From The Dark Side
Intelligence from the criminal underground — ransomware gang activity, credential markets, initial access brokers, data breach tracking, and emerging attack tooling. Curated by Security Arsenal analysts so your team has what it needs to stay ahead.
Live Ransomware Victims
refreshed every 5 minActive ransomware gang postings from public leak sites. For awareness and defensive intelligence only.
| Threat Group | Victim | Sector | Country | Discovered | |
|---|---|---|---|---|---|
| DYSPHOR1A | RTAD GOV MM | Government & Defense | MM | Sep 6, 2026 | Details |
| direwolf | eAssist Dental Solutions 🇺🇸 US COMPANY | Healthcare | US | Sep 6, 2026 | Details |
| chaos | evergenbio.com 🇺🇸 US COMPANY | Healthcare | US | Sep 6, 2026 | Details |
| Panzer | KHALED ALFAGIH ENGINEERING CONSULTANCY | Professional Services | SA | Sep 6, 2026 | Details |
| Panzer | Edacentrum | Not Found | DE | Sep 6, 2026 | Details |
| Vexy Ransomware | Sancity | Other | IN | Sep 6, 2026 | Details |
| direwolf | myLaurel 🇺🇸 US COMPANY | Healthcare | US | Sep 6, 2026 | Details |
| direwolf | Mission Pet Health 🇺🇸 US COMPANY | Healthcare | US | Sep 5, 2026 | Details |
| kazu | Spirit Cultural Exchange - US 🇺🇸 US COMPANY | Education | US | Sep 5, 2026 | Details |
| Vexy Ransomware | Mega Velocity | Transportation | MX | Sep 5, 2026 | Details |
Showing latest 10 victims. Full searchable database available.
View All & SearchIntelligence Categories
Click a category for full archive + SIGMA rulesUnderground Intelligence Feed
KRYBIT Ransomware Gang: 5 New Victims Posted — Healthcare and Education Targeting With Perimeter-Edge CVE Pressure
KRYBIT posted 5 new victims across healthcare, professional services, education and agri-food; defenders should prioritize edge-VPN, ScreenConnect, Exchange and pre-encryption staging hunts.
PANZER Ransomware: 4 Victims Posted in 72 Hours — European & Middle East Targeting, Sector Analysis & Detection Rules
PANZER posted 4 victims in 72 hours across Saudi Arabia, Germany, and Indonesia, hitting government, education, and professional services. Detection rules and IR priorities inside.
THEGENTLEMEN Ransomware Gang: 5 Victims in 5 Days — Transportation, Healthcare & Technology Under Active Fire
THEGENTLEMEN posted 5 victims across 4 countries in 5 days, hitting Transportation, Healthcare, Retail, and Tech. Enterprises with exposed VPNs, RDP, or unpatched KEV flaws should hunt now.
MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack
MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.
MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack
MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.
DIREWOLF Ransomware: 6 Victims in 5 Days — Cross-Sector Campaign Hits US Tech, Thai Energy, and Global Manufacturing
DIREWOLF posted 6 victims in 5 days spanning tech, energy, transportation, and manufacturing across US, ZA, TH, BR, ID. Edge-VPN and remote access exploitation suspected. Patch and hunt now.
FDMTP Implant via QuickFox Supply Chain Attack + ENDLESSDOORS Router Backdoor (CVE-2026-66747): OTX Detection Pack
Two supply chain campaigns exposed: trojanized QuickFox VPN installers deploying the FDMTP implant, and Zbtlink routers shipping with the pre-installed ENDLESSDOORS backdoor (CVE-2026-66747).
VEXY Ransomware Gang: 5 New Victims in 4 Days — India & LATAM Campaign, Sector Analysis & Detection Rules
VEXY Ransomware posted 5 victims in 4 days spanning manufacturing, retail, and hospitality across India, Ecuador, and Brazil. Edge-VPN CVEs flagged as likely entry vectors.
QILIN Ransomware Gang: 7 Victims in 5 Days — Government, Energy & Manufacturing Targeting with Detection Rules
Qilin (Agenda) posted 7 victims in 5 days across CA, US, CL, TR, AR — hitting government, energy co-ops, and manufacturing. KEV-linked edge exploitation suspected; detection rules included.
SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack
Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.
STORM Ransomware Gang: 8 New Victims in 72 Hours — Energy, Financial & Healthcare Targeting Analysis with Detection Rules
STORM posted 8 victims across CA, US, and AU in 72 hours, hitting energy, financial services, transportation, agriculture, and healthcare. Detection rules and IR priorities inside.
The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack
OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.
Frequently Asked Questions
Is Your Organization in the Underground?
Security Arsenal monitors dark web markets, ransomware leak sites, and criminal forums for your domains, IP ranges, and executive identities. We'll tell you if you're already being sold — before the attack begins.