Evolving Threat Patterns: Handala’s Operational Shift and Ashab al-Yamin Amplification Across Telegram

April 29, 2026

Recent activity from Handala Hacking Team and Ashab al-Yamin highlights a growing overlap between cyber operations, influence campaigns, and real-world incidents. While these actors are not necessarily coordinated, their activity reflects similar patterns across Telegram and affiliated platforms, where claims, media, and narratives move quickly through a shared ecosystem.

Analysis for this report was conducted using DarkOwl Vision, leveraging keyword-based searches and targeted monitoring of Telegram channels to identify relevant activity and amplification patterns.

On April 26, 2026, the Handala hacking group announced a rebrand to The Handala Popular Resistance Front (HPR), signaling a potential shift in both branding and operational focus.

In the same announcement, the group claimed responsibility for an attack targeting an office allegedly linked to a company associated with the Shabak’s Iran Desk in Israel. The claim was posted twice to Handala’s official Telegram channel and included links to a bot designed to recruit potential insiders in Israel. This indicates a more deliberate effort to facilitate human-enabled access rather than relying solely on external cyber intrusion.

Figure 1: Handala Telegram Post + Insider Recruitment Bot

The content was rapidly reshared across affiliated Telegram channels, including accounts that have historically been aligned with Iranian Ministry of Intelligence messaging and insider recruitment advertisements:

  • Iranian Intelligence Voice (English)
  • Iranian Intelligence Voice (Arabic)
Figure 2: Resharing Across MOI/IRGC-Aligned Channels

This announcement followed a data leak released approximately 24 hours earlier across Handala-linked surface websites, including Handala-Hack and Handala-Redwanted. The leak allegedly exposed sensitive information tied to more than 100 Israeli personnel, including individuals allegedly associated with the IDF’s Maglan Unit, a specialized commando unit responsible for covert and high-risk operations.

Figures 3 & 4: Handala Leak Data / Maglan Unit Exposure

In a separate but related release on April 28, 2026, Handala also claimed to have exposed personal information tied to 2,379 U.S. Marines stationed in the Gulf region. The accompanying messaging emphasized surveillance capabilities, including identities, routines, and personal details, while framing the release as a limited demonstration of broader access. The tone of the post focused heavily on psychological pressure, warning of future escalation and reinforcing the perception of persistent monitoring.

While the veracity of these claims remains unconfirmed, the messaging reflects a clear expansion in targeting scope, extending beyond Israeli entities to include U.S. military personnel. This aligns with broader narrative patterns observed across Iran-aligned ecosystems, where exposure of personal data is used not only as proof of access, but as a mechanism for deterrence and intimidation.

Figure 5: Handala Claim of U.S. Marines Exposure

Handala’s recent activity shows a clear progression from leaking sensitive information to rapid amplification, to issuing targeting claims, and ultimately to encouraging insider recruitment. Recent claims involving the exposure of both Israeli and U.S. military personnel further suggest an expansion in targeting scope. This sequence reflects more than opportunistic hacktivism. It aligns with structured influence and access-enablement playbooks observed across Iran-aligned operations, where cyber activity is used to support both psychological pressure and real-world targeting narratives.

While direct command-and-control relationships remain unverified, the consistency in messaging, targeting focus, and amplification pathways suggests integration into a broader proxy-aligned ecosystem rather than isolated activity. Attribution across this ecosystem is intentionally diffuse, but the operational patterns remain consistent.

April 29, 2026 (0500 MST) – A knife attack in London was first reported via Telegram by the Al Faqaar channel as a text-only alert.

Al Faqaar functions similarly to established IRGC-aligned media outlets such as Sabereen News, acting as an early dissemination node for emerging incidents. As Ashab al-Yamin has moved away from centralized official channels, Al Faqaar increasingly operates as a primary publisher, often posting first and shaping how events are framed across the broader network.

Figure 6: Initial Al Faqaar Text Post

Following the initial alert, Al Faqaar published a series of updates between 0500 and 0830 MST, providing near real-time coverage of the incident, including developments related to the attack and the subsequent arrest.

Video of Knife Attack

Figure 7: Attack Footage

Video of Arrest by Police

Figure 8: Arrest Footage

Final Official Video Release

Figure 9: Branded Ashab/Al Faqaar Media Output

Notably, the messaging in the final video frames the attack as being carried out by “lone wolves,” introducing ambiguity in how the operation should be interpreted. This framing may suggest the attackers were self-directed individuals acting without direct operational control. However, the speed and structure of the subsequent media release and amplification indicate the incident was either anticipated or quickly incorporated into a broader narrative framework.

Rather than demonstrating direct coordination, the use of “lone wolf” language may reflect a deliberate strategy that allows groups to claim or amplify attacks while maintaining plausible deniability. In this model, the line between inspiration, opportunistic amplification, and operational involvement remains intentionally blurred.

Shortly after the release of the final video, the same content was reshared across at least 25 Telegram channels associated with the broader Islamic Resistance and Axis of Resistance ecosystem. In this instance, Al Faqaar appears to have served as the initial distribution point before wider propagation.

This activity reflects a decentralized dissemination model where speed, redundancy, and narrative control take priority over centralized branding. Channels such as Al Faqaar function as early distribution nodes within a wider media architecture that exhibits consistent coordination patterns without relying on a single authoritative source. The rapid propagation across aligned channels reinforces a pattern in which content origin is less important than how quickly it is amplified, enabling near real-time narrative shaping across a broader network of aligned actors.

  • Hybridization of Threat Activity: Handala’s evolution highlights the convergence of cyber operations, influence messaging, and physical-world targeting.
  • Escalation via Insider Recruitment: The use of Telegram bots to solicit insiders signals movement toward enabling real-world access.
  • Proxy-Aligned Propagation: Handala and Ashab-related content are consistently amplified through channels aligned with Iranian intelligence and proxy media ecosystems, even where formal attribution remains unclear.
  • Speed Over Attribution: Decentralized Telegram networks enable near real-time dissemination, allowing narrative shaping to outpace verification.
  • Structured Ambiguity: Attribution is deliberately obscured, but coordination patterns remain observable across platforms.

Follow along as we keep an eye on developments. Follow us on LinkedIn.

Understanding the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)

April 28, 2026

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) represents one of the most significant shifts in U.S. cybersecurity regulation in over a decade. Signed into law in March 2022, CIRCIA establishes mandatory cyber incident reporting requirements for organizations operating across all 16 critical infrastructure sectors. With CISA’s final rule expected in May 2026, the window for preparation is rapidly closing.

This blog explains what CIRCIA requires, which organizations are subject to compliance, and how DarkOwl’s dark web intelligence platform positions covered entities to meet their obligations proactively—before an incident ever occurs.

CIRCIA—the Cyber Incident Reporting for Critical Infrastructure Act of 2022—grants the Cybersecurity and Infrastructure Security Agency (CISA) authority to mandate reporting of cyber incidents and ransomware payments from owners and operators of critical infrastructure. The law tasks CISA with developing and enforcing a rulemaking process that creates standardized, time-sensitive reporting obligations across the private and public sectors.

Substantial Cyber Incidents: Covered entities must report significant cyber incidents to CISA within 72 hours of reasonably believing an incident has occurred.

Ransomware Payments: Any ransomware payment made by a covered entity must be reported to CISA within 24 hours of the payment being made.

These requirements are not merely informational. Organizations must demonstrate that they have the infrastructure and processes in place to detect incidents, assess their significance, and report within these tight windows. Failure to report carries legal consequences, including subpoena authority granted to CISA.

CISA estimates that approximately 300,000 entities will be subject to CIRCIA’s reporting requirements once the final rule takes effect. Coverage spans all 16 critical infrastructure sectors designated by the Department of Homeland Security:

The final rule will define specific thresholds and criteria for which organizations within each sector qualify as “covered entities.” Based on the NPRM and public comments, covered entities are expected to include:

Importantly, covered entity status is not limited to large enterprises. The breadth of the estimated 300,000-entity scope reflects CISA’s intent to create comprehensive visibility across the critical infrastructure ecosystem, from utilities and hospitals to transportation networks and financial institutions.

