Darknet Monitoring: A Critical Tool for Executive Risk Management

July 16, 2026

C-suite executives are prime targets for cybercriminals because they hold the keys to an organization’s most valuable assets: sensitive data, financial authority, and strategic decision-making power. Their visibility inside and outside the company also makes them easier to identify and profile. As a result, executive-focused attacks such as business email compromise (BEC), often referred to as “whaling,” have become one of the most costly forms of cybercrime, resulting in billions of dollars in losses each year. The threat is amplified by executives’ growing digital footprints. Research from ZeroFox found that 75% of executives already have exposed credentials available online, providing threat actors with a rich source of information to fuel targeted attacks.

Darknet monitoring serves as a critical early warning system for organizations seeking to stay ahead of emerging threats. While it is often impossible to prevent stolen credentials, sensitive data, or other compromised information from appearing on the dark web once it has been exposed, early detection can significantly reduce the potential impact. By identifying risks before they are weaponized, organizations can take proactive steps—such as resetting credentials, strengthening access controls, and enhancing monitoring—to prevent financial loss, data breaches, and reputational damage.

The dark web hosts a wide range of stolen and compromised information that can be exploited for fraud, cybercrime, and further attacks. Commonly traded data includes personally identifiable information (PII) such as names, addresses, identification documents, and medical records; login credentials for email, social media, and business systems; financial information including credit card and banking details; intellectual property such as source code, research, and product designs; corporate network access credentials; and customer databases containing contact information and purchasing histories. These datasets are often used to facilitate identity theft, phishing campaigns, account takeovers, financial fraud, and unauthorized access to corporate environments.

C-suite executives are frequent targets of cyberattacks, yet many organizations still do not provide additional cybersecurity protections for their leadership teams. This gap leaves executives and organizations at increased risk.

According to SOCRadar, executive identity fraud has become a widespread security concern, with more than half of U.S. companies reporting incidents involving executive impersonation. Identity-based attacks targeting senior leaders are no longer isolated events – they are an ongoing challenge for security teams.

Credential exposure is also a significant issue. Research shows that most executives have had at least one cleartext credential exposed in a data breach, often involving passwords reused across personal and professional accounts. These exposures can create easy entry points for attackers. Additionally, executive and corporate credentials are commonly found on the dark web, where stolen passwords, personal information, and access credentials are bought and sold. Without proactive monitoring and executive protection measures, these exposures can lead to phishing attacks, account takeovers, executive impersonation, and broader organizational risk.

Darknet monitoring involves continuous scanning and intelligence gathering across hidden areas of the internet that are not indexed by traditional search engines, including networks such as Tor, I2P, ZeroNet, and encrypted communication channels. Cybercriminals frequently use these platforms to buy and sell stolen data, discuss vulnerabilities and exploits, share attack techniques, and coordinate malicious activities.

By monitoring these environments, organizations can identify potential threats before they develop into full-scale incidents. Effective dark web surveillance provides early warning of compromised credentials, leaked corporate information, and other indicators of malicious activity. This allows security teams to take proactive measures—such as resetting passwords, notifying affected users, strengthening access controls, and increasing monitoring—before attackers can exploit the information.

Not all data discovered on the dark web presents the same level of risk, but much of it can be highly sensitive. Common findings include stolen credentials such as email and password combinations or VPN logins, breached corporate databases containing financial, human resources, or customer information, identity documents such as Social Security numbers and passports, and leaked internal communications or proprietary intellectual property. Even seemingly minor exposures can provide attackers with the information needed to launch more sophisticated attacks or gain unauthorized access to critical systems. As a result, organizations increasingly rely on data leak monitoring and dark web alerting capabilities to detect and respond to threats before they escalate.

Dark web monitoring also plays an important role in identifying social engineering and account takeover risks. Threat actors often use phishing campaigns, credential theft, social engineering tactics, and brute-force attacks to gain control of legitimate social media, email, and business accounts. In other cases, they invest significant time and resources into creating convincing fake online personas designed to establish trust with employees, partners, or executives. For example, attackers may build fraudulent professional profiles complete with fabricated work histories, endorsements, certifications, and conference participation records. Advances in artificial intelligence and digital content generation are making these impersonation efforts increasingly realistic, allowing threat actors to create more persuasive identities and making it more difficult for organizations to distinguish legitimate contacts from malicious actors.

Effective executive protection begins with understanding the threat landscape itself. Organizations must develop a clear picture of the malicious terrain, the actors operating within it, and the security tools available to counter emerging risks. By leveraging threat intelligence, security teams can identify executive exposure across the surface, deep, and dark web, enabling proactive detection and mitigation of potential threats. To fully understand the risks facing senior leaders, organizations must first understand the environment in which those threats originate.

A comprehensive executive cyber protection strategy should include the following measures:

  • Continuously Assess Executive Exposure: Executives are often targeted through both personal and professional channels. Regular assessments of digital exposure across public, deep-web, and dark-web sources can uncover sensitive information, impersonation attempts, credential leaks, and other indicators of risk before they are exploited.
  • Deliver Executive-Focused Security Awareness Training: Traditional security training can fail to resonate with senior leaders. Instead, organizations should provide concise, engaging learning sessions that incorporate real-world phishing simulations and executive-specific threat scenarios. Regular, targeted training helps executives recognize and respond to evolving attack techniques.
  • Formalize and Measure Security Programs: Executive protection should be integrated into a broader cybersecurity framework that aligns with business objectives. Establishing key performance indicators (KPIs), implementing controls such as multi-factor authentication, and regularly measuring security outcomes help create a mature and accountable security program.
  • Provide Ongoing Threat Intelligence Updates: The threat landscape evolves rapidly, making regular executive briefings essential. Security leaders should deliver concise updates on emerging threats, attack trends, and organizational risk exposure using business-focused metrics and contextualized reporting that supports informed decision-making.
  • Communicate Risk in Business Terms: Cybersecurity discussions are most effective when framed around business impact. Executives should understand how cyber incidents can affect revenue, operations, regulatory compliance, and brand reputation. Sharing lessons learned from high-profile breaches can help reinforce the real-world consequences of inadequate security practices.
  • Conduct Executive Cyber Crisis Simulations: Preparation is critical during a cyber incident. Executive Breach Attack Simulations (BAS) and tabletop exercises help leadership teams understand their roles during a cyber crisis, improve decision-making under pressure, and strengthen coordination between business and security stakeholders.

By combining threat intelligence, executive education, governance, and continuous monitoring, organizations can significantly reduce cyber risk to their leadership teams while building a stronger overall security posture.


Learn how DarkOwl can help. Contact us.

Q2 2026 Product Updates and Highlights 

July 16, 2026

A look at new capabilities, platform improvements, and notable darknet intelligence collected across April, May, and June. 

This quarter centered on three themes: less manual reading, thanks to new AI summarization; more context on the leaks already indexed in the platform; and clearer, more navigable views into how DarkOwl’s dataset breaks down across industries and time. Keep an eye out for enhanced data structuring for our Leak and Stealer Log data in the coming quarters! 

Forum threads can run for hundreds of posts, and market listing reviews pile up fast — reading through all of it to find the signal is one of the more time-consuming parts of darknet research. New generative AI features, now in beta, automatically summarize forum threads and market listing reviews, distilling long-running conversations and vendor reputations into a concise, readable summary in a fraction of the time it would take to read the original thread. 

Understanding how leaks are distributed — across industries and over time — matters for prioritization, trend analysis, and benchmarking against peers. New Industry Insights in Leak Explore visualize how DarkOwl’s leak dataset breaks down by sector and time period, surfacing patterns that are hard to see one leak at a time. Alongside those insights, three new filters — Associations, Industries, and Stealer Logs — make it faster to narrow the dataset down to exactly what’s relevant to an organization or sector. 

For teams managing licenses and tracking platform usage, reporting got more flexible this quarter. Date range options now include 180-day and 365-day lookback periods alongside existing ranges, giving users a longer view into usage trends. Logins have been added to the Activity display for better visibility into who’s accessing the platform and when, and Usage Reports can now be downloaded as a PDF, making it easier to share usage data with stakeholders outside the platform. 

