From The Dark Side
Intelligence from the criminal underground — ransomware gang activity, credential markets, initial access brokers, data breach tracking, and emerging attack tooling. Curated by Security Arsenal analysts so your team has what it needs to stay ahead.
Live Ransomware Victims
refreshed every 5 minActive ransomware gang postings from public leak sites. For awareness and defensive intelligence only.
| Threat Group | Victim | Sector | Country | Discovered | |
|---|---|---|---|---|---|
| qilin | Law Office of Steven R Smith 🇺🇸 US COMPANY | Business Services | US | May 4, 2026 | Details |
| qilin | Foxstone Financial | Financial Services | AU | May 4, 2026 | Details |
| qilin | Lexus | Manufacturing | JP | May 4, 2026 | Details |
| qilin | Rizzuto Law Firm 🇺🇸 US COMPANY | Business Services | US | May 4, 2026 | Details |
| qilin | General Hardware | Manufacturing | CO | May 4, 2026 | Details |
| chaos | vacaero.com | Hospitality and Tourism | MX | May 4, 2026 | Details |
| chaos | www.cswindustrials.com 🇺🇸 US COMPANY | Manufacturing | US | May 4, 2026 | Details |
| interlock | Lonestar Truck Group & Tag Truck Center 🇺🇸 US COMPANY | Transportation/Logistics | US | May 4, 2026 | Details |
| lamashtu | Luna Group | Not Found | EG | May 4, 2026 | Details |
| qilin | City of Sandstone 🇺🇸 US COMPANY | Public Sector | US | May 4, 2026 | Details |
Showing latest 10 victims. Full searchable database available.
View All & SearchIntelligence Categories
Click a category for full archive + SIGMA rulesUnderground Intelligence Feed
KarstoRAT, LofyStealer & Malicious AI Extensions: OTX Pulse Analysis — Credential Theft & Supply Chain Threats
Emerging threats: KarstoRAT, ClickFix, LofyStealer, and malicious AI extensions target credentials via gaming lures, supply chain, and browser extensions. Urgency: High.
Frequently Asked Questions
Is Your Organization in the Underground?
Security Arsenal monitors dark web markets, ransomware leak sites, and criminal forums for your domains, IP ranges, and executive identities. We'll tell you if you're already being sold — before the attack begins.