Uptime Hamster: 21d 12h 46mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza x-cti

x-cti

47 incidentes 5 paises 5 sectores Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →

Actores similares

they-have-victimized-at-lactor · 1activistsactor · 1damage---destructionactor · 1nbsp-activeactor · 1crimson-collectiveactor · 1actiniumactor · 1Extra Window Memory Injectionactor · 1Gather Victim Host Informationactor · 1Internet Connection Discoveryactor · 1Email Collectionactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownnitter.netRansomware Monitor: Actor: #Qilin Victim: NASCO Date: 2026-06-29 10:23:25 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added NASCO to its victims.
X/Twitterunknownx.comRansomware Monitor: Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims.
DLS / leak siteunknownnitter.netRansomware Monitor: Actor: #Qilin Victim: AXIONLOG Date: 2026-06-29 10:23:27 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added AXIONLOG to its victims.
DLS / leak siteunknownnitter.netDark Web Informer: Ancient civilization used to call this cable management.
Forounknownx.comDark Web Informer: Government of Colima e-signature system compromise claim posted on a forum ACTIVA appears to be tied to the advanced electronic signature system used by the Government of the State of Colima, Mexico. A forum user claims they gained administrator access to the ACTIVA Firma portal and allegedly deleted users from the system, leaving only an administrator account under their control.
DLS / leak siteunknownnitter.netRansomware Monitor: Actor: #Qilin Victim: TRANSCORE Date: 2026-06-29 02:30:45 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added TRANSCORE to its victims.
DLS / leak siteunknownnitter.netRansomware Monitor: Actor: #Qilin Victim: 1-800-DENTIST Date: 2026-06-29 02:30:48 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added 1-800-DENTIST to its victims.
DLS / leak siteunknownnitter.netDark Web Informer: RT by @DarkWebInformer: ‼ CVE-2026-48907: Joomla! JCE extension 2.9.99.5 - unauthenticated Remote Code Execution Video Credit: @0xgh057r3c0n
DLS / leak siteunknownnitter.netDark Web Informer: RT by @DarkWebInformer: ‼ CVE-2026-48907: Joomla! JCE extension 2.9.99.5 - unauthenticated Remote Code Execution Video Credit: @0xgh057r3c0n
DLS / leak siteunknownnitter.netDark Web Informer: I haven't posted many Ransomware free posts on the website in quite some time... that should change this week. I wanted to settle on a template that works better than the threat alert one I'm using. Nothing else changes in general... socials still get all the normal posts.
DLS / leak siteunknownnitter.netDark Web Informer: ‼ 1-800-DENTIST has been claimed a victim to Qilin Ransomware
DLS / leak siteunknownnitter.netDark Web Informer: Ugh, you may want to fix your auto posts mate.
DLS / leak siteunknownnitter.netDark Web Informer: Ugh, you may want to fix your auto posts mate.
Forounknownnitter.netDark Web Informer: Amigo Tech patient dataset claim posted on a forum Amigo Tech is a Brazilian healthtech company connected to healthcare scheduling and patient management services. A forum user claims a partial breach tied to Amigo Tech, allegedly containing 121,678 patient records from March 2026.
DLS / leak siteunknownnitter.netDark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion
DLS / leak siteunknownnitter.netDark Web Informer: Priorities: save the codebase, then yourself.
Forounknownnitter.netDark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.
Forounknownnitter.netDark Web Informer: VRI Portal de Conteúdo dataset claim posted on a forum VRI Portal de Conteúdo is a Brazilian content portal focused on technical material in accounting, corporate, labor, and tax law areas. A forum user claims a dataset tied to VRI Portal de Conteúdo was exposed, allegedly containing 40K rows.
Forounknownnitter.netDark Web Informer: Government of Colima e-signature system compromise claim posted on a forum ACTIVA appears to be tied to the advanced electronic signature system used by the Government of the State of Colima, Mexico. A forum user claims they gained administrator access to the ACTIVA Firma portal and allegedly deleted users from the system, leaving only an administrator account under their control.
Foroseizednitter.netDaily Dark Web: Major International Anti-Piracy Operation Seizes Pirate Streaming Infrastructure Law enforcement agencies from multiple countries have seized domains and infrastructure associated with large-scale piracy services as part of **Operation Offside**. * The seizure banner identifies participation from agencies including: * U.S.
Forounknownx.comDaily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.
Forounknownnitter.netDaily Dark Web: Is this accurate?
Forounknownnitter.netDaily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.
Forounknownnitter.netDaily Dark Web: What do you think?
Victimas
31
TTPs unicas
1
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