Knowing a leak exists is only half the picture; knowing who it targeted, and what that target does, is usually the more urgent question. We’ve significantly expanded the enrichment attached to a leak’s Target, adding descriptions, associated domains, countries, and industry classification. Analysts now get the context needed to assess relevance at a glance. The enrichment now covers all historical leaks indexed in DarkOwl Vision. 

Our data collection team continues to astonish us with the quantity of data made available across all DarkOwl products, including year over year growth for the number of email addresses, domains, credit card numbers, IP addresses, and crypto addresses.

Our collection and research teams had a busy quarter. Here’s a snapshot of some of the most significant data leaks and original research that happened in Q2. 

Original Research: Mapping Darknet Drug Markets and Vendors 

Beyond the platform itself, DarkOwl’s Data Science team published new original research this quarter: “From Listings to Lineage: Mapping Darknet Drug Markets and Vendors in Early 2026.” The report traces how darknet drug marketplaces and vendor networks have shifted heading into 2026, offering a data-driven look at market structure, vendor migration, and lineage across the current darknet drug trade landscape. 

ShinyHunters Leaks

DarkOwl has ingested a number of leaks this quarter from the ShinyHunters extortion site. These leaks span multiple industries – Healthcare, Finance, Insurance, Transportation, Retail, and more – and have had a global impact due to the high volume exposure of corporate data. These leaks not only include PII but also extensive customer data, internal documents, vendor information and other intellectual property. DarkOwl has observed a high return rate of actionable intelligence within these leaks. 

proactivemedical.com

Data purported to be from Proactive Medical Inc. was posted on Cl0p, on May 12, 2026. Data exposed includes Customer information, Email addresses, Physical addresses, Account information, Device information, SSNs, Messages, User IDs, Website mentions, Phone numbers, IP addresses, Credit cards, Source code, Medical information, Company names, Internal emails, Names, Expiration dates, Internal documents, and Product data.

B1acks Stash 8 Million CVV2

A post on b1ack’s Stash, a dark web marketplace, linked to a series of files containing credit card “freebies” between May 18 and 21, 2026. Data exposed includes Credit cards, Full Names, Company names, Email addresses, Expiration dates, Phone numbers, IP addresses, and Physical addresses.


Curious how these features and data can make your job easier? Get in touch! 

FortiBleed Exploited: Tracking Initial Access Broker Dark_Alpha on Darkforums

July 15, 2026

In mid-June 2026, security researchers identified a large-scale credential compromise campaign targeting Fortinet FortiGate firewalls, quickly dubbed FortiBleed. Unlike a traditional zero-day, FortiBleed is not tied to a single new vulnerability. Instead, threat actors systematically extracted configuration files from internet-facing FortiGate devices and cracked the stored password hashes — exploiting the fact that many organizations running older FortiOS versions continued to store administrator credentials as legacy SHA-256 hashes rather than the more secure PBKDF2 format Fortinet introduced in FortiOS 7.2.11, 7.4.8, and 7.6.1. Devices upgraded from earlier versions retain SHA-256 hashes until each administrator logs in post-upgrade, leaving a window of exposure that the campaign actively exploited at scale.

The result: verified working administrator credentials for between 73,932 and 86,000 devices across 21,632 organizations in 194 countries — roughly half of all internet-facing FortiGate firewalls at the time of discovery. The United States, India, and Mexico were among the most heavily affected countries. CISA issued an advisory on June 18, 2026 urging organizations to rotate credentials, enforce MFA, and restrict management interface access.

Darkforums is currently the fastest-growing English-language cybercrime forum on the darknet. Originally launched as “DARK4RMY Forums” by a hacking group called DarkArmy, it rebranded following the April 2025 collapse of BreachForums and rapidly absorbed much of that platform’s displaced user base — recording a 600% surge in activity between April and June 2025. Now operated by administrators AnonOne and Knox, the forum hosts over 12,700 registered members and offers a tiered membership model (VIP, MVP, and GOD ranks) alongside a full range of cybercrime content: leaked databases, stealer logs, combo lists, malware tools, and access listings. It is on this forum that DarkOwl researchers identified the threat actor Dark_Alpha advertising FortiGate access tied to the FortiBleed campaign.

On June 20th, 2026, a threat actor using the handle “Dark_Alpha” — an MVP-tier member of Darkforums — posted a thread titled “[ FortiBleed ] FortiGate / Fortinet Access 35k ip”.

This content was identified and captured by DarkOwl Vision during routine dark web collection.

DarkOwl analysts identified a corroborating listing on the Russian-language Exploit forum, posted by an actor operating under a distinct handle but sharing an identical TOX ID — suggesting a high likelihood of the same underlying threat actor. The following screenshot was captured via DarkOwl Vision.

“Dark_Alpha” is an MVP member of Darkforums. On Darkforums, MVP membership is available to any user for a one-time fee of €40, granting elevated privileges such as the ability to change usernames (twice), +60 forum credits, a higher daily post limit of 10, and the ability to edit or delete posts for up to two months — as detailed in Screenshot.

Dark_Alpha is advertising FortiGate/Fortinet access to 35,000 corporate targets for $25,000. According to the actor, the dataset spans 194 countries — a geographic footprint that aligns precisely with the confirmed scope of the FortiBleed campaign as documented by Arctic Wolf and CISA, lending the listing a degree of credibility. The data is structured in the format “url:user:pass:domain:revenue.” The actor provided a TOX ID for contact.

According to the actor’s profile, Dark_Alpha joined Darkforums on February 28, 2025, and has since created 6 threads and 11 posts, accumulating a forum reputation score of 6. The profile signature reads “ALPHA-GROUP”.

The actor also lists a QTOX ID on their profile and can be reached via the forum’s private messaging feature.

Beyond the FortiBleed listing, Dark_Alpha has been actively posting access listings targeting organizations across Bolivia, Vietnam, India, the United States, and Brazil — including at least two alleged government entities. DarkOwl researchers identified the following threads attributed to this actor on Darkforums:

  • On June 9th, 2026, Dark_Alpha listed administrator-level GitLab access to a Bolivian government entity — identified by the thread title as AGETIC (Bolivia’s national e-government agency) — with reported revenue of $69.6 million, priced at $1,000
  • On June 11th, 2026, the actor listed admin-level GitLab access to a Brazilian government entity for $2,000. The target’s revenue is claimed at $50 million. The actor claims the access was obtained via a zero-day exploit — a claim DarkOwl cannot independently verify and which predates the public FortiBleed disclosure, suggesting this may be a separate intrusion vector. The listing includes tokens, APIs, database keys, source code, and environment variables.
  • On June 12th, 2026, Dark_Alpha listed FortiGate VPN access to a Vietnamese entity with over 90 hosts, super-admin rights, and claimed revenue of $22 million, priced at $1,000 . As with the Brazil listing, the actor claims access was obtained via a zero-day exploit. Given that this listing also predates the public FortiBleed disclosure, whether it is related to FortiBleed or an independent intrusion is unclear.
  • Later that same day, the actor posted a second listing: FortiGate VPN/portal access to an Indian entity in the Medical Devices & Equipment sector, with claimed revenue of $3 billion and 1,193 hosts.
  • On June 21st, 2026 — three days after CISA’s FortiBleed advisory — Dark_Alpha listed 6,355 valid FortiGate device accesses from U.S.-based entities, explicitly citing the FortiBleed vulnerability as the acquisition method. Given that India, the U.S., and Mexico collectively account for a significant share of the 73,000+ compromised devices identified by researchers, a U.S.-focused subset of that scale is plausible. Targeted organizations span a revenue range of $1 million to $200 billion. The bulk price is $7,000, with individual access also available. Notably, the actor accepted payment via the forum’s escrow system — a mechanism that may indicate a higher degree of transactional credibility.

