Q4 2025: Product Updates and Highlights

February 04, 2026

As we have wrapped up Q4, we’re excited to share major updates to our DarkOwl Vision product suite. Below we highlight some of the most exciting feature updates and launches. These enhancement and net new features reflect our commitment to providing continued value to our partner, clients, and the cybersecurity community. We look forward to what is in store in Q1 of 2026!

Understanding darknet marketplaces is critical for identifying emerging threats, monitoring illicit activity, and staying ahead of the evolving cyber‑risk landscape. DarkOwl’s Market Explore feature delivers an intuitive experience to dive deep into our enhanced darknet marketplace dataset. We now have 81 markets, with more than 387,651 listings and 16,225 vendors in our enhanced market listing DarkMart database.

At the top of the Market Explore page, you’ll find a set of visualizations that help you quickly understand: 

  • Overall listing volume and vendor activity 
  • Top shipping sources by listing count 
  • Darknet markets and vendors with the highest activity levels 

Selecting View Charts expands the charts into a full‑screen visualization experience, where you can explore trends like: 

  • Enhanced Markets by Topic 
  • New Listings Over Time 
  • Shipping Sources Across the Entire Dataset 

Each market’s Overview page provides a snapshot of marketplace activity: 

  • Total Listings: Unique listings available within our dataset 
  • Total & Top Vendors: Overall vendor count and top vendors ranked by listing volume 
  • Top Shipping Source: The region shipping the highest volume of listings 
  • New Listings Over Time: Daily/weekly/monthly visual trends 
  • Shipping Sources Map: Color‑coded visualization from highest volume to lowest 

Additional analyst‑curated information may include Market Descriptions, Currencies Accepted, Admin Handles, Contact Information (emails, Jabber servers, PGP keys). If a PGP key exists, users can reveal and copy it with a single click. You can also jump directly from the Overview into the Markets Research section to further investigate specific listings. 

Building on the launch of DarkOwl’s Enhanced Marketplace Research in Q3, the team added several Research features: support for Findings, Search Blocks, and Site Context. Additionally, we have completed currency normalization for prices in market listings, allowing for Sort by Price features. 

Search results from selected paste sources have a new look + improved searchability. Paste results (more than 40 million documents) are now eligible to be returned when you filter by Post Date or Username in both Vision UI or Vision API. If available, Paste Authors are shown on the top of a UI search result and include a pivot link, just like Forum Post Authors or Market Vendors.  

We launched our Findings Export feature for Cases, allowing our users to bulk export important results out of Vision UI into Word, CSV, or JSON. It makes sharing reports and moving data out of Vision UI faster and easier. This was a top feature request from our customers and we are thrilled to have delivered on this ask! 

  • To more easily filter our noisy sites, or data leaks you’ve already seen, we’ve added an “Exclude this Source” option on the Vision UI search result table. 
  • We added 9 new actors to our Actor database in Q4. Additionally, Actor Explore and Actor API now include associated Sites in the Darknet Fingerprint tab. 

Highlights 

Quarter after quarter, our data collection team continues to astonish us with the quantity of data made available across DarkOwl products. Let’s highlight just some of that growth:

  • 6% increase in credit card numbers
  • 2.5% increase in IPs
  • 5% increase in data leak records

When your search results are from data leaks, users can review additional information curated by DarkOwl analysts, giving you enrichment on the data leak. The descriptions below are all available in our Leak Explore UI feature, or Leak Context API endpoint. 

Ryanair Internal Communications

Data purported to be from RYANAIR was posted on DarkForums, a hacking forum, on November 19, 2025. According to the post, the data breach includes email addresses, ticket bookings, travel details (departures, destinations), flight numbers, and ticket claimants. Data exposed includes names, email addresses, internal documents, company names, and internal emails.

IRAN IP NETWORK INFRASTRUCTURE

A post on DarkForums, a hacking forum, on August 22, 2025 linked to the file: iran-net-100k.json. According to the post, the “Caucasian Brotherhood” leaked a dataset of Iranian network information that included IP addresses, open ports, software versions, and DNS records. Data exposed includes countries, IP addresses, and locations.

Farm Credit Union Of Colorado Bank

Data purported to be from Farm Credit was posted on BreachForums, a hacking forum, on September 8, 2025. Data exposed includes names, customer information, physical addresses, online profiles and user identification number (UID).


Curious how these features and data can make your job easier? Get in touch!

Threat Intelligence RoundUp: January

February 02, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. ‘Bad actor’ hijacks Apex Legends characters in live matches – BleepingComputer

Over the weekend of January 09, players in Apex Legends, a battle royale shooter game, reported game disruptions caused by threat actors hijacking characters, disconnecting users, and changing nicknames. Respawn, the publisher of the game, confirmed the security incident claiming “bad actor is able to control the inputs of another player remotely in Apex Legends”. The company does not believe threat actors were able to exploit or infect malware, nor execute code. Read full article.

2. 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials – The Hacker News

On December 23, 2025 the Socket Threat Research Team announced the discovery of a 5 month long spear-phishing operation that turned 27 npm packages “into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in”. The campaign targeted 25 organizations across the U.S. and Allied nations focusing on manufacturing, industrial automation, plastics, and healthcare. Specializing in focusing on sales and commercial personnel, the operation repurposed npm and package CDN’s “into durable hosting infrastructure, delivering client-side HTML and JavaScript lures that the threat actor embeds directly in phishing pages.” Following initial interaction, the script redirects the browser to threat-actor controlled infrastructure. Article here.

ReliaQuest’s Threat Research team has discovered a new phishing campaign using private messages to deliver malicious payloads with the intent to deploy remote access trojan (RAT). The attack began with a message sent via LinkedIn that contained a “malicious WinRAR self-extracting archive”. Once opened, the archive extracts four components, mainly a PDF disguised with names that align with the victim’s industry. The final payload attempts to communicate with an external server that can grant persistent remote access. Read more here.

Recent activity shows Chinese threat actor, Silver Fox, has begun using income tax themed lures to distribute ValleyRAT. The group has focused on Indian entities, using phishing emails containing decoy PDFs claiming to be from India’s Income Tax Department. Opening the attachment leads victims to download files that injects ValleyRAT into the system and communicates with external servers. Read here.

5. University of Hawaii Cancer Center hit by ransomware attack – BleepingComputer

In August 2025, the University of Hawaii’s (UH) Cancer Center was victim of a ransomware breach that stole participants data, including documents from the 1990’s containing Social Security numbers.  UH reported to the state legislature threat actors broke into Cancer Center services, “encrypted files related to a cancer study and demanded payment for a program to decrypt the files”. The breach targeted a specific research project and had no effect on clinical operations or patient care. Learn more.

6. North Korea-Linked Hackers Target Developers via Malicious VS Code Projects – The Hacker News

The Contagious Interview campaign, which has been linked to North Korean threat actors, has been observed leveraging a version of Microsoft Visual Studio Code (VS Code) to deploy a backdoor on compromised systems. First discovered in December 2025, the attack involves instructing targets to clone a repository “on GitHub, GitLab, or Bitbucket, and launch the project in VS Code as part of a supposed job assessment.” The overall goal is for payload to run every time a file in the folder is opened, which eventually leads to deployment of malwares like, BeaverTail and InvisibleFerret. Read full article.

7. Hackers claim to hack Resecurity, firm says it was a honeypot – BleepingComputer

Scattered Lapsus$ Hunters (SLH) announced via Telegram that they had breached systems belonging to Resecurity and stole internal data. To prove their claims SLH posted screenshots of the data which revealed communications between employees and Pastebin personnel. Resecurity published a report in December 2025 disputing the claims and stated after identifying threat actor probing activity in November 2025, they deployed a “honeypot” account. The account was in an isolated environment that contained fake information and was being monitored. Read full article.

8. China-linked hackers exploited Sitecore zero-day for initial access – BleepingComputer

The China-linked threat actor UAT-8837 has been observed attempting to compromise North American infrastructure by exploiting both known and zero-day vulnerabilities. The attacks begin with leveraging compromised credentials or by exploiting server vulnerabilities. Recent attacks include zero-day flaw in Sitecore products, CVE-2025-53690. Researchers claim UAT-8837 uses “open-source and living-off-the-land utilities, continually cycling variants to evade detection.” Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

Darknet forum RAMP4U seized by FBI

January 29, 2026
Figure 1 – RAMP4U.io seizure notice

On 28 January 2026 a seizure notice appeared on the notorious darknet forum RAMP4U. The notice stated the FBI had seized the site. Both the clear net and onion domains showed this notice.

