Author: kathy hoffman

Why Cybersecurity Is a Business Issue, Not Just an IT issue!

August 13, 2026

Cybersecurity is no longer a concern confined just to IT departments. It is a fundamental business issue that should touch every layer of an organization. Attacks against organizations can have far reaching implications. For instance, a single breach can result in devastating financial losses, regulatory fines, operational downtime, and irreparable damage to brand reputation and customer trust.

Business leaders, boards, and executives must recognize that cyber risk is business risk, the decisions made about data governance, vendor partnerships, employee access, and digital infrastructure all carry security implications that directly impact the bottom line.

Although IT departments are responsible for protecting systems through implementing cybersecurity strategies and tools, this does not mean that it is their sole responsibility to guard against cyber risks. This misunderstanding can lead to confusion within an organization.  IT teams must ensure that their respective organization meets mandatory privacy and security standards – this is often mistaken for or confused as cybersecurity. The reason we hear these terms used interchangeably is because the world is becoming more digitalized, and with that comes more sensitive information in the cloud instead of filing cabinets.

So, how do we differentiate between the two fields? Cybersecurity is the practice of safeguarding computer systems, networks, and programs sensitive information from damage, theft or unauthorized use. While Information Technology is the practice of ensuring an organization’s systems stay online and accessible through both software and hardware issues.

Whether you operate a small business or enterprise-level organization, cybersecurity can have similar positive impacts. With more data being stored every day, and most businesses operating at least partially online, the effect a cyberattack can have on business operations cannot be understated. Attackers also understand this as just cyber data breaches alone have seen a 70% increase since 2023.

There is an extensive list of reasons as to why a business needs to invest in cybersecurity; protection of sensitive information, maintaining business operations, compliance, building customer trust, are among some of the most important. A successful cyberattack against an organization can impact all these issues at the same time, but the primary target for an attacker is usually sensitive information. Information like emails, passwords, and financial records can be ransomed or used by an attacker for their own benefit or indeed to conduct further attacks.

Ransomware attacks continue to be on the rise, causing not only financial devastation to companies but huge reputational damage as well. Even if the data is not shared, ransomware leak sites advertise to all that a threat actor has been able to gain access to an organization and information has been stolen. This can have implications for partnerships in the future which may deem an organization too risky to do business with.

To give an example of the scale of victims of ransomware, the below image from DarkOwl Vision shows the number of posted victims in the last year as collected by DarkOwl – 22,354,572 documents with victims.

The sites/sources you see here are just the tip of the iceberg when it comes to groups ransoming information on the dark web.

Penetration testing can be a useful tool for organizations seeking to identify and patch vulnerabilities. Penetration testers, or pen testers operate much like hackers, although they are given permission by the company to try as many methods as possible to find possible vulnerabilities in their systems before an attacker does. Pen testing is an important aspect of cybersecurity and plays a critical role in keeping business operations running smoothly.

There are many different methods of penetration testing and they don’t all need to be technical in nature, with social engineering pen testing, internal/external network pen testing, web application pen testing, and cloud pen testing being the most relevant for most businesses. Social engineering pen testing can take place face-to-face or on the phone with either an employee or executive at the given organization. Someone posing as an executive leader, for example, might ask an employee to give up sensitive information like a username and password to access systems under their account. This type of test can determine if employees have been trained properly on this topic.

Ideally, a company should have pen testing done once a year depending on the organization’s industry. For example, HIPAA expects healthcare entities to maintain a strong security posture due to the sensitivity and the amount of information that is stored within their system. Therefore, the healthcare industry has regular testing of their systems. Other frameworks like PCI DSS (Payment Card Industry Data Security Standard) which is a globally recognized security standard, mandate penetration tests at least annually or after a significant system change.

Long story short, pen testing connects a cybersecurity practice with the security of business systems. These tests can provide a first alert for a business’s systems and decrease the likelihood of an attacker gaining access to sensitive information.

While securing systems requires a significant investment of time and money, the benefits far outweigh the costs. Take the Zero Trust framework, for example. By limiting user access to only the resources necessary for their role, organizations reduce the potential impact of security breaches. Implementing Zero Trust takes time, as development and IT teams must carefully assign and manage user permissions. However, once established, the framework can save organizations more than $1 million per cloud-related security incident. This is just one example of how cybersecurity investments deliver measurable value, demonstrating that even a single security initiative can have a substantial financial impact.

As mentioned earlier, ransomware remains one of the most significant cybersecurity threats facing businesses today. In a ransomware attack, malicious actors encrypt an organization’s files and systems, making them inaccessible until a ransom is paid, often in Bitcoin or another cryptocurrency. A notable example occurred in July 2020, when CWT Global paid approximately $4.5 million in Bitcoin to regain access to its systems after a ransomware group compromised a large portion of the company’s computers. The attackers initially demanded $10 million, but the parties ultimately reached a lower settlement. This incident highlights the severe operational and financial consequences that ransomware attacks can have on organizations.

Cybersecurity is no longer just an IT concern; it is a critical business issue that affects every aspect of an organization. As businesses continue to rely on digital systems, cloud services, and online operations, the potential consequences of a cyberattack extend far beyond technical disruptions. Data breaches, ransomware attacks, regulatory penalties, and reputational damage can all have significant financial and operational impacts. While IT teams are responsible for implementing and managing security controls, protecting an organization requires support from leadership, employee awareness, and ongoing investment in cybersecurity initiatives. Whether through penetration testing, Zero Trust frameworks, or employee training, proactive cybersecurity measures help organizations reduce risk and maintain customer trust. In today’s digital environment, cybersecurity is not simply a technology expense—it is a strategic business investment that protects an organization’s people, operations, and future success.


Don’t miss anything – follow us on LinkedIn.

What Is Your Data Worth? Dark Web Pricing Intelligence as an Enterprise Risk Signal in 2025-2026

August 11, 2026

Dark web market pricing is one of the more useful leading indicators of threats available to enterprise security leaders. It shows where attacker investment is concentrating, which sectors are being actively targeted, and which gaps in your control framework the criminal market has already priced in. The organizations ahead of this curve treat dark web pricing intelligence the way they treat CVE feeds: as actionable signal, not academic trivia. Here is what the 2025-2026 price data says.

Prices at the low end of the stolen data market have fallen to near-throwaway levels. Individual US Social Security numbers trade at roughly $1 to $6. Minimal PII (a name paired with an email address) sells for under $15, while a full identity kit runs about $20 to $100. That kit, known as a “fullz” package, bundles a name, address, SSN, and date of birth. A standard US payment card with CVV trades between $10 and $40.

The volume behind those prices is staggering. KELA’s State of Cybercrime 2026 report identified 2.86 billion compromised credentials circulating through criminal channels in 2025 alone. Flashpoint’s midyear analysis found 1.8 billion credentials stolen in just the first half of 2025, an 800% increase over the previous six months, driven largely by infostealer malware.

The operational implication is direct: at these volumes and prices, a correct username and password is no longer meaningful evidence of identity. If your authentication architecture still treats it that way, your controls have not caught up to where the market already is.

While commodity prices deflate, the top of the market is moving the other way, though the headline number needs careful reading.

Rapid7’s research on Initial Access Brokers (IABs), the criminals who sell verified footholds inside corporate networks, found the average listing price across five major forums jumped from roughly $2,726 in 2024 to $113,275 in 2025. That is an increase of about 4,055%. The average is heavily skewed by a small number of very large listings claiming access to high-revenue victims, concentrated on the DarkForums marketplace. Typical access still sells for hundreds to a few thousand dollars, and Cyberint’s independent data put the 2024 average listing at about $1,295. The honest read: the median IAB sale stayed cheap, but 2025 saw the emergence of a new ultra-premium tier for access to large enterprises. It was also a year of major market disruption, including the BreachForums shutdown after a law-enforcement compromise in April 2025 and the arrest of the alleged XSS.is forum administrator in Kyiv that July.