CIRCIA’s reporting obligations create a fundamental challenge: organizations cannot report what they cannot detect. The 72-hour window for substantial cyber incidents and the 24-hour window for ransomware payments demand that covered entities have continuous, proactive threat detection capabilities—not reactive, post-breach discovery processes.

DarkOwl provides dark web intelligence and credential exposure monitoring that directly addresses this challenge. Our platform enables organizations to identify indicators of compromise, data exposure, and threat actor activity before they escalate into reportable incidents—or to detect them the moment they do.

Threat actors frequently surface intent, tooling, and stolen data on dark web forums, marketplaces, and encrypted channels days or weeks before a formal attack is launched or discovered by the target organization. DarkOwl’s continuous monitoring of these environments provides covered entities with:

  • Early warning of data exfiltration, including stolen credentials, proprietary documents, and sensitive internal communications appearing on dark web markets
  • Detection of ransomware group communications referencing an organization or its vendors, often preceding deployment of ransomware payloads
  • Identification of threat actor reconnaissance and targeting activity associated with specific sectors or infrastructure types
  • Alerting on newly compromised credentials that may indicate an active breach or imminent attack

This intelligence directly supports the 72-hour reporting window by giving security teams a head start—enabling them to investigate, scope, and assess the significance of potential incidents before the clock starts.

Credential theft is among the most common precursors to significant cyber incidents. Compromised usernames and passwords—particularly those tied to privileged accounts, VPNs, or cloud infrastructure—frequently appear on dark web forums and criminal marketplaces following data breaches at third-party services.

DarkOwl’s credential exposure monitoring enables covered entities to:

  • Continuously scan for employee and customer credentials appearing in dark web breach compilations and stealer logs
  • Receive actionable alerts when new credential exposures are detected, enabling rapid password resets and account lockdowns
  • Attribute credential exposure to specific breach events, supporting incident scoping and regulatory notification decisions
  • Maintain an ongoing audit trail of exposure detection and response actions—critical documentation for demonstrating compliance due diligence

CIRCIA does not simply require organizations to report incidents—it implicitly requires that they have the detection infrastructure capable of identifying those incidents within compressed timeframes. Regulators and legal counsel will increasingly ask whether covered entities exercised reasonable diligence in monitoring for threats.

By deploying DarkOwl’s platform, organizations create a documented, auditable record of proactive threat intelligence activity. This serves multiple compliance functions:

  • Evidence of reasonable cybersecurity diligence in the event of a regulatory inquiry or breach litigation
  • Structured detection workflows that align with incident response plans and reporting procedures
  • Intelligence feeds that can integrate with SIEM, SOAR, and incident response platforms to accelerate detection-to-reporting timelines
  • Sector-specific threat intelligence relevant to each of the 16 critical infrastructure categories

CIRCIA’s scope extends to organizations that are integral to critical infrastructure operations—including technology vendors, managed service providers, and supply chain partners. A breach at a third-party vendor can create a reportable incident obligation for a covered entity, even if the covered entity’s own systems were not directly compromised.

DarkOwl supports supply chain risk management by monitoring for dark web activity associated with key vendors and third-party partners, providing covered entities with a broader view of their threat exposure across the entire organizational ecosystem.

CIRCIA represents a fundamental shift in how the U.S. government expects critical infrastructure operators to approach cybersecurity. Mandatory reporting obligations, compressed timelines, and broad sectoral coverage create both regulatory urgency and strategic imperative: covered entities must build proactive threat detection capabilities or face significant compliance risk.

DarkOwl’s dark web intelligence and credential exposure monitoring platform is designed precisely for this environment. By surfacing threats early—often before they escalate into reportable incidents—DarkOwl enables covered entities to meet their CIRCIA obligations, demonstrate proactive due diligence, and strengthen their overall security posture.


How can DarkOwl help your company prepare for CIRCIA compliance? Contact Us.

What is Push Bombing?

April 23, 2026

Cybersecurity might as well have its own language. There are so many acronyms, terms, sayings that cybersecurity professionals and threat actors both use that unless you are deeply knowledgeable, have experience in the security field or have a keen interest, one may not know. Understanding what these acronyms and terms mean is the first step to developing a thorough understanding of cybersecurity and in turn better protecting yourself, clients, and employees. 

In this blog series, we aim to explain and simplify some of the most commonly used terms. Previously, we have covered bullet proof hosting, CVEs, APIs, brute force attacks, zero-day exploits, doxing, data harvesting, IoCs, credential stuffing, and ransomware as a service. In this edition, we dive into push bombing.

Push bombing, also known as “MFA Fatigue” or “MFA Spamming,” is a deceptive social engineering tactic in which an attacker repeatedly triggers MFA push notifications to the victims device. Multi-factor authentication (MFA) has long been considered a cornerstone of modern cybersecurity. By requiring users to verify their identity through an additional factor—like a push notification to a mobile device—organizations have significantly reduced the risk of account compromise. Multifactor authentication is not invincible. As always, attackers adapt. Attackers increasingly exploit user behavior instead of cryptographic weaknesses. And this is where push bombing comes into the scene.

The goal is simple: flood a target with repeated MFA push notifications in the hope that they will eventually “approve” one. At a high level, push bombing is a shortcut. Instead of breaking through authentication controls, attackers pressure users into opening the door for them.

The process usually begins after an attacker has already obtained a user’s valid credentials, often through phishing, credential stuffing, or darknet data leaks. Once the attacker attempts to log in, the system sends a push notification to the legitimate user’s mobile app. When the user denies the request, the attacker immediately triggers another, and another—sometimes hundreds of times in a row, often in the middle of the night when the victim is less likely to be alert. Attackers often combine push bombing with chat-based impersonation, fake IT support calls, and SMS messages – creating a sense of urgency and legitimacy.

The Cybersecurity and Infrastructure Security Agency has published guidance highlighting this growing tactic.

Early warning indicators include:

  • Multiple MFA prompts within short time periods
  • Authentication approvals outside normal working hours
  • Users reporting repeated push requests they did not initiate

When a user comments, “I keep getting login prompts even though I’m not trying to sign in” that’s not a help desk or internal IT nuisance. It’s an intrusion attempt in progress.

Push bombing is actively used in real-world attacks and breaches by threat actors targeting organizations of all sizes, often as the final step in an account takeover chain. Consequences of a successful push bombing attack extend way beyond the single compromised account. Once inside, attackers can:

  • Launch impersonation or fraud campaigns
  • Access sensitive corporate systems
  • Move laterally across networks
  • Steal data or deploy ransomware

Uber

In 2022, a threat actor associated with the Lapsus$ group gained access to Uber’s internal systems. After obtaining a contractor’s password, the attacker sent a barrage of MFA requests. When the contractor initially ignored them, the attacker contacted them on WhatsApp, pretending to be from Uber IT, and told them they needed to approve the request to stop the notifications. The contractor complied, giving the attacker full access to the corporate environment.

Cisco

Also in 2022, Cisco fell victim to a series of sophisticated push bombing attacks. After compromising a user’s personal Google account to find stored credentials, the attackers moved to the corporate network. They used a combination of voice phishing (vishing) and MFA fatigue to trick the employee into granting access, eventually allowing the attackers to move laterally through the network.

What makes push bombing especially dangerous is its simplicity. It doesn’t require sophisticated malware or zero-day exploits—just stolen credentials and persistence.

Of course DarkOwl will always recommend using MFA, but let’s go one step further: choose a phishing-resistant MFA. Not all MFA is equal. SMS codes and push prompts can be bypassed (push fatigue, SIM swaps). Where available, use FIDO2 keys, WebAuthn, and passkeys, particularly for privileged and external-facing accounts for phishing-resistant authentication. Never approve a push you didn’t initiate; report repeated prompts to IT. Ask your org to move critical apps to phishing-resistant MFA.