In July 2021, Russian-speaking threat actors on the darknet forums XSS and exploit.in began advertising a new ‘ransomware’ specific discussion forum called RAMP. This appeared to be in response to XSS and Exploit banning the advertising of ransomware on their respective sites. RAMP was advertised to be a ‘safe space’ where ransomware-related discussions and coordination could freely and openly be discussed.   

Figure 2 – Post on XSS banning the advertising of ransomware

DarkOwl assess that RAMP originated with members or affiliates of the Babuk ransomware gang. Babuk launched their operation in January 2021 and quickly received notoriety for their cyber campaigns. In early April 2021, the group successfully compromised and allegedly exfiltrated over 250GB of sensitive data from the Washington, DC Metropolitan Police.

Figure 3 – Historic view of RAMP4u forum

While the FBI are yet to make a formal statement in relation to the seizure of RAMP4U, the domains now point to domain servers which are used by the FBI when seizing infrastructure.

Figure 4 – NS look up

Furthermore, the alleged administrator of RAMP4U appeared to confirm the seizure on a post via XSS.

Figure 5 – DarkOwl Vision post on XSS confirming seizure of RAMP4U

This current activity highlights a continued trend in Law Enforcement seizure of darknet forums, with BreachForums and XSS being notable takedowns in the last 6 months. However, it remains to be seen the effect that this will have, where will the users of RAMP4U move to and or will the site reappear under a new guise. Time will tell.


Make sure to register for our weekly newsletter to get the latest updates.

Cyber Resolutions: 5 Habits for a Safer 2026

January 29, 2026

Every January, organizations roll out security initiatives, refresh slide decks, and announce new tools. This happens every year because breaches continue to happen every year. More often than not through the same well-known traps.

The uncomfortable truth is that most cyber incidents aren’t caused by a lack of technology or understanding of said technology. They are caused by inconsistent or poor habits.

As we head further into 2026, the most effective cybersecurity resolution isn’t by signing up for or buying another platform, it is institutionalizing repeatable behaviors that reduce risks every day.

Below are five cyber habits that can combat how attackers operate today.

The network perimeter is gone. The device perimeter is shrinking. Making ‘Identity’ what attackers target first. Credential theft.

Credential theft through infostealers, phishing kits, MFA fatigue, and token hijacking remains the fastest path to initial access. If identity controls fail, everything else becomes irrelevant. A safer 2026 begins by treating authentication as critical infrastructure rather than a convenience feature.

That shift means moving beyond basic MFA (multifactor authentication) toward phishing-resistant options such as FIDO2 keys, WebAuthn, and passkeys, particularly for privileged and external-facing accounts. It requires eliminating shared credentials and reducing service account sprawl that quietly accumulates over time. OAuth grants and long-lived tokens must be reviewed regularly, as attackers increasingly rely on them for persistence that survives passwords resets. Most importantly, authentication monitoring needs a focus on behavioral anomalies rather than simple success failure.

Attackers don’t need to waste their time with malware if they can use your credentials to log in. Make authentication harder to abuse than to bypass.

Most organizations have gotten the memo to collect logs, however, few treat them like the forensic evidence they are.

When an incident occurs, defenders often discover too late that critical data has already been overwritten, was never retained, or lacks the context required to reconstruct attacker activity. These gaps don’t just slow investigations, they make accurate timelines impossible.

A mature security habit is logging with intent. That means deliberately retaining the artifacts you may need, because if you can’t quickly answer What happened first?, attackers already have the advantage.

At a minimum, that includes:

  • Identity and authentication logs retained long enough to reconstruct timelines
  • Endpoint telemetry with process linage and command execution context
  • DNS, proxy, and network logs that reveal how systems communicate
  • Cloud control plane and audit logs that are enabled to centrally stored
  • Normalized timestamps and identity fields across all sources

Without this foundation, even well-detected incidents turn into partial stories rather than defensible investigations.

Not all vulnerabilities are equal, and attackers know it… even if organizations don’t.

While many organizations still prioritize patching based on severity scores alone, real-world threat actors focus on systems that provide leverage and persistence. Edge devices, exposed management interfaces, and internet-facing services continue to dominate initial access pathways, particularly when public proof-of-concept exploits accelerated attacker timelines.

A safter approach isn’t patching everything immediately but patching the right things first. Perimeter and identity infrastructure should be treated as endgame assets, with exploit availability and evidence of active abuse prioritized over theoretical risk. In some cases, the most effective remediation is not another compensating control, but the removal of legacy services altogether. Attackers move faster than patch cycles, and defensive prioritization must reflect that reality.

Burned-out analysts miss early warning signs just as overloaded detection systems bury real threats.

Many security programs accumulate alerts and tools without revisiting whether those signals still provide value. Over time, if everything becomes high priority then genuine threats blend into the background noise.

Operational discipline is a security habit, in its own right. Alerts should map cleanly to response actions, detections should be tuned to the environment they protect, and enrichment should be automated, so analysts spend their time making decisions rather than gathering context. Security teams rarely fail because they lack data, they fail because they cannot prioritize data effectively under pressure.

Many incident response plans look excellent on paper but collapse like a house of cards under real-world pressure.

Teams often understand what they are supposed to do, but they don’t always understand who is supposed to do it, how to quickly make decisions, or what authority is required to act. Organizations that recover faster teat response as a practiced skill, not a “theoretical” exercise.

That practice includes realistic tabletop exercises, rehearsing difficult trade-offs between containment and continuity, and pre-approving actions that would otherwise stall response efforts while leadership is looped in. Clear escalation paths outside normal business hours matter just as much as technical controls. When something goes wrong, muscle memory matters more than documentation.

Cybersecurity resolutions in 2026 won’t be met by throwing around buzzwords or buying new tools. Resolutions will be met by organizations that turn good security theory into daily practices.

Identity-first controls, intentional logging, threat-informed patching, operational clarity, and practiced responses aren’t flashy. However, they are effective.

Make these five habits your new year’s resolution and keep them long after January fades into a distant memory.


Trends to look out for in 2026

January 27, 2026

As we enter 2026, the story of cyber risk continues to evolve. At the same time, there are consistencies we have seen growing for some time. Attackers don’t need unique or specialized skills anymore – the world of hacking is much more accessible, especially when they [threat actors] can log in like you or convince you to log in on their behalf. Automation is making that easier, faster, and cheaper than ever, especially with the development of AI.

Here we explore some of the cyber security and crime trends that look most defining for 2026, based on what major incident and law-enforcement reporting has been showing through 2024–2025.

Identity-based attacks have been on the rise for some time, and we expect this to continue throughout 2026. These types of attacks remain one of the primary paths attackers take to compromise corporate networks. This is due to the fact that credential information is readily available on the dark web, and it remains one of the simplest ways to gain access, not requiring specialized hacking skills. Therefore, expect 2026 to be the year more organizations stop treating identity as a feature of IT and start treating it as a core security control.

Verizon’s 2025 DBIR notes that Basic Web Application Attacks commonly involve stolen credentials, and credential abuse remains a dominant initial access method across multiple attack patterns.

Because of this, you should expect to see more phishing-resistant authentication being implemented across systems as well as continuous verification.

Threat actors don’t only have the ability to steal credentials; they can also coerce them from unwitting employees through social engineering. A common target in 2025 was to trick the help desk into resetting MFA and it is expected this will continue into 2026.

With the continued development of AI, it is likely that social engineering attacks will improve with the ability to create deepfakes to fool people into believing they are providing a legitimate person access. DarkOwl analysts started exploring this trend in 2024 here.

Infostealer malware isn’t new but in the last year they have appeared to be more widespread and relied upon to conduct real-world intrusions.

Mandiant highlights infostealers as an ongoing pipeline for initial access, where stolen creds from “logs” enable follow-on compromises that end in data theft and extortion.

