If losing it would devastate you... BACK IT UP.
Photos. Videos. Documents. Work.
If you only have one copy, you don't have a backup.
Photos. Videos. Documents. Work.
If you only have one copy, you don't have a backup.
โค4
Media is too big
VIEW IN TELEGRAM
Another good banger.
311 - Come Original
Song Released: October 12, 1999
311 - Come Original
Song Released: October 12, 1999
๐ฅ2
๐จ Kleptomania Stealer advertised on a cybercrime forum, extensive browser and cryptocurrency theft capabilities claimed
โ
Kleptomania Stealer, a newly advertised Windows information-stealing malware, is being promoted on a cybercrime forum with claims that it can harvest credentials, browser data, cryptocurrency wallets and active application sessions from infected systems.
โ
Advertised capabilities
โ
โข Password, cookie and browser history theft
โข Saved payment card and CVV/CVV2 data
โข Google OAuth token theft
โข Autofill and form data collection
โข Screenshot capture
โข Telegram and Discord session theft
โข 70+ Chromium-based browsers
โข 35+ Gecko-based browsers
โข 125+ cryptocurrency browser extensions
โข 65+ desktop cryptocurrency wallets
โข 20+ gaming clients
โข 15+ messaging applications
โข 15+ VPN clients
โข 20+ FTP clients
โข Smart file grabbing and sorting
โข Anti-VM and obfuscation features
โ
The seller specifically advertises support for software including Chrome, Edge, Brave, Firefox, MetaMask, Phantom, Trust Wallet, Exodus, Electrum, Steam, Telegram, Discord, Mullvad, NordVPN, FileZilla and WinSCP.
โ
Additional modules advertised include a seed phrase scanner, cryptocurrency wallet targeting, and planned loader, clipper, HVNC and macOS components.
โ
Kleptomania is advertised at $150 for one month, $400 for three months, or $1,500 for 12 months. The seller also claims a roughly 700 KB build size and promotes a claimed 98% reporting rate.
โ
The malwareโs capabilities, effectiveness and compatibility claims have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Kleptomania Stealer, a newly advertised Windows information-stealing malware, is being promoted on a cybercrime forum with claims that it can harvest credentials, browser data, cryptocurrency wallets and active application sessions from infected systems.
โ
Advertised capabilities
โ
โข Password, cookie and browser history theft
โข Saved payment card and CVV/CVV2 data
โข Google OAuth token theft
โข Autofill and form data collection
โข Screenshot capture
โข Telegram and Discord session theft
โข 70+ Chromium-based browsers
โข 35+ Gecko-based browsers
โข 125+ cryptocurrency browser extensions
โข 65+ desktop cryptocurrency wallets
โข 20+ gaming clients
โข 15+ messaging applications
โข 15+ VPN clients
โข 20+ FTP clients
โข Smart file grabbing and sorting
โข Anti-VM and obfuscation features
โ
The seller specifically advertises support for software including Chrome, Edge, Brave, Firefox, MetaMask, Phantom, Trust Wallet, Exodus, Electrum, Steam, Telegram, Discord, Mullvad, NordVPN, FileZilla and WinSCP.
โ
Additional modules advertised include a seed phrase scanner, cryptocurrency wallet targeting, and planned loader, clipper, HVNC and macOS components.
โ
Kleptomania is advertised at $150 for one month, $400 for three months, or $1,500 for 12 months. The seller also claims a roughly 700 KB build size and promotes a claimed 98% reporting rate.
โ
The malwareโs capabilities, effectiveness and compatibility claims have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ธ๐ฌ Malone Lam pleads guilty over $245M Bitcoin social engineering heist
The 22-year-old Singaporean admitted his role in the operation that stole more than 4,100 BTC from a single Washington, D.C. victim in August 2024.
Members of the group impersonated Google and Gemini representatives and convinced the victim to provide access to his Google Drive and security codes, allowing Lam to drain the wallets.
The stolen Bitcoin was worth more than $245M at the time.
Lam and his associates then laundered the crypto and went on a massive spending spree involving private jets, mansions, luxury watches, and exotic cars.
Lam alone reportedly:
โข Spent $569K in one night at an LA nightclub
โข Bought a $2M watch
โข Acquired more than 30 cars, including Porsches, Lamborghinis, and Ferraris
The broader enterprise is accused of stealing more than $263M in cryptocurrency through social engineering, hacking, money laundering, and even home break-ins targeting hardware wallets.
18 people have been charged. Lam is the 11th to plead guilty.
He faces up to 20 years in federal prison. A sentencing date has not yet been set.
Source: https://abcnews.com/Business/wireStory/singapore-man-pleads-guilty-orchestrating-240-million-bitcoin-136279302
The 22-year-old Singaporean admitted his role in the operation that stole more than 4,100 BTC from a single Washington, D.C. victim in August 2024.