Push bombing is the second stage of a compromise; the first stage is the loss of credentials. Awareness of when your employees’ or customers’ credentials have been leaked on the darknet can help you stay ahead of these attacks.

Leveraging a continuously updated darknet data index enables organizations to detect security gaps before a threat actor begins a push bombing campaign. By monitoring for leaked usernames and passwords associated with your domain, you can proactively force password resets and invalidate sessions, neutralizing the attacker’s ability to even trigger that first notification.


Curious to learn more about dark web monitoring? Contact us.

Q1 2026 Product Updates and Highlights 

April 21, 2026

The team is excited to share the new capabilities, platform improvements, and notable darknet intelligence collected across January, February, and March. 

Q1 was a big quarter for the DarkOwl platform. We’ve been laser-focused on one goal: helping analysts work faster and smarter — surfacing the right intelligence at the right moment, without ever breaking their flow. Here’s a look at what’s new. 

It’s never been faster to assess vendor scale, longevity, and risk — all without leaving the market listing result you’re already looking at. Vendor Context delivers an instant, comprehensive snapshot of any known vendor — directly within a Market Research listing. With a single click, analysts can see: 

  • Total markets and listings the vendor has appeared in 
  • First and last observed activity dates 
  • Top markets where the vendor is most active 
  • Primary shipping sources 
  • The vendor’s five most recent listings across all markets 

Vendor Context expands on DarkOwl’s market dataset and features, providing a purpose-built, structured investigative capability specifically designed for darknet marketplace analysis. Markets are among the most operationally significant environments on the dark web—serving as hubs for the sale of drugs, weapons, stolen data, counterfeit goods, and as nexus points for the criminal networks. DarkOwl’s enhanced market holdings now include more than 431,000 listings which extract vendor identity, product description, category, price, accepted payment methods, shipment origin/destination, reviews, and more. 

A substantial portion of threat actor activity, forum discussions, marketplace listings, and leaked data originates from Russian, Chinese, Arabic, Farsi, and other non-English-speaking communities. Global threat intelligence means working across dozens of languages. We’ve made that dramatically easier with Translation for search results. Instantly translate any text from search or alert results inline, now covering all 52 languages supported by Vision UI. No external tools, no copy-pasting — just highlight, click, and read. And because we know it matters for sensitive environments: translation runs entirely within the DarkOwl platform, with no data leaving our closed environment. 

  • Expanded Site Lexicon and Context — Data Sharing and File Repository are now recognized site categories, with full Site Context enabled across results — making it easier to identify and investigate these areas of the darknet. Key press releases, law enforcement actions, and major news coverage are now linked directly within a new media reporting field in Site Context. 
  • Export by Date Range — Generate time-based reports from Case Findings to share only the most relevant data or align exports with reporting or investigative timeframes.  
  • Save as Finding Snippet — Highlight any text in a result, click “Save as Finding Snippet,” and the Add Finding panel opens automatically. Analysts can save both the original and translated text as separate snippets within the same Finding — ideal for reporting, collaboration, and evidence tracking. 
  • Additional UX improvements — A Case Overview redesign to ensure critical alerts are now front and center; easier navigation in Actor Explore; additional fields on results from Paste sites. 

For teams building on the DarkOwl API, Q1 brought expanded data access and improved developer experience: 

  • Paste-specific fields now available in Search API: author, postDate, expires, and key 
  • Media Reporting in Context API for sites  
  • Updated API documentation for a smoother integration experience 

Our data collection team continues to astonish us with the quantity of data made available across all DarkOwl  products. Let’s highlight just some of that growth year over year:

  • 21% increase in credit card numbers
  • 20.5% increase in email addresses
  • 9% increase in IPs

Our collection and research teams had a busy quarter. Here’s a snapshot of some of the most significant data leaks and original research that happened in Q1. 

Original Research

In March 2026, our team published an in-depth analysis of how dark web and adjacent communities responded to the escalating conflict between Iran, Israel, and the United States. Hacktivist groups launched over 149 DDoS attacks against 110 organizations—107 of them in the Middle East—within days of the strikes. Jihadist communities on Telegram and Rocket.Chat used the conflict to amplify recruitment narratives, including a call for “global cyber jihad” from a group claiming al-Qaeda ties. Iranian-aligned militia channels circulated target lists and operational claims, while a notable crossover emerged between extremist ideological communities as groups linked to Nihilistic Violent Extremism blurred traditional political lines. DarkOwl continues to monitor these ecosystems as the conflict evolves. 

Leaks of Interest  

Posted on January 9, 2026, this leak exposed personal data for approximately 324,000 BreachForums users. The exposed data includes usernames, email addresses, and IP addresses for a large population of actors who may participate in buying and selling stolen data. The data came from a database backup dated August 11, 2025, inadvertently left in a publicly accessible directory during a site restoration. A 4,400-word manifesto attributed to a threat actor using the pseudonym “James” accompanied the data, framing the leak as deliberate retaliation against the forum’s users following attacks on French infrastructure.  

Posted on ShinyHunters on February 4, 2026, this dataset purports to contain 1 million records from Harvard’s Alumni Affairs and Development systems. The breach originated from a vishing campaign in November 2025 where attackers impersonated support staff and bypassed Multi-Factor Authentication in real time. Researchers describe the exposed data as a “map of influence”—including private home addresses and mobile numbers for prominent individuals alongside sensitive donor contracts and internal strategy documents. The combination of donor financial data, direct contact information, and internal strategy documents creates a rich target for spear-phishing, fraud, and reputational exploitation across a high-profile institution’s network. For security teams evaluating their own exposure, this is immediately relevant to how they think about vishing defenses and privileged access to constituent or membership systems. 

Posted to DarkForums on March 3, 2026 by threat actor FulcrumSec, this breach exploited an unpatched React application on LexisNexis AWS infrastructure via a React2Shell vulnerability combined with a weak RDS master password. The actor claims to have exfiltrated over 2GB of data including plaintext credentials and contact details for 118 U.S. government employees—including federal judges and DOJ attorneys. LexisNexis characterizes the data as largely pre-2020 legacy records. FulcrumSec frames the attack as separate from a 2024 breach that prompted a class-action lawsuit and states it was not geopolitically motivated, but intended to highlight a “sustained pattern of negligence.” For organizations that rely on LexisNexis—law firms, financial institutions, government agencies—exposure of the underlying records is a direct concern. The inclusion of federal judiciary and DOJ contact information in a publicly accessible darknet post significantly elevates risk.  


Curious how these features and data can make your job easier? Get in touch! 

Harakat Ashab al-Yamin al-Islamia: A New Group or Part of a Broader Iranian-Aligned Network?

April 16, 2026

A previously unknown group calling itself Harakat Ashab al-Yamin al-Islamia (Ashab al-Yamin) has recently emerged, claiming responsibility for a series of attacks across Europe and quickly attracting attention from analysts and media outlets. Reporting by CBS News, citing researchers from Tech Against Terrorism and others, has highlighted the group’s sudden appearance and raised questions about whether it represents a genuine operational network or a rapidly assembled media construct linked to broader geopolitical dynamics.

The group’s presence appears largely confined to Telegram, where it publishes a mix of attack claims, propaganda, and geopolitical commentary. Its Telegram footprint is fragmented, with limited persistent content and much of its activity preserved through secondary or supporter accounts.

Rather than evaluating Ashab al-Yamin as a standalone entity, a closer examination of its Telegram activity suggests a different framing. Patterns of shared content, cross-channel distribution, and overlapping narratives indicate that the group operates within a broader, loosely connected ecosystem of Iranian-aligned channels. This ecosystem overlaps with networks commonly associated with the “Islamic Resistance,” where claims, media, and messaging circulate across multiple accounts rather than originating from a single source.

This raises a central question: is Ashab al-Yamin a distinct organization, or a visible node within a broader networked ecosystem? Let’s dive in.

