Under the Spotlight: RAMP Forum
Under the Spotlight: RAMP Forum In July 2021, a new Russian-speaking forum called RAMP, Russian Anonymous Market Place, which attracts a lot of interest from researchers and cybercriminals, was forme...
AstraLocker Shut Down Their Operations and Released Decryptor
AstraLocker Shut Down Their Operations and Released Decryptor A ransomware gang AstraLocker, recently announced they are shutting down their operations and shared decryptors related to all the campaig...
Dark Web Profile: Netwalker Ransomware
Dark Web Profile: Netwalker Ransomware Today, with the effects of digitalization, most of the information is stored online. This situation creates a vulnerability for organizations because the number ...
Deep Web Profile: REvil
Deep Web Profile: REvil REvil is a ransomware hacking group, as its name suggests -REvil = “ransomware” + “evil”-. This ransomware group is thought to be centered in Russia. It is also named “Sodinoki...
20 Interesting Facts About Ransomware
20 Interesting Facts About Ransomware Ransomware attacks marked 2021 and continue to make a splash in 2022. We’ve compiled some interesting information about this type of attack that has frightened fi...
Deep Web Profile: Karakurt Extortion Group
Deep Web Profile: Karakurt Extortion Group Karakurt has extorted sensitive data from nearly 40 different organizations within a year, a Russian-originated cybercriminal organization. So what is the ca...
The Week in Dark Web - 16 May 2022 - Access Sales and Data Leaks
The Week in Dark Web – 16 May 2022 – Access Sales and Data Leaks Powered by DarkMirror™ This week’s edition covers the latest dark web news from the past week. Again, rise of ransomware attacks, some ...
What is the RaidForums?
What is the RaidForums? RaidForums was launched in 2015 by Diogo Santos Coelho of Portugal, aka Omnipotent. Cybercriminals enormously used the RaidForums hacker site to obtain and sell stolen da...
The Week in Dark Web - 9 May 2022 - Access Sales and Data Leaks
The Week in Dark Web – 9 May 2022 – Access Sales and Data Leaks Powered by DarkMirror™ This week’s edition covers the latest dark web news from the past week. Again, rise of ransomware attacks, some d...
The Week in Dark Web - 25 April 2022 - Access Sales and Data Leaks
The Week in Dark Web – 25 April 2022 – Access Sales and Data Leaks Powered by DarkMirror™ This week’s edition covers the latest dark web news from the past week. Again, rise of ransomware attacks, som...
Deep Web Profile: AgainstTheWest / BlueHornet [Part 2]
Deep Web Profile: AgainstTheWest / BlueHornet [Part 2] As explained in the first part, the famous leak group AgainstTheWest/BlueHornet decided to shut their operations after their unsuccessful private...
The Week in Dark Web - 18 April 2022 - Access Sales and Data Leaks
The Week in Dark Web – 18 April 2022 – Access Sales and Data Leaks Powered by DarkMirror™ This week’s edition covers the latest dark web news from the past week. Again, rise of ransomware attacks, som...
Deep Web Profile: AgainstTheWest / BlueHornet [Part 1]
Deep Web Profile: AgainstTheWest / BlueHornet [Part 1] In October 2021, a new leak group emerged in RaidForums with the handle AgainstTheWest. They have started actively targeting major organizations ...
‘Fullz,’ ‘Dumps,’ and More: What do Hackers Sell on the Black Market?...
‘Fullz,’ ‘Dumps,’ and More: What do Hackers Sell on the Black Market? It’s easy to appreciate the importance hackers place on stolen bank accounts, credit cards, and social security numbers. Each of t...
The Top 10 Dark Web Telegram Chat Groups and Channels
The Top 10 Dark Web Telegram Chat Groups and Channels After the privacy policy scandal of WhatsApp in January 2021, Telegram was one of the trending apps to replace WhatsApp regarding its privacy poli...
Is Nginx Zero-Day RCE Vulnerability False Alarm?
Is Nginx Zero-Day RCE Vulnerability False Alarm? On Saturday, April 9, it was announced that there was a zero-day RCE vulnerability for webserver Nginx version 1.18 in the post made from the Twit...
Android Banking Malware Octo Allows Remote Control on Infected Devices
Android Banking Malware Octo Allows Remote Control on Infected Devices A banking trojan Octo has been discovered, downloaded from the Google Play Store, and targeting banks and financial institutions....
New Remote Access Trojan (RAT) named Borat on the Darknet Markets
New Remote Access Trojan (RAT) named Borat on the Darknet Markets Threat actors are developing more advanced attack techniques every day. They even help non-technical attackers by publishing toolkits....
What Cyber Security Experts Think: How to Make Money on the Dark Web?
What Cyber Security Experts Think: How to Make Money on the Dark Web? People increasingly purchase and sell items in the Internet’s most obscure corners. Amazon, Shopify, Walmart, and eBay are all wel...
Dark Web Profile: Lapsus$ Extortion Group
Dark Web Profile: Lapsus$ Extortion Group [Update] August 11, 2023: The Cyber Safety Review Board (CSRB) published a review of the Lapsus$ extortion group’s attacks. Read more under: “A Review of Laps...