Note on escrow: An escrow system acts as a trusted intermediary, holding payment until the buyer confirms receipt of the promised goods — a mechanism designed to reduce fraud between anonymous parties and one that more established actors tend to offer.

While Dark_Alpha has been active on Darkforums since February 2025, some earlier threads are no longer accessible due to the forum’s repeated TLD changes. DarkOwl maintains historical records across all known Darkforums domains, enabling researchers to track actor activity across those domain transitions.

DarkOwl analysts identified a corroborating finding wherein a network access broker operating on the Russian-language forum XSS, who shared a Telegram contact, utilized the identical handle “Dark_Alpha.” While this handle overlap suggests a potential link to the actor discussed above, attribution across forums cannot be confirmed with certainty, and the possibility of handling reuse by a distinct threat actor cannot be ruled out at this time.

The activity attributed to Dark_Alpha illustrates how rapidly IABs capitalize on newly disclosed — and in this case, still unfolding — credential exposure events. In under two weeks following the public emergence of FortiBleed, this actor posted listings spanning six countries, two alleged government entities, and thousands of compromised devices across critical sectors including government IT and medical devices. The listing of 6,355 U.S. FortiGate accesses posted the same week as the CISA advisory underscores how quickly the darknet economy responds to public disclosures: rather than dampening activity, news coverage appears to have been used as a sales tool.

The “ALPHA-GROUP” signature warrants further monitoring. Whether this represents a larger team or a solo actor cultivating a brand, the pace and breadth of Dark_Alpha’s listings in such a compressed timeframe — and the actor’s apparent access to data that aligns with the confirmed FortiBleed scope — suggests an established and operationally capable presence in the access brokering ecosystem.

It is also worth noting that separate research linked the original FortiBleed data exposure to a threat actor operating under the handle “SantaAd” on a Russian-language cybercrime forum. Whether Dark_Alpha is independently operating, reselling data obtained from SantaAd, or represents a separate arm of the same operation is an open question and a thread worth pulling.

Organizations running FortiGate or Fortinet devices should treat FortiBleed as an active, exploited threat and verify patch status immediately. Rotating credentials, enforcing MFA, and removing management interfaces from the public internet remain the highest-priority mitigations per CISA’s guidance. DarkOwl’s Vision UI enables security teams to monitor darknet forums for mentions of their organization, IP ranges, and credentials in near real-time — providing early warning of exposure before it can be operationalized by threat actors like Dark_Alpha.


Keep up with us. Follow us on LinkedIn.

Gaming’s Dark Side: How Discord and Steam Became Tools for Cybercrime

July 8, 2026

It is estimated that over three billion people play video games. That is nearly 43% of the worlds population! Cybercriminals know that — and they’ve spent years turning the platforms gamers trust most into infrastructure for malware, money laundering, and stolen credential markets.

Gaming has a cybercrime problem that goes way beyond cheaters and griefers. The same platforms where players organize raids, share mods, and trade rare skins have become genuine darknet-adjacent ecosystems, hosting criminal marketplaces, command-and-control servers, and sophisticated money laundering pipelines. Two platforms in particular sit at the center of this, Discord and Steam.

Gaming environments are built on trust. Players routinely download mods from strangers, click invite links from people they’ve never met, and hand over login credentials to access new servers or betas. That culture of openness is exactly what attackers exploit.

In 2025, security researchers documented millions of malicious files disguised as mods, cheat tools, and cracked games for titles like GTA, Minecraft, and Call of Duty. Behind every fake cheat was the same payload: infostealer malware designed to harvest saved browser passwords, Steam session cookies, Discord tokens, and crypto wallet keys — all in one hit, from one infected machine.

The Malware-as-a-Service (MaaS) economy has turbocharged this. New stealers like Katz and Bee (the latter priced at just $300/month on criminal forums) were built with explicit focus on Discord and gaming platforms. Katz even injected malicious JavaScript directly into Discord’s own application files to establish a persistent backdoor. Low barrier to entry, high-value targets: it’s a formula that’s working.

Discord was designed to be a gaming community tool, built with persistent servers, voice channels, file sharing, bots, invite links, fine-grained permissions, and the option to make servers completely private. However, it has also become widely used as a criminal infrastructure tool for exactly the same reasons. Fake Steam, PlayStation, and Xbox login pages were widely distributed through Discord in 2025 which were promoted via messages promising free skins, beta access, or exclusive item drops. Classic social engineering, delivered through a trusted platform.

As law enforcement took down major darknet markets through the early 2020s, a lot of criminal communities migrated to Discord, trading the anonymity of Tor for Discord’s ease of use and real-time collaboration. DarkOwl monitors a large number of servers and channels hosted on Discord that are used to discuss and share malicious activity. These aren’t amateur operations. They’re organized by commodity, with dedicated channels for combolists (username/password pairs from breached databases), fraud tutorials, stolen session tokens, and cracking tools. They maintain mirror servers specifically to survive takedowns and reconstitute banned communities within hours.

Figure 1: Discord channel offering hacking services

Discord as a Malware Delivery Network

When you upload a file to Discord, it gets hosted on Discord’s own content delivery network (CDN) and generates a permanent direct link. Attackers exploit this constantly. They upload malicious payloads to Discord’s CDN, then distribute the links through phishing campaigns, fake gaming community invites, or DMs. Because Discord’s infrastructure is trusted, often explicitly allowlisted by enterprise security tools, the malicious traffic can blend in with normal activity.

In mid-2025, researchers uncovered a campaign exploiting a flaw in Discord’s invite link system to redirect victims through silent redirection chains ending in multi-stage malware. Payloads included AsyncRAT, Skuld Stealer, and ChromeKatz — all designed to drain credentials, browser cookies, and active Discord session tokens. The attack worked because users trusted the Discord branding.

Nation-States Are Using Discord Too

This isn’t just criminal-grade activity. Nation-state actors have adopted Discord as command-and-control (C2) infrastructure because it’s so hard to detect. When malware communicates over Discord’s API, the traffic is encrypted, globally distributed, and indistinguishable from a developer’s legitimate bot.

In late 2025, the Rust-based ChaosBot malware was discovered inside a financial services firm’s network, using Discord to create a private text channel named after the victim’s computer and receive commands through it. Separately, the China-aligned APT group Webworm deployed a backdoor called EchoCreep specifically engineered to use Discord for C2, targeting government institutions and enterprises across Europe and Asia. Another China-linked group, GopherWhisper, used Discord for data exfiltration in attacks on Mongolian government entities. Discord isn’t just a gaming platform anymore — it’s part of the nation-state toolkit.

Valve’s Steam platform is the world’s largest PC gaming store, with over 130 million registered accounts and stored payment data for most of them. That makes it an extremely attractive target and an effective vehicle for financial crime.

Steam Accounts for Sale

In May 2025, a threat actor listed what they claimed was a database of 89 million Steam accounts on a dark web forum, asking $5,000 to start. The gaming world panicked. Valve investigated and determined the dataset was mostly expired SMS authentication codes, not passwords or payment data, likely sourced from a supply chain compromise of Twilio, the communications provider that delivers Steam’s SMS verification messages, a useful reminder that your platform’s security is only as strong as its weakest third-party vendor.

The more common Steam account compromises are lower-tech: credential stuffing with passwords reused from other breaches, phishing via fake login pages promoted on Discord, and infostealer malware that captures active Steam session tokens from infected PCs bypassing two-factor authentication entirely.

Virtual Items as a Money Laundering Vehicle

Steam’s virtual item economy has been systematically exploited for money laundering. Criminals will use stolen credit cards to buy tradeable in-game items or currency and then sell those items on secondary markets for real money.

The most documented case: Counter-Strike: Global Offensive container keys. These were freely tradeable on the Steam Community Market until Valve shut it down in 2019 after discovering that worldwide fraud networks had taken over, at the time of the shutdown, Valve acknowledged that nearly all significant key purchases on the market were fraud-sourced. A Vice investigation had found that 90% of CS:GO loot box transactions globally were being used to launder illicit funds.