Elsewhere in the premium tier, the pattern is steadier. Healthcare records held at roughly $250 to $310 per record in 2024-2025, about ten times the price of a stolen payment card, because medical history (unlike a card number) cannot be cancelled and reissued. Verified cryptocurrency exchange accounts top the consumer financial chart: a verified Kraken account has listed at up to $1,170 and a verified Binance account around $410. Coinbase accounts, once anchored near $610, have fallen to roughly $107 to $250 as stealer logs industrialized account takeover.

For security leaders in financial services, healthcare, and critical infrastructure, elevated pricing for access to your sector is a market signal of active targeting. It warrants a review of your external attack surface and lateral-movement detection coverage.

Among credential types, listings that demonstrably bypass MFA carry a significant price premium, and stolen session cookies are chief among them. The reason is simple: when a user logs into a corporate application, the system issues a session token that keeps them authenticated. An attacker who steals that token impersonates an already-authenticated user with no password or MFA prompt required. The longer your organization lets tokens live, and the fewer device bindings placed on them, the more exploitable (and valuable) they become. That premium is the market telling you precisely where your authentication architecture is exposed. Read the signal: shorten session lifetimes, bind tokens to devices, and monitor for session replay.

AI tooling has split the market into grades. Bulk credential dumps keep deflating on oversupply, while AI-curated datasets, sorted and precision-targeted against specific organizations or roles, command premiums reflecting their operational value to buyers.

The performance gap explains the pricing. In a controlled study by Harvard researchers, generic phishing emails achieved a 12% click-through rate, while fully AI-automated spear phishing achieved 54%. That matched human experts at a fraction of the cost. Resilience’s Midyear 2025 Cyber Risk Report cites the same comparison and found social engineering behind 88% of material insurance losses. Attackers with AI capability are producing a measurably better product, and the market is pricing it accordingly. Expect the commodity-to-premium gap to keep widening.

  • Credentials are a commodity: 2.86 billion compromised in 2025 alone. Passwords plus SMS codes are no longer a meaningful identity control; move toward phishing-resistant MFA and continuous verification.
  • A new ultra-premium tier for corporate network access emerged in 2025. If you operate in a highly priced sector, assume active targeting and test your external attack surface accordingly.
  • Session cookies carry an MFA-bypass premium. Shorten token lifetimes, bind sessions to devices, and detect replay.
  • Healthcare and financial records hold value because they are permanent. Prioritize data-loss prevention where the data cannot be reissued.
  • Treat dark web pricing as a continuous intelligence input to control prioritization and board reporting, not a once-a-year curiosity.

Make sure to stay up to date. Follow us on LinkedIn.

ExfilSquad: A New “Data extortion group” Player Claiming High-Profile Breaches Across the US, UK, and Beyond

August 6, 2026

ExfilSquad is a newly emerged threat actor in the cybercriminal landscape, claiming responsibility for alleged breaches of 15 high-profile victims across multiple countries as of the time of writing this report. The alleged victims span the United States (9 victims), the United Kingdom (3 victims), Sweden (1 victim), and Nigeria (1 victim). The group maintains a dedicated onion-based Data Leak Site (DLS) where victims are listed alongside ransom deadlines, claimed breach sizes, revenue figures, country of origin, and sample files in .7z format or torrent links as proof of compromise (POC).

Notably, all listed victims share an identical ransom payment deadline of 05.08.2026, suggesting a coordinated and simultaneous extortion campaign rather than a series of independent intrusions.

Figure 1: “Exfilsquad” data extorsion group main page listed the victims

ExfilSquad can be identified and monitored through DarkOwl Vision, as captured in Screenshot below.

Figure 2: Darkowl ‘s Vision, crawled the “Exfilsquad”

The following entities are listed on ExfilSquad’s DLS as of the time of writing:

  • Microsoft
  • Wesco International
  • UK Department for Education (education.gov.uk)
  • Police National Legal Database
  • Allstate
  • TaylorMade & Sun Day Red Golf
  • Frontier Airlines
  • Zenith Bank Plc
  • District of Columbia Public Schools (dcps.dc.gov)
  • Newcastle University (ncl.ac.uk)
  • Viavi Solutions
  • City of Houston (houstontx.gov)
  • City of Atlanta (atlantaga.gov)
  • Bonava, the Swedish residential real estate development company headquartered in Stockholm, Sweden.

What elevates several of these claims beyond typical unverified dark web listings is that the UK Police National Legal Database (PNLD) has publicly confirmed that police, government, and customer contact information was compromised and published by the ExfilSquad group, with over 100,000 UK police officers and staff affected. This confirmation lends credibility to the group’s broader list of claimed victims and warrants serious consideration by all allegedly affected entities.

Figure 3: BleepingComputer’s report on alleged Breach of the UK ‘s Police National Legal Database by Exfilsquad

The group listed two contact methods on their DLS, an onionmail and a QTOX ID:

OnionMail — a free, anonymous email service designed for privacy, featuring automatic PGP encryption, native Tor network access (.onion), and requiring no personal data or phone numbers to register.

QTox — a free, open-source, and secure instant messaging and video calling client that uses the decentralized Tox Protocol, featuring end-to-end encryption, zero central servers, and no advertisements.

The use of both OnionMail and qTox reflects a deliberate operational security posture, leveraging decentralized and encrypted communication channels to minimize attribution risk.

Beyond their dedicated DLS, DarkOwl researchers observed an actor operating under the same handle “exfilsquad” promoting two of the alleged breaches — both from the United Kingdom — across two dark web forums: Spear and PwnForums.

Spear Forum

Spear is an English-language dark web forum that emerged in early 2026 and has gained traction among cybercriminal communities as a platform for advertising sensitive data, network access, and geopolitically motivated listings. The forum operates on both a clearnet domain and an onion domain. On July 25, 2026, at 04:06 AM, the actor operating under the handle “exfilsquad” initiated a thread on Spear titled “UK POLICE NATIONAL LEGAL DATABASE”, sharing sample data and a link to their DLS.

Figure 4: UK Police National Legal Database listed on Spear forum 07-25-2026 by the actor Exfilsquad

The actor’s claim on Spear forum was crawled the same day on July 25, 2026 and was accessible on DarkOwl ‘s Vision.

Three minutes later, on July 25, 2026, at 04:09 AM, the same actor initiated a second thread titled “UK DEPARTMENT FOR EDUCATION”, again sharing sample data and the same DLS link.

Figure 6: UK Department for Education listed on Spear forum 07-25-2026 by the actor Exfilsquad

DarkOwl researchers identified that the ExfilSquad account on Spear, joined the forum on July 15, 2026, has initiated 2 threads and 2 posts since joining, and listed the ExfilSquad DLS onion address in the website section of their profile. The account has remained inactive since July 27, 2026, at 12:56 PM as of the time of writing this report.

Figure 7: Exfilsquad profile on spear forum

PwnForums

PwnForums is an English-language cybercriminal forum that serves as a platform for a broad range of illicit activities, including the advertisement and sale of stolen databases, network access, and sensitive government and military data. The forum operates on both a clearnet domain and an onion domain.

On July 25, 2026, at 02:56 AM, the actor operating under the handle “exfilsquad” initiated a thread on PwnForums titled “UK POLICE NATIONAL LEGAL DATABASE”, sharing sample data and a link to the ExfilSquad DLS.

Figure 8: UK Police National Legal Database listed on Pwnforums  07-25-2026 by the actor Exfilsquad

The actor’s claim on Pwnforums was crawled the same day on July 25, 2026, and was accessible on DarkOwl ‘s Vision.

Figure 9: UK Department for education listed on Pwnforums  07-25-2026 listed in DarkOwl ‘s Vision

On July 25, 2026, at 03:41 AM, the same actor initiated a second thread titled “UK DEPARTMENT FOR EDUCATION”, sharing sample data, details of the alleged breach, and the onion address of their DLS.