In 2026 we expect more stealer log compromises that start outside the enterprise – meaning employee personal devices, unmanaged browsers, and reused passwords. As well as the use of stolen cookies/tokens, not just passwords.

As Telegram continues to be a source for both free and paid stealer log subscriptions, they remain relatively easy for threat actors to access, again lowering the threshold for the sophistication that actors need to have to gain access to systems.

Ransomware has been around for a long time, and it doesn’t show any signs of slowing down as we head into 2026. However, it has developed over the years with ransomware groups operating like mature businesses with specializations, supply chains, affiliate programs, PR, and negotiation playbooks.

In addition, their techniques have also developed, although we commonly refer to these attacks and groups as ransomware, data theft is common, and data theft extortion events where no ransomware is deployed are becoming increasingly common.

In 2026 we expect more “no-encryption” extortion attacks where actors steal data, threaten to leak on a dark web site and do so if the extortion payment is not paid – without ever encrypting the data.

In 2026, AI isn’t just “writing better phishing emails” – it’s enabling highly targeted, multilingual scams at scale, voice cloning for “CEO fraud” and synthetic identities, and deepfake-driven coercion.

European law enforcement has been explicit that AI is accelerating organized crime and enabling impersonation and scalable fraud. ENISA’s 2025 Threat Landscape also notes criminal abuse around AI tooling, including fraudulent AI tool sites used to deliver malware and concerns about AI supply chain risks.

Generative AI will also make it cheap to produce high quality lures for cyberattacks, and it can do this at scale meaning that threat actors can use AI to industrialize phishing attacks as well as other methods of attack.

As highlighted above, social engineering is an attack vector which is likely to increase in 2026, and AI will be at the forefront of enabling that growth. AI-assisted social engineering will include voice cloning for “urgent CFO calls,” fake candidates in hiring funnels, vendor payment diversion among many other techniques – some probably not yet thought of.

However, AI can and will also be a useful tool in defending against threat actors. AI can be used to automate and triage vulnerabilities and risk indicators for faster detection and investigation.

Cybercrime isn’t only “breaches.” In raw victim impact, fraud dominates, and it’s increasingly industrialized. The FBI’s Internet Crime Report for 2024 reported record losses and flagged investment fraud, often crypto-related, as a major driver of dollar losses. This is likely to continue to rise.

Dark web marketplaces continue to be a hot bed of activity when it comes to financial crime, with credit cards, bank account information, and access to payment apps being traded routinely.

Since the invasion of Ukraine by Russia in 2022, hacktivist groups have been particularly vocal and active. This only grew after the October 7 attacks in Israel. The groups primarily conduct DDOS (distributed denial of service) attacks but have also conducted many defacement attacks and in recent times have been more likely to leak data and dox individuals.

This threat is not likely to diminish in 2026, with geopolitics continuing to remain strained throughout the world. It is likely that more groups will emerge in response to real world events and political affiliations.

Many of the cybercrime and cyber security trends of 2025 will continue into 2026, but it is likely to become more difficult to keep up with the speed and scale of attacks due to the use of AI.

It is important for organizations and individuals to remain vigilant and ensure that they are using appropriate precautions to protect themselves.


[Podcast Transcription] AI on the Record – Episode 2: Exploring the Dark Side of Technology

January 22, 2026

Or, watch on YouTube

This podcast features DarkOwl Regional Director and OSINT expert, Lindsay Whyte, and Jennifer Woodard, Chief Product & Technology Officer at Logically.ai who discuss how AI is accelerating cybercrime by powering malicious large language models that generate phishing emails, malware, and ransomware with little user skill required. These tools dramatically scale attacks, leading to everything from personal account takeovers to multimillion‑dollar business email compromise and widespread ransomware incidents. While the threat is growing, Lindsay emphasizes that awareness, simple verification practices, strong security culture, and international cooperation can still meaningfully reduce risk — offering some optimism amid an increasingly complex cyber landscape.


Jennifer: Welcome back to AI on the Record, the podcast that brings together voices from media, policy, enterprise and civil society to explore where influence is heading, how AI is being governed and what decision makers should be paying attention to next. I’m Jennifer Woodard, your host.

Now, today, we’re going somewhere most of us don’t often go – into the darker side of technology, the shadowy corners of the internet and the world of cyber. And we’ll be looking at how AI is now intersecting with these spaces in ways that are both fascinating and, frankly, alarming. With me today is Lindsay White of OSINT UK. He’s an expert in open-source intelligence and cybercrime investigations. Let’s get into it.

So, with me today is Lindsay Whyte of OSINT UK. He’s an expert in open-source intelligence and cybercrime investigations. Lindsay, welcome to the show.

Lindsay: It’s a pleasure to be here. Thank you, even if the topic is somewhat a bit dark.

Jennifer: Indeed. Indeed, it is a little bit dark but thank you so much for being here. Could you just give us a quick intro into a little bit about your background and what you do?

Lindsay: Sure thing. So, I’m a former British soldier and now I’m the co-founder of the UK community, which is a volunteer run, not for profit seeking to bolster the UK’s intelligence capabilities by reintroducing in-person interactions into the world of security, but also at the same time crowdsourcing, new innovations in the rapidly growing world of open-source intelligence technology. My day job is working for DarkOwl, which is a leading darknet intelligence collections company, which was actually founded by the same person that founded the Tor Project itself. So, we illuminate darknet data for governments and security professionals around the world.

Jennifer: That’s very interesting. It’s incredible to hear. And, you know, as you’ve explored these spaces, I’m assuming you’ve seen technology evolve and now that we’re kind of in the age of AI. AI is coming into its own. AI is now part of this kind of cybercrime dark web story. Could you help us understand a little bit about how cyber criminals are using AI, and whether that’s something that we should actually be worried about?

Lindsay: Absolutely. I think it’s a great place to start because, you know, you and I know ChatGPT. I think most people have at least heard of ChatGPT by now. And that’s what, you know, we call a large language model. Basically, it’s a very sophisticated AI that can understand and generate human like text. Now, big companies like OpenAI and Anthropic, they build things which you call guardrails. So, these are rules that prevent their AI from helping you do bad things.

So, if you ask ChatGPT to hack someone’s bank account, it will politely refuse. But malicious large language models (LLMs) – they are the sort of evil twins and they’re built from scratch or modified specifically to remove those sorts of guardrails. They’ll happily help you craft phishing emails, write malware, generate ransomware code, ransomware notes, you name it. Really. So, what’s interesting, of course, is that already this sort of malicious LLM ecosystem, they’re already selling their software in subscription form, so you’ll be able to buy malicious LLM’S on a monthly plan, on an annual plan, a lifetime. I mean, there’ll probably be Christmas discounts, you know, before long. So, it’s basically cybercrime as a service, as the security industry have always known it. But now with that AI superpower. Yeah, I wish I was joking, but that’s the real reality of it.

And, I guess to understand how this matters, we need to talk about the dual use dilemma, which I know, Jennifer, you probably know a lot more about from that sort of policy perspective. But, you know, fundamentally, this dual use dilemma in AI is about, how you use the exact same technology for both good, but also for, you know, for harm and how it can get sort of weaponized for harm. You know, a little like nuclear physics. It’s something which can power a city for, for free and transform a society. But it can also be used in weapons to sort of level a city. So, AI kind of has to be thought of, I think, in the same kind of same kind of way. You know, it gives us the same capabilities, allow a company to automate customer support for the good, or help students, write better essays at university, but it also helps criminals scale up their tax. So even if the technology is neutral, the intent is not.

So, I guess this is where it gets pretty interesting because, you know, the same linguistic precision that makes AI great at, you know, university essays and helping write emails can also make incredibly convincing phishing emails. So, the same coding ability that helps developers debug software, can actually customize malware in the same amount of time, and that’s kind of what makes it tricky from a regulatory perspective. I guess for me, what really concerns me is the way that AI is now democratizing cybercrime, because it used to be that attacks required a certain level of skill. So, you know, language skills, a certain amount of coding knowledge, a deeper understanding of like social engineering per culture in which you’re trying to action this, this attack. This is now available to anyone. So, you know, we’re talking about a skill level between someone who maybe knows how to use Google and understands basic computer concepts. That’s all you need now. So, the days of being an expert coder or a wizard of some description to run a sophisticated attacker are over, you know, and that’s kind of the reality that we’re living with. You know, would you rather face, as someone said it to me once, you know, would you rather face one expert swordsman or a thousand people with guns and you know, these malicious LLMS, they are giving everyone a gun. It’s scale over skill, and from a perspective of cyber defense, that’s pretty terrifying because now attacks that used to take days of research, maybe weeks of research and hours of coding can now be done in minutes by someone who has no prior experience in the field.