TTPs observadas

T1566 Phishing

Paises afectados

United States (8) France (3) Brazil (1) Mexico (2) Croatia (1)

Sectores atacados

Media (21) Healthcare (2) Legal (1) Government (2) Law (2)

URLs nuevas detectadas en IntelTracker

nitter.net x.com nitter.net nitter.net x.com nitter.net nitter.net nitter.net nitter.net nitter.net nitter.net nitter.net

Victimas (31)

Ransomware Monitor: Actor: #Qilin Victim: NASCO Date: 2026-06-29 10:23:25 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added NASCO to its victims.29 Jun 2026
Ransomware
Actor: #Qilin Victim: NASCO Date: 2026-06-29 10:23:25 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence T…
Ransomware Monitor: Actor: #Qilin Victim: AXIONLOG Date: 2026-06-29 10:23:27 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added AXIONLOG to its victims.29 Jun 2026
Ransomware
Actor: #Qilin Victim: AXIONLOG Date: 2026-06-29 10:23:27 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligenc…
Ransomware Monitor: Actor: #Qilin Victim: TRANSCORE Date: 2026-06-29 02:30:45 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added TRANSCORE to its victims.28 Jun 2026
Ransomware
Actor: #Qilin Victim: TRANSCORE Date: 2026-06-29 02:30:45 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligen…
Ransomware Monitor: Actor: #Qilin Victim: 1-800-DENTIST Date: 2026-06-29 02:30:48 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#Qilin” Ransomware group has added 1-800-DENTIST to its victims.28 Jun 2026
Ransomware
Actor: #Qilin Victim: 1-800-DENTIST Date: 2026-06-29 02:30:48 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intell…
Dark Web Informer: RT by @DarkWebInformer: ‼ CVE-2026-48907: Joomla! JCE extension 2.9.99.5 - unauthenticated Remote Code Execution Video Credit: @0xgh057r3c0n28 Jun 2026
Vulnerability Media
RT by @DarkWebInformer: ‼ CVE-2026-48907: Joomla! JCE extension 2.9.99.5 - unauthenticated Remote Code Execution Video Credit: @0xgh057r3c0n Dark web …
Dark Web Informer: I haven't posted many Ransomware free posts on the website in quite some time... that should change this week. I wanted to settle on a template that works better than the threat alert one I'm using. Nothing else changes in general... socials still get all the normal posts.28 Jun 2026
Ransomware
I haven't posted many Ransomware free posts on the website in quite some time... that should change this week. I wanted to settle on a template t…
Dark Web Informer: ‼ 1-800-DENTIST has been claimed a victim to Qilin Ransomware28 Jun 2026
Ransomware Media
‼ 1-800-DENTIST has been claimed a victim to Qilin Ransomware Dark web monitoring and threat intelligence feed on ransomware groups and data leak site…
Dark Web Informer: Amigo Tech patient dataset claim posted on a forum Amigo Tech is a Brazilian healthtech company connected to healthcare scheduling and patient management services. A forum user claims a partial breach tied to Amigo Tech, allegedly containing 121,678 patient records from March 2026.28 Jun 2026
Breach United States Healthcare
Amigo Tech patient dataset claim posted on a forum Amigo Tech is a Brazilian healthtech company connected to healthcare scheduling and patient managem…
Dark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion28 Jun 2026
Ransomware Media
‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion Dark web monitoring and threat intelligence fe…
Dark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.28 Jun 2026
Ransomware France Media
Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a foru…
Dark Web Informer: VRI Portal de Conteúdo dataset claim posted on a forum VRI Portal de Conteúdo is a Brazilian content portal focused on technical material in accounting, corporate, labor, and tax law areas. A forum user claims a dataset tied to VRI Portal de Conteúdo was exposed, allegedly containing 40K rows.28 Jun 2026
Breach Brazil Legal
VRI Portal de Conteúdo dataset claim posted on a forum VRI Portal de Conteúdo is a Brazilian content portal focused on technical material in accountin…
Daily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.28 Jun 2026
Vulnerability United States Media
Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-…
Daily Dark Web: Clearcover Customer Data Allegedly Offered for Sale A threat actor claims to be selling a database allegedly belonging to U.S. auto insurer Clearcover. * According to the forum post, the dataset is dated **25 June 2026** and allegedly contains **448,603** records.28 Jun 2026
Breach Media
Clearcover Customer Data Allegedly Offered for Sale A threat actor claims to be selling a database allegedly belonging to U.S. auto insurer Clearcover…
Daily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.28 Jun 2026
Breach United States Media
Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global …
Daily Dark Web: Croatian Student Database Allegedly Shared on Dark Web Forum A threat actor has published what they claim is a database containing approximately 954,000 records related to students from Croatian primary and secondary schools.28 Jun 2026
Breach Croatia Education
Croatian Student Database Allegedly Shared on Dark Web Forum A threat actor has published what they claim is a database containing approximately 954,0…
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.28 Jun 2026
Ransomware France Healthcare
French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating fro…
Ransomware Monitor: Actor: #akira Victim: Precise Forms Date: 2026-06-26 19:01:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#akira” Ransomware group has added Precise Forms to its victims.26 Jun 2026
Ransomware
Actor: #akira Victim: Precise Forms Date: 2026-06-26 19:01:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intell…
Ransomware Monitor: Actor: #nova Victim: NSW Rural Fire Service Date: 2026-06-26 17:15:21 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nova” Ransomware group has added NSW Rural Fire Service to its victims.26 Jun 2026
Ransomware
Actor: #nova Victim: NSW Rural Fire Service Date: 2026-06-26 17:15:21 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threa…
Ransomware Monitor: Actor: #payload Victim: Software Arge Date: 2026-06-26 17:19:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Software Arge to its victims.26 Jun 2026
Ransomware Software
Actor: #payload Victim: Software Arge Date: 2026-06-26 17:19:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Inte…
Ransomware Monitor: Actor: #payload Victim: Clínica La Sabana Date: 2026-06-26 17:19:50 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Clínica La Sabana to its victims.26 Jun 2026
Ransomware
Actor: #payload Victim: Clínica La Sabana Date: 2026-06-26 17:19:50 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat …
Ransomware Monitor: Actor: #nova Victim: vslmarine Date: 2026-06-26 14:13:51 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nova” Ransomware group has added vslmarine to its victims.26 Jun 2026
Ransomware
Actor: #nova Victim: vslmarine Date: 2026-06-26 14:13:51 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligenc…
Ransomware Monitor: Actor: #payload Victim: Mosaic Partners Date: 2026-06-26 16:17:54 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Mosaic Partners to its victims.26 Jun 2026
Ransomware
Actor: #payload Victim: Mosaic Partners Date: 2026-06-26 16:17:54 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat In…
Ransomware Monitor: Actor: #ailock Victim: Hokua Date: 2026-06-26 14:38:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#ailock” Ransomware group has added Hokua to its victims.26 Jun 2026
Ransomware
Actor: #ailock Victim: Hokua Date: 2026-06-26 14:38:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence …
Ransomware Monitor: Actor: #incransom Victim: GSP Crop Science Pvt Date: 2026-06-26 07:10:34 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added GSP Crop Science Pvt to its victims.26 Jun 2026
Ransomware
Actor: #incransom Victim: GSP Crop Science Pvt Date: 2026-06-26 07:10:34 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Th…
Ransomware Monitor: Actor: #incransom Victim: Life Bridges Date: 2026-06-26 05:08:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added Life Bridges to its victims.26 Jun 2026
Ransomware
Actor: #incransom Victim: Life Bridges Date: 2026-06-26 05:08:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Int…
Ransomware Monitor: Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims.26 Jun 2026
Ransomware
Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat …
Group-IB Threat Intelligence: Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and resilience, making detection more challenging. The #Telegram Bot API remains the core C2 mechanism.25 Jun 2026
Malware Media
Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C…
Group-IB Threat Intelligence: SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. These additions reflect the growing focus on direct monetization within modern #malware ecosystems.10 Jun 2026
Malware United States Media
SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifact…
Group-IB Threat Intelligence: Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records that contain legitimate individual identifiers but do not represent actual customers of the targeted organizations.20 May 2026
Breach Media
Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corr…
Group-IB Threat Intelligence: Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Europe, APAC, and the US. Despite sector-specific lures, the geographic distribution and brand impersonation patterns indicate coordinated deployment within the same smishing infrastructure. #ThreatIntel29 Apr 2026
Phishing United States Media
Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and teleco…

Mostrant 30 de 31 victimas. Ver todas