Figure 10: UK Department for education listed on Pwnforums  07-25-2026 by the actor Exfilsquad

DarkOwl researchers identified that the ExfilSquad account on PwnForums, joined the forum on July 24, 2026, has initiated 2 threads and 2 posts since joining, and listed the ExfilSquad onion address in the Homepage section of their profile.

Figure 11:  Exfilsquad profile on Pwnforums

Notably, the actor holds a GOD member status on PwnForums — a paid membership tier available for €50 lifetime, which grants the holder +30 reputation, +120 credits, the ability to edit and delete their own posts for 3 months, and additional forum features.

Figure 12: VIP, MVP and GOD membership features and price on Pwnforums

ExfilSquad represents a notable new entrant in the data extortion landscape, distinguishing itself through a simultaneously broad victim portfolio, a confirmed breach of a sensitive law enforcement database, and active cross-platform promotion across multiple dark web forums. The group’s operational security posture — leveraging OnionMail, qTox, and a dedicated onion DLS — reflects a degree of technical sophistication consistent with an actor seeking to establish credibility and longevity within the cybercriminal ecosystem.

The confirmation by the UK Police National Legal Database of a genuine compromise lends material weight to ExfilSquad’s broader claims and warrants urgent attention from all allegedly affected organizations. DarkOwl will continue to monitor ExfilSquad’s activity across dark web and open-source channels as the situation develops.

DarkOwl does not endorse, promote, or amplify the content of any threat actors referenced herein. The authenticity of all advertised breach claims referenced in this report, beyond those independently confirmed by affected entities, has not been verified by DarkOwl.

The Kill Trump Bounties: An OSINT Investigation

July 30, 2026

As tensions between the United States and Iran continue to escalate, DarkOwl researchers have observed a marked increase in online threats targeting the life of President Donald Trump. These threats span multiple layers of the internet — from dark web onion sites and encrypted Telegram channels to mainstream Iranian state-aligned media — and reflect both grassroots extremist sentiment and coordinated state-adjacent messaging. This post details DarkOwl’s findings.

DarkOwl researchers identified an onion site operating under the name “8647 Kill Donald Trump”, claiming to have allegedly gathered over $300,000 USD and actively promoting a $1 million fundraising campaign. The site describes its operators as a team of “highly qualified professionals united by a single goal: to eliminate the threat and protect the world from those who create danger.”

The site is published in three languages — English, Arabic, and Chinese — suggesting an intent to reach a broad international audience. Two QR codes are displayed on the site: one linked to a Bitcoin (BTC) wallet address, and one to a Monero (XMR) wallet address, providing anonymous payment channels for potential donors.

Figure 1: Homepage of the “8647 Kill Donald Trump” onion site, showing its fundraising pitch and QR codes for Bitcoin and Monero donations.

The number “8647” embedded in the site name carries specific significance. Multiple sources report that Republicans have flagged the number as split into two parts — 86 and 47 — read as a call for the assassination of President Trump, the 47th president. In American slang, “86” means to remove or get rid of someone, making “8647” a thinly veiled reference to eliminating him.

DarkOwl researchers observed IRGC-associated Telegram channels actively promoting the hashtag “کشتن ترامپ” — translating directly to “Kill Trump” — across multiple platforms.

Sabereen News, a pro-Iranian Telegram channel closely aligned with Iran’s “Axis of Resistance” narrative and considered to have close ties to the IRGC, posted on March 19th, 2026, that the offer for killing President Trump was being raised to $100 million USD, sharing a clearnet website alongside the announcement.

Figure 2: Sabereen News Telegram post announcing the bounty on President Trump had been raised to $100 million USD.

The same campaign was subsequently amplified by two additional IRGC-tied channels — the IRGC Quds Force News Channel and another pro-regime outlet — with posts published on March 21st and March 23rd, 2026, respectively.

Figure 3: Post from the IRGC Quds Force News Telegram channel amplifying the Kill Trump bounty campaign.
Figure 4: Post from a second pro-regime Telegram channel amplifying the Kill Trump bounty campaign.

Researchers identified a domain — killtrump.info — that was promoted across these channels. While the domain is no longer online at the time of writing, WHOIS records reveal it was registered through an Iranian hosting company, Netmihan Communication Company Ltd, a finding that points to Iranian infrastructure underpinning the campaign.

The campaign was seeded on Iranian domestic social media platforms Eitaa and Rubika — both widely used inside Iran — days before being promoted on the above-mentioned Telegram channels, suggesting a deliberate domestic-first promotion strategy. A further Eitaa post was also identified as part of the same seeding activity.

Figure 5: Eitaa post seeding the Kill Trump campaign on Iranian domestic social media.
Figure 6: Rubika post seeding the Kill Trump campaign on Iranian domestic social media.

FarsNews — the pro-Iranian news agency directly and formally affiliated with the IRGC, widely described as the cornerstone of the IRGC’s disinformation and propaganda apparatus, and designated by the U.S. Treasury under Executive Order 13553 in September 2023 — published a report on March 17th, 2026 covering the emergence of the Kill Trump campaign and its $100 million USD reward, sharing the fundraising website used to collect donations for it.

Figure 7: FarsNews article covering the Kill Trump campaign and its $100 million USD reward.

The fact that an IRGC-affiliated news agency was covering — and effectively amplifying — the campaign underscores how far this narrative has been normalized within Iran’s information ecosystem.

Some members of the Iranian diaspora community also reported that Iranian citizens residing inside Iran were receiving unsolicited SMS messages promoting the Kill Trump fundraising campaign and calling on recipients to participate, as documented by IranWire on X.

Figure 8: IranWire post on X documenting unsolicited SMS messages sent to Iranian citizens promoting the Kill Trump fundraiser.

On March 24th, 2026, the Iranian news agency Mehr News reposted a statement from the Handala hacking group. In direct response to a $10 million USD bounty placed on Handala members by the U.S. Department of Justice, the group announced a $50 million USD reward for the killing of both President Donald Trump and Israeli Prime Minister Benjamin Netanyahu.

Figure 9: Mehr News repost of the Handala hacking group’s statement announcing a $50 million USD reward for killing President Trump and Prime Minister Netanyahu.

This $50 million USD reward for Trump and Netanyahu remains active on Handala’s most prominent domain as of the time of writing, with the original post dated March 24th, 2026.

Figure 10: Handala’s website listing the active $50 million USD reward for Trump and Netanyahu.

Handala’s entry into this campaign is significant: it represents a named, organized threat actor with established cyber capabilities formally attaching itself to a targeted assassination bounty — and one that has directly responded to U.S. law enforcement pressure with an escalatory public threat.

On March 31st, 2026, Sabereen News introduced yet another domain — killtrump[.]me — which was found to be hosted on an IP address based in Iran, again belonging to Netmihan Communication Company Ltd.

Figure 11: Sabereen News Telegram post introducing the killtrump.me domain.

The same site was shared across Iranian websites on March 30th, 2026 — one day prior to the Telegram announcement — again suggesting pre-seeding on domestic platforms before broader promotion.

Figure 12: Iranian website post sharing the killtrump.me domain a day before its Telegram announcement.

On April 5th, 2026, a further domain — killtrump[.]ir — was introduced and shared via a post in the Sabereen News channel on the Iranian social platform Eitaa. This domain uses Iran’s country-code top-level domain (.ir) and was not available at the time of writing.

Figure 13: Sabereen News post on Eitaa introducing the killtrump[.]ir domain.

The site was hosted on an Iranian IP address — 185.143.234.235 — belonging to subnet 185.143.232.0/22, AS 205585, operated by Noyan Abr Arvan Co. (Private Joint Stock), a major Iranian cloud infrastructure provider. The latest archived records of the domain suggest the title translates to English as “Kill Trump.”

Figure 14: Archived record of the killtrump.ir site, with its title translated to English as “Kill Trump.”