Jennifer: Wow, that’s really jarring. And like you said, that’s the reality that we’re living in right now. These aren’t even hypothetical risks anymore. I mean, I remember years ago people talking about this might be on the horizon. What we’re actually living with this right now. It seems like it almost snuck up on us in some cases. So, the tools that you’re talking about to develop these, you know, types of malignant actions, they’re actively in use. Could you walk us through some examples of what those tools look like? I mean, what are they actually called. Are they methods. Could you just kind of walk us through that?

Lindsay: Yeah, yeah. Tragically, that is the case that these already do exist. So, two big names have emerged in the last few weeks are WormGDP, GPT, sorry, and KawaiiGPT. That’s actually wrong. Uh, WormGPT has been around for a while, but I’ll talk about WormGPT specifically because I think it really opens up everyone’s eyes because this is something that appeared, I think it was sort of summer 2023 on underground forums, like hack forums. For those who don’t know, hack forums is pretty much exactly as it sounds, not like friendly Reddit threads. These are places where cyber criminals congregate and share ideas. And WormGPT was being hawked, a bit like the latest smartphone. So, the marketing, I think, even included like a creepy little character with red eyes, it was like the most unsubtle kind of thing, but basically what they were advertising is an uncensored alternative to mainstream ChatGPT – no ethical boundaries whatsoever.

And it was built on open-source model. It was fine-tuned specifically against malicious data sites so malware code phishing email templates, exploit write ups and that sort of thing, and it directly trained itself on that model. So, it was mainly being used for business email compromise. So, that’s where criminals basically impersonate a CEO or a company supplier or something like that. And it tricks employees into sending sensitive information or wiring money outside of the company as part of a scam and normally with these business email compromise emails and messages that we receive, there were telltale signs that it was a scam. So, there would be weird grammar, it would be awkward phrasing, and that would sort of tip us off. But with WormGPT, it could, and it can, generate perfectly fluent professional sounding messages, which even the most savvy employee could fall for. And, and I guess, you know, ironically, WormGPT became a bit of a victim of its own success because the media exposure it got was so big that the creator actually shut it down quite soon after setting it up because it got so much heat. But of course, the problem with that is that the cat was already out of the bag, and it meant that a lot of copycat GPT appearing on the market and other versions started coming out. And, you know, currently you’re looking at sort of WormGPT4, which is more commercialized. It’s got a really slick website.

Remember, I’m talking about a malicious piece of technology here. They have a subscription pricing model. I think it’s like 50 bucks a month, a hundred bucks a year and 200 bucks for, like, lifetime access. So, it’s very affordable. It becomes very problematic. It’s got a big sort of telegram ecosystem that’s growing. It’s like running itself like a legitimate software company. And, you know, people have tested this. It can spit out ransomware notes, ransomware script, with encryption to infect computers. I think the ransomware note that it can generate gives you, it provides the level of detail where it’s instructing a victim how to buy Bitcoin to pay the ransom if they don’t already know how to do it and what sites to use. It’s very smart.

As I mentioned, there’s another one called Kawaii. I think I’m pronouncing that right – KawaiiGPT, basically just Google KawaiiGPT. And that takes a slightly different approach. It markets itself as like a friendly, playful chatbot but it’s, you know, it’s completely free. It was on GitHub until very recently. It may still be there and basically allows people to download it for free. Some security researchers have started to ask it to like, as in legitimately to see its power, test if it can write script for lateral movement. So lateral movement is where an attacker basically goes into one computer in a network and then crab walks into other computers on that network like dominoes falling. It’s able to do all of these things and is pretty terrifying, really, because all of this can be generated in a few seconds. So, yeah, I think overall, what’s worrying about both of these tools is that they’re creating, like any professional tool these days, an ecosystem of developers, of communities, of people, you know, giving feedback and then the product being improved. It’s like these telegram channels, they read a bit like LinkedIn for criminals. It’s pretty surreal.

Jennifer: Yeah, it’s democratization and the worst possible sense. Right? I mean, it’s really the ability to scale this like, never before. And the barrier to entry being so low that just about anybody has access to these types of tools. Anyone who wants to do, do harm. When you lay it out like that, it’s really, I mean, it’s really scary how big this impact is. So, you mentioned a little bit about the victims. You know, you referenced kind of like corporation CEOs. What happens to the victims of these types of attacks? What’s the aftermath of something like this happening?

Lindsay: Well, I mean, the impact does kind of range between, you know, the corporates that you mentioned, right down to sort of like individuals, who fall for this. It can be anything from just being really annoying to completely devastating and life destroying.

I mean, at the lower end, a successful phishing attack that compromises an individual account, you know, an email gets hacked or someone’s social media gets taken over. It’s embarrassing. It’s potentially financially damaging. It might be recoverable but, you know, people can lose their accounts for a while. They might lose their identity. So, it can be a real hassle. It may not necessarily be life destroying, but when you scale up the chain and you start then looking at business email compromise, which I said is the main focus initially of WormGPT, for example. That’s when it gets very serious because a company employee can get tricked into wiring money to a scammer’s account. We’re talking six, seven figures. I’m not exaggerating. I mean, companies have literally gone bankrupt because of successful business email compromise attacks. And imagine you’re the CFO and you get what looks like a legitimately urgent request from the CEO to wire funds for like, an acquisition or something else. That money is then gone. It’s irretrievable and you’re left kind of explaining to the Board how you just wired all of that money out of the business.

And then at the top end, you’ve got ransomware attacks where all of the cybercrime sort of focuses, I’d say right now, where an attacker gets into a network, they spread through the system, they encrypt everything, and demand payment to unlock it. And we’ve seen this happen to hospitals, you know, doctors not being able to access patient records, manufacturers shutting down operations for weeks and for manufacturers, operations being shut down is millions and millions of pounds lost in production. School districts not being able to access their pupil records or that kind of thing before exams. You know, the impact then isn’t just financial. It’s actually emotional as well. And that’s pretty immense. So, I mean, LMS (language models) are making all of these things easier – the sort of the improvements in how it generates convincing language for phishing emails, instant code generation for malware. These tools are accelerating every single phase of an attack. And as I said, what used to take a team, a skilled team, days and weeks can now be done by one person in a matter of hours. Again, imagine someone who is maybe a disgruntled former employee or a, I don’t like to say teenager stuck in their bedroom because that’s such a stereotype, but you don’t need much to trigger someone to then pay that $50 monthly subscription for one of these malicious GPTS. You know, you just need a fraction of these people paying and getting access, and then suddenly you’ve got an enormous, enormous problem on your hands. These aren’t, you know, the companies behind them, of course, you know, they’re not hobbyists themselves, that they are themselves very professional business operations with customer support and engineers and all this sort of thing. Just because you and I could use it and people without much knowledge can use it that does not reflect the level of sophistication on the other side of the fence. They are professional businesses. Right. That’s something that people often forget. These people really know what they’re doing. They’re very well organized. You know, they learn how businesses work. They’ve worked in legitimate businesses in the in the past more often than not.

Jennifer: And cutting edge, it sounds like cutting edge technology developers as well. They’re not just a mom-and-pop shop. Wow. That’s hard to hear, quite alarming. But, you know, in spite of all this, I assume that something is being done to mitigate these risks, right? This is a risk to every sector, every part of the globe. It’s risk to economies worldwide. What is happening on that front? Can these tools actually be stopped, or is this kind of a new reality that we need to adapt to?

Lindsay: This is the problem, I suppose, is that, it does get complicated because there is no silver bullet. If we look to the sort of legal and regulatory side of things, we are sort of in murky waters and you’ll probably know this, that – okay, the original say, WormGPT, this malicious LM was shut down voluntarily by its creator but then we do have other GPT’s, you know, on GitHub and still running. So, you’re going to have to ask like legitimate website, the hosting code that they have to police what kind of code people can share. And that opens up a whole can of worms, to pardon the pun because, you know, here’s the thing. You know, these exact same tools are crucial for legitimate penetration testing.