Members of the group impersonated Google and Gemini representatives and convinced the victim to provide access to his Google Drive and security codes, allowing Lam to drain the wallets.
The stolen Bitcoin was worth more than $245M at the time.
Lam and his associates then laundered the crypto and went on a massive spending spree involving private jets, mansions, luxury watches, and exotic cars.
Lam alone reportedly:
โข Spent $569K in one night at an LA nightclub
โข Bought a $2M watch
โข Acquired more than 30 cars, including Porsches, Lamborghinis, and Ferraris
The broader enterprise is accused of stealing more than $263M in cryptocurrency through social engineering, hacking, money laundering, and even home break-ins targeting hardware wallets.
18 people have been charged. Lam is the 11th to plead guilty.
He faces up to 20 years in federal prison. A sentencing date has not yet been set.
Source: https://abcnews.com/Business/wireStory/singapore-man-pleads-guilty-orchestrating-240-million-bitcoin-136279302
โค1
๐ช That Dark Web Guy - Part 3 ๐ช
โ ๏ธ Avoid using DarkMatter Market. The admin has not provided any new information in the past 24 hours. The market may be in the process of conducting an exit scam. Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/76b7ab226321fdbcab2e
All DarkMatter onions are being monitored by the FBI Watchdog script. https://t.me/FBI_Watchdog
Telegram
FBI Watchdog Alerts by Dark Web Informer
Website: darkwebinformer.com
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
๐จ๐ง๐ท Cia de Trade allegedly breached, 965 staff credentials and Philip Morris campaign data claimed
โ
Cia de Trade, a Brazilian trade marketing agency and web host involved in Philip Morris International brand campaigns, is named in a cybercrime forum post where a threat actor claims to have compromised internal systems and obtained staff, campaign and HR data.
โ
Claimed exposure
โ
โข 965 staff login accounts with MD5-salted password hashes
โข 379 accounts using @pmi.com email addresses
โข 27 accounts using @contracted.pmi.com addresses
โข 87,762 access-log records containing IPs, page URIs and timestamps
โข 12,293 session records
โข 8,093 distinct campaign session tokens
โข 956 client records and 156 client logins
โข Multiple MySQL database dumps
โข 215 MB Outlook PST archive
โข Brazilian employee paystubs containing HR PII
โข 46 keys identifying client brands
โ
The actor claims the compromised infrastructure supported Philip Morris campaigns and the Dapal loyalty platform, alongside work involving other major brands and organizations.
โ
The post also claims credentials associated with Dapal and several other corporate domains were present in the exposed account data.
โ
The breach claim, exposed data and scope have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
โ
Cia de Trade, a Brazilian trade marketing agency and web host involved in Philip Morris International brand campaigns, is named in a cybercrime forum post where a threat actor claims to have compromised internal systems and obtained staff, campaign and HR data.
โ
Claimed exposure
โ
โข 965 staff login accounts with MD5-salted password hashes
โข 379 accounts using @pmi.com email addresses
โข 27 accounts using @contracted.pmi.com addresses
โข 87,762 access-log records containing IPs, page URIs and timestamps
โข 12,293 session records
โข 8,093 distinct campaign session tokens
โข 956 client records and 156 client logins
โข Multiple MySQL database dumps
โข 215 MB Outlook PST archive
โข Brazilian employee paystubs containing HR PII
โข 46 keys identifying client brands
โ
The actor claims the compromised infrastructure supported Philip Morris campaigns and the Dapal loyalty platform, alongside work involving other major brands and organizations.
โ
The post also claims credentials associated with Dapal and several other corporate domains were present in the exposed account data.
โ
The breach claim, exposed data and scope have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
๐จ GirlsChase.TV dataset allegedly offered on a cybercrime forum
โ
GirlsChase.TV is a platform focused on dating, social skills, and relationship advice.
โ
A threat actor using the handle zooz claims to possess the platformโs full dataset and published a sample containing customer, subscription, and payment-related records.
โ
Sample data includes:
โ
โข Customer email addresses
โข Stripe and PayPal references
โข Customer and subscription IDs
โข Payment amounts and currencies
โข Transaction timestamps
โข Subscription and payment status information
โ
The claim and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
GirlsChase.TV is a platform focused on dating, social skills, and relationship advice.
โ
A threat actor using the handle zooz claims to possess the platformโs full dataset and published a sample containing customer, subscription, and payment-related records.
โ
Sample data includes:
โ
โข Customer email addresses
โข Stripe and PayPal references
โข Customer and subscription IDs
โข Payment amounts and currencies
โข Transaction timestamps
โข Subscription and payment status information
โ
The claim and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โผ๏ธ Security researcher Nightmare Eclipse has created a new GitHub repository called ShieldCrash, which is described as a Windows Defender zero-day vulnerability.