A clear and deliberate pattern emerges across all these domains: the “KillTrump” brand remains consistent, with only the TLD rotating — .info, .me, .ir — suggesting an operational strategy to maintain the campaign’s online presence even as individual domains are taken down.

A report published by Iran International on March 25th, 2026 cited pro-Iranian regime media claiming that more than $25 million USD had been donated toward the Kill Trump campaign reward fund. While these figures cannot be independently verified by DarkOwl, their amplification by state-adjacent media lends the campaign a degree of institutional visibility that goes well beyond fringe activity.

Figure 15: Iran International report claiming more than $25 million USD had been donated to the Kill Trump campaign.

The campaign extends well beyond anonymous dark web actors and fringe Telegram channels into the highest levels of Iranian political commentary.

On June 28th, 2026, Hossein Shariatmadari (حسین شریعتمداری) — an Iranian journalist and political commentator best known as the editor-in-chief of the conservative newspaper Kayhan (کیهان), a representative of the Supreme Leader, and a hardliner with significant influence in Iranian decision-making — published an article addressing three points on negotiations with the United States. The final point read: “And finally, the effort and expense to take revenge on the murderer of our martyred Imam, in that very land of America” — widely read as a thinly veiled reference to retaliatory action against President Trump on U.S. soil.

Figure 16: Kayhan article by Hossein Shariatmadari referencing revenge against “the murderer of our martyred Imam… in that very land of America.”

On July 11th, 2026, Hamshahri Online — a major Persian-language national daily newspaper owned and operated by the Tehran Municipalitypublished a report citing Iran’s new Supreme Leader stating that revenge is “a definite demand of the nation,” and listing 13 named individuals including Donald Trump and Benjamin Netanyahu as targets.

Figure 17: Hamshahri Online report citing Iran’s Supreme Leader and listing 13 targets, including Trump and Netanyahu.

On July 16th, 2026, the Islamic Resistance in Iraq (Arabic: المقاومة الإسلامية في العراق) — an Iran-backed umbrella coalition of Shia militant factions operating under the strategic direction of the IRGC Quds Force — promoted a $10 million USD reward for anyone who kills President Trump or provides assistance toward his assassination.

Figure 18: The Iran-backed Islamic Resistance in Iraq (المقاومة الإسلامية في العراق) promoting a $10 million USD reward for the assassination of President Donald Trump.

These findings do not exist in a vacuum. On March 6th, 2026, the U.S. Department of Justice announced the conviction of Asif Merchant, also known as Asif Raza Merchant — an Iranian intelligence agent found guilty of terrorism and murder-for-hire charges in connection with a foiled plot to assassinate U.S. politicians and government officials, including President Trump, on American soil. The conviction confirms that Iranian-linked assassination plotting against the U.S. president has already moved from online rhetoric to operational planning.

The findings documented above reflect a multi-layered, persistent, and escalating campaign spanning anonymous dark web infrastructure, IRGC-affiliated Telegram channels, Iranian domestic social media platforms, state-adjacent and state-owned news agencies, named hacking groups, and senior regime voices. Several indicators are worth highlighting:

Iranian hosting infrastructure — specifically Netmihan Communication Company Ltd and Noyan Abr Arvan Co. — is used consistently across multiple killtrump domains, pointing to organizational coordination rather than spontaneous grassroots activity.

TLDs rotate deliberately as domains are taken down, an operational resilience that suggests continuity of intent and a structured effort to maintain the campaign’s online presence.

The Handala hacking group’s involvement adds a cyber threat dimension to what might otherwise appear to be a purely rhetorical campaign, particularly given its direct response to U.S. DOJ pressure with an escalatory $50 million bounty.

Content is pre-seeded on domestic Iranian platforms — namely Eitaa and Rubika — before international Telegram amplification, pointing to a structured dissemination strategy rather than organic spread.

Senior regime-aligned voices have amplified the campaign, including a representative of the Supreme Leader, a Tehran Municipality-owned newspaper, and the Iran-backed Islamic Resistance in Iraq, elevating the campaign from fringe extremism to something with demonstrable institutional backing.


DarkOwl will continue to monitor developments across dark web and open-source channels as the situation evolves. Stay up to date.

Your Help Desk is a Target: Using Darknet Intelligence to Get Ahead of AI-Powered Social Engineering

July 28, 2026

“Hey John, it’s Jamie. I’m locked out of my email and I left my cell at the office. If I don’t get this spreadsheet over to finance by COB tonight, Bill is going to melt down for sure. Can you help me get into my email to send this one thing???”

Jamie sounds like Jamie, Bill is indeed the department head, and the company’s financial quarter is set to close within the next day.

Jamie sounds stressed, even close to tears, and John of course wants to help her out.

The problem is that Jamie is being impersonated using AI deepfake tech, and once John resets the MFA (multi-factor authentication), attackers will be inside the network within minutes.

As long as humans are part of any workflow, security is vulnerable to human error. Social engineering, the attack method utilizing convincing pretext to deceive and manipulate, is nothing new. However, AI has intensified the threat landscape.

Deepfakes, voice cloning, and synthetic identities mean human judgement defenses are more vulnerable now than they were a few years ago.

The Help Desk Is a Key Targeted Entry Point

Help desks are valuable targets for threat actors using these tactics.

Muddled Libra (one alias for this group is Scattered Spider) is one such threat group utilizing these tactics, as outlined by Palo Alto Networks in June 2025, where they saw evidence of the group identifying key personnel, using publicly available information to build a profile and then use this to impersonate the employee, thus allowing them to gain access to systems and monetize attacks quickly.

Personal relationships which may exist between help desk and other company staff are often exploited, using deepfake tech to impersonate not only voice, but also cadence, inflection, and keyword peculiarities specific to the chosen individual.

Threat actor methods and tracking can be time consuming. It is important to note threat actors often share scripts, refine techniques, and trade stolen data on the dark web. Leaving threat actors un-investigated means leaving behind key defensive intel crucial for your business.

The NY Times identified threat actor Scattered Spider as being investigated for the 2025 Marks & Spencer cyberattack in Britain.

DarkOwl Vision offers intel and dossiers on threat actors. Scattered Spider is one such entity whose methods, aliases, tools, and other information are available. The identified alias of “Muddled Libra” is seen below for threat actor “Scattered Spider” in Dark Owl Vision:

Additional details for this threat actor include other targeted industries, Telegram accounts, and known tactics:

Social engineering defense is key, however, knowing specific attack methods can increase network defenses.

Three CVE’s have been identified as in use by Scattered Spider in DarkOwl Vision:

A known enemy is always better than fighting blind. Monitoring dark web content as part of proactive security measures can help defend against emerging attack vectors.

Network defenders can also watch for signals before an attack. To catch adversary reconnaissance from darknet sources, monitoring and subsequent alerting are key.

DarkOwl Vision’s Alerting function can ensure keywords specific to your company can be monitored, with alerts generated from any findings. Identified corporate keyword chatter on dark forums can be utilized as an advanced warning to all company staff in anticipation of social engineering attacks. If any are discovered, security passphrases can be refreshed, and additional social engineering prevention trainings issued.

Remember, the attackers already have enough data points to pull off a convincing pretext against your staff. The United States is by default opted IN, not opted out, of data brokers. The personal and specific details of your staff are already public. Names, roles, manager’s role, and other details are easily found.

Adding AI impersonations with deepfake technology, and you’ve got a recipe for disaster. Methods discussed online quickly turn into real world intrusion attempts.

Go back to John for a second. By the time “Jamie” called, the attacker had already done the hard part of research and preparation including details, urgency, voice, etc. That’s the uncomfortable truth about this kind of attack: the call itself is just the final step in a process that’s been visible, in pieces, for days or weeks beforehand. The organizations that get ahead of this are the ones who were watching the early signals closely enough that the call never had a chance to work in the first place. AI has made the pretext better. It hasn’t made the playbook any less visible to the people willing to look for it.


Learn more about DarkOwl’s features mentioned throughout this blog. Contact us.