Penetration testing is an absolutely vital part of cybersecurity posture because essentially what penetration testers do, these are the good guys who are hired to break into a system to find vulnerabilities so that you can bolster your defenses. So again, we’re into that dual use dilemma. The tool itself is neutral and that makes regulatory regulation incredibly difficult in my opinion. Because how do you ban something that has a legitimate use. But I guess there are other approaches that need to happen. I mean, again, I’m not an expert on it, but developers of mainstream API models need to continue with their safety measures. So, making it harder to jailbreak these systems and that sort of thing. Law enforcement needs to get better at tracking the financial flows – so identifying the people behind these cryptocurrency flows, and pursuing them, because as part of my day job at DarkOwl, that’s what we spend our time doing is illuminating dark web forums and crypto currency. And then, I guess, most importantly, is promoting international cooperation on these subjects, because this means absolutely nothing if we don’t have some global approach to countering this because cybercrime is, in its nature, just borderless. You know, you’re always going to attack the jurisdiction that is far away from your own as possible, right? That’s just that’s just common sense if you’re a criminal. So that’s pretty important. Obviously, there’s other things on the side of sort of like the EU AI act, which I’m not quite as familiar with.

But for individuals, there’s quite a bit you can do. I want to be positive here and this is where I get optimistic because even the most convincing phishing email fails if people are trained to verify requests through secondary channels. If your CEO sends you an email asking for an urgent wire transfer, picking up the call, picking up the phone and calling them is what you need to do, and that’s where, you know, the AI model kind of fails because simple practices like this will defeat AI generated attacks in person and face to face options as well to kind of do this, you know, companies specifically. Yes, there’s sort of layered defenses. So, there’s various cybersecurity practices you can put in place good security practices, a healthy amount of skepticism. These are all things that will help. I mean, fundamentally, this is an ongoing arms race. Attackers are going to develop new tools, defenders are going to attack. Attackers are going to evolve. Defenders respond. It’s just going to keep going on and on. It’s been like that in cybersecurity forever. And so, nothing’s really changed.

Jennifer: Right? It’s about staying one step ahead of the bad guys. It’s the same type of a situation as in cyber, for the past, you know, 20, 30 years. Yeah. I’m glad that you bring a little bit of optimism into this, because I’d like to hear, you know, from a technology perspective, given how difficult this is, it sounds almost insurmountable. What is it? What is something that actually gives you hope? Something that makes you think from a technology perspective that we can actually kind of make a difference here?

Lindsay: Yeah, I think there is some hope. And just to sort of flesh out, you know, my optimism on this. Increased awareness does help things tremendously. You know, conversations like this where we’re educating people about these threats do make a real difference. As someone said, an informed public is the best defense. So, when people understand that emails can be generated by AI, you know that perfect grammar is no longer the guarantee of legitimacy, that verification is essential and that sort of thing. This really does change the game. You can have the most sophisticated technical defenses in the world, but if your employees know to pick up the phone and verify a wire transfer request you have just defeated there, and then a multi-billion-pound AI powered attack with a 30 second phone call.

It’s not necessarily about blocking specific tools. I think that’s a losing game. It’s about building systems and cultures to be resilient at scale, and understand the speed of how AI evolves. You know, bringing back human interactions. I’m a big believer in this, whether we do this with, with government or with our own companies – nothing can beat that human interaction to verify something 100%. I think one of the things I’ve always worried about is the way in which and, you know, one thing we haven’t really spoken about is the way in which nation state actors are and governments are actually funding and promoting a lot of this malicious LLM use. Sometimes I think democracies look to the digital world as a form of efficiency, and I think we’re entering into that, and that is right. I mean, it’s changed everything. It’s been revolutionary. But we may be entering into a period where it’s giving us diminishing returns, and we need to return to more in-person interactions, in-person verification. What that looks like, I’m not entirely sure, but you always have that. And I think, you know, understanding that and recognizing that we can’t just rely on digital systems for everything could be counterproductive.

There’s things that are sort of keeping me up at night. I think the accessibility, you know, something that used to need a lot of skill, doesn’t need a lot of skill. There aren’t those barriers anymore. But I think, you know, there is something that we can rely on. And that’s the sort of human element as both the, the biggest weakness, but also the greatest strength that we have.

Jennifer: Yeah, that is actually encouraging, reassuring. You brought up some topics that kind of bring back the optimism to the conversation. So, before we go, I’d like to ask our guests if listeners could take one thing away from today’s conversation about AI and cybercrime, you know what they really, really need to remember? What should it be?

Lindsay: What I would suggest people do is that they start to really think in a hybrid mindset when building technology, managing people, improving society. Don’t rely on technology to save you. Don’t rely and think likewise that technology is going to ruin you. The fact is, it is just another tool. Are we building a society and are you building a business I suppose that takes into account all of these various facets? Sorry, I can’t be more specific than that. I’m still learning a lot about AI. I can’t claim to know everything about how AI is being used within the cybercrime world. It is evolving every second but I think we need to understand and appreciate more the benefits of thinking holistically when talking about even the most digital of phenomena.

Jennifer: And that is a great way to end it, because that’s something that’s in our hands. It’s all about understanding awareness, educating ourselves, and kind of staying ahead of the curve. So, thank you so much, Lindsay Whyte, for joining me today on AI On the Record. It was a pleasure having you here. Even though the topic was a little bit dark, there is some hope for the future, it sounds like. And thank you so much for joining us.

Lindsay: It’s a pleasure, Jennifer. Thank you very much indeed.

Jennifer: That’s it for AI on the record. Thanks so much to Lindsay Whyte for scaring us a little but also adding a little hope in the struggle of good versus bad in the world of AI. If you found this conversation valuable, share it with someone who thinks deeply about tech, trust, and the future of information. Until next time, I’m Jennifer Woodard. Thanks for listening.


Threat Actor Spotlight: Scattered Lapsus$ Hunters

January 20, 2026

Scattered Lapsus$ Hunters, is reported to be a hybrid threat actor group forged from three separate groups, who collectively emerged onto the scene in 2025 and quickly made their mark on the cybersecurity world. Announcing their existence following ShinyHunters alleged social engineering campaign that purportedly resulted in the theft of 1.5 billion Salesforce records, the group consists of threat actors from ShinyHunters, Scattered Spider, and Lapsus$ extortion members.

The three factions were all heavily active in 2024, resulting in a series of arrests of members of the group Scattered Spider in 2024. The group remerged in April 2025 with an attack on UK retailers Marks and Spencer. Due to the significant attacks carried out by the individual groups in recent years, the convergence of their members has introduced even greater chaos into an already volatile landscape.

On October 03, 2025,Scattered Lapsus$ Hunters launched a data leak site extorting 39 companies that were impacted by the Salesforce breaches. The companies extorted in the link include Disney/Hulu, FedEx, Google, McDonald’s and more. A separate entry on the site requested that Salesforce pay a ransom to prevent impacted customers (approximately 1 billion records containing personal information) from being released. The group set an October 10 deadline for Salesforce to pay the ransom, or for potentially affected companies to contact the group to secure their data. Salesforce refused to negotiate with the threat actors, believing their threats were unsubstantiated and offered support to any of their affected clients.

While the group had threatened to release all information if their demands were not met, eventually they only leaked data from six companies. The victims included Albertsons, Engie Resources, Fujifilm, Gap, Qantas, and Vietnam Airlines. Qantas and Vietnam Airlines each had more than five million customer records exposed. The group later announced on its Telegram channel that it would not release any additional information until 2026, stating that it was unable to leak further data, though no specific reason was provided. The limited amount of victim information leaked during the October extortion attack led some individuals to question the extent of the data the group possesses. This behavior appears to indicate the group believes it can still extract a substantial payment from Salesforce or the affected individuals.

