From The Dark Side
Intelligence from the criminal underground — ransomware gang activity, credential markets, initial access brokers, data breach tracking, and emerging attack tooling. Curated by Security Arsenal analysts so your team has what it needs to stay ahead.
Live Ransomware Victims
refreshed every 5 minActive ransomware gang postings from public leak sites. For awareness and defensive intelligence only.
| Threat Group | Victim | Sector | Country | Discovered | |
|---|---|---|---|---|---|
| xpl0itrs | BMW Group | Manufacturing | DE | Aug 17, 2026 | Details |
| Global Secret Group | The Rubber Group 🇺🇸 US COMPANY | Manufacturing | US | Aug 17, 2026 | Details |
| Global Secret Group | 4M REALTY COMPANY 🇺🇸 US COMPANY | Retail & E-Commerce | US | Aug 17, 2026 | Details |
| Panzer | DL E&C | Manufacturing | KR | Aug 17, 2026 | Details |
| direwolf | Wishfully Studios | Technology | SE | Aug 17, 2026 | Details |
| direwolf | Arizona State University (ASU) 🇺🇸 US COMPANY | Education | US | Aug 17, 2026 | Details |
| direwolf | Eva AI Limited | Technology | GB | Aug 17, 2026 | Details |
| direwolf | Mighty Kingdom | Technology | AU | Aug 17, 2026 | Details |
| Panzer | Castilla La Mancha | Government & Defense | ES | Aug 17, 2026 | Details |
| Panzer | Doimo Cucine | Manufacturing | IT | Aug 17, 2026 | Details |
Showing latest 10 victims. Full searchable database available.
View All & SearchIntelligence Categories
Click a category for full archive + SIGMA rulesUnderground Intelligence Feed
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack
Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.
Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack
Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.
BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules
BLACKWATER posted 2 victims (IN, AR) to its dark web leak site on 2026-08-15. Healthcare & professional services orgs should hunt for VPN exploitation and pre-encryption staging now.
QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules
QILIN posted 15+ victims in a single day spanning manufacturing, financial services, transportation, and education across 8 countries. Enterprise defenders must patch Check Point, ConnectWise, and Exchange CVEs now.
LOCKBIT5 Ransomware Gang: 5 New Victims Posted in 48 Hours — European Campaign Analysis, CVE Exploitation Links & Detection Rules
LOCKBIT5 posted 5 victims in 48 hours across Germany, Italy, and France, hitting technology, energy, agriculture, and professional services. Patch Check Point, ScreenConnect, and Exchange now.
MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Campaign Analysis, Pre-Encryption Hunt Logic & Containment Playbook
MEDUSALOCKER posted 5 victims across tech, retail, manufacturing and transport in GB/DE/FR/ZA. Patch edge CVEs, hunt PsExec/WMI staging, isolate backup paths now.
XPL0ITRS Ransomware Gang: 3 New Victims Posted — Retail & Tech Sector Targeting Analysis with Detection Engineering
XPL0ITRS posted 3 new victims to its dark web leak site on 2026-08-15, spanning AU retail and US technology. Enterprises running Check Point, ScreenConnect, or Exchange must act now.
NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack
NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.
DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection Rules
DIREWOLF posted 6 victims in a single burst across healthcare, tech, and financial services in GB/US/BR/IN. Detection rules and IR priorities for defenders inside.
HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack
Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.
PAYLOAD Ransomware Gang: 4 New Victims Posted in 5 Days — DACH/Levant Targeting Analysis & Detection Engineering
PAYLOAD posted 4 new victims across Jordan, Germany, and Switzerland, hitting financial services, manufacturing, professional services, and tech. Mid-market orgs in DACH and the Levant should harden VPN/RDP perimeters now.
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack
Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.
Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack
OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.
Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack
UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.
Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack
OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.
THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection Rules
THEGENTLEMEN posted 15 victims in 24 hours spanning healthcare, manufacturing, retail and technology across 8 countries. Technology, healthcare and SMB-sector orgs must patch exposed gateways and hunt for pre-encryption staging now.
Frequently Asked Questions
Is Your Organization in the Underground?
Security Arsenal monitors dark web markets, ransomware leak sites, and criminal forums for your domains, IP ranges, and executive identities. We'll tell you if you're already being sold — before the attack begins.