As of early April 2026, the group’s primary Telegram channel, Harakat Ashab al-Yamin al-Islamia, appears to have been removed or banned from the platform. The most recent identifiable content, dated April 4, included a video claiming responsibility for an attack targeting a building associated with Christians for Israel in Nijkerk, Netherlands. No clear successor channel has been identified at the time of writing, further reinforcing the group’s fragmented and unstable presence across Telegram, where continuity appears dependent on redistribution rather than sustained ownership of a single channel.

As a result, much of the group’s observable activity is derived from secondary or supporter channels, such as صفي الدين, which continues to circulate attack claims, propaganda, and related content attributed to the group.

Initial review of these channels suggests they do not function solely as claim-of-responsibility outlets. Instead, they operate as hybrid media nodes, combining attack claims, geopolitical commentary, and propagandistic amplification of broader regional narratives.

For example, content includes battlefield or intelligence-style analysis, such as satellite imagery purportedly showing damage to U.S.-linked air facilities in Bahrain and Kuwait following Iranian strikes. The accompanying text describes specific targets such as hangars, fuel storage, and drone infrastructure.

Figure 1: Satellite imagery / strike analysis post

This style of posting is consistent with content observed across pro-Iranian Telegram channels, where content blends battlefield updates, geopolitical commentary, and narrative amplification alongside claims of responsibility for attacks in Europe.

Figure 2: London ambulance attack claim video

One such example includes a video documenting an arson attack in London targeting ambulances associated with a Jewish community organization. The accompanying Arabic-language caption frames the incident as an operation carried out by Ashab al-Yamin, referencing a synagogue in the British capital and linking the action to broader anti-Israel narratives.

More recent content attributed to the group includes claims related to an attack targeting a commercial center in Amsterdam. One such post states:

Figure 3: Amsterdam attack video from Ashab al-Yamin

حركة أصحاب اليمين الإسلامية تتبنى استهداف المركز التجاري العالمي في أمستردام، وتدعو شعوب أوروبا إلى الابتعاد عن المصالح الأمريكية والصهيونية فوراً.

Translation: “The Islamic Movement of Companions of the Rights claims responsibility for targeting the World Trade Center in Amsterdam and calls on the peoples of Europe to immediately distance themselves from American and Zionist interests.”

The limited availability of such claims on the group’s official channel, combined with their continued circulation across secondary and affiliated channels, complicates efforts to assess a single point of origin. Instead, messaging is distributed across multiple accounts, where content persists through redistribution rather than consistent publication from a single source.

One particularly notable detail is the presence of Sabereen News branding within video content that was previously reposted by Ashab al-Yamin’s official Telegram channel.

Figure 4: Ashab al-Yamin post showing Sabereen News watermark; London attack

Sabereen News is a Telegram-based media outlet widely associated with Iranian-aligned networks, with multiple analyses pointing to links with Iran’s Islamic Revolutionary Guard Corps–Qods Force (IRGC-QF) and Iran-backed militia groups. Research by the Washington Institute for Near East Policy notes “strong indicators” of IRGC-QF connections and highlights that the channel first appeared on Telegram in January 2020. More recent reporting from Iran International similarly reflects its position within IRGC-linked messaging networks.

The visible Sabereen News watermark within the footage of the London ambulance attack suggests that the video was either sourced from, or circulated through, an Iranian-aligned media channel prior to being reposted by Ashab al-Yamin. Rather than serving as definitive proof of origin, this overlap indicates participation in a shared media pipeline where content is reused and redistributed across channels.

This interpretation is further supported by activity observed on Sabereen News channel, which regularly publishes operational updates, threat messaging, and geopolitical narratives aligned with Iranian interests.

Additional Sabereen content illustrates this narrative.

Figures 6 & 7: Sabereen News corporate targeting / company list

In this example, Sabereen News publishes a list of Western companies, including technology firms, financial institutions, and defense-related entities, framing them as potential targets linked to broader geopolitical events. While this is not a direct claim of responsibility, it reflects a broader pattern of signaling and narrative shaping seen across affiliated channels.

Additional recent content from Sabereen News further illustrates its role as a central distribution node within this ecosystem. In some cases, this aggregation extends beyond Iranian-aligned actors.

For example, Sabereen News has been observed resharing content attributed to Sunni jihadist groups, including material linked to Ajnad Bayt al-Maqdis. The original post appears to have been published by a Telegram account operating under the name “hamid alqawsi,” before being redistributed through Sabereen. The group’s recent pledge of allegiance to al-Qaeda, dated February 2026, coincides with broader regional escalation reinforcing patterns of opportunistic emergence tied to major geopolitical events. This further illustrates how content moves across distinct networks through centralized amplification channels.

Figures 8 & 9: Original Telegram post from “hamid_alqawsi” account and subsequent repost by Sabereen News

In a separate example, the channel reposts video footage attributed to Hezbollah depicting a missile strike on the Israeli town of Kiryat Shmona. While not directly linked to Ashab al-Yamin, this type of cross-group content aggregation highlights how Sabereen functions as a broader amplification hub, circulating material from multiple actors and reinforcing shared narratives across the network. Channels such as Sabereen News therefore remain key points of observation for tracking how new identities emerge and reappear within this network.

Figure 10: Sabereen News Telegram post reposting Hezbollah-attributed missile strike footage targeting Israel

An earlier Telegram channel, Haraka Ashab Al Yamin, identified as one of the first to publish content associated with the Amsterdam attack, appears to have been removed or banned from the platform, further complicating efforts to trace content back to a single point of origin.

Across posts, several additional patterns emerge that reinforce this ambiguity. The language is primarily Arabic, with no observable use of Farsi despite speculation of Iranian association, and messaging consistently incorporates anti-Israel and anti-Western themes aligned with broader regional narratives. Taken together, these characteristics further complicate attribution and raise questions about the group’s structure, consistency, and underlying coordination, which become more apparent when examining its claims and media output more closely.

The available Telegram content presents a mixed picture of Ashab al-Yamin’s credibility as an operational group. While the channel attempts to project visibility through attack claims and messaging, it lacks several features typically associated with more established militant organizations.

Unlike known Iranian-aligned and PMF-affiliated groups, Ashab al-Yamin does not consistently produce formalized statements, leadership messaging, or a clearly defined media structure. Its presence appears limited in scale, with no clear evidence of sustained or centralized coordination.

At the same time, the quality and style of its media output vary noticeably, with some videos appearing more refined and others more rudimentary. This inconsistency likely reflects contributions from multiple actors rather than a single coordinated media wing. This aligns with assessments from analysts cited in CBS News, who note that such output may be designed to generate psychological impact rather than demonstrate operational sophistication.

The group’s messaging also closely tracks ongoing geopolitical developments, suggesting a degree of responsiveness and an understanding of how to maximize visibility within a rapidly evolving information environment. Taken together, these patterns support the interpretation put forward by the Foundation for Defense of Democracies: that Ashab al-Yamin may function less as a centralized organization and more as a front identity used to claim attacks carried out by loosely connected or externally recruited individuals. This ambiguity becomes more meaningful when placed alongside the wider ecosystem in which the group operates.

More broadly, this model reflects a pattern observed across comparable ecosystems, where decentralization, narrative amplification, and perceived reach are often prioritized over formal organizational structure. In such contexts, visibility and attribution can be strategically leveraged to amplify perceived impact without requiring sustained operational capability.

Rather than viewing Ashab al-Yamin in isolation, its activity is more clearly understood when placed alongside a broader cluster of Telegram channels linked to the “Islamic Resistance” ecosystem.

This ecosystem includes a mix of militia-linked channels, media outlets, and amplifier accounts. Channels such as:

· شباب الإسلام

· أصحاب الكهف

· جيش الغضب

· صفي الدين

· التعبئة الشعبية للمقاومة الإسلامية في العراق ( بسيج العراق)

· القدرات العسكرية الإيرانية

These channels regularly publish claims, updates, and propaganda tied to attacks against U.S. and allied targets, while also forwarding and resharing content from one another. These channels function as an interconnected network, regularly cross-posting and reinforcing shared narratives.