Stealer Logs: The Underground Commodity Powering Modern Cybercrime

July 23, 2026

A stealer log is not merely a log file. It is a structured, compressed archive of everything a piece of stealer malware has silently harvested from an infected device usually before the victim had any idea anything was wrong, if they ever did. Unlike ransomware, which announces itself with locked screens and ransom notes, infostealer malware operates without disrupting normal device function and therefore can be difficult to detect. The infected machine keeps running. The user keeps working. Meanwhile, the malware is methodically copying credentials from every browser, extracting active session cookies, reading cryptocurrency wallet files, and sometimes even photographing the desktop — then packaging everything into a neat archive and transmitting it to an attacker-controlled server.

Each log, in the language of underground markets, represents one “bot” — one compromised device, one victim’s complete digital footprint, ready for purchase and exploitation.

The value of a stealer log to a criminal depends heavily on what it contains. Logs with bank credentials, for instance, will be more valuable than other types of credentials. However, there are a lot of other data types withing a stealer log which can be very advantageous to criminals. Logs are typically organized by data type within the archive, making it simple for buyers to locate specific categories of value. The standard contents break down into six main categories:

  • Browser Credentials — Every saved username and password from any browser used on the infected machine such as Chrome, Edge, Firefox, Brave, and Opera, sorted by domain. One infection compromises dozens of accounts simultaneously.
  • Session Cookies & Auth Tokens — Active session tokens that bypass MFA entirely. An attacker importing a valid session cookie can access accounts without triggering any new authentication prompt.
  • Autofill & Payment Data — Names, addresses, phone numbers, dates of birth, and payment card details stored in browser autofill, enabling identity fraud beyond credential abuse. Think about this next time your browser asks you if you want to save your information for the future.
  • Cryptocurrency Wallets — Wallet files, browser extension data, seed phrases, and private keys for Bitcoin, Ethereum, and other cryptocurrencies. Funds can be drained within minutes of purchase.
  • System & Device Information — Hardware IDs, OS version, installed software, IP address, geolocation, and a desktop screenshot taken at infection time.
  • VPN, FTP & Application Tokens — Remote access credentials, FTP configs, and tokens for Slack, Discord, GitHub, and cloud services which can provide direct network footholds for corporate intrusions.

One particularly dangerous aspect of a stealer log infection is its attack on session persistence. When a user logs into a website and completes multi-factor authentication, the browser stores a session cookie confirming that the device has already authenticated. An attacker who imports that cookie can access the same account with no password required, and no MFA challenge triggered. Microsoft’s own documentation confirms that certain session cookies can persist until explicit logout or token expiration, potentially enabling weeks of undetected access with a single stolen log.

Sellers routinely re-package the same log multiple times — as a cheap raw dump, a premium corporate set, and a crypto-only slice — reselling the same victim data to multiple buyers. Underground market research suggests tens of billions of stolen cookies were circulating in 2025.

The infostealer malware ecosystem operates as a commercially organized, subscription-driven marketplace. Most major variants are sold as Malware-as-a-Service (MaaS), with developers offering monthly subscriptions, customer support forums, update bulletins, and affiliate programs. According to IBM X-Force’s 2025 threat intelligence report, the following families dominated dark web forum activity throughout 2024 and into 2025:

The broader pattern is consistent across every law enforcement disruption: when one major infostealer family is taken down, market share migrates to alternatives within days to weeks, or the malware is updated on new C2 servers run by other affiliates. This resilience stems from the structural nature of the ecosystem. Low development barriers, open-source code availability, and persistent criminal demand ensure that neutralizing any single actor creates an immediate commercial opportunity for others.

The underground market for stealer logs operates across several parallel channels, each serving different buyer profiles and transaction volumes. Understanding where logs are distributed is central to understanding how quickly stolen data can be weaponized after an infection.

Following the Genesis Market seizure in April 2023, SecureWorks documented a 670% increase in Russian Market activity as buyers and sellers migrated. This pattern has repeated across every major marketplace takedown: the criminal ecosystem absorbs the disruption rapidly, and within weeks, activity consolidates on surviving platforms or new entrants.

Stealer logs are usually the first step in an often more sophisticated attack. Information that can be found in logs is often used as part of other attacks, usually against organizations rather than against the individuals that were initially infected.

Initial Access Brokers (IABs) will sift through millions of logs, which they may control themselves or have purchased, looking specifically for corporate VPN credentials, SSO tokens, and domain admin access. Qualifying logs are re-packaged and sold on dark web forums for significantly higher prices.

Ransomware affiliates purchase verified corporate access from IABs and or have access to their own logs containing this information and use it to log directly into target networks which allows them to bypass perimeter defenses entirely. According to Verizon’s 2025 DBIR, 54% of ransomware victims had domain credentials in stealer logs before the attack. This makes it a lot less effort for ransomware groups to infiltrate organizations but can cause massive financial and reputational damage.

Account Takeover and Financial Fraud is another attack type which benefits from data included within stealer logs.  Session cookies enable immediate account takeover without triggering MFA. Buyers can drain linked payment methods, redirect wire transfers, access cryptocurrency exchanges, and commit identity fraud without ever needing to use a credential or use sophisticated hacking techniques. This significantly lowers the barrier to entry for unsophisticated or “script kiddie” threat actors.  Account takeover fraud totaled nearly $13 billion in 2023-2024.

The infostealer landscape shifted substantially in the second half of 2025 and into 2026, driven by a series of major law enforcement takedowns and the resulting scramble to fill vacated market share. But despite the takedowns, it has only grown with new stealer log families circulating all the time.

Following the disruption of LummaC2 in May 2025, established families moved quickly to absorb displaced activity. Rhadamanthys led through the summer until its own infrastructure was taken down by law enforcement in November 2025. By January 2026, Vidar 2.0 had emerged as the most widely used infostealer among threat actors, according to Flashpoint’s 2026 Global Threat Intelligence Report. As of early 2026, AhnLab ASEC’s February trend data identifies four families as dominating active distribution: LummaC2 (partially recovered), ACRStealer, StealC, and Vidar.

ACRStealer, also referred to as Acreed, is one of the most significant new entrants of 2025–2026, it rapidly ascended to become one of the top four most actively distributed infostealer families by early 2026

The macOS infostealer market has grown significantly from a niche concern into one of the fastest-expanding segments of the credential theft ecosystem. Atomic macOS Stealer (AMOS) dominated the macOS market through most of 2025, disappearing in October before returning in February 2026. MacSync (formerly Mac.C) emerged as the primary commodity macOS infostealer by year-end 2025. Poseidon and Odyssey are also active macOS-targeting families tracked in current reporting.

The table below highlights the most commonly observed stealer log families as of June 2026, including families that have rebranded or have been disrupted.

  • Infostealer malware stole 1.8 billion credentials in 2025, with IBM reporting an 84% year-over-year increase in phishing delivery of stealers.
  • Over half of ransomware victims in 2024-2025 had domain credentials in stealer logs prior to the attack, often with as little as a 48-hour window between log sale and intrusion.
  • Russian Market has emerged as the dominant venue for stealer log transactions, listing over 180,000 logs in H1 2025 and demonstrating consistent resilience to law enforcement pressure.
  • Session cookie theft renders MFA ineffective — 77% of logs on Russian Market contained SSO tokens in ReliaQuest’s analysis, making credential-only defenses insufficient.
  • Law enforcement operations against major infostealer families produce real but temporary disruption; the ecosystem reconstitutes rapidly due to low barriers to entry and consistent criminal demand.
  • Credential exposure from older logs carries persistent risk; stolen credentials remain valid and tradeable indefinitely unless explicitly revoked and rotated.

DarkOwl collects Stealer Log information from across the dark web and Telegram and makes this available through Vision so organizations can identify any credential exposure which may lead to further attacks. Contact us to learn more.