Fortnite’s V-Bucks saw the same pattern: stolen cards used to bulk-buy currency, then sold at a discount on dark web markets and grey-market platforms. Academic analysis of Steam Marketplace transaction data has since confirmed that identifying money laundering patterns is feasible with straightforward detection methods, and found numerous accounts warranting investigation.

It’s tempting to frame gaming cybercrime as a consumer problem, something that affects individual players, not enterprises. That framing is dangerously incomplete. An employee whose personal gaming PC is compromised by an infostealer doesn’t just lose their Steam library. Infostealers harvest everything from an infected machine: every saved browser password, every active session token, every stored credential. A compromised gaming machine is frequently a compromised enterprise access point.

The same Discord servers trading gamer credentials are trading enterprise combolists. The same C2 infrastructure being used to control gaming-targeted malware is being deployed against financial services firms. The overlap between gaming culture and cybercriminal culture, particularly among younger threat actors, means these ecosystems are deeply intertwined, not parallel.


DarkOwl monitors dark web forums, Telegram channels, Discord servers, and paste sites continuously — surfacing gaming platform credentials, session tokens, and threat actor activity relevant to your organization’s exposure. Get in touch to learn more about our darknet intelligence capabilities.

Threat Intelligence RoundUp: June

July 01, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. French govt messaging service breached in account hijacking attack – Bleeping Computer

France’s digital affairs directorate (DINUM) disclosed a breach of Tchap, the French government’s encrypted messaging platform, after attackers gained access through a compromised user account. The incident was detected by ANSSI on Sunday, and authorities have notified the CNIL due to potential exposure of personal data. A threat actor claimed the breach resulted from a social engineering attack, alleging they obtained leaked LDAP credentials and exfiltrated over 13.5GB of documents and media files shared by government employees. While DINUM has not confirmed these claims, it has alerted all Tchap users and reminded them that public chat rooms are not encrypted. Read full article.

2. FBI Warns of Phishing-as-a-Service Platform Compromising Microsoft 365 – ic3

The FBI has issued a warning about Kali365, a phishing-as-a-service (PHaaS) platform used to compromise Microsoft 365 accounts. The platform leverages device code phishing techniques, exploiting OAuth device code authentication to steal session tokens and circumvent multi-factor authentication (MFA). This authentication method lets devices with limited input capabilities such as smart TVs, conference room systems, streaming devices, printers, and IoT devices to sign in using a short code on another device through Microsoft’s device code login portal. Beginning in April, the platform was distributed via Telegram channels for cybercriminals looking for an easier way to compromise Microsoft 365.

The Silent Ransom Group (SRG) is actively targeting law firms through sophisticated social engineering campaigns. Threat actors typically impersonate IT support personnel via phone calls and phishing emails to gain access to victim systems. Once trust is established, they use legitimate remote access tools to infiltrate networks and exfiltrate sensitive data. In some cases, SRG has reportedly gone a step further by sending individuals to a victim organization’s office to obtain physical access to computers. This activity follows an FBI FLASH advisory issued last week warning that SRG was targeting U.S. law firms through social engineering schemes and in-person data theft operations. Mandiant has released additional technical details describing the group’s intrusion methods. According to Mandiant, SRG targeted dozens of organizations across the legal, financial, and professional services sectors between January and May 2026. Read more here.

On May 27, the Spanish National Police arrested the individual behind data leaks that published information from the State Attorney General’s Office, National Cybersecurity Institute (INCIBE), the National Police, the Civil Guard, and the National Security Council. In February the INCIBE announced an ongoing doxing operation that targeted collection and publication of data impacting key entities and their employees. Potential sources of this information include historical data breaches, credential dumps, and OSINT tools. The data may have been aggregated and correlated from multiple sources to create curated datasets. Some leaked records reportedly contained outdated information, including the names of individuals who had left INCIBE several years earlier. Read here.

5. Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks – Bleeping Computer

Observed activity indicates the threat actor DriveSurge is leveraging compromised websites to facilitate a large-scale distribution campaign utilizing ClickFix and FakeUpdates techniques. Researchers at Silent Push report the DriveSurge campaign has compromised thousands of websites, redirecting visitors to malware-delivery infrastructure. The operation relies on social engineering tactics like ClickFix, which tricks users into running malicious commands under the guise of fixing issues, and FakeUpdates, which uses fake browser update prompts to install malware. Silent Push says DriveSurge mainly acts as an Initial Access Broker (IAB) using a pay-per-install (PPI) model, selling access to infected systems for follow-on cyberattacks. Learn more.

6. FBI warns of in-person data theft attacks from extortion gang – Bleeping Computer

In a recent FBI flash alert, the agency warned that the Silent Ransom Group (SRG) has been targeting U.S.-based law firms through in-person data theft operations. Reports claim that SRG actors employ social engineering tactics by impersonating members of a victim organization’s IT department. These actors either place direct phone calls or send phishing emails instructing employees to contact a fraudulent IT support representative. During the interaction, the SRG actor persuades the employee to grant access through a remote desktop session. If remote access attempts are unsuccessful, SRG may dispatch an individual to the victim’s physical location to obtain direct access and insert a storage device into the victim’s computer. Read full article.

7. China-linked JDY botnet expands targeting of U.S. military networks – Bleeping Computer

The JDY botnet, previously linked to Chinese threat actors such as Volt Typhoon, has significantly expanded its targeting and reconnaissance activities. Researchers at Black Lotus Labs report that JDY remains heavily focused on the United States, particularly military and related networks. The botnet has grown from about 650 active bots in January 2024 to more than 1,500 compromised SOHO and IoT devices today. Analysis of the activity indicates that China-nexus APT actors rapidly operationalize reconnaissance efforts following public vulnerability disclosures, focusing on identifying and targeting vulnerable infrastructure. This activity has been observed across multiple sectors, with U.S. military networks and affiliated organizations representing a primary area of interest. Read full article.

8. Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT – The Hacker News

The Pakistan-aligned threat group SideCopy is believed to be behind a spear-phishing campaign, called Operation XENOFISCAL, targeting Afghanistan’s Ministry of Finance and other government entities. The attack uses a malicious Windows Shortcut (LNK) file that launches “mshta.exe” to retrieve a remote HTA file from a compromised Afghan education website. This file executes obfuscated JavaScript in memory, establishes persistence by impersonating Microsoft Edge through Registry modifications, and deploys Xeno RAT 1.8.7 using a DLL-based loader. A decoy document is also displayed to distract victims. Additional targets include provincial revenue and finance directorates, Pashto-speaking government officials, and other provincial government employees. Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

DarkOwl’s Busiest Year Ever at ISS World Europe 2026

June 25, 2026

ISS World Europe is one of the biggest dates in the calendar for intelligence agencies and technology vendors. Widely considered the largest of the ISS World Series conferences, which are held elsewhere during the remainder of the year, DarkOwl was busy (re)connecting with customers old and new – from exhibitors to guests.

In what was DarkOwl’s 10th year exhibiting and speaking at the event, a booth team of 4 DarkOwlers were on hand at the 2026 edition. For three days the team explained DarkOwl’s role in OSINT workflows, demoing a new structured marketplace feature, collecting product feedback, meeting customers and holding a DarkOwl Vision platform workshop for police officers.

Figure 1: DarkOwl Team talking to ISS World attendees

ISS World Europe – held in Prague – is the world’s largest gathering of regional Law Enforcement, Intelligence and Homeland Security analysts, Telecoms, Financial (and Cyber) Crime investigators and electronic surveillance professionals.

Real estate in the exhibitor halls proved to be at a premium, with many exhibitors filling dead space in corridors, entrances and even service areas to meet this year’s unprecedented demand.

In addition to enabling public-private partnerships in the exhibition halls, ISS World runs exclusive workshops for law enforcement guests. DarkOwl is a regular fixture. DarkOwl held a workshop to educate law enforcement and government analysts managing intelligence and investigations in the digital realm. We spoke about the DarkOwl Vision practitioner journey: from using our technology to accelerate criminal investigations, to educating our practitioners about navigating internal procurement for darknet monitoring tools.