Following the partial leak, Scattered Lapsus$ Hunters posted a Telegram announcement threatening the remaining victims and Salesforce. The statement urged Salesforce to “put down your pride/ego” or their next campaign will be more “destructive” and they have the time and resources to ensure this fate. They warn against policies that mirror Australia’s “Cyber Security Act of 2024” which introduced mandatory reporting of ransomware and cyber extortion payments, as well as strongly discouraging complying with threat actors demanding ransom.  The group identified themselves as businesspeople and rejected the label of terrorists or attackers.

The post was signed “We will never stop, see you all in 2026” indicating the group will return with further activity in the new year.

In November 2025, the group announced the development of a Ransomware-as-a-Service (RaaS) platform named, ShinySp1d3r. On a Telegram channel used by the group, they claimed the ransomware was in development and will be led by ShinyHunters but operated under the “Scattered Lapsus$ Hunters” brand. Previously, these threat actors have used ransomware encryptors such as Qilin, RansomHub, and DragonForce. Victims of ShinySp1d3r will receive a note that they have “three days to begin negotiations before the attack is made public on the data leak site”.

Samples of the ransomware have been uploaded to VirusTotal and show a mix of common features and new features developed by the group. The encrypted files will contain “information on what happened to a victim’s files, how to negotiate the ransom, and a TOX address for communications”.

ShinyHunters claims that organizations in the healthcare sector, including pharmaceutical companies, hospitals, clinics, and insurance providers, are excluded from being targeted by its encryptor. However, researchers report that many groups have made similar assurances in the past, only for those self-imposed restrictions to be routinely ignored or violated.

Scattered Lapsus$ Hunters are expected to remain active this year, leveraging both new and familiar tactics to cause disruption across the cyber landscape. The combination of the three groups demonstrates the shift for cybercriminal branding, appearing to highlight credibility and visibility. Given their broad range of targets, effective information sharing between organizations will be critical to countering this threat actor. To mitigate the risks posed by Scattered Lapsus$ Hunters and similar groups, organizations must prioritize monitoring these dark web activities.


To ensure your organization is taking the necessary steps to mitigate threats from these groups, contact us.

2025 – A Year of Constant Upheaval on the Dark Web

January 15, 2026

If you watched the dark web ecosystem in 2025, like DarkOwl does, you may have noticed that it seemed very unstable. While the dark web is notorious for being unstable with onion sites often going up and down, this year felt different – with more permanent changes to mature and established sites and a seemingly revolving door of admins.

Long-running drug markets vanished overnight in coordinated international operations. Fraud and hacking forums were seized and marked with law enforcement seals. Others simply went dark in classic exit scams, taking millions in crypto with them.

The most notable sites to be impacted this year were XSS – a long-standing Russian-language hub for exploits, access, and ransomware affiliates and BreachForums – the English-language epicenter of data breach leaks and credential trading, which has been subject to changes over many years but always seems to come back.

But they were only part of a much larger story that included major markets like Archetyp and Abacus, plus “shadow markets” on platforms like Telegram.

As 2026 begins, we wanted to delve into what happened in 2025: XSS, the ongoing BreachForums saga as well as review some of the major marketplace hits and exit scams, how exit scams and takedowns reshape trust in the underground and what all of this means for defenders and analysts.

For years, XSS (formerly DaMaGeLaB) was one of the most influential Russian-language cybercrime forums. It served as a marketplace for exploits, stolen access, and malware as well as a recruiting ground for ransomware crews. A well-established site, it fostered a high-trust environment among its users, who were able to trade tools and services. The site had been operating since 2013 and was estimated to have over 50,000 registered users.

However, in mid-2025, the XSS era effectively ended. Law enforcement agencies in France and Ukraine, supported by Europol, targeted XSS after a multi-year investigation which began in 2021. This led to the arrest of a 38-year-old suspect alleged to be the main XSS administrator in Kyiv. Shortly after, the XSS domain displayed a classic law enforcement seizure banner, signaling that authorities had taken control of infrastructure and likely obtained access to backend data and communications. This marked a change for law enforcement who have typically targeted English-speaking sites on the dark web with Russian sites usually being more difficult to infiltrate.

Figure 1: XSS Seizure Notice

For a forum that catered to serious actors, including affiliates of major ransomware groups, this was a significant blow. The value of the takedown wasn’t just the shutdown, but the potential intelligence gathered, thought to include database content, private messages, transaction details, and operational. It also initially appeared to leave a void of where these actors could interact and advertise.

However, as usual, the community did not vanish with the domain, which did reappear. Some members migrated to other Russian-language forums such as Exploit or RAMP. Exploit another well-established forum appeared to be the primary forum of choice. Others attempted to relaunch XSS under slightly different branding, trying to keep the reputation and user base intact. However, the registration for new users proved challenging, and many commentators online felt that XSS was now a honeypot run by law enforcement. It appeared that many in the community were reticent to continue using the updated site.

The net effect, XSS as a brand is fractured, but the underlying actors remain active and mobile on other forums. For cyber security analysts, the center of gravity moved, but the threat did not disappear. The game of wack-a-mole continues.

On the English-speaking side, BreachForums has been the high-profile home for many years, having launched around 2022 in the aftermath of the RaidForums seizure. The site was known primarily for selling and sharing data breach leaks, trades and giveaways of credential dumps as well as the discussion of hacks, access sales, and “clout” postings.

Since then, BreachForums has been stuck in a loop.

BreachForums v1 (breached / breached.vc, etc.) – launched after RaidForums was seized, was itself later taken offline after the arrest of its founder “Pompompurin” (Conor Fitzpatrick). Fitzpatrick was subsequently charged, and rumors swirled that the site was operating as a honeypot.

In September 2025, founder Conor Fitzpatrick was re-sentenced to a longer prison term after an appeals court deemed the original sentence too lenient. That move signaled that U.S. courts view BreachForums as a serious, high-impact cybercrime platform, not just a “kids swapping databases” site.

Subsequent versions of BreachForums followed the same pattern. New domains and infrastructure spun up (e.g., breachforums[.]st) quickly, claiming to be the successor and controlled by affiliates of previous versions. The community reconvened, often with familiar staff and leak actors (including groups like ShinyHunters). However, law enforcement seized infrastructure again, posting FBI banners on front-end domains and, in some cases, gaining access to backend data and user logs.

However, in 2025, a few milestones stood out as different to the pattern, and the activity appeared to occur much more rapidly than it had with previous iterations.

One BreachForums instance announced it was closing after operators claimed law enforcement had exploited a 0-day in MyBB (their forum software) to gain access. Whether this was accurate or an excuse, the result was the same: another dead forum, more scattered users. Yet another BreachForums-branded domain displayed an FBI seizure notice, underscoring that law enforcement was tracking the brand as much as the infrastructure.

Every new BreachForums revival faces the same dilemma, If it’s real, it’s a prime target. If it’s not real, it might be a honeypot or undercover operation. This creates a deep trust problem inside the community.

So, while BreachForums keeps coming back in some form, each iteration is more paranoid, more fragmented, and less trusted than the last. Because of that, similar to XSS we have seen the community seek other sites as refuge from the law enforcement action and fear of honeypots. In 2025, a clear front runner has been Dark Forums. However, this site has also already experienced changes in management as well as technical issues leading to downtime as well as changes in domains.

Beyond forums, darknet marketplaces remain a central pillar of the underground economy, especially for drugs, fraud services, and stolen data. In 2025, they were hammered from both sides.

Archetyp Market was first seen in May 2020 and quickly became one of the largest drug markets operating. It specialized in the sale of drugs, including high risk substances such as fentanyl. The site required registration and accepted funds via the “privacy” cryptocurrency Monero. With over 600,000 users and 3,200 vendors, the market facilitated transactions involving cocaine, meth, MDMA, and other narcotics. By its final days, it had moved an estimated $250–290 million in illicit goods, making it a titan among darknet marketplaces.

From June 11–13, 2025, Operation Deep Sentinel, led by Germany’s BKA and supported by Europol, Eurojust, Homeland Security Investigation (HSI) and law enforcement from five other countries, executed a coordinated takedown. Servers were seized in the Netherlands, digital assets frozen, and the suspected site administrator, a 30-year-old German, was arrested in Barcelona. In addition, authorities confiscated millions in cryptocurrency, luxury vehicles, phones, and drugs in sweeping raids.

This followed a familiar pattern from earlier eras: Silk Road, AlphaBay, Hansa, Hydra. Each time, a flagship market becomes large and visible enough international law enforcement teams invest the time and resources to take it down.