Figure 11: Safee al-Deen / ecosystem connections post

Posts such as the above highlight explicit relationships between multiple groups operating under the umbrella of the “Islamic Resistance,” including Ashab al-Kahf and Jaysh al-Ghadab.

Ashab al-Kahf is an Iraqi militia group aligned with the Islamic Resistance in Iraq, known for claiming attacks against U.S. military and allied targets in the region. Its Telegram presence reflects a structured communication style, including consistent branding, formalized statements, and clearly framed claims of responsibility.

Figure 12: Ashab al-Kahf Telegram profile / branding insignia

Jaysh al-Ghadab similarly operates within this ecosystem, publishing claims and messaging tied to attacks and broader resistance narratives. Like Ashab al-Kahf, its content reflects a more established and consistent media presence, with recognizable visual identity and integration into a wider network of affiliated channels.

Figure 13: Jaysh al-Ghadab Telegram profile / branding insignia

While these groups exhibit more structured branding and communication styles, they operate within the same broader environment as Ashab al-Yamin. Figures 14 and 15 illustrate formalized statements published by Ashab al-Kahf and Jaysh al-Ghadab, both of which were subsequently forwarded by the Shabab al-Islam channel. This pattern highlights how official statements originating from more established actors are redistributed across affiliated channels, reinforcing shared narratives, and expanding reach.

Figures 14 & 15: PMF formal statement example

Both statements follow a consistent format typical of PMF-aligned media output, including religious framing, attribution of attacks against U.S. and Israeli interests, and references to specific operations. For example, one statement claims responsibility for a drone attack targeting Israeli-affiliated infrastructure in Jordan, while emphasizing civilian evacuation warnings and framing the operation within a broader resistance narrative. The second statement similarly adopts formalized language, invoking religious justification, and positioning the attack within the context of ongoing regional conflict. This contrast becomes more apparent when comparing how similar attack-related content appears across different channels within the network.

Figure 16: London ambulance attack claim Ashab al-Yamin TG channel
Figure 17: London ambulance attack claim: Safee al-Deen TG channel

Figures 16 and 17 show the same London ambulance attack being circulated through Ashab al-Yamin and Safee al-Deen channels, illustrating how identical content is redistributed across different nodes within the network, often with variations in framing and presentation.

These examples illustrate how similar content is circulated, reframed, and redistributed across different channels, reinforcing visibility and narrative consistency.

The emergence of Ashab al-Yamin aligns with a broader pattern seen across similar ecosystems: the rapid creation of new identities designed to claim responsibility, amplify narratives, and generate strategic effects. Recent analysis by Militant Wire similarly suggests that the group may function less as a traditional organization and more as an “astroturfed” identity embedded within existing Iranian-aligned networks, leveraging low-cost, high-visibility activity to maximize perceived impact.

Rather than representing the development of a traditional, hierarchical organization, this model prioritizes speed, flexibility, and visibility. New entities can quickly establish a presence, insert themselves into ongoing events, and reinforce narratives already circulating across interconnected channels. As noted in reporting by CBS News, even relatively unsophisticated or ambiguous content can achieve outsized strategic effects. This aligns with analysis from the Foundation for Defense of Democracies, which notes that such models can rely on low-cost, deniable actors and coordinated messaging without requiring a formal organizational structure. Recent research by the Global Network on Extremism and Technology similarly highlights how digital actors across different ideological and operational backgrounds can converge within shared wartime ecosystems, forming loose networks that amplify common narratives and targets.

These dynamics are not limited to militant media channels. Similar patterns can be observed among pro-Iranian hacktivist groups, which use Telegram to promote alleged data breaches and advertise them on darknet marketplaces. For example, “APT Iran” has claimed to possess stolen data from Lockheed Martin, promoting it through Telegram and advertising it on a Russian-language darknet marketplace known as “Threat Market.”

The listing advertises an estimated value of approximately $374 million, with an exclusive buyout price nearing $600 million, alongside tiered pricing for partial data access. While these figures remain unverified, their scale reflects a broader pattern of inflated valuation and narrative amplification, where the perceived significance of a breach is emphasized as much as the underlying data itself.

Figures 18 & 19: APT Iran Telegram post referencing Lockheed; Lockheed leak posted on Threat Market

More recent activity suggests increasing instability and responsiveness to external pressure. Following attention surrounding the alleged Lockheed Martin leak, the actor associated with “APT Iran” appears to have changed its Telegram identity to “Brona

Blanco had begun posting images of purported source code tied to the breach. Concurrent messaging in Farsi references potential law enforcement scrutiny, including warnings about FBI targeting of infrastructure linked to Threat Market and the implementation of contingency measures such as a “dead man’s switch.”

Figure 20: APT Iran Telegram post referencing the FBI targeting Threat Market
Figure 21: APT Iran/Brona Blanco Telegram post referencing Lockheed Martin Source Code

While these claims remain unverified, this shift in tone and behavior reinforces a consistent pattern observed across these actors: rapid escalation in claims, reactive messaging driven by perceived pressure, and an emphasis on perceived impact over independently verifiable outcomes.

This same dynamic is evident in recent claims by a group calling itself “Ababil of Minab,” which has claimed responsibility for a cyber incident targeting Los Angeles Metro infrastructure. As reported by Dark Web Informer, the group used Telegram to publicize the claim, asserting large-scale data exfiltration and system disruption while providing limited verifiable evidence. While attribution remains unclear, the group’s messaging style and distribution patterns reflect characteristics observed across other Iranian-aligned or Iran-affiliated cyber personas.

Figure 22: “Ababil of Minab” Telegram posts claiming responsibility for a cyber intrusion targeting LA Metro

As with other actors in this ecosystem, the framing of the operation emphasizes scale and impact, including claims of hundreds of terabytes of data being wiped and additional sensitive data extracted. This reflects a recurring dynamic in which perceived significance is amplified through messaging rather than confirmed technical outcomes. This interpretation is consistent with emerging reporting on Iran-linked hybrid activity, where analysts have noted coordination across pro-Iranian online ecosystems and raised questions about the authenticity of some groups operating within them.

Harakat Ashab al-Yamin al-Islamia has emerged rapidly, but its fragmented Telegram presence, recycled media, and overlap with Iranian-aligned channels complicate its assessment as a standalone organization.

Instead, it is best understood as part of a broader ecosystem in which content is circulated, repurposed, and reinforced across multiple actors. In this environment, attribution becomes less about identifying a single origin point and more about understanding how narratives move across channels.

This model allows new entities to project visibility and claim relevance without demonstrating sustained operational capability, blurring the line between coordinated activity and opportunistic amplification.

As this ecosystem evolves, tracking how new entities emerge, gain visibility, and integrate into existing networks will remain critical to assessing how influence and perceived operational reach are constructed within these networks.


Keep up with the latest. Follow us on LinkedIn.

Ransomware in 2025: A Year of Record Attacks, Rising Costs, and Expanding Threat Actors

April 14, 2026

If 2024 signaled that ransomware was becoming a systemic threat, 2025 confirmed it. Over the course of the year, ransomware evolved into one of the most disruptive forces in the cyber landscape, affecting thousands of organizations and costing billions of dollars in damages. What distinguishes 2025 is not just the scale of attacks, but the speed, accessibility, and industrialization of ransomware operations.

In this blog we will review ransomware attacks in 2025 and how they have evolved.

Estimates of global ransomware attacks in 2025 ranged between roughly 7,400 and more than 9,000 incidents, representing a sharp increase, at around 40–50 percent increase over the previous year. On average, attacks were occurring at an almost continuous pace worldwide, with hundreds of organizations falling victim each month.

Victim counts followed a similar trajectory. In some datasets, more than 7,000 organizations were publicly identified as ransomware victims, while others tracked thousands more unreported or undisclosed incidents. Growth rates in victim numbers exceeded 50 percent year over year, and the final quarter of 2025 alone saw record-breaking figures.

What stands out is not just the volume, but the breadth. Ransomware was no longer reserved for high-value, carefully selected targets. Instead, it became a high-frequency, opportunistic threat—impacting organizations across every sector and size.