Figure 2: A photo of DarkOwl’s ISS Workshop this year

A notable theme from the conference included the application of agentic AI to investigative workflows. Also, lawful interception in the age of encryption and privacy configuration.

The challenge of harnessing OSINT at-scale was another topic. As OSINT becomes relevant across all intelligence disciplines, there’s a choice to be made: Do we upskill the general population of analysts with OSINT tradecraft, or focus on fusion cells and labs to concentrate OSINT expertise in government?

Overall, whether it was listening and learning from the 15+ exhibitors that are already using DarkOwl, to the young LEA analysts from various EU police forces seeking to do so, ISS World Europe was a reminder of why it’s one of our favorite shows.


Interested in meeting DarkOwl? See where we will be in-person and virtually and request some time! We would love to meet up.

Ransomware Negotiation Tactics and Real-Life Examples

June 23, 2026

Your files are locked. A countdown timer is ticking. And someone you’ve never met is demanding $2 million in Bitcoin before the clock hits zero.

For thousands of organizations every year, this isn’t a hypothetical; it’s Tuesday morning. And in that moment, the instinct is to panic, pay, and pray. But the organizations that come out ahead aren’t the ones who act the fastest. They’re the ones who act the smartest.

Ransomware negotiation has quietly evolved into a professional discipline, complete with its own playbook, psychology, and practitioners. What looks like a hostage situation is actually a business transaction — one with leverage points, bluffs, and countermoves that most victims never think of using. By employing the right negotiation strategies, organizations may be able to protect critical data, reduce operational disruption, and minimize reputational damage.

While paying the ransomware may be the individuals first thought, the FBI strongly suggests not paying a ransom in response to an attack. Their reasoning states three separate factors: 

  1. No guarantees: Paying does not ensure your network or encrypted files will be successfully restored.
  2. Encourages more crime: Submitting to demands funds the perpetrators and incentivizes them to target you and others again.
  3. Operational funding: Ransomware payments provide capital for threat actors to grow their criminal enterprises. 

The U.S. Joint Ransomware Task Force (JRTF), co-chaired by the FBI and CISA, represents a coordinated national effort to combat the growing threat of ransomware attacks. The task force brings together government agencies and private sector partners to improve information sharing, strengthen operational coordination, and streamline the federal response to ransomware incidents. Through joint investigations, threat disruption operations, and the development of cybersecurity best practices, the JRTF plays a critical role in helping organizations prevent, respond to, and recover from ransomware attacks. Its creation marks a significant step toward a more unified and proactive approach to defending against evolving cyber threats.

However, some victims do choose to pay.

If your organization has decided to engage in negotiations with the threat actors, several steps should be taken before and during communications to help ensure the situation is managed as effectively and efficiently as possible. The following are recommended tactics and considerations for organizations that choose to pursue negotiations with threat actors.

  1. Gather Professional Assistance/a Team: Ransomware response requires coordinated decision-making across security, legal, business continuity, and executive leadership teams, with incident response leads managing containment, forensic analysis, regulatory obligations, and communications. Organizations should never respond to ransomware incidents alone; instead, they should engage cybersecurity experts, CERTs, ransomware recovery specialists, cyber insurance providers, and law enforcement to ensure a structured, legally compliant, and effective response. All communication with attackers should be centralized through a single authorized point of contact, while critical decisions such as ransom payment approval and business continuity actions remain restricted to C-level leadership.
  2. Begin Forensic Analysis: Forensic analysis should determine the extent of both encryption and potential data exfiltration by examining network logs, endpoint detection telemetry, and threat intelligence related to the ransomware variant involved. Incident response teams should confirm whether exfiltration occurred, identify the affected systems, and assess the types of data that may have been compromised, while preserving evidence for legal and regulatory requirements. Understanding the tactics of the ransomware group, such as RansomHub, can help predict the likelihood and timing of data exposure. 
  3. Monitor Leak Sites and Extortion Channels Early: Organizations should begin monitoring leak sites and underground channels as soon as there are indications that data may have been stolen. Threat actors increasingly use dedicated leak platforms to apply pressure, damage reputations, and create urgency around payment demands. Monitoring should extend beyond the organization’s primary name to include subsidiaries, brands, executive names, and other identifiable assets. Early visibility into leak activity can help organizations understand the threat actor’s tactics, anticipate public disclosures, and prepare appropriate communications responses.

    Many ransomware groups release small samples of allegedly stolen data before publishing larger datasets. Tracking these developments in real time allows organizations to validate claims, assess potential business impact, and make informed decisions without relying solely on information provided by the attacker.
  1. Establish Controlled Communication: Centralizing communication prevents mixed messages, unauthorized concessions, and tactical mistakes that can weaken the organization’s position. It also ensures that discussions remain consistent and aligned with legal, operational, and business objectives. The initial response typically acknowledges receipt of the ransom demand while requesting additional time for internal review and executive decision-making. Every interaction should be carefully documented to support legal, regulatory, insurance, and post-incident reporting requirements.
  2. Buy Time and Manage Expectations: Time is one of the most valuable assets during a ransomware incident. Every additional hour allows incident responders to collect forensic evidence, IT teams to validate backup and recovery options, legal teams to conduct sanctions screening, and leadership to evaluate potential courses of action.

    Experienced negotiators use legitimate business processes to slow the pace of discussions. Requests for additional approvals, verification of impacted assets, or assessments of operational impact can all create valuable breathing room. Negotiations may pause and resume multiple times as new information emerges, and recovery efforts progress. At the same time, negotiators can begin shaping expectations around what the organization can realistically pay by referencing constraints such as insurance coverage limits, financial approval requirements, or board-authorized spending thresholds.
  3. Keep Record of all Correspondence: If ransom negotiations are pursued, maintain detailed records of all communications and payment instructions to support law enforcement and investigative efforts. Additionally, request that the attackers demonstrate the validity of the decryption key by successfully decrypting several randomly selected files.

Instructure (2025) – On May 01, 2026, the threat actor group, ShinyHunters, revealed on their data leak site that they had allegedly breached the education technology company Instructure, a cloud-based education technology company best known for its Canvas learning management system, which schools and universities use to manage coursework, assignments, grading, and communication. The group had claimed to have stolen 280 million records connected to students and staff from over 8K colleges, school districts, and online education platforms. Using Canvas data export feature ShinyHunters was able to harvest “hundreds of gigabytes of user records, messages, and enrollment data”. According to the data leak site, ShinyHunters extended their deadline until May 12, claiming some of the affected institutions were engaging with the group.

In a statement on May 11, Instructure, announced they had reached an “agreement” with ShinyHunters to prevent recently breached data from being leaked. The company also disclosed that ShinyHunters had returned the stolen data and provided proof of destruction. ShinyHunters removed the warning from their leak site and posted a press statement saying they had no comment and all data had been destroyed. The FBI has warned against paying ransoms, noting that doing so does not guarantee threat actors will refrain from selling stolen data. However, the company said it acted in what it believed was the best interest of its “community”.

On May 12, the U.S. House Committee on Homeland Security requested Instructure executives to testify on the two cyberattacks by ShinyHunters on the company. The Homeland Security Committee said the repeated breaches raise “serious questions” about Instructure’s incident response practices and its ability to safeguard the data in its possession. The committee asked Instructure to participate in a briefing by May 21 to address both incidents, including the scope of the compromised data, containment and notification measures, and the company’s coordination with federal agencies.

CWT Global (2020) – In July 2020, the ransomware group Ragnar Locker infiltrated U.S. travel management company, CWT’s network, shutting down more than 30,000 computers and exfiltrating sensitive corporate data. After the attack, the threat actors demanded a $10 million ransom in exchange for a promise not to publicly release the stolen information. To demonstrate the credibility of their threat, Ragnar Locker directed CWT to a password-protected press release hosted on a hidden section of the group’s website, detailing the impending data leak.

