,056,196 files.

The actor claims the material includes extensive SQL datasets and healthcare records accumulated throughout the organization's operations.

The advertised data includes:

• Records associated with 160,870 patients
• 4.18 million diagnosis records
• 7.6 million allegedly unencrypted EHR scans
• Social Security numbers
• Passport information
• Patient personal information
• Electronic health records
• Financial statements
• Salary information
• Tax-related records
• Additional internal healthcare and business data

The actor is offering the alleged material for sale privately and did not provide a public asking price.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇷🇺 FlorandGlass customer dataset allegedly leaked on a cybercrime forum, 4,522 records claimed

FlorandGlass, a Russia-based e-commerce website, is allegedly affected by a data exposure after a threat actor published what they claim is a dataset containing 4,522 order and customer records.

The advertised data includes:

• Customer names
• Email addresses
• Phone numbers
• Billing addresses
• Shipping addresses
• Postal codes, cities and countries
• Customer IP addresses
• User-agent information
• Order numbers and dates
• Order status information
• Payment methods
• Transaction IDs
• Order totals and subtotals
• Tax and shipping information
• Discount and coupon data
• Product line items
• Customer notes
• Refund information
• WooCommerce order attribution and session metadata

The post provides a direct download link for the alleged dataset and lists extensive WooCommerce-related customer, order, payment and shipping fields.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Fingerprint is a search engine for public data. Social Search takes a username or an email address and checks it against 700+ platforms in parallel, streaming matches back while the search is still running.

Website: https://fingerprint.to/
Demo: https://fingerprint.to/demo

People Search is the separate workflow for names, and it queries public-record providers.
🚨🇮🇹 Italian Ministry of Interior police webmail access allegedly offered on a cybercrime forum

Italy’s Ministry of the Interior, which oversees national public security and law enforcement functions, is allegedly affected by a security compromise after a threat actor advertised access described as belonging to Italian police webmail infrastructure.

The actor claims the access provides connectivity to additional law enforcement resources, including Global Kodex, and could expose sensitive investigative and legal information.

The advertised access allegedly includes:

• Police webmail access
• Access to law enforcement portals
• Global Kodex access
• Retrieval of legal and investigative documents
• Information associated with individuals
• Access to security-camera imagery
• Additional law enforcement-related records and resources

The actor published a screenshot presented as proof of access and is directing interested parties to make contact privately.

No public asking price is provided in the listing.

The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Can’t wait for the ‘school is pointless’ crowd to meet mandatory Monday meetings.
😭5
‼️ Microsoft Outlook, Microsoft 365, ChatGPT, Canvas, Azure, Teams and Astound Broadband are all having outage issues for hundreds of users.
😁1