CVE Exploit Sale, Pakistan Telecom Data Claim, WineStyle Leak, RDWeb Access, and Moscow Health Database Sale
SOCRadar Dark Web Team identified several new underground posts involving alleged exploit sales, large-scale database claims, and initial access broker activity. The findings include an alleged RCE exploit for CVE-2024-38077, a claimed Pakistan telecom database containing 30 million citizen records, an alleged WineStyle customer database leak, RDWeb access to a Spanish manufacturing firm, and a claimed Moscow City Health Department database sale.
Receive a Free Dark Web Report for Your Organization:
Alleged CVE-2024-38077 RCE Exploit Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged Remote Code Execution exploit for CVE-2024-38077, targeting Windows Server 2022. The seller claimed the package was designed for direct compromise and priced the exploit at $50,000.
The listing also claimed to include additional privilege escalation payloads based on Potato-family techniques and PrintSpoofer, suggesting the actor was marketing the package as a broader post-exploitation toolkit rather than a standalone exploit. If functional, such a package could support remote compromise, privilege escalation, lateral movement, and ransomware deployment against unpatched Windows Server environments.
Alleged Pakistan Telecom Citizen Database Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged database containing 30 million Pakistani citizen records, claimed to be sourced from a telecommunications provider. The listing stated that the dataset includes first names, last names, CNIC numbers, and physical addresses.
The exposure of CNIC numbers is especially sensitive, as these identifiers are widely used across financial, government, and utility services in Pakistan. However, the low asking price of $150 for such a large dataset raises questions about its freshness, exclusivity, or authenticity, meaning the claim should be treated as unverified until validated.
Alleged WineStyle Customer Database Leak is Detected

SOCRadar Dark Web Team detected a post claiming a breach of WineStyle, a Russian omnichannel retailer. The actor claimed to possess 1.1 million B2C and B2B customer records, including names, verified emails, direct phone numbers, order IDs, and purchase history.
If authentic, the dataset could be useful for targeted phishing and fraud because it combines contact details with transactional context. The inclusion of B2B customer records may also increase risk for corporate social engineering, where attackers can tailor lures around previous purchases, invoices, or vendor communications.
Alleged RDWeb Access to Spanish Manufacturer is Detected

SOCRadar Dark Web Team detected an initial access broker listing advertising alleged RDWeb access to a Spanish manufacturing company. The post described the target as a manufacturing firm with roughly $13 million in annual revenue, domain user access, and Sophos security software in the environment.
The auction started at $1,250, with a $2,500 blitz price. Even domain user-level RDWeb access can be valuable to ransomware operators, as it may provide an entry point for internal reconnaissance, credential theft, privilege escalation, and later-stage compromise.
Alleged Moscow Health Department Database Sale is Detected

SOCRadar Dark Web Team detected a post advertising an alleged database from mosgorzdrav.ru, associated with the Moscow City Health Department. The seller claimed the dataset contains 87 million records from 2025 and listed it for sale on a dark web forum.
The actor provided limited technical detail about the intrusion method or exact contents of the database. If authentic, the exposure could involve sensitive citizen or healthcare-related data, creating risks of identity theft, fraud, and targeted phishing. However, the unusually large claimed volume means the dataset may be exaggerated or aggregated from multiple sources rather than representing a single confirmed breach.
Powered by DarkMirror™
Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.