Facing significant financial challenges caused by the COVID-19 pandemic, CWT reportedly negotiated the ransom demand down to $4.5 million. The payment was ultimately made in Bitcoin, after which Ragnar Locker claimed to honor its agreement by deleting the stolen data. The group provided CWT with credentials to access a cloud storage repository containing the exfiltrated files and removed the prepared leak announcement from its website.

In an unusual ending to the incident, Ragnar Locker also shared recommendations for improving cybersecurity defenses. Among their suggestions were stronger internal security policies and employee awareness measures, arguing that antivirus software alone is often insufficient to prevent sophisticated ransomware attacks.

University of California San Francisco (2020) – In June 2020, the University of California, San Francisco (UCSF) became the victim of a significant ransomware incident when cybercriminals encrypted critical servers and data belonging to the institution. The attack was carried out by operators of the NetWalker ransomware, a notorious malware strain responsible for numerous high-profile extortion campaigns. Although UCSF’s School of Medicine was heavily involved in leading COVID-19 antibody testing research at the time, university officials stated that the attack was not specifically directed at the institution.

After gaining access to UCSF’s network, the attackers encrypted important files and demanded a substantial ransom for their release. Ultimately, the university agreed to pay more than $1 million to the cybercriminals in exchange for a decryption key and assurances that copies of the stolen data would be returned or destroyed.

According to university officials, the payment enabled the restoration of access to critical files and systems. While UCSF declined to disclose the exact nature of the data involved, it emphasized that there was no evidence suggesting that patient medical records had been compromised during the incident.

While negotiating with ransomware attackers may appear to be the quickest path to recovery, organizations should approach that decision with extreme caution. Paying a ransom can fund future criminal operations, incentivize additional attacks, and potentially mark an organization as a willing target for future extortion attempts.

Perhaps most importantly, payment offers no certainty. Threat actors may fail to provide a working decryption key, demand additional payments, or retain stolen data despite receiving the ransom. As a result, ransomware negotiation should never be viewed as a guaranteed solution.

The most effective defense against ransomware remains preparation: maintaining secure backups, implementing strong cybersecurity controls, developing a tested incident response plan, and engaging experienced legal, cybersecurity, and negotiation professionals when an attack occurs. By focusing on resilience rather than reaction, organizations can reduce the impact of ransomware incidents and make informed decisions that align with both their operational needs and long-term security objectives.


Learn how DarkOwl can help. Contact us.

Marketplace Spotlight: DarkBay

June 18, 2026

Darknet marketplaces (DNMs) have become one of the defining features of the dark web, enabling anonymous users to buy and sell illicit goods and services beyond the reach of traditional online platforms. Early marketplaces like The Farmer’s Market laid the groundwork, but it was Silk Road that brought global attention to the underground economy operating through anonymized networks such as Tor. Since Silk Road’s takedown by law enforcement in 2013, the DNM ecosystem has remained in constant flux, with competing platforms emerging, collapsing, or disappearing altogether as vendors and buyers migrate in search of stability and security.

In recent years, law enforcement agencies have significantly improved their ability to disrupt and seize DNMs, forcing marketplaces to adapt, else vanish. At the same time, users face growing risks from “exit scams,” where marketplace administrators abruptly shut down operations and abscond with funds held in escrow. This instability has accelerated the rise of more security-conscious platforms that prioritize operational resilience and tighter user vetting.

Modern DNMs typically operate on Tor or similar anonymity-focused networks, using layered trust and security mechanisms to protect both buyers and sellers. Features such as encrypted communications using PGP (Pretty Good Privacy), escrow payment systems, user verification, and rotating mirror domains are designed to reduce exposure and maintain continuity during takedowns. Some platforms have gone further by adopting invite-only models, restricting access to vetted users in an effort to strengthen operational security and avoid infiltration.

Darkbay is a darknet marketplace accessible through the Tor network, with a name seemingly designed to mirror the familiarity of the legitimate platform eBay. Like many dark web marketplaces, it connects buyers and vendors involved in the trade of illicit goods and services, including narcotics, stolen financial data, counterfeit documents, malware, and hacking tools. Transactions are typically conducted using cryptocurrencies, while features such as vendor ratings and escrow services help build trust in an otherwise high-risk environment. As with other DNMs, users face significant risks ranging from scams and financial loss to potential law enforcement action. According to DarkOwl’s Vision, we have over 12,534 results pertaining to DarkBay Market. Open-source information reveals versions of the DNM have existed since 2020. Since first collection, activity has remained steady averaging around 500 listings per month, excluding a drastic increase of listings in January 2026. Analysis of the increase in January reveal over 2K listings made by the vendor amazonianstore selling primarily prescription drugs. According to DarkOwl Vision, amazonianstore, is the most active vendor on the site posting over 7K listings.

Figure 1: DarkOwl Vision Graph of DarkBay Market Activity
Figure 2: DarkOwl Vision Top 10 Vendor List for DarkBay Marketplace
Figure 3: DarkOwl Vision Graph Activity for Vendor Amazonianstore

Open-source reporting on the marketplace remains limited. However, a Reddit discussion from January 2020 included multiple users questioning the site’s legitimacy. More recent analysis suggests that vendors primarily operate through associated Telegram channels, which buyers can contact directly. The overall credibility of sellers on the platform remains difficult to verify, and the extent of fraudulent activity is unclear.

The below screenshot shows DarkBay’s homepage. Unlike other DNM’s the site does not require you to log in to view “merchandise”. DarkBay’s page layout advertises popular sales, such as drugs and weapons, database leaks, and even a Goldendoodle puppy.

On the left-hand side, the page provides links to specific sales categorizing them as:

  • Drugs (38,292 Listings)
  • Electronics (1,101 Listings)
  • Finance (45,233 Listings)
  • Hacking (7,898 Listings)
  • Other (16,612 Listings)

Currently (as of early June, 2026) there is a total of 109,136 product listings. The drugs section currently contains the most product listings, while Miscellaneous contains the fewest listings. The products with the most listings are currently prescriptions (11,063 listings), weapons (10,507 listings), and credit cards (9,992 listings).

Additionally, DarkBay features dedicated “store” pages that highlight individual sellers and present them as verified vendors. These pages allow buyers to browse all products offered by a seller and indicate their experience through a simple thumbs-up or thumbs-down rating system.

The drugs section on DarkBay offers a variety of illicit narcotics and prescription drugs (including tobacco products) such as marijuana, MDMA, LSD, and more. Currently (as of early June, 2026) there are a total of 38,292 drug listings on this market. The below displays a preview of these listings: 

  • LSD Pacman 22mcg, $30 USD 
  • MDMA, 10 pills/$40.00 USD 
  • Magic Mushrooms, 30 grams/$90 USD 

DarkOwl analysts selected one product (see below screenshots) to further examine. The below product is allegedly “Pure Uncut Heroin 90%” shipped from Germany. According to the description the product is “Pure uncut Afghan heroin” and can ship worldwide. The site does not provide an area for reviews or comments. Since November 2025, DarkOwl Vision shows over 300 listings for “Heroin” from 7 vendors.

Figure 9: DarkOwl Vision Vendor List

The Electronics section on DarkBay features a wide range of illicitly sold devices, including smartphones, computers, smartwatches, and other consumer electronics. Among the available categories, the computers section contains the highest number of listings, totaling approximately 428 active posts. In addition to hardware sales, vendors also advertise cyber-related services such as social media account hacking, as well as fraudulent documents including fake driver’s licenses and passports.

A significant portion of the smartphones listed for sale — including both Apple and Android devices — are offered by vendors identified as “verified sellers” on the platform, suggesting an established reputation within the marketplace. The prevalence of verified accounts may contribute to increased buyer trust and the continued growth of illegal electronic commerce on the site.

The Finance section offers “Counterfeits, Credit Cards, Cryptocurrency, Gift Cards, PayPal, and Transfers” with counterfeits and credit cards containing the highest number of results. The section’s homepage prominently showcases counterfeit currency and fraudulent credit card offerings, indicating that these products constitute a significant portion of the marketplace’s financial activity.