One of the characteristics of ransomware activity in 2025 was its focus on critical industries. Roughly half of all attacks targeted sectors that underpin modern economies, including manufacturing, healthcare, energy, transportation, and financial services. Manufacturing, in particular, emerged as the most frequently targeted industry, accounting for a significant share of global incidents.

When production lines halt, hospitals lose access to patient systems, or energy infrastructure is disrupted, the pressure to pay a ransom increases dramatically. Cybercriminals have become adept at identifying and exploiting this urgency.

At the same time, small and medium-sized businesses continued to bear a disproportionate share of attacks. With fewer resources to invest in cybersecurity and often relying on outdated systems, these organizations presented attractive, low-resistance targets. Ransomware groups no longer needed to focus exclusively on large enterprises to generate profit; scale alone could drive returns.

Geographically, the United States remained the epicenter of ransomware activity, accounting for roughly half of all recorded attacks. Thousands of incidents were reported across the country, with Europe as a whole, and Canada also experiencing notable increases. This concentration reflects both the density of high-value targets and the interconnected nature of global supply chains.

While ransom payments themselves often make headlines, they represent only a fraction of the total economic impact. In 2025, global ransomware damages were estimated at tens of billions of dollars, with some projections placing the figure as high as $57 billion.

The average cost of a ransomware attack, including downtime, recovery, legal fees, and reputational damage hovered around $5 million. Even when companies chose not to pay the ransom, recovery costs alone frequently exceeded $1 million.

Furthermore, a single attack could also impact supply chains, disrupting thousands of dependent businesses. Industry analyses throughout 2025 consistently highlighted the systemic impact of ransomware events, particularly in manufacturing and industrial sectors.

The tactics used by ransomware groups in 2025 reflected a shift toward greater sophistication and efficiency. Double extortion became the standard model, with attackers not only encrypting data but also exfiltrating sensitive information and threatening to release it publicly. This ensured leverage even when victims had reliable backups.

In some cases, the data was not even encrypted with victims being extorted purely on the basis of the risk posed by having their data exposed. This approach reduced operational complexity while maintaining high pressure on victims.

Artificial intelligence also played an increasingly important role. AI-driven phishing campaigns enabled attackers to craft highly convincing, personalized messages at scale, dramatically improving success rates. Automation allowed cybercriminals to launch and adapt attacks more quickly than ever before, compressing timelines and overwhelming traditional defenses. There were also the beginnings of AI being used to develop ransomware or utilize it which has been observed in early 2026.

Underlying all of this was the continued growth of ransomware-as-a-service (RaaS) platforms. These ecosystems provided tools, infrastructure, and support to affiliates, allowing even relatively inexperienced actors to carry out sophisticated attacks. As a result, the number of active ransomware groups expanded significantly, with well over a hundred groups operating throughout the year. DarkOwl monitors these leak sites so organizations can monitor if any companies in their supply chain have been impacted.

In 2025, several groups stood out for their scale and impact. Qilin emerged as one of the fastest-growing ransomware-as-a-service operations, leveraging an affiliate model that enabled rapid expansion and a steady stream of attacks. Its accessibility made it particularly influential in lowering the barrier to entry for new cybercriminals.

Akira was another prominent group, targeting enterprises and critical infrastructure with a high volume of attacks.

RansomHub gained notoriety for sheer scale, reportedly linked to hundreds of victims across multiple sectors.

Meanwhile, Clop continued to execute large-scale campaigns, often exploiting vulnerabilities in widely used software to compromise multiple organizations simultaneously.

In addition to these established groups, 2025 saw the rise of more fluid, collaborative networks—sometimes described as “supergroups”—where actors shared tools, infrastructure, and intelligence. This blurred the lines between distinct organizations and made attribution more difficult.

Ransomware in 2025 was defined by scale, speed, and systemic impact. Attacks reached record levels; victims spanned every sector, and the financial consequences extended far beyond individual organizations. The rise of new groups, maturation of existing groups, and the evolution of attack methods underscored a fundamental shift: ransomware is no longer a niche cyber threat but a core challenge for modern economies.

As organizations look ahead, the lessons of 2025 are clear. Defending against ransomware will require not only stronger technical controls but also a deeper understanding of the threat ecosystem, greater resilience in critical systems, and a willingness to adapt to an adversary that continues to evolve.


Curious how DarkOwl tracks ransomware activity? Contact us.

What Movies and Shows about Cybercrime Got Right and Wrong

April 08, 2026

Imagine this: you throw on a black hoodie, turn off the lights, and sit hunched over your computer while lines of code fly across the screen. Congratulations you’re officially a “hacker.” At least that’s how movies and TV have trained us to picture it.

For decades, pop culture has leaned hard into the stereotype of the mysterious genius typing furiously in the dark, breaking into systems in seconds while dramatic music swells. Most of the time it’s wildly exaggerated, sometimes to the point of being laughable. But every now and then, a show or film comes along that actually gets parts of it right.

In this blog, we’ll review some of our favorite portrayals of hacking in media and what they nailed, what they completely missed, and why some stand out as surprisingly realistic in a sea of blinking screens and instant “I’m in!” moments. 

When it comes to television series that portray cybercrime with striking realism, USA Network’s Mr. Robot consistently ranks among the best. Airing from 2015 to 2019, the series centers on a young cybersecurity engineer in New York City whose exceptional hacking skills draw him into an underground collective of hacktivists. As he becomes entangled in their mission to dismantle corporate power structures, he evolves into a deeply flawed and morally conflicted cyber-vigilante.

Within the first episodes of the show, Hollywood’s normal treatment of hacking is thrown out the window. What would normally be shown as maniacal keyboard typing was instead focused on social engineering and email phishing. By showing these acts, it aligned more closely with activity seen by real life threat actors.

A component of Mr. Robot’s accuracy is derived from experts behind the scenes. The show consulted with Michael Bazzell, a cybercrime detective with 10 years’ experience with the FBI. In interviews, Mr. Bazzel states that all code used in the show was real and was created by the individuals on the team. If aspects of the hacking were unable to exist in the real world, those storylines would often be scrapped. Many individuals within cybersecurity applauded the show’s accuracy, expressing positive opinions of legitimate attack patterns and authentic hacker methodology.

Released during the Cold War, the 1983 film WarGames follows high school student, David, who accidently hacks into a military computer and wages a war between the U.S. and USSR. After David mistakenly identifies the military supercomputer as belonging to a video game company, two experienced hackers introduce him to the concept of “backdoor passwords.” Using this hidden access method, they can bypass normal security protocols and enter the system, reinforcing the film’s surprisingly realistic portrayal of early computer security vulnerabilities.

Despite a seemingly unrealistic plot, President Reagan ordered a full national security review after viewing the film. This led to a determination by the Joints Chief of Staff that the plot was “technically possible” and 18 months later, President Regan released the first Presidential directive on computer security. Eventually the Computer Fraud and Abuse Act was passed in 1984 with the House Committee making specific reference to the film.

One of the key factors behind the film’s technical credibility was due to the depth of its research. During development, the screenwriters consulted with Willis Ware, author of the influential 1967 paper, Security and Privacy in Computer Systems. Ware confirmed that military computer systems could, in fact, have remote access points — a detail that helped shape the film’s central premise.

Leveraging the star power of Chris Hemsworth, the 2015 action thriller Blackhat follows a furloughed convict and elite hacker who becomes the only person capable of helping authorities track down cybercriminals responsible for breaching a nuclear power plant. While the film delivers explosive, high-stakes action, many cybersecurity experts have noted that its depiction of hacking techniques reflects a surprisingly authentic approach to real-world cyber operations. While the film eventually departs from realism, many experts praise the setup and the more practical elements presented in its first half.

The characters in the film are trying to prevent a malware attack, based on the Stuxnet attack, targeted at critical infrastructure. The Stuxnet attack refers to the 2009 malware attack that caused substantial damage to the Iran nuclear program after it was installed on computers at the Natanz Nuclear Facility. The malware reportedly destroyed one-fifth of Iran’s nuclear centrifuges.