Darknet Monitoring: A Critical Tool for Executive Risk Management

July 16, 2026

C-suite executives are prime targets for cybercriminals because they hold the keys to an organization’s most valuable assets: sensitive data, financial authority, and strategic decision-making power. Their visibility inside and outside the company also makes them easier to identify and profile. As a result, executive-focused attacks such as business email compromise (BEC), often referred to as “whaling,” have become one of the most costly forms of cybercrime, resulting in billions of dollars in losses each year. The threat is amplified by executives’ growing digital footprints. Research from ZeroFox found that 75% of executives already have exposed credentials available online, providing threat actors with a rich source of information to fuel targeted attacks.

Darknet monitoring serves as a critical early warning system for organizations seeking to stay ahead of emerging threats. While it is often impossible to prevent stolen credentials, sensitive data, or other compromised information from appearing on the dark web once it has been exposed, early detection can significantly reduce the potential impact. By identifying risks before they are weaponized, organizations can take proactive steps—such as resetting credentials, strengthening access controls, and enhancing monitoring—to prevent financial loss, data breaches, and reputational damage.

The dark web hosts a wide range of stolen and compromised information that can be exploited for fraud, cybercrime, and further attacks. Commonly traded data includes personally identifiable information (PII) such as names, addresses, identification documents, and medical records; login credentials for email, social media, and business systems; financial information including credit card and banking details; intellectual property such as source code, research, and product designs; corporate network access credentials; and customer databases containing contact information and purchasing histories. These datasets are often used to facilitate identity theft, phishing campaigns, account takeovers, financial fraud, and unauthorized access to corporate environments.

C-suite executives are frequent targets of cyberattacks, yet many organizations still do not provide additional cybersecurity protections for their leadership teams. This gap leaves executives and organizations at increased risk.

According to SOCRadar, executive identity fraud has become a widespread security concern, with more than half of U.S. companies reporting incidents involving executive impersonation. Identity-based attacks targeting senior leaders are no longer isolated events – they are an ongoing challenge for security teams.

Credential exposure is also a significant issue. Research shows that most executives have had at least one cleartext credential exposed in a data breach, often involving passwords reused across personal and professional accounts. These exposures can create easy entry points for attackers. Additionally, executive and corporate credentials are commonly found on the dark web, where stolen passwords, personal information, and access credentials are bought and sold. Without proactive monitoring and executive protection measures, these exposures can lead to phishing attacks, account takeovers, executive impersonation, and broader organizational risk.

Darknet monitoring involves continuous scanning and intelligence gathering across hidden areas of the internet that are not indexed by traditional search engines, including networks such as Tor, I2P, ZeroNet, and encrypted communication channels. Cybercriminals frequently use these platforms to buy and sell stolen data, discuss vulnerabilities and exploits, share attack techniques, and coordinate malicious activities.

By monitoring these environments, organizations can identify potential threats before they develop into full-scale incidents. Effective dark web surveillance provides early warning of compromised credentials, leaked corporate information, and other indicators of malicious activity. This allows security teams to take proactive measures—such as resetting passwords, notifying affected users, strengthening access controls, and increasing monitoring—before attackers can exploit the information.

Not all data discovered on the dark web presents the same level of risk, but much of it can be highly sensitive. Common findings include stolen credentials such as email and password combinations or VPN logins, breached corporate databases containing financial, human resources, or customer information, identity documents such as Social Security numbers and passports, and leaked internal communications or proprietary intellectual property. Even seemingly minor exposures can provide attackers with the information needed to launch more sophisticated attacks or gain unauthorized access to critical systems. As a result, organizations increasingly rely on data leak monitoring and dark web alerting capabilities to detect and respond to threats before they escalate.

Dark web monitoring also plays an important role in identifying social engineering and account takeover risks. Threat actors often use phishing campaigns, credential theft, social engineering tactics, and brute-force attacks to gain control of legitimate social media, email, and business accounts. In other cases, they invest significant time and resources into creating convincing fake online personas designed to establish trust with employees, partners, or executives. For example, attackers may build fraudulent professional profiles complete with fabricated work histories, endorsements, certifications, and conference participation records. Advances in artificial intelligence and digital content generation are making these impersonation efforts increasingly realistic, allowing threat actors to create more persuasive identities and making it more difficult for organizations to distinguish legitimate contacts from malicious actors.

Effective executive protection begins with understanding the threat landscape itself. Organizations must develop a clear picture of the malicious terrain, the actors operating within it, and the security tools available to counter emerging risks. By leveraging threat intelligence, security teams can identify executive exposure across the surface, deep, and dark web, enabling proactive detection and mitigation of potential threats. To fully understand the risks facing senior leaders, organizations must first understand the environment in which those threats originate.

A comprehensive executive cyber protection strategy should include the following measures:

  • Continuously Assess Executive Exposure: Executives are often targeted through both personal and professional channels. Regular assessments of digital exposure across public, deep-web, and dark-web sources can uncover sensitive information, impersonation attempts, credential leaks, and other indicators of risk before they are exploited.
  • Deliver Executive-Focused Security Awareness Training: Traditional security training can fail to resonate with senior leaders. Instead, organizations should provide concise, engaging learning sessions that incorporate real-world phishing simulations and executive-specific threat scenarios. Regular, targeted training helps executives recognize and respond to evolving attack techniques.
  • Formalize and Measure Security Programs: Executive protection should be integrated into a broader cybersecurity framework that aligns with business objectives. Establishing key performance indicators (KPIs), implementing controls such as multi-factor authentication, and regularly measuring security outcomes help create a mature and accountable security program.
  • Provide Ongoing Threat Intelligence Updates: The threat landscape evolves rapidly, making regular executive briefings essential. Security leaders should deliver concise updates on emerging threats, attack trends, and organizational risk exposure using business-focused metrics and contextualized reporting that supports informed decision-making.
  • Communicate Risk in Business Terms: Cybersecurity discussions are most effective when framed around business impact. Executives should understand how cyber incidents can affect revenue, operations, regulatory compliance, and brand reputation. Sharing lessons learned from high-profile breaches can help reinforce the real-world consequences of inadequate security practices.
  • Conduct Executive Cyber Crisis Simulations: Preparation is critical during a cyber incident. Executive Breach Attack Simulations (BAS) and tabletop exercises help leadership teams understand their roles during a cyber crisis, improve decision-making under pressure, and strengthen coordination between business and security stakeholders.

By combining threat intelligence, executive education, governance, and continuous monitoring, organizations can significantly reduce cyber risk to their leadership teams while building a stronger overall security posture.


Learn how DarkOwl can help. Contact us.

FortiBleed Exploited: Tracking Initial Access Broker Dark_Alpha on Darkforums

July 15, 2026

In mid-June 2026, security researchers identified a large-scale credential compromise campaign targeting Fortinet FortiGate firewalls, quickly dubbed FortiBleed. Unlike a traditional zero-day, FortiBleed is not tied to a single new vulnerability. Instead, threat actors systematically extracted configuration files from internet-facing FortiGate devices and cracked the stored password hashes — exploiting the fact that many organizations running older FortiOS versions continued to store administrator credentials as legacy SHA-256 hashes rather than the more secure PBKDF2 format Fortinet introduced in FortiOS 7.2.11, 7.4.8, and 7.6.1. Devices upgraded from earlier versions retain SHA-256 hashes until each administrator logs in post-upgrade, leaving a window of exposure that the campaign actively exploited at scale.

The result: verified working administrator credentials for between 73,932 and 86,000 devices across 21,632 organizations in 194 countries — roughly half of all internet-facing FortiGate firewalls at the time of discovery. The United States, India, and Mexico were among the most heavily affected countries. CISA issued an advisory on June 18, 2026 urging organizations to rotate credentials, enforce MFA, and restrict management interface access.