After reviewing the counterfeit cash offerings, analysts identified a significant volume of sales linked to the verified seller, DigitalPrint. The vendor advertises counterfeit currency from multiple countries and claims to operate out of the United States. In promotional posts, the seller states they “take care of every detail: watermarks, serial numbers, paper type, color-shifting inks, security threads, 3D security ribbons and that makes it extremely hard to distinguish our fake notes from real ones even with UV detectors.” They also caution buyers against depositing the counterfeit currency into banks.

A review of the credit cards for sale indicates that many of the listings claim to include preloaded spending limits. This section appears to contain a higher number of random, unverified sellers compared to the counterfeit documents section. In the example below, a seller advertises an American Express card with a purported $4,500 limit for $450 USD. The listing also states that the card includes a PIN and cash withdrawal instructions.

The Hacking section offers a range of illicit “products,” including database leaks and services claiming to provide unauthorized access to email and social media accounts. This includes alleged “pre-built” malware that buyers can purchase and use to infect machines of their choosing.

Due to the absence of review or feedback mechanisms on the site, the credibility and effectiveness of these sellers’ claimed hacking capabilities cannot be verified. Although sellers rarely disclose how the information was obtained, it is likely that at least some of the account data originates from prior database breaches or leaked credential collections.

The “Other” category includes a variety of miscellaneous sale sections, such as COVID-19 items, gambling services, passports, vehicles, and weapons. Among these, weapons account for the largest volume of listings, with a total of 10,507 sales. Another notably active section is passports, where buyers can obtain counterfeit identification documents, including Social Security numbers.

Open-source information revealed a 2021 publication from the National Library of Medicine (NLM) that referenced the sale of COVID-19-related materials on DNMs prior to the availability of legitimate vaccines. The publication specifically identified DarkBay marketplace as hosting the majority of COVID-19-related listings, with personal protective equipment (PPE) being the most frequently advertised product category. The chart below presents NLM’s findings on COVID-19–related listings across DarkBay compared with other analyzed marketplaces, showing a significantly higher number of such listings on DarkBay.

Figure 16: https://pmc.ncbi.nlm.nih.gov/articles/PMC7819623/

Analyst review of the current COVID-19 section found that most listings now appear to involve illegal prescription drug sales, representing a shift from the activity observed in 2021. The reason these prescription drug listings remain categorized under the COVID-19 section is unclear.

While DarkBay appears to lack the legitimacy and reputation of more established DNMs, many buyers are still drawn to them because they offer products at lower prices. Its rise in prominence reflects the disruption caused by the shutdown of major marketplaces such as Silk Road seizure and AlphaBay shutdown. Although the legitimacy of vendors and listings on these platforms is often uncertain, the products advertised are typically in high demand among individuals seeking illicit goods. As a result, transactions continue to occur on these sites regardless of concerns about their credibility or authenticity.


Curious to learn more about darknet monitoring? Contact us.

What are Man-in-the-Middle Attacks?

June 18, 2026

Cybersecurity might as well have its own language. There are so many acronyms, terms, sayings that cybersecurity professionals and threat actors both use that unless you are deeply knowledgeable, have experience in the security field or have a keen interest, one may not know. Understanding what these acronyms and terms mean is the first step to developing a thorough understanding of cybersecurity and in turn better protecting yourself, clients, and employees. 

In this blog series, we aim to explain and simplify some of the most commonly used terms. Previously, we have covered bullet proof hosting, CVEs, APIs, brute force attacks, zero-day exploits, doxing, data harvesting, IoCs, credential stuffing, ransomware as a service, push bombing, web application attacks. In this edition, we dive into man-in-the-middle attacks.

While the concept itself is straightforward, the digital execution can be incredibly sophisticated. Let’s explore what a man-in-the-middle attack is, how threat actors pull it off, and how you can protect your data from being intercepted.

Man-in-the-middle attacks may not generate the same headlines as ransomware or major data breaches, but they remain a significant threat across the cybercrime ecosystem. These statistics highlight a simple reality: while many organizations focus on attacks against endpoints and applications, data in transit remains a highly valuable target for cybercriminals.

  • Industry reports suggest nearly 58% of all posts on criminal forums and marketplaces contain banking data of others collected by MITM or other attack types.
  • Estimates show that 35% of exploitation activity involves man-in-the-middle attacks.
  • MITM attacks continue to evolve alongside cloud adoption, mobile devices, and remote work environments, creating new opportunities for attackers to intercept sensitive communications.

A Man-in-the-Middle Attack (MitM) is an attack that compromises the communication between the two parties who believe that they are communicating directly with each other. Instead of data moving directly from a user to a website, application, or service, the attacker inserts themselves into the connection to observe, steal, or manipulate information being transmitted, placing themselves “in the middle.”

The goal of an MitM attack is to compromise the CIA Triad, specifically violating confidentiality (by reading private data) and integrity (by altering the data in transit). Threat actors use these attacks to steal credentials, account details, credit card numbers, to inject malware into a victim’s system, or to create a smokescreen for an advanced attack. Depending on the technique used, victims may never realize their traffic was compromised.

  • Confidentiality: is your sensitive information only accessible to those authorized to see it?
    • Common Threats: phishing, ma-in-the-middle attacks, human error
  • Integrity: is your data authentic, accurate, and reliable?
    • Common Threats: man-in-the-middle attacks, human error, malware, hardware/software glitches

When you type a web address into your browser, your device trusts the local network to direct it to the correct destination. Threat actors exploit this trust using a couple of distinct phases: Interception and Decryption.

First, the attacker must get between the victim and their network destination. This can happen through compromised Wi-Fi networks, malicious routers, spoofed websites, DNS manipulation, or malware infections. Public Wi-Fi networks are a common target because users often connect without verifying the legitimacy or security of the network. Once traffic passes through the attacker-controlled system, the threat actor can monitor the communication in real time. After gaining access to credentials, cookies, or authentication tokens, attackers may impersonate the victim and gain unauthorized access to accounts or systems.

Common Types of Man-in-the-Middle Attacks

ARP Spoofing: Address Resolution Protocol (ARP) links IP addresses to physical MAC addresses on a local network. An attacker sends fake ARP messages to link their own MAC address with a legitimate server’s IP address. Suddenly, all data meant for the server goes to the attacker first.

Wi-Fi Eavesdropping / Rogue Access Points: An attacker sets up a malicious, free public Wi-Fi network with a common name (like “Free Airport Wi-Fi”). When a user connects, the attacker can view all unencrypted traffic flowing through the router.

DNS Spoofing (DNS Cache Poisoning): Attackers alter a DNS server or a device’s local cache to route a user to a fraudulent website that looks identical to a legitimate one (like a banking portal), allowing them to steal credentials.

Session Hijacking: Attackers steal session cookies or authentication tokens to impersonate legitimate users without needing their password.

SSL Stripping: SSL stripping downgrades secure HTTPS connections to unencrypted HTTP communications. This enables attackers to intercept information that users assume is encrypted.

Public Wi-Fi Credential Theft

While individual incidents often go unreported, cybersecurity firms routinely observe threat actors creating fake Wi-Fi networks that mimic legitimate hotel, airport, and conference, coffee shop wireless networks. Unsuspecting users connect to these networks and unknowingly expose login credentials, emails, and sensitive corporate traffic. These attacks remain one of the most common real-world examples of man-in-the-middle activity because they require relatively little sophistication and can affect large numbers of victims.

MyEtherWallet BGP Hijacking (2018)

In 2018, attackers hijacked internet routing to redirect users attempting to access MyEtherWallet. Victims were presented with a fraudulent SSL certificate and redirected to attacker-controlled infrastructure, allowing credentials and wallet information to be captured. The incident resulted in the theft of cryptocurrency and demonstrated how internet infrastructure attacks can facilitate man-in-the-middle operations.

