From The Dark Side
Intelligence from the criminal underground — ransomware gang activity, credential markets, initial access brokers, data breach tracking, and emerging attack tooling. Curated by Security Arsenal analysts so your team has what it needs to stay ahead.
Live Ransomware Victims
refreshed every 5 minActive ransomware gang postings from public leak sites. For awareness and defensive intelligence only.
| Threat Group | Victim | Sector | Country | Discovered | |
|---|---|---|---|---|---|
| m3rx | cipher.systems 🇺🇸 US COMPANY | Technology | US | Sep 26, 2026 | Details |
| Barracuda | International Chemical Co. | Manufacturing | — | Sep 26, 2026 | Details |
| termite | Crossett 🇺🇸 US COMPANY | Other | US | Sep 25, 2026 | Details |
| SilentRansomGroup | N... | Not Found | — | Sep 25, 2026 | Details |
| SilentRansomGroup | S... | Not Found | — | Sep 25, 2026 | Details |
| metaencryptor | GE Vernova Inc. 🇺🇸 US COMPANY | Energy & Utilities | US | Sep 25, 2026 | Details |
| metaencryptor | PKF Hadiwinata | Professional Services | ID | Sep 25, 2026 | Details |
| metaencryptor | Platinum Healthcare Staffing 🇺🇸 US COMPANY | Healthcare | US | Sep 25, 2026 | Details |
| everest | Securitas Group | Professional Services | SE | Sep 25, 2026 | Details |
| emperador | Electrolux & Ontrac | Manufacturing | — | Sep 25, 2026 | Details |
Showing latest 10 victims. Full searchable database available.
View All & SearchIntelligence Categories
Click a category for full archive + SIGMA rulesUnderground Intelligence Feed
Moobot/Mirai Botnet Resurgence: Open Directory Exposure of 'StresD Pro+' DDoS-as-a-Service Panel — OTX Pulse Analysis & Detection Pack
OTX pulse reveals exposed Moobot source code and active 'StresD Pro+' DDoS panel post-2024 takedown. IoT botnet ops tied to China-linked infrastructure. High urgency.
DARKLANTERN, SPEAKINGSTONE & ENDLESSDOORS: ZBT Router Firmware Implants in the Global Supply Chain — OTX Pulse Analysis & Detection Pack
Three firmware implants embedded in ZBT routers expose root shell access via unauthenticated UDP 9992 backdoor. Global supply chain reach across 11 countries. Critical urgency.
BARRACUDA Ransomware Gang: 3 New Leak-Site Listings — Sector Targeting Analysis, Detection Rules & Response Playbook
BARRACUDA listed 3 organizations on its dark web leak site this week — manufacturing and services firms, with Argentina in scope. Unverified claims; detection rules inside.
THEGENTLEMEN Ransomware Gang: 4 New Leak-Site Claims — Sector Targeting Analysis & Detection Engineering
THEGENTLEMEN has listed 4 new organizations on its dark web leak site spanning Technology, Manufacturing, and Retail across US, SG, and PT. All listings are single-source, unverified claims.
AKIRA Ransomware Gang: 5 New Victim Claims Posted — Manufacturing & Professional Services Listing Analysis With Detection Rules
AKIRA's leak site added 5 new claimed victims in 72 hours, concentrated in US manufacturing and professional services. Unverified claims — but the exposure signals are actionable now.
TERMITE Ransomware Gang: 4 New Leak-Site Listings in 4 Days — US-Only Targeting, Sector Analysis & Detection Rules
TERMITE listed 4 US organizations on its leak site between 2026-09-22 and 2026-09-25 — all single-source claims spanning manufacturing, financial services, and real estate. Unverified; defenders should treat as exposure signal.
Salt Typhoon / Fire Ant TACACS+ Pre-Auth RCE (CVE-2026-48842): OTX Pulse Analysis — Telecom Infrastructure Detection Pack
OTX flags critical pre-auth RCE in TACACS+ (CVE-2026-48842) tied to Salt Typhoon/Fire Ant telecom espionage. Pre-authentication exploitation of network AAA. URGENT.
AnonyMousKIT AI-Powered PhaaS Supply Chain: 506-Domain Apple Activation Lock Phishing Network — OTX Detection Pack
OTX exposes AnonyMousKIT, an AI-driven PhaaS with 506 domains harvesting Apple ID credentials via SMS, WhatsApp, email & vishing. Gov/Edu targeted. HIGH urgency.
EVEREST Ransomware Gang: 6 New Leak-Site Listings Posted — Sector Targeting Analysis & Detection Rules
EVEREST listed six organizations across professional services, healthcare, technology and education; defenders in SE, ZA, JP and BE should hunt pre-encryption staging now.
OpenSUpdater SFX Evasion, Sliver C2 Against Philippine Nuclear/Defense, and SilentXMRMiner On-Endpoint Compilation: OTX Pulse Analysis — Enterprise Detection Pack
Three active campaigns: OpenSUpdater hidden in recompiled 7zip SFX, Chinese-speaking APT exfiltrating 9GB from Philippine nuclear/defense targets, and silent Monero miners compiled directly on endpoints. High urgency.
ClickFix Clipboard Poisoning via third-party.com, Galago Ransomware Emergence, and TACACS+ Pre-Auth RCE: OTX Pulse Analysis — Enterprise Detection Pack
ClickFix lures hijack placeholder domain third-party.com; Galago ransomware hits Icelandic healthcare; critical pre-auth RCE in TACACS+ protocol. Hunt now.
WALLSTREET Ransomware Gang: 7 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
WALLSTREET listed 7 organizations across manufacturing, energy, finance, healthcare, legal, and education in GB/US/SV. Unverified claims; defenders should hunt pre-ransom TTPs now.
Dark Caracal GoCaracal Framework + Russian Evilginx OAuth Phishing Clusters: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal Dark Caracal's new GoCaracal modular espionage framework targeting Latin America and Russian clusters (UNC6293/UNC7005/UNC5976) running Evilginx OAuth/device-code phishing against academia and government. High urgency — credential theft at scale.
INCRANSOM: 6 New Leak-Site Listings — Healthcare and Professional Services Claims, Exposure Analysis & Detection Rules
INCRANSOM listed six organizations across healthcare, professional services, and manufacturing; defenders should prioritize access, staging, and exfiltration controls.
RemotePanel + BoundSiphon: ClickFix-Delivered Dual-Payload Toolkit for Persistent Access & Browser Credential Theft — OTX Detection Pack
OTX pulse details two undocumented .NET payloads — RemotePanel HVNC RAT and BoundSiphon browser stealer — deployed via ClickFix chains with blockchain-based C2 resolution. Immediate credential rotation advised.
N0N Ransomware Gang: 3 Leak-Site Listings Across Technology and Retail — Detection Rules & Sector Exposure
N0N lists 3 orgs across US, ML, and UZ technology and retail; all are single-source claims. Technology, retail, and IT services teams should hunt remote-access and staging indicators.
HookBot Android Banking Trojan Leak, ClickFix Clipboard Poisoning & Konni VelvetCake LNK Campaign: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose leaked HookBot/ERMAC panels with default creds, ClickFix lures on third-party[.]com, and Konni's VelvetCake LNK campaign targeting Ukraine. Hunt now.
Frequently Asked Questions
Is Your Organization in the Underground?
Security Arsenal monitors dark web markets, ransomware leak sites, and criminal forums for your domains, IP ranges, and executive identities. We'll tell you if you're already being sold — before the attack begins.