In contrast to Archetyp’s law enforcement takedown, Abacus Market appears to have chosen the exit-scam route. An exit scam occurs when the administrators of a site close it down and, in the process, steal funds that they are holding in escrow from their customers and vendors.

Abacus had, by many accounts, become one of the highest-earning Western darknet markets in 2025. Then the warning signs started; users began reporting withdrawal delays and stuck balances. At the time admins blamed technical problems, DDoS attacks (distributed denial of service attack), and onboarding chaos from refugees fleeing other shut-down markets.

However, over time, more evidence pointed to a classic rug pull: no seizure banner, no official statement—just vanished infrastructure and a lot of missing crypto.

By mid-2025, most analysts agreed Abacus had exit-scammed, likely taking a substantial share of user balances and escrowed payments with it.

From the average user’s perspective, the result of both scenarios looks the same; one day the site works, the next day it doesn’t—and your coins are gone. However, the implications are very different.

In a Law enforcement takedown scenario. Agencies aim to identify operators, seize servers, and collect evidence. This means that you will often see official seizure banners on the site, indicating that it has been taken down and by who. Law enforcement wants the users of the site to know that they have acted and view it as a warning to others. Increasingly, law enforcement has accessed the registered users of these sites to warn them that they are participating in criminal activity to try and dissuade users from continuing this activity.

For participants, that means risk doesn’t end when the site goes down; it may only be starting. Data recovered in 2025 can fuel cases and investigations for many years.

In an exit scam, the admins’ primary objective is to take as much money as possible and disappear. Early warning signs can include:

  • “Temporary” withdrawal freezes
  • Sudden policy changes around escrow and wallet management
  • Increasingly vague or aggressive communication from staff

Unlike with law enforcement action, there is no public banner and usually no immediate arrests—just silence.

Legally, the admin’s exposure doesn’t change much: they were already running an illegal market. But for users, the fallout is more about financial loss and fractured trust, rather than immediate deanonymization through seized databases.

In both cases though, the users of the sites will have to find a new home to conduct their illegal trades and communities.

While Tor-based marketplaces and forums grab headlines, 2025 also highlighted another front, shadow markets built on mainstream platforms. DarkOwl will often refer to these sites as dark web adjacent, as they are used by the same actors for illegal activity but don’t actually exist on the dark web technology.

A notable example was the crackdown of channels associated with the underground ecosystem on Telegram. After the arrest of Telegram’s CEO in late 2024, the platform began to increase its moderation of the app, actively banning and suspending channels which it alleged were breaking their terms and conditions. This was not solely focused on markets on Telegram but was wide ranging.

These bans have had an impact on the market side of telegram particularly fraud services, laundering, and illicit financial services which were run via channels and bots.

Telegram’s enforcement actions—including mass bans and account purges—disrupted what analysts described as a multi-billion-dollar illicit economy.

This illustrates a broader trend – crime is platform-agnostic. When Tor markets are unstable, actors move to, encrypted messaging apps (Telegram, Signal, Threema), private Discord servers and niche forums and invite-only groups or even surface web sites. As TOR becomes more unstable and more likely to be disrupted by law enforcement action many actors favor a simpler way of setting up their businesses.

For cyber security analysts, focusing solely on .onion sites risks missing a big slice of activity that’s happening on “regular” platforms. This is why DarkOwl monitors not just the dark web but also dark web adjacent sites.

Given all the takedowns and scams, is the dark web actually shrinking?

The short answer is no, not really. There is still a huge amount of criminal activity taking place on the dark web and it is important to track and monitor this activity to protect yourself and your organization and to combat crime. However, it is also important to acknowledge that the dark web is becoming more fragmented, less stable, and much harder to trust and therefore harder to track.

Long-lived giants like XSS and Archetyp are being removed or compromised. New markets and forums:

  • Launch quickly
  • Hit critical mass
  • Either get seized or exit-scam once the risk feels too high

That constant churn makes it harder to operate large-scale, long-term criminal infrastructure.

Vendors and buyers increasingly assume every market will die. Meaning that they

  • They keep smaller balances in market wallets.
  • They distribute activity across multiple platforms.
  • They rely more heavily on out-of-band communication (e.g., direct contact over Telegram) and reputation that travels across sites.

Exit scams hurt, but they are no longer surprising.

Forums like XSS and BreachForums played a key role in:

  • Announcing new markets
  • Arbitrating disputes
  • Establishing trust and reputations

But this made them and sites like them prime targets for:

  • Seizure and infiltration
  • Undercover operations
  • Intelligence collection on active and prospective offenders

By 2025, many actors treat high-profile forums as necessary but risky.

The XSS takedown and BreachForums sentencing are reminders that investigations often span multiple years before going public. Sentencing can be revisited and made harsher as courts and prosecutors recalibrate how serious digital crimes are. And that Law-enforcement agencies are increasingly comfortable with crypto tracing, infiltration, and complex international joint operations.

The underground can adapt quickly, but investigators are learning and iterating too.

If you follow this space for security, research, or policy, 2025 offers some clear lessons:

Names like “XSS,” “BreachForums,” or “Abacus” come and go. But what does persist is the actors that are active on these sites, they are often working on multiple sites, and it is important to track how and if they continue to operate and what networks the operate within. One way of doing this is following the money and monitoring any wallet addresses shared and how these transactions operate across the blockchain. It is also possible to identify new an upcoming site by monitoring other sites and adjacent sites for chatter from actors, as well as identifying infrastructure patters such as hosting choices and tools used.

Takedowns come with positives and negatives for investigators; on the one hand a source of intelligence has been removed. Sometimes we lose access to sites for which we have good access and are able to obtain a large amount of information that can assist with our investigations. Furthermore, the users of these sites tend to scatter, and it is a race to find the next site and where the actors we are most interested in have moved to.

On the other hand, it is great that illegal activity has been thwarted, usually leading to arrests and the seizure of infrastructure which decreases the activity. While we sometimes have to scramble to maintain oversite, the actors also have to scramble to find a new home which can really slow them down, plus they have the fear that they are now on the radar of law enforcement which may deter them fully from the activity. Furthermore, newly unsealed indictments can reveal OPSEC failures and tradecraft which can assist in future investigations, seizure notices and infrastructure details can feed your detections, and you can update risk assessments for actors tied to seized forums and markets.

As exit scams become more common offenders tend to gravitate toward smaller, more “community-focused” markets. More trading moves into semi-closed spaces like invite-only Telegram channels and some actors may experiment with more robust escrow, multisig, and reputation mechanisms—but trust remains fragile. This means it can be more difficult to infiltrate and track the activity that is occurring. That has implications for everything from undercover operations to intelligence collection.

Serious illicit trade often uses a mix of different platforms, and it is important to have oversight of all of them which can include:

  • Tor markets and forums
  • Clearnet infrastructure (CDNs, bulletproof hosts, compromised servers)
  • Encrypted messaging platforms

A defensive strategy that stops at Tor is going to miss much of the real activity.

2025 didn’t “end” the dark web. But it did accelerate a shift that’s been visible for years:

  • Big, stable, centralized markets and forums are increasingly unsustainable.
  • Law enforcement is better at seizing infrastructure and tracing crypto.
  • Admins are quicker to pull the plug and disappear with user funds.
  • Users are more paranoid, more fragmented, and more willing to move between platforms.

For analysts, this is both good and challenging news. The chaos slows down some criminal operations—but it also pushes activity into smaller, harder-to-observe corners of the ecosystem. DarkOwl can assist in making sure you are able to monitor all areas where illicit activity is occurring and help you track actors as they react to takedowns and exit-scams. The dark web will continue but it will evolve and to mitigate risk it is important to closely track these changes.


Curious how DarkOwl can help? Contact us.

Content, Content, Content: Top Blogs from DarkOwl in 2025

January 13, 2026

Thanks to our analyst and content teams, DarkOwl published over 100 pieces of content last year. DarkOwl strives to provide value in every piece written, highlighting new darknet marketplaces and actors, trends observed across the darknet and adjacent platforms, exploring the role the darknet has in current events, and highlighting how DarkOwl’s product suite can benefit any security posture. Below you can find 10 of the top pieces published in 2025.