Iranian Cyber-Espionage Campaign Using Fraudulent SSL Certificates (2011)

In 2011, attackers compromised Dutch certificate authority DigiNotar and generated fraudulent SSL certificates for domains including Google. Security researchers and Google reported that the certificates were used in man-in-the-middle attacks targeting users in Iran, allowing attackers to intercept supposedly secure communications such as Gmail traffic. Investigators later estimated that as many as 300,000 Iranian users may have been affected, making it one of the most significant documented MitM attacks ever discovered.

The common thread across MitM is trust: attackers succeed when they can convince victims—or their devices—that malicious communications are legitimate. Organizations and individuals can significantly reduce risk by following security best practices:

  • Use HTTPS: Always verify websites use HTTPS encryption. Modern browsers warn users about insecure connections, but users should still validate certificates and domains before entering credentials.
  • Avoid Untrusted Public Wi-Fi: Public wireless networks increase exposure to interception attacks. If you must use public Wi-Fi, always use a reputable Virtual Private Network (VPN) to securely tunnel and encrypt your traffic.
  • Implement Strong Wi-Fi Security: Ensure your home and office networks use strong encryption protocols (like WPA3) and change default router admin credentials immediately.
  • Enable Multi-Factor Authentication (MFA): Even if an attacker steals login credentials via an MitM attack, MFA acts as an extra layer of defense, making it much harder for them to gain access.
  • Keep Systems Updated: Security patches help close vulnerabilities attackers may exploit to conduct interception or session hijacking attacks.
  • Use VPNs: Virtual Private Networks encrypt internet traffic and reduce the risk of traffic interception on untrusted networks.
  • Monitor for Suspicious Network Activity: Organizations should implement network monitoring and anomaly detection to identify unauthorized devices, DNS changes, or unusual traffic patterns.
  • Implement Endpoint Protection: Ensure your corporate devices utilize robust endpoint detection software capable of identifying network anomalies, rogue certificates, and localized ARP spoofing attempts.
  • Train Employees on Phishing and Network Security: Many MitM attacks begin with social engineering or fake infrastructure designed to appear trustworthy. Security awareness training helps reduce successful compromises.

Security is a holistic culture, not just a software update. By understanding how threat actors operate and protecting both the physical and digital layers of your defense, you can ensure your data remains confidential, secure, and out of the middle.


Curious to learn more about dark web monitoring? Contact us.

What Darknet Markets Actually Look Like From the Inside 

June 11, 2026

Across 53 darknet marketplaces actively observed between January and April 2026, DarkOwl collected new listings spanning more than 3,200 unique category labels. That fragmentation is not an accident — markets and vendors invent categories independently, which means a listing for methamphetamine might be filed under “Stimulants,” “RC Chems,” “Speed,” “Uppers,” or something else entirely depending on where it’s posted. 

Making sense of that data requires moving past the labels. Rather than treating market-defined categories as meaningful, DarkOwl normalizes every listing into a consistent framework, then aggregates those normalized categories to produce a fingerprint: a profile of what a market actually hosts, expressed as a distribution across standardized categories. 

When you compare those fingerprints across the 53 markets active in Q1 2026, five structural groupings emerge. Below, we take a look at these findings. 

First Cluster: Fraud-Dominant Markets 

Avalon, Crown Market, and Courier Market group together because financial fraud, identity documents, and stolen credentials dominate their listing mix — not drugs. Sklad Market, Mist Market, and Apocalypse Market form a related sub-cluster, where fraud remains primary but is accompanied by a substantial hacking and cybersecurity presence. None of these markets are necessarily known by reputation as fraud platforms, but their listing distributions are unambiguous. 

Second Cluster: Mixed-Activity Markets 

Nexus Market, Atlas Market, Prime, and We-The-North maintain roughly balanced distributions across drugs, fraud, hacking tools, and compromised accounts. No single category dominates. Shadow-X occupies this cluster but stands out within it — it carries a notable share of luxury goods that distinguishes its profile from its peers. Anubis Market and Venom are grouped nearby, differentiated by a higher concentration of weapons listings alongside drugs. 

Third Cluster: Cannabis-Focused Markets 

Smokersco, CannaExpress, Drug-Town, and Trading-Market-Exchange group together not because they’re small or inactive but because their category distributions are so concentrated. These platforms sell almost exclusively cannabis — sometimes 85–90% of all listings fall into a single subcategory. Fingerprinting separates them from the broader drug markets precisely because their specialization is so pronounced. A platform that’s 90% cannabis looks nothing like a platform that’s 70% drugs across stimulants, opioids, psychedelics, and other classes. 

Fourth Cluster: Broad Drug Markets 

Omg-omg, TorZon, Blacksprut, Cocorico, and Vortex Market group here — drug listings dominate at 70–80%, with fraud and hacking as secondary categories. These are the markets the ecosystem knows by reputation, and their fingerprints confirm it. 

Fifth Cluster: Atypical Outliers 

Zelenka-LolzTeam hosts almost nothing but gaming accounts and social media profiles — its fingerprint bears no resemblance to any other market in the dataset. RoiBusiness and Ares are drug-focused but have low enough listing volumes that they remain separate from the main drug cluster, making cross-market comparison unreliable without accounting for scale. 

Markets Don’t Stay Still 

The cluster analysis reflects a four-month average, which obscures something important: several markets changed their category composition significantly over the period. Some changes are consistent with normal variation — different vendors posting different volumes in different months. Others are not. 

Stargate Market is the clearest example. January listings are dominated by adult content — the platform looks, at first glance, like a niche adult market. By February the adult content has largely disappeared, replaced by drugs and fraud. March shifts again to cannabis and services. By April, financial accounts, identity fraud, and hacking tools dominate, and drug listings have almost vanished. Over four months, Stargate cycled through four structurally different profiles. 

Avalon shows a different trajectory. January is drug-dominant. February brings a sharp increase in fraud. March sees reduced volume with a higher proportion of hacking and cybersecurity. By April, volume is significantly lower, and remaining listings are primarily fraud. The arc is consistent with a platform losing its drug vendor base — through enforcement action, vendor migration, or market reputation decline — with fraud listings filling the remaining activity. 

Shadow-X begins the period with a distinctive luxury goods presence that places it as an outlier within the mixed cluster. That distinguishing feature disappears by April, replaced by the drugs-and-fraud profile that characterizes most of its neighbors. Whatever made Shadow-X distinctive in January was gone by Q2. 

DarkHub shows the opposite pattern: category composition stays relatively consistent across all four months, but listing volume drops sharply in March and April. The mix doesn’t change — drugs and fraud, roughly stable proportions — but the platform is generating far fewer new listings. That’s a different kind of signal: not a change in what’s being sold, but a contraction in who’s selling it. 

Market reputation — what a platform is known for in forums, reviews, or community discussion — is a lagging and often inaccurate indicator of what’s actually being sold. Avalon does not carry a reputation as a fraud market. Its January data wouldn’t suggest one. Its April data is almost entirely fraud. An investigator relying on reputation-based targeting would have the wrong picture of Avalon for much of the year. 

The cluster analysis and temporal tracking together point toward a more reliable approach: compare what a market is really hosting, using normalized categories, against the broader ecosystem. Markets that appear structurally similar to known fraud-dominant platforms are worth treating as fraud-dominant platforms, regardless of what they’re called or how they’re marketed. Markets whose category composition is shifting toward fraud or hacking-focused activity are worth monitoring more closely, because that shift is often a precursor to vendor migration, enforcement attention, or platform collapse. 

When a market does collapse — as happens regularly in darknet ecosystems — its vendor population redistributes. Fingerprinting the collapsed market makes it possible to track that redistribution: look for increases in specific category clusters on other active platforms in the weeks following shutdown. The category signal persists after the market name disappears. 

Analysis based on DarkOwl’s DarkMart dataset, covering 53 active markets and new listings observed from January through April 2026. Category distributions are derived from DarkOwl’s normalized category framework, applied uniformly across all markets including listings without market-defined categories. 


Curious how DarkOwl can do deeper analysis for your company? Contact us.

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.