Viewers also praised the film for its relatively authentic portrayal of hacking. Instead of relying solely on flashy visuals, it depicts Chris Hemsworth’s character working with black terminal screens, command-line arguments, and tools such as Tor and keyloggers. Like many successful tech-focused films,  Blackhat relied on multiple consultants during the development and production phases. One of the most prominent was former blackhat hacker turned journalist Kevin Poulsen, who previously served three years in prison and contributed extensively to the film’s technical realism. Some viewers have even speculated that Hemsworth’s character was partially inspired by Poulsen. Another consultant was mathematician Christopher McKinley, known for his analysis and hack of the dating site OKCupid.

While researching shows and movies for this blog, one theme repeatedly appeared when discussing believability: time. To maintain pacing and excitement, many portrayals show hacking happening almost instantly. After only a few keystrokes and quick swipes across a screen, the hacker is suddenly inside the most secure government databases. For instance, in the 2001 film Swordfish, the main character is held at gunpoint and forced to hack into the DEA’s system; something he manages to accomplish in just sixty seconds.

A separate scenario seen in entertainment, especially when focused on law enforcement, is when a victim “knows” they are being hacked. The main point of hacking a system is to do so as quietly as possible in the hopes to acquire a large amount of information. Additionally, systems will rarely start displaying UI elements that would notify you that your system is under attack.

A common theme in many cybercrime films and television shows is the choice of targets. These stories often focus on hackers going after the biggest and most powerful entities, such as governments or major financial institutions. In reality, the most frequent victims of cyberattacks are ordinary individuals who often lose personal information when hackers breach databases containing private customer data.

And finally, even though the media often depict someone yanking the power cord from a monitor to stop a hack, remember that unplugging your monitor won’t actually stop an attack on your system.

A trend seen with many of the shows that are praised for being realistic is the use of consulting with experts in the field. Sometimes real-world events are so strange or unbelievable that they feel like they were written for TV. Those moments can make great plot devices and when shows draw from situations that have happened, it can make their stories feel even more realistic.

As demonstrated by the film WarGames, fictional stories can still drive real-world change. President Reagan’s inquiry following the movie prompted intelligence efforts to strengthen the United States’ defensive and offensive cyber capabilities. This underscores one of the many reasons why getting these portrayals right matters – entertainment projects can leave a lasting imprint on history.


Subscribe to our weekly newsletter to get the latest delivered to your inbox!

Threat Intelligence RoundUp: March

April 02, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. Fake Google Security site uses PWA app to steal credentials, MFA codes – Bleeping Computer

Using a fake Google Account security page, a recent phishing campaign was discovered delivering a web-based app designed to steal “one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker traffic through victims’ browsers”. The campaign uses social engineering and Progressive Web App (PWA) features to convince users that they are interacting with a legitimate Google webpage. The threat actors use the domain (google-prism[.]com) and have users follow a four-step process that gives permissions and allows the installation of malware. Once installed the malware can exfiltrate contacts, real time GPS data, and clipboard contents. Read full article.

2. UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware – The Hacker News

Recent social engineering attacks targeting European financial institutions has been attributed to the Russian linked threat actor, UAC-0050 (DaVinci Group). According to researchers, the attack mimicked a Ukrainian judicial domain “to deliver an email containing a link to a remote access payload.” The attack begins with a spear-phishing email designed to look urgent and legitimate. It uses legal-themed language to pressure the recipient into acting. The email includes a link that directs the target to download a compressed file hosted on PixelDrain, a file-sharing service. If the victim opens the fake “PDF,” the malicious file runs and installs an MSI package for Remote Manipulator System (RMS). Article here.

Surveillance firm, Intellexa, utilizes a single hook function (‘HiddenDot::setupHook()’) inside Springboard that prevents sensor activity updates in IOS products. This activity had been acknowledged previously, but the way the firm carried it out was not well understood. Recent research by Jamf analyzed Predator samples and was able to document the hiding process. The malware does not exploit IOS vulnerabilities but instead leverages “previously obtained kernel-level access to hijack system indicators that would otherwise expose its surveillance operation”. This information has helped address previously existing gaps in understanding the exploitation techniques used by commercial spyware. Read more here.

Since 2024, Chinese aligned threat group (Silver Dragon) has been observed operating within the umbrella of APT41 and targeting organizations throughout Europe and Southeast Asia. Silver Dragon gains its initial access by exploiting public-facing internet servers and delivering phishing emails that contain malicious attachments. To maintain persistence, the group hijacks legitimate Windows services, which allows the malware processes to blend into normal system activity. The group’s operations appear to specifically target government organizations. On compromised systems, they deploy Cobalt Strike beacons to maintain persistence, along with GearDoor, a backdoor that uses Google Drive as its command-and-control (C2) channel. Read here.

5. Medtech giant Stryker offline after Iran-linked wiper malware attack – Bleeping Computer

Iranian linked and pro-Palestinian hacktivist group, Handala, has claimed to have wiped tens of thousands of systems and servers belonging to medical technology company, Stryker. In a statement Handala stated “over 200,000 systems, servers, and mobile devices have been wiped and 50 terabytes of critical data have been extracted,”. The attack allegedly forced offices in 79 countries to shut down. The group does not give details on logistics but declared to target the company in “retaliation for the brutal attack on the Minab school” as well as the companies alleged “Zionist” ties. Learn more.

6. SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks – The Hacker News

On February 22, 2026, Scattered Lapsus$ Hunters (SLH) posted on their Telegram Channel stating, “if you are female and want to make some money via calling for us hit up”. The group is offering women $500-$1000 per call to help desks, with a provided written script. The recruitment seems to be an effort by the group to sidestep the “traditional” attacker profiles that IT help desk staff are trained to recognize, thereby making their impersonation attempts more convincing and effective. SLH’s primary objective is to target help desks and call centers as entry points into organizations, further highlighting the intent behind their new recruitment strategy. Read full article.

7. Poland’s nuclear research centre targeted by cyberattack – Bleeping Computer

On March 12, Poland’s National Centre for Nuclear Research (NCBJ) claimed hackers had targeted their IT infrastructure but were blocked before accessing information. The organization stated that its early-detection security systems and internal procedures prevented a breach and allowed IT staff to rapidly secure the targeted systems. The attack has not been formally attributed to any group. While Polish authorities say early indicators suggest a possible connection to Iran, they warn that the evidence could represent a false-flag attempt meant to take advantage of ongoing global tensions. Read full article.

8. SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains – The Hacker News

SloppyLemming, a threat activity cluster, has been linked to two separate attack chains that delivered malware to government agencies and critical infrastructure operators in Pakistan and Bangladesh between January 2025 and January 2026. The first attack delivered PDF lure documents to victims that once open installed his application installed a package that included a legitimate Microsoft .NET file (NGenTask.exe) and a malicious file (mscorsvc.dll). The malicious file used a technique called DLL sideloading to run. It then decrypted and launched a custom 64-bit shellcode implant. The second attack deployed Excel documents that contained malicious macros that deliver “keylogger malware”. Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

The New Face of Deception

April 01, 2026

While you’re hopefully busy avoiding all the harmless classic April Fool’s jokes, the threat actors lurking in the corners of the darknet are busy perfecting much more convincing—and dangerous—”pranks”.

Over the last few years, we’ve tracked how phishing evolved from misspelled emails to AI-generated perfection. But this year, the joke is getting even more personal.

In our previous April Fools’ specials, we’ve explored everything from the absurdity of 24 hours on the dark web to the rise of AI-powered smishing. This year, threat actors aren’t just writing better emails—they’re stealing faces and voices. Threat actors have evolved. They’re no longer just blasting generic emails into the void—they’re refining tactics using real data, automation, and even AI-generated content to increase success rates.

The AI Factor

More and more phishing messages aren’t feeling like scams: no spelling errors, no awkward phrasing, no obvious red flags. That’s because they probably weren’t written by humans. AI is now being used to generate phishing emails, fake profiles, and even voice messages that mimic real people—making scams faster, cheaper, and more believable than ever. The old advice of “look for bad grammar” is quickly becoming outdated.