Currently, the repository is empty.
GitHub: https://github.com/MSNightmare/ShieldCrash
Currently, the repository is empty.
GitHub: https://github.com/MSNightmare/ShieldCrash
๐ฅ4
OSIRIS: Open Source Intelligence & Reconnaissance Integrated System
Live Demo: https://osirisai.live/
GitHub: https://github.com/simplifaisoul/osiris
Osiris is a production-grade OSINT platform designed to deliver real-time situational awareness across multiple intelligence domains. Built with Next.js 16 and MapLibre GL, it uses WebGL rendering to maintain smooth 60 FPS performance, even when visualizing thousands of entities simultaneously.
Live Demo: https://osirisai.live/
GitHub: https://github.com/simplifaisoul/osiris
Osiris is a production-grade OSINT platform designed to deliver real-time situational awareness across multiple intelligence domains. Built with Next.js 16 and MapLibre GL, it uses WebGL rendering to maintain smooth 60 FPS performance, even when visualizing thousands of entities simultaneously.
๐ช That Dark Web Guy - Part 3 ๐ช
โผ๏ธ Security researcher Nightmare Eclipse has created a new GitHub repository called ShieldCrash, which is described as a Windows Defender zero-day vulnerability. Currently, the repository is empty. GitHub: https://github.com/MSNightmare/ShieldCrash
The repository has been updated.
๐ฅ1
๐จ Cybercrime forum member recruiting an Offensive Windows Developer
โ
A forum member using the handle Lockdowneds is seeking a low-level Windows developer for offensive security tooling, with emphasis on Windows internals rather than standard application development.
โ
Requested skills include:
โ
โข C/C++ and .NET
โข Windows API and Windows Internals
โข Portable Executable (PE) format
โข Understanding AV/EDR detections
โข Evasion techniques
โข Low-level Windows development
โข Custom offensive tooling
โข Implant and loader development
โ
Experience with reverse engineering, Red Team operations, and developing custom PoCs is listed as a major advantage.
โ
The poster states they are not looking for someone who can simply compile existing PoCs, but rather a strong low-level developer capable of building custom Windows tooling from scratch.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
A forum member using the handle Lockdowneds is seeking a low-level Windows developer for offensive security tooling, with emphasis on Windows internals rather than standard application development.
โ
Requested skills include:
โ
โข C/C++ and .NET
โข Windows API and Windows Internals
โข Portable Executable (PE) format
โข Understanding AV/EDR detections
โข Evasion techniques
โข Low-level Windows development
โข Custom offensive tooling
โข Implant and loader development
โ
Experience with reverse engineering, Red Team operations, and developing custom PoCs is listed as a major advantage.
โ
The poster states they are not looking for someone who can simply compile existing PoCs, but rather a strong low-level developer capable of building custom Windows tooling from scratch.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค2
โผ๏ธ SafePay Ransomware claims 9 victims
๐ต๐น HBPro Informรกtica e Serviรงos - A Portuguese IT and telecommunications company providing infrastructure, networking, cybersecurity, disaster recovery, printing, and technical support services.
๐ช๐ธ GSN Gestiรณn - A Spanish property-management company specializing in the administration of residential communities, commercial properties, garages, and other real estate.
๐ต๐ญ Century Maritime Agencies (CENMAR) - A Philippine crewing and manning agency that recruits and supplies Filipino seafarers for international shipping companies.
๐ช๐ธ Gayafores - A Spanish ceramic manufacturer specializing in porcelain floor and wall tiles for residential and commercial markets.
๐ฎ๐น Assiprime - An Italian insurance and financial services company providing insurance brokerage, risk management, financing, and financial consulting.
๐ฆ๐ท Fragancias Cannon - An Argentine fragrance company that develops, manufactures, and distributes perfumes, toiletries, and licensed fragrance brands.
๐ฆ๐น Municipality of Reichenau an der Rax - An Austrian municipal government providing public services and administration for the community of Reichenau an der Rax.
๐บ๐ธ Palmetto Eye Institute - A South Carolina ophthalmology practice specializing in cataract surgery, comprehensive eye care, and treatment of vision conditions.
๐จ๐ฆ McNish Steel - An Edmonton-based steel company specializing in reinforcing steel fabrication, welded cages, anchor bolts, and other rebar products.
๐ต๐น HBPro Informรกtica e Serviรงos - A Portuguese IT and telecommunications company providing infrastructure, networking, cybersecurity, disaster recovery, printing, and technical support services.
๐ช๐ธ GSN Gestiรณn - A Spanish property-management company specializing in the administration of residential communities, commercial properties, garages, and other real estate.
๐ต๐ญ Century Maritime Agencies (CENMAR) - A Philippine crewing and manning agency that recruits and supplies Filipino seafarers for international shipping companies.