Darkforums is currently the fastest-growing English-language cybercrime forum on the darknet. Originally launched as “DARK4RMY Forums” by a hacking group called DarkArmy, it rebranded following the April 2025 collapse of BreachForums and rapidly absorbed much of that platform’s displaced user base — recording a 600% surge in activity between April and June 2025. Now operated by administrators AnonOne and Knox, the forum hosts over 12,700 registered members and offers a tiered membership model (VIP, MVP, and GOD ranks) alongside a full range of cybercrime content: leaked databases, stealer logs, combo lists, malware tools, and access listings. It is on this forum that DarkOwl researchers identified the threat actor Dark_Alpha advertising FortiGate access tied to the FortiBleed campaign.

On June 20th, 2026, a threat actor using the handle “Dark_Alpha” — an MVP-tier member of Darkforums — posted a thread titled “[ FortiBleed ] FortiGate / Fortinet Access 35k ip”.

This content was identified and captured by DarkOwl Vision during routine dark web collection.

DarkOwl analysts identified a corroborating listing on the Russian-language Exploit forum, posted by an actor operating under a distinct handle but sharing an identical TOX ID — suggesting a high likelihood of the same underlying threat actor. The following screenshot was captured via DarkOwl Vision.

“Dark_Alpha” is an MVP member of Darkforums. On Darkforums, MVP membership is available to any user for a one-time fee of €40, granting elevated privileges such as the ability to change usernames (twice), +60 forum credits, a higher daily post limit of 10, and the ability to edit or delete posts for up to two months — as detailed in Screenshot.

Dark_Alpha is advertising FortiGate/Fortinet access to 35,000 corporate targets for $25,000. According to the actor, the dataset spans 194 countries — a geographic footprint that aligns precisely with the confirmed scope of the FortiBleed campaign as documented by Arctic Wolf and CISA, lending the listing a degree of credibility. The data is structured in the format “url:user:pass:domain:revenue.” The actor provided a TOX ID for contact.

According to the actor’s profile, Dark_Alpha joined Darkforums on February 28, 2025, and has since created 6 threads and 11 posts, accumulating a forum reputation score of 6. The profile signature reads “ALPHA-GROUP”.

The actor also lists a QTOX ID on their profile and can be reached via the forum’s private messaging feature.

Beyond the FortiBleed listing, Dark_Alpha has been actively posting access listings targeting organizations across Bolivia, Vietnam, India, the United States, and Brazil — including at least two alleged government entities. DarkOwl researchers identified the following threads attributed to this actor on Darkforums:

  • On June 9th, 2026, Dark_Alpha listed administrator-level GitLab access to a Bolivian government entity — identified by the thread title as AGETIC (Bolivia’s national e-government agency) — with reported revenue of $69.6 million, priced at $1,000
  • On June 11th, 2026, the actor listed admin-level GitLab access to a Brazilian government entity for $2,000. The target’s revenue is claimed at $50 million. The actor claims the access was obtained via a zero-day exploit — a claim DarkOwl cannot independently verify and which predates the public FortiBleed disclosure, suggesting this may be a separate intrusion vector. The listing includes tokens, APIs, database keys, source code, and environment variables.
  • On June 12th, 2026, Dark_Alpha listed FortiGate VPN access to a Vietnamese entity with over 90 hosts, super-admin rights, and claimed revenue of $22 million, priced at $1,000 . As with the Brazil listing, the actor claims access was obtained via a zero-day exploit. Given that this listing also predates the public FortiBleed disclosure, whether it is related to FortiBleed or an independent intrusion is unclear.
  • Later that same day, the actor posted a second listing: FortiGate VPN/portal access to an Indian entity in the Medical Devices & Equipment sector, with claimed revenue of $3 billion and 1,193 hosts.
  • On June 21st, 2026 — three days after CISA’s FortiBleed advisory — Dark_Alpha listed 6,355 valid FortiGate device accesses from U.S.-based entities, explicitly citing the FortiBleed vulnerability as the acquisition method. Given that India, the U.S., and Mexico collectively account for a significant share of the 73,000+ compromised devices identified by researchers, a U.S.-focused subset of that scale is plausible. Targeted organizations span a revenue range of $1 million to $200 billion. The bulk price is $7,000, with individual access also available. Notably, the actor accepted payment via the forum’s escrow system — a mechanism that may indicate a higher degree of transactional credibility.

Note on escrow: An escrow system acts as a trusted intermediary, holding payment until the buyer confirms receipt of the promised goods — a mechanism designed to reduce fraud between anonymous parties and one that more established actors tend to offer.

While Dark_Alpha has been active on Darkforums since February 2025, some earlier threads are no longer accessible due to the forum’s repeated TLD changes. DarkOwl maintains historical records across all known Darkforums domains, enabling researchers to track actor activity across those domain transitions.

DarkOwl analysts identified a corroborating finding wherein a network access broker operating on the Russian-language forum XSS, who shared a Telegram contact, utilized the identical handle “Dark_Alpha.” While this handle overlap suggests a potential link to the actor discussed above, attribution across forums cannot be confirmed with certainty, and the possibility of handling reuse by a distinct threat actor cannot be ruled out at this time.

The activity attributed to Dark_Alpha illustrates how rapidly IABs capitalize on newly disclosed — and in this case, still unfolding — credential exposure events. In under two weeks following the public emergence of FortiBleed, this actor posted listings spanning six countries, two alleged government entities, and thousands of compromised devices across critical sectors including government IT and medical devices. The listing of 6,355 U.S. FortiGate accesses posted the same week as the CISA advisory underscores how quickly the darknet economy responds to public disclosures: rather than dampening activity, news coverage appears to have been used as a sales tool.

The “ALPHA-GROUP” signature warrants further monitoring. Whether this represents a larger team or a solo actor cultivating a brand, the pace and breadth of Dark_Alpha’s listings in such a compressed timeframe — and the actor’s apparent access to data that aligns with the confirmed FortiBleed scope — suggests an established and operationally capable presence in the access brokering ecosystem.

It is also worth noting that separate research linked the original FortiBleed data exposure to a threat actor operating under the handle “SantaAd” on a Russian-language cybercrime forum. Whether Dark_Alpha is independently operating, reselling data obtained from SantaAd, or represents a separate arm of the same operation is an open question and a thread worth pulling.

Organizations running FortiGate or Fortinet devices should treat FortiBleed as an active, exploited threat and verify patch status immediately. Rotating credentials, enforcing MFA, and removing management interfaces from the public internet remain the highest-priority mitigations per CISA’s guidance. DarkOwl’s Vision UI enables security teams to monitor darknet forums for mentions of their organization, IP ranges, and credentials in near real-time — providing early warning of exposure before it can be operationalized by threat actors like Dark_Alpha.


Keep up with us. Follow us on LinkedIn.

Gaming’s Dark Side: How Discord and Steam Became Tools for Cybercrime

July 8, 2026

It is estimated that over three billion people play video games. That is nearly 43% of the worlds population! Cybercriminals know that — and they’ve spent years turning the platforms gamers trust most into infrastructure for malware, money laundering, and stolen credential markets.

Gaming has a cybercrime problem that goes way beyond cheaters and griefers. The same platforms where players organize raids, share mods, and trade rare skins have become genuine darknet-adjacent ecosystems, hosting criminal marketplaces, command-and-control servers, and sophisticated money laundering pipelines. Two platforms in particular sit at the center of this, Discord and Steam.

Gaming environments are built on trust. Players routinely download mods from strangers, click invite links from people they’ve never met, and hand over login credentials to access new servers or betas. That culture of openness is exactly what attackers exploit.

In 2025, security researchers documented millions of malicious files disguised as mods, cheat tools, and cracked games for titles like GTA, Minecraft, and Call of Duty. Behind every fake cheat was the same payload: infostealer malware designed to harvest saved browser passwords, Steam session cookies, Discord tokens, and crypto wallet keys — all in one hit, from one infected machine.

The Malware-as-a-Service (MaaS) economy has turbocharged this. New stealers like Katz and Bee (the latter priced at just $300/month on criminal forums) were built with explicit focus on Discord and gaming platforms. Katz even injected malicious JavaScript directly into Discord’s own application files to establish a persistent backdoor. Low barrier to entry, high-value targets: it’s a formula that’s working.

Discord was designed to be a gaming community tool, built with persistent servers, voice channels, file sharing, bots, invite links, fine-grained permissions, and the option to make servers completely private. However, it has also become widely used as a criminal infrastructure tool for exactly the same reasons. Fake Steam, PlayStation, and Xbox login pages were widely distributed through Discord in 2025 which were promoted via messages promising free skins, beta access, or exclusive item drops. Classic social engineering, delivered through a trusted platform.

As law enforcement took down major darknet markets through the early 2020s, a lot of criminal communities migrated to Discord, trading the anonymity of Tor for Discord’s ease of use and real-time collaboration. DarkOwl monitors a large number of servers and channels hosted on Discord that are used to discuss and share malicious activity. These aren’t amateur operations. They’re organized by commodity, with dedicated channels for combolists (username/password pairs from breached databases), fraud tutorials, stolen session tokens, and cracking tools. They maintain mirror servers specifically to survive takedowns and reconstitute banned communities within hours.

Figure 1: Discord channel offering hacking services

Discord as a Malware Delivery Network

When you upload a file to Discord, it gets hosted on Discord’s own content delivery network (CDN) and generates a permanent direct link. Attackers exploit this constantly. They upload malicious payloads to Discord’s CDN, then distribute the links through phishing campaigns, fake gaming community invites, or DMs. Because Discord’s infrastructure is trusted, often explicitly allowlisted by enterprise security tools, the malicious traffic can blend in with normal activity.

In mid-2025, researchers uncovered a campaign exploiting a flaw in Discord’s invite link system to redirect victims through silent redirection chains ending in multi-stage malware. Payloads included AsyncRAT, Skuld Stealer, and ChromeKatz — all designed to drain credentials, browser cookies, and active Discord session tokens. The attack worked because users trusted the Discord branding.

Nation-States Are Using Discord Too

This isn’t just criminal-grade activity. Nation-state actors have adopted Discord as command-and-control (C2) infrastructure because it’s so hard to detect. When malware communicates over Discord’s API, the traffic is encrypted, globally distributed, and indistinguishable from a developer’s legitimate bot.

In late 2025, the Rust-based ChaosBot malware was discovered inside a financial services firm’s network, using Discord to create a private text channel named after the victim’s computer and receive commands through it. Separately, the China-aligned APT group Webworm deployed a backdoor called EchoCreep specifically engineered to use Discord for C2, targeting government institutions and enterprises across Europe and Asia. Another China-linked group, GopherWhisper, used Discord for data exfiltration in attacks on Mongolian government entities. Discord isn’t just a gaming platform anymore — it’s part of the nation-state toolkit.

Valve’s Steam platform is the world’s largest PC gaming store, with over 130 million registered accounts and stored payment data for most of them. That makes it an extremely attractive target and an effective vehicle for financial crime.

Steam Accounts for Sale

In May 2025, a threat actor listed what they claimed was a database of 89 million Steam accounts on a dark web forum, asking $5,000 to start. The gaming world panicked. Valve investigated and determined the dataset was mostly expired SMS authentication codes, not passwords or payment data, likely sourced from a supply chain compromise of Twilio, the communications provider that delivers Steam’s SMS verification messages, a useful reminder that your platform’s security is only as strong as its weakest third-party vendor.

The more common Steam account compromises are lower-tech: credential stuffing with passwords reused from other breaches, phishing via fake login pages promoted on Discord, and infostealer malware that captures active Steam session tokens from infected PCs bypassing two-factor authentication entirely.

Virtual Items as a Money Laundering Vehicle

Steam’s virtual item economy has been systematically exploited for money laundering. Criminals will use stolen credit cards to buy tradeable in-game items or currency and then sell those items on secondary markets for real money.

The most documented case: Counter-Strike: Global Offensive container keys. These were freely tradeable on the Steam Community Market until Valve shut it down in 2019 after discovering that worldwide fraud networks had taken over, at the time of the shutdown, Valve acknowledged that nearly all significant key purchases on the market were fraud-sourced. A Vice investigation had found that 90% of CS:GO loot box transactions globally were being used to launder illicit funds.

Fortnite’s V-Bucks saw the same pattern: stolen cards used to bulk-buy currency, then sold at a discount on dark web markets and grey-market platforms. Academic analysis of Steam Marketplace transaction data has since confirmed that identifying money laundering patterns is feasible with straightforward detection methods, and found numerous accounts warranting investigation.

It’s tempting to frame gaming cybercrime as a consumer problem, something that affects individual players, not enterprises. That framing is dangerously incomplete. An employee whose personal gaming PC is compromised by an infostealer doesn’t just lose their Steam library. Infostealers harvest everything from an infected machine: every saved browser password, every active session token, every stored credential. A compromised gaming machine is frequently a compromised enterprise access point.

The same Discord servers trading gamer credentials are trading enterprise combolists. The same C2 infrastructure being used to control gaming-targeted malware is being deployed against financial services firms. The overlap between gaming culture and cybercriminal culture, particularly among younger threat actors, means these ecosystems are deeply intertwined, not parallel.


DarkOwl monitors dark web forums, Telegram channels, Discord servers, and paste sites continuously — surfacing gaming platform credentials, session tokens, and threat actor activity relevant to your organization’s exposure. Get in touch to learn more about our darknet intelligence capabilities.

DarkOwl Assessed “Awardable” for Department of War contracts in the CDAO’s Tradewinds Solutions Marketplace

Denver, CO – June 29, 2026

DarkOwl, LLC, the industry’s leading provider of darknet data today announced that it has achieved “Awardable” status through the Chief Digital and Artificial Intelligence Office’s (CDAO) Tradewinds Solutions MarketPlace.

The Tradewinds Solutions Marketplace is the premier offering of Tradewinds, the Department of War’s (DoW’s) suite of tools and services designed to accelerate the procurement and adoption of Artificial Intelligence (Al)/Machine Learning (ML), data, and analytics capabilities.

DarkOwl’s Vision UI platform is designed to collect and store data in near real-time, allowing darknet sites that frequently change location and availability to be monitored in a safe and secure manner without having to access the darknet itself.  DarkOwl’s Vision UI is the analyst interface to this dataset, giving government users on-demand access to the largest commercially available darknet dataset.  The platform is used by a wide range of businesses, including Fortune 500 companies, small businesses, and US and international government agencies.

“Achieving Awardable status on the Tradewinds Solutions Marketplace is a significant milestone for DarkOwl,” shared Mark Turnage, CEO of DarkOwl.  “It is a testament to the value of darknet intelligence within the Department of War’s digital ecosystem. Our Vision UI platform allows government analysts direct access to our darknet dataset — enabling faster, more informed decisions at every level of the mission.”

DarkOwls’ video, DarkOwl Vision UI – Darknet Intelligence for Government Missions, accessible only by government customers on the Tradewinds Solutions Marketplace, presents a brief overview of the Vision UI platform and its capabilities. DarkOwl was recognized among a competitive field of applicants to the Tradewinds Solutions Marketplace whose solutions demonstrated innovation, scalability, and potential impact on DoW missions. Government customers interested in viewing the video solution can create a Tradewinds Solutions Marketplace account at tradewindAl.com.

DarkOwl is the industry’s leading provider of darknet data. We offer the world’s largest commercially available database of information collected from the darknet. Using machine learning and AI, as well as human analysts, we automatically, continuously, and anonymously collect and index darknet, deep web, and high-risk surface net data. Our platform collects and stores data in near real-time, allowing darknet sites that frequently change location and availability to be searched and monitored in a safe and secure manner without having to access the darknet itself. Customers are able to turn this data into a powerful tool to identify organizational risk and criminal and adversarial behavior. For more information, contact us.

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.