Here are the new ways threat actors are trying to “fool” you this year:

Using just a few minutes of public video from LinkedIn or a recorded webinar, threat actors can now overlay a “digital mask” in real-time; this is a deepfake. Don’t be fooled into your “boss” asking for an urgent wire transfer on what seems to be a standard zoom call. Watch for unnatural blinking, “glitching” around the neck area, or a slight delay between their mouth moving and the audio.

We’ve warned about vishing (voice phishing) before, but it has leveled up. Threat actors no longer need to “act” like your IT person. With as little as 30 seconds of audio, they can clone a specific person’s voice to leave a voicemail that is indistinguishable from the real thing. Our analysts have seen a 40% uptick in “Urgent Voicemail” scams where the actor impersonates a C-suite executive requesting a password reset “while they’re boarding a flight.”

Forget the broad survey scams and junk car emails from the past. Today’s threat actor uses AI to scrape your entire digital footprint—your recent vacation photos, your “workversary” post, and even your favorite coffee shop—to build a persona that feels like a long-lost friend. We always suggest exercising caution when sharing online. Imagine this: you return home from attending a work conference and get a message on LinkedIn: “Hey [Your Name], saw you were at the Cybersecurity Summit last week! I’m the guy who sat next to you during the AI keynote. Here’s that whitepaper we discussed.” One click, and you’ve installed a specialized infostealer.

Spotting a digital deception requires a keen eye and a bit of healthy skepticism.

  • Implement a “Safe Word”: For high-stakes financial transactions, establish an offline “challenge-response” phrase that only your team knows.
  • Trust, But Verify: If your “boss” makes an unusual request via video or voice, hang up and call them back on a known, trusted number.
  • Assume Nothing is Private: If it’s on the internet, a threat actor can use it to build a profile of you. Tighten those privacy settings!

Cyber threats continue to evolve—but the fundamentals still matter: enable multi-factor authentication, use strong, unique passwords, verify before you click, and stay informed.

Technology moves fast, but the goal of the threat actor remains the same: to exploit human trust. This April Fools’ Day, let’s keep the surprises limited to harmless office pranks. Stay vigilant, stay skeptical, and remember: if a request feels “off,” it probably is.


Follow us on LinkedIn.

What is Ransomware as a Service?

March 19, 2026

Cybersecurity might as well have its own language. There are so many acronyms, terms, sayings that cybersecurity professionals and threat actors both use that unless you are deeply knowledgeable, have experience in the security field or have a keen interest, one may not know. Understanding what these acronyms and terms mean is the first step to developing a thorough understanding of cybersecurity and in turn better protecting yourself, clients, and employees. 

In this blog series, we aim to explain and simplify some of the most commonly used terms. Previously, we have covered bullet proof hosting, CVEs, APIs, brute force attacks, zero-day exploits, doxing, data harvesting, IoCs, and credential stuffing. In this edition, we dive into Ransomware as a Service.

Ransomware has become one of the most disruptive cyber threats affecting organizations worldwide. What was once a technically complex attack carried out by a small number of sophisticated hackers has evolved into a scalable criminal ecosystem. Today, ransomware can be purchased, deployed, and monetized through a model known as Ransomware-as-a-Service (RaaS). It is a business model for cybercriminals to hire ransomware operators to launch ransomware attacks on their behalf.

DarkOwl research and analysis shows how ransomware groups operate like structured businesses on darknet forums and marketplaces—recruiting affiliates, sharing tools, and dividing profits. Understanding how this ecosystem works is critical for organizations seeking to defend against it.

RaaS is a business model in which ransomware developers create malware and infrastructure, then lease it to affiliates who carry out attacks. In turn, the developers get a percentage of the ransom earnings from the affiliates. Typically, the affiliate keeps 70-80%, while the developer takes a 20-30% “licensing fee.” This model lowers the barrier to entry and this model of cybercrime is now the driving force behind the global surge in extortion attacks. Individuals with limited technical skills can participate in ransomware campaigns simply by purchasing access to a RaaS toolkit.

Ransomware groups often operate similarly to legitimate businesses, complete with recruitment processes, internal management tools, and operational dashboards used to track victims and ransom payments. DarkOwl analysts often find “starter kits” for sale on darknet forums. These kits include everything a criminal needs: the malware, a user manual on how to infect a target, and even 24/7 technical support from the developers. It is a professionalized industry where reputation and “customer service” matter to the criminals.

Figure 1: Post on criminal market XSS offers triple extortion software for purchase; Source: DarkOwl Vision

RansomHub 

The group RansomHub first appeared in February 2024, with an announcement on the Russian forum RAMP. The group operates a ransomware-as-a-service (RaaS) model, targeting multiple platforms, including Windows, Linux, and ESXi.  A user named “koley” made the announcement and invited others to join their affiliate program. RansomHub quickly became one of the most active ransomware groups, claiming 593 victims by the end of the year. RansomHub’s affiliate program has been prolific over taking established groups, such as LockBit, in the number of victims they have. Notably, RansomHub was responsible for a significant breach of the U.S. healthcare payment system in 2024. 

Hive

First observed in 2021, Hive operated as a RaaS platform with affiliates targeting organizations worldwide. The group notably targeted healthcare organizations and used double-extortion tactics—encrypting systems while also threatening to release stolen data. In 2023, an international law-enforcement operation seized Hive’s infrastructure after the group had already impacted more than 1,500 organizations globally.

Conti

Conti was one of the most prolific ransomware operations in the world. Internal chat logs leaked in 2022 revealed a highly organized operation that included employee-like roles, development pipelines, and operational dashboards used to track victims and payments. Although the group officially shut down, many of its members dispersed into other ransomware operations, continuing the ecosystem under new names.

BlackCat

Also known as ALPHV, BlackCat emerged in 2021 and quickly gained attention for being written in the Rust programming language. The group implemented a public data-leak site that indexed stolen files, increasing pressure on victims to pay ransom demands.

Ransomware is an efficient criminal operation yielding high profit for minimal work. Due to pseudo-anonymous technology, using the dark web for ransomware operations and cryptocurrency for payments, as well as email and VPN services that do not track physical location, ransomware groups will continue their activities because the risk of punishment is minimal, and the operations are profitable.

As always, DarkOwl recommends practicing cyber hygiene at work and home.

  1. The 3-2-1 Backup Rule: Keep three copies of your data, on two different media types, with one copy stored completely offline. By using multiple storage types and locations, it helps you avoid having a single point of failure.
  2. Enable Multi-Factor Authentication (MFA): Turn on MFA for every account. It adds a second proof (app prompt, code, or security key) so a stolen password alone won’t grant access.
  3. Patches and Updates: Keep everything current—laptops, phones, browsers, and even routers/IoT. Updates patch known flaws attackers actively exploit. Criminals look for “holes” in outdated software.
  4. Phishing Awareness & Training: Most RaaS attacks start with a simple phishing email. Slow down on links and attachments. Verify unusual requests on a separate channel and report suspicious emails/messages to IT.

Ransomware is not only a problem for those directly affected. Awareness of events among your own or your customers’ supplier ecosystems can help you stay aware of potential vectoring threats. The DarkOwl Ransomware API is designed to answer the essential question: Has an organization I monitor been extorted or compromised in a cybersecurity incident?

Leveraging the world’s leading and continuously updated darknet data index, you can gain insight into potential risk by conducting targeted ransomware searches. Ransomware API enables users to safely query continuously sourced and updated ransomware sites, primarily but not exclusively hosted in TOR and Telegram, run by criminal gangs, and threat actors to detect mentions of criminal activity against an organization.

Search parameters enable queries by company website, company name, contact name, or other proximity indicators such as products, brands, or other intellectual property.  Automated monitoring and alerting ensure continuous vigilance to a dynamic list of sources continually updated by DarkOwl.


Curious to learn more about Ransomware API? Contact us.

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.