๐ช๐ธ Gayafores - A Spanish ceramic manufacturer specializing in porcelain floor and wall tiles for residential and commercial markets.
๐ฎ๐น Assiprime - An Italian insurance and financial services company providing insurance brokerage, risk management, financing, and financial consulting.
๐ฆ๐ท Fragancias Cannon - An Argentine fragrance company that develops, manufactures, and distributes perfumes, toiletries, and licensed fragrance brands.
๐ฆ๐น Municipality of Reichenau an der Rax - An Austrian municipal government providing public services and administration for the community of Reichenau an der Rax.
๐บ๐ธ Palmetto Eye Institute - A South Carolina ophthalmology practice specializing in cataract surgery, comprehensive eye care, and treatment of vision conditions.
๐จ๐ฆ McNish Steel - An Edmonton-based steel company specializing in reinforcing steel fabrication, welded cages, anchor bolts, and other rebar products.
โผ๏ธ Liquid Network provided an incident report update. The latest update is that 3,400 BTC has been returned, while roughly 598.5 BTC, worth about $47 million, remains with the "self-described" white-hat actors.
Liquid is still paused while Blockstream and federation members complete security work and prepare a coordinated restart. ๐
https://x.com/Liquid_BTC/status/2097404704028545175
Liquid is still paused while Blockstream and federation members complete security work and prepare a coordinated restart. ๐
https://x.com/Liquid_BTC/status/2097404704028545175
X (formerly Twitter)
Liquid Network ๐ (@Liquid_BTC) on X
LIQUID NETWORK UPDATE: INCIDENT REPORT
Status as of September 8, 2026, 19:10 UTC
What Happened?
On September 6, 2026 at 15:53:10 UTC (Liquid block 4,050,336), a vulnerability in the open-source โฆ
Status as of September 8, 2026, 19:10 UTC
What Happened?
On September 6, 2026 at 15:53:10 UTC (Liquid block 4,050,336), a vulnerability in the open-source โฆ
โค1
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Tue, 8 Sep 2026 16:29:11 EDT
A cybersecurity incident has been disclosed by Veradigm Inc., Inc CIK: 0001124804, Ticker: (https://www.google.com/search?q=%24None+ticker).
View SEC Filing
Tue, 8 Sep 2026 16:29:11 EDT
A cybersecurity incident has been disclosed by Veradigm Inc., Inc CIK: 0001124804, Ticker: (https://www.google.com/search?q=%24None+ticker).
View SEC Filing
Dark Web Informer - Private
Cybersecurity Incident Disclosure Tue, 8 Sep 2026 16:29:11 EDT A cybersecurity incident has been disclosed by Veradigm Inc., Inc CIK: 0001124804, Ticker: (https://www.google.com/search?q=%24None+ticker). View SEC Filing
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
๐จ VERADIGM INC. has filed form 8-K due to a Cybersecurity incident
Incident: https://t.co/1W9ukJsvyq
"Veradigm Inc. (the โCompanyโ) recently learned that one of its third-party vendors experienโฆ
Incident: https://t.co/1W9ukJsvyq
"Veradigm Inc. (the โCompanyโ) recently learned that one of its third-party vendors experienโฆ
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
Texas Couple Sentenced for Operating Website Selling Smuggled Pesticides and Veterinary Drugs
Thao Duong and Lam Mai, a wife and husband from Garland, Texas, were sentenced today in federal court to charges stemming from their operation of a website selling veterinary drugs and pesticides smuggled into the United State from Mexico. Duong was sentencedโฆ
๐จ๐บ๐ธ 2.7M-user dataset from U.S. social marketplace allegedly offered on a cybercrime forum
โ
The listing describes the source as a U.S.-based social marketplace/network, though the specific platform is not identified in the post.
โ
A threat actor using the handle KrebsonFanAccount claims to be selling a private dataset containing approximately 2.7 million users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs and usernames
โข Password hashes
โข Email addresses
โข Display names
โข Account registration dates
โข User URLs
โข Account status information
โข Activation keys
โข Spam/deletion status fields
โ
The actor states the passwords use portable PHP password hashing and published a 1,000-record sample as proof of the claim.
โ
The claim, source of the dataset, and total number of affected records have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
The listing describes the source as a U.S.-based social marketplace/network, though the specific platform is not identified in the post.
โ
A threat actor using the handle KrebsonFanAccount claims to be selling a private dataset containing approximately 2.7 million users and published a sample of the purported records.
โ
Claimed data includes:
โ
โข User IDs and usernames
โข Password hashes
โข Email addresses
โข Display names
โข Account registration dates
โข User URLs
โข Account status information
โข Activation keys
โข Spam/deletion status fields
โ
The actor states the passwords use portable PHP password hashing and published a 1,000-record sample as proof of the claim.
โ
The claim, source of the dataset, and total number of affected records have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐1