From The Dark Side
Intelligence from the criminal underground — ransomware gang activity, credential markets, initial access brokers, data breach tracking, and emerging attack tooling. Curated by Security Arsenal analysts so your team has what it needs to stay ahead.
Live Ransomware Victims
refreshed every 5 minActive ransomware gang postings from public leak sites. For awareness and defensive intelligence only.
| Threat Group | Victim | Sector | Country | Discovered | |
|---|---|---|---|---|---|
| bravox | MEDICOS | Healthcare | FR | Aug 7, 2026 | Details |
| spacebears | Hitech Distribuzione Informatica S.r.l. (HTDI) | Technology | IT | Aug 7, 2026 | Details |
| qilin | Astro Electroplating 🇺🇸 US COMPANY | Manufacturing | US | Aug 7, 2026 | Details |
| qilin | Filtronic | Manufacturing | GB | Aug 7, 2026 | Details |
| qilin | John C Saunders, CPA 🇺🇸 US COMPANY | Professional Services | US | Aug 7, 2026 | Details |
| clop | CONTINENTAL.AERO 🇺🇸 US COMPANY | Transportation | US | Aug 7, 2026 | Details |
| clop | MINDRAY.COM | Healthcare | CN | Aug 7, 2026 | Details |
| incransom | ATMS | Transportation | IN | Aug 7, 2026 | Details |
| thegentlemen | Hartfiel Automation | Manufacturing | DE | Aug 7, 2026 | Details |
| Helix | Venture Logistics | Transportation | — | Aug 7, 2026 | Details |
Showing latest 10 victims. Full searchable database available.
View All & SearchIntelligence Categories
Click a category for full archive + SIGMA rulesUnderground Intelligence Feed
BRAVOX Ransomware Gang: 2 New Victims Posted — European Healthcare & Industrial Targeting Analysis with Detection Rules
BRAVOX posted 2 new victims on its leak site (FR healthcare, CH industrial). European healthcare and mid-market orgs should audit VPN/edge device exposure and deploy the included detection content now.
KRYBIT Ransomware Gang: 5 New Victims Posted in 24 Hours — French SMB Surge, Cross-Continent Reach & Detection Rules
KRYBIT posted 5 victims to its dark web leak site on 2026-08-07, concentrated in France with reach into South Africa and Peru. Technology and professional services firms should audit VPN and remote access exposure now.
Vanta Stealer: Python-Based Cross-Platform Infostealer Targets Browser Credentials, Discord Tokens & Crypto Wallets — OTX Detection Pack
OTX pulse exposes Vanta Stealer, a PyArmor-obfuscated Python infostealer harvesting Chromium credentials, Discord/Telegram tokens, gaming accounts & crypto wallets. Hunt now.
LYNX Ransomware Gang: 2 New Victims Posted on Leak Site — Campaign Analysis, KEV Exploitation Links & Detection Rules
LYNX ransomware posted 2 new victims (GB, US) to its dark web leak site on 2026-08-06. Edge-device and MSP-tool CVE exploitation is the suspected access vector — patch and hunt now.
ENDLESSDOORS Router Backdoor + Legion Loader TDS + MUSTANG PANDA ZOHOMURK: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal pre-installed IoT backdoors (ENDLESSDOORS), a 12,700-domain fake-CAPTCHA traffic distribution system, and MUSTANG PANDA espionage against India's government and energy sectors.
Vidar Stealer, Overlord RAT & MacSync: Cross-Platform Credential Theft Campaign — OTX Pulse Detection Pack
OTX pulses expose coordinated stealer campaigns: Vidar+XMRig via malvertising, Overlord RAT via fake Zoom on macOS, and MacSync via ClickFix fake CAPTCHA. High urgency for SOC teams.
Vidar/XMRig Factory-v3, Vanta, MacSync ClickFix, UNC6671 Vishing and Storm-2755 AiTM: OTX Credential-Theft Detection Pack
OTX pulses flag Vidar/XMRig malvertising, Vanta and MacSync stealers, UNC6671 vishing/AiTM and Storm-2755 M365 payroll BEC. Credential theft risk: high.
HELIX Ransomware Gang: 5 New Victims Posted in 24 Hours — Transportation & Financial Services Surge, Detection Rules Included
HELIX posted 5 victims to its dark web leak site on 2026-08-07, hitting Transportation and Financial Services across US/CA. Detection rules and IR playbook inside.
DARK PROJECT Ransomware Gang: 3 New Victims Posted — Energy, Transportation & Automotive Targeting Analysis With Detection Rules
DARK PROJECT posted 3 victims to its .onion leak site on 2026-08-04, hitting US energy and automotive firms plus a Philippine logistics operator. Energy, transportation, and mid-market enterprises should review perimeter CVEs and lateral movement detections now.
DRAGONFORCE Ransomware Gang: 4 US Victims in Single-Day Leak Batch — SMB Targeting Analysis & Detection Rules
DragonForce posted 4 US victims in one day across healthcare, manufacturing, and hospitality. SMB-focused campaign analysis, Sigma rules, KQL hunts, and IR guidance.
Larva-26005 Xctdoor Backdoor, UAT-7810 LapDogs ORB Expansion & Fake CAPTCHA TDS: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose North Korea-linked Xctdoor backdoor ops, UAT-7810's LapDogs ORB malware family, and a 12,700-PDF fake CAPTCHA traffic distribution network. High urgency.
Larva-26005 (North Korea) Xctdoor Backdoor Campaign: CRAT Lineage, DLL Side-Loading & Ngrok C2 — OTX Enterprise Detection Pack
DPRK-linked Larva-26005 distributes Xctdoor backdoors via spear-phished LNK files and fake security installers, targeting Korean defense & tech orgs. Hunt and block now.
QILIN Ransomware Gang: 11 New Victims in 72 Hours — Manufacturing Surge, Edge-Device CVE Exploitation & Detection Rules
QILIN posted 11 victims across 7 countries in 72 hours, heavily targeting manufacturing and professional services. Energy, financial, and industrial orgs must patch edge CVEs and hunt for staging indicators now.
keyv & cacheable npm Supply Chain Compromise: Self-Propagating Cloud Credential Theft — OTX Pulse Analysis & Enterprise Detection Pack
Active npm supply chain attack via compromised keyv/cacheable packages deploys self-propagating cloud credential stealers through preinstall hooks. Tens of millions of weekly downloads affected. Immediate action required.
BARRACUDA Ransomware Gang: 4 New Victims Posted in 48 Hours — Manufacturing & Healthcare Targeting Analysis with Detection Rules
BARRACUDA posted 4 new victims across CN, US, and KR in 48 hours, hitting manufacturing, healthcare, and technology firms. Security teams must verify perimeter patching and hunt pre-encryption staging now.
npm Supply Chain Compromise: keyv & cacheable Packages Poisoned with Ethereum C2 Credential Stealer — OTX Pulse Analysis
Active npm supply chain attack hits keyv/cacheable (tens of millions of weekly downloads). Malicious preinstall hooks steal cloud credentials via Ethereum-contract C2. Hunt now.
CL0P Ransomware Gang: 40 New Victims Posted — Sector Targeting Analysis & Detection Rules
CL0P posted 40 victims on 2026-08-05, mostly sector-unattributed with Technology and Financial Services confirmed; edge, finance and tech teams should patch KEVs and hunt pre-encryption staging.
Frequently Asked Questions
Is Your Organization in the Underground?
Security Arsenal monitors dark web markets, ransomware leak sites, and criminal forums for your domains, IP ranges, and executive identities. We'll tell you if you're already being sold — before the attack begins.