Don’t forget to subscribe to our blog at the bottom of this page to be notified as new blogs are published.

1. Telegram’s Crackdown: Why Accounts Are Getting Banned and What You Need to Know

The founder and CEO of Telegram, Pavel Durov, was arrested on August 24, 2024, at Paris-Le Bourget Airport. French authorities detained him as part of an investigation into Telegram’s alleged insufficient moderation of illegal activities on its platform, including child exploitation and drug trafficking. Following his arrest, Durov was indicted on multiple charges on August 28, 2024. He was placed under judicial supervision, prohibited from leaving France, and required to post bail of €5 million. As of February 2025, Durov remains under judicial supervision in France, awaiting further legal proceedings where he must appear at a police station twice a week. Should he be found guilty the most serious charge complicity in the administration of an online platform to enable organized crime and illicit transactions carries a maximum penalty of 10 years’ imprisonment, and a €500,000 ($521,000) fine.

In response to their CEO’s arrest Telegram announced plans to enhance its moderation policies and has expressed a willingness to cooperate more closely with law enforcement. They have been seeking to ensure that they are co-operating with authorities while claiming to continue to prioritize users’ privacy.

In this blog, we will explore what changes Telegram have said they have made, what effect DarkOwl analysts are seeing in response to these changes and what impact we expect to see in the future. Read blog here.

The darknet is a hidden part of the internet that operates beyond the reach of traditional search engines and mainstream platforms. Within this space, darknet marketplaces have emerged as virtual bazaars where anonymous buyers and sellers trade goods and services, often illicit, using privacy-focused technologies like Tor and cryptocurrencies such as Monero and Bitcoin. These markets are structured much like legitimate e-commerce sites, featuring product listings, vendor ratings, customer reviews, and even dispute resolution systems.

DarkOwl collects data from a wide range of marketplaces, capturing the breadth of listings, vendor activity, and community interactions. In this blog, we explore the state of darknet markets in 2025, highlighting which platforms lead in listings and vendor count, how products are distributed across categories, the flow of shipments around the world, and patterns of user engagement through reviews.

By examining these factors, we aim to provide a window into the scale, structure, and dynamics of this hidden economy, revealing both the major players and the underlying trends shaping the market landscape. Full blog here.

3. Extra! Extra! Read all about it! Archetyp Marketplace Takedown! 

In a major blow to the online drug trade, law enforcement agencies across Europe and the U.S. have taken down Archetyp Market, one of the most active and profitable dark web drug markets of the past five years. 

Launched in 2020, Archetyp wasn’t just another black market, it was the market. With over ~600,000 users and ~3,200 vendors, the platform facilitated transactions involving cocaine, meth, MDMA, and other narcotics. By its final days, it had moved an estimated $~250–290 million in illicit goods, making it a titan among darknet marketplaces. Read blog here.

4. BreachForums Disruption Sparks Copycat Domains and Darknet Chaos

BreachForums abruptly went offline, prompting a wave of opportunistic copycat domains and widespread confusion within the dark web community. The shutdown—now allegedly confirmed via a PGP-signed statement by former administrators—was attributed to a zero-day exploit targeting the MyBB forum software. This vulnerability was reportedly exploited either by law enforcement or rival threat actors. Read more.

5. Dark Web Pharmacy and Illegal PX Medication Sales 

Dark web “pharmacies” have become a global black market for prescription medications and counterfeit drugs. These underground vendors operate on hidden parts of the internet, accessible only with special software like Tor, and sell everything from opioid painkillers and anxiety meds to fake pills. Recent international crackdowns have led to hundreds of arrests across multiple continents, showing just how far-reaching and organized this trade has become. By using encryption and anonymous networks, dark web drug sellers connect with buyers around the world while evading traditional law enforcement. This blog looks at where these rogue pharmacies are found and the platforms they use to move drugs outside the law. Check it out.

6. Threat Actor Spotlight: The Terrorgram Network: Origins, Operations, and Downfall

In April 2024 the UK took the unprecedented step to sanction a group known as Terrorgram as a terrorist organization.  The UK was the first country to take this step, proscribing the group which consists of various Telegram channels which have been used to share and encourage extremist ideologies and methodologies. This marked the first time a group that is primarily organized on a messaging app has been declared a terrorist organization.  

In this blog we will explore the origins of the group, how they operated and the current status of the organization. Read more.

7. Whistleblower Sites 101

In this blog, DarkOwl analysts provide a summary of the digital whistleblower landscape, outlining the role of the dark web and examining some noteworthy whistleblower platforms. Read blog here.

8. What is Doxing?

This blog aims to provide a comprehensive overview of doxing, its implications, and strategies to safeguard against it. Learn more.

As we entered 2025, we predicted what would be the major trends of the year. The ever-shifting landscape of cybercrime continues to evolve, with the darknet remaining a significant hub for illicit activities. From emerging technologies to shifting criminal tactics, understanding these trends is critical for cybersecurity professionals, law enforcement agencies, and the general public alike. Drawing on industry expertise, this post identified seven major threats and trends expected to shape the darknet.
Full blog here.

10. Is Your City on the Dark Web? What Local Agencies Need to Know 

In 2023, investigators in a midsize U.S. city were tipped off to a darknet marketplace vendor offering “same-day delivery” of fentanyl-laced pills within specific zip codes. The listing named street corners and used coded references to local schools. It was not discovered by routine patrols or a community tip. It was found in an online space most local agencies never check: the dark web. 

The dark web is not just a place for global cybercriminal networks. It is a sprawling ecosystem where local-level threats are planned, traded, and discussed. Understanding what is being said about your city, and acting on it, can mean stopping crime before it happens. Read blog here.

2025, That’s a Wrap!

Thank you to everyone who reads, shares and interacts with our content! Anything you would like to see more of, let us know by writing us at [email protected]. Can’t wait to see what 2026 brings! Don’t forget to subscribe to our newsletter below to get the latest research delivered straight to your inbox every Thursday.

Threat Intelligence RoundUp: December

January 06, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. Bloody Wolf Threat Actor Expands Activity Across Central Asia – InfoSecurity Magazine

The threat actor group, Bloody Wolf, has been observed using remote-access software to infiltrate government targets throughout Central Asia. Cybersecurity researchers claim the group has shifted from traditional malware to “a streamlined Java-based delivery method”. Reports claim the group has been operating a sustained campaign in Kyrgyzstan since June 2025 and recently began targeting Uzbekistan. By using counterfeit PDF documents, spoofed web domains, and fraudulent emails to pose as the country’s Ministry of Justice, the group has manufactured an air of legitimacy that has facilitated their access. Once a victim opens the downloaded JAR file, the loader retrieves additional components and installs NetSupport RAT for remote control. Read full article.

2. Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment – Bleeping Computer

Three Ukrainians, claiming to be IT specialists, were arrested by Polish police while traveling through Europe. During a routine traffic stop, officers conducted a search of the threat actor’s vehicle, discovering suspicious items that could be “used to interfere with the country’s strategic IT systems, breaking into IT and telecommunications networks”. The seized equipment included “spy device detector, advanced FLIPPER hacking equipment, antennas, laptops, a large number of SIM cards, routers, portable hard drives, and cameras.” The data seized was encrypted but according to officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) claim to have been able to collect evidence. Article here.

Hours after CVE-2025-55182 was made public, Amazon Web Services (AWS) observed two different Chinese hacking groups, Earth Lamia and Jackpot Panda, beginning to weaponize the vulnerability. CVE-2025-55182, aka React2Shell, allows unauthenticated remote code execution in React Server Components (RSC). Using automated scanning tools, these threat actors have been observed exploiting additional vulnerabilities including CVE-2025-1338. AWS identified Earth Lamia due to the use of previously used infrastructure the group had demonstrated earlier in the year. This situation highlights threat actors systematic approach in abusing vulnerabilities quickly and learning to scan for common vulnerabilities. Read more here.

On November 26, the Federal Communications Commission (FCC) announced threat actors had been hijacking US radio transmission equipment and broadcasting fake emergency tones and offensive material. Several stations in Texas and Virginia were targeted, resulting in broadcasts being disrupted by emergency signals, alert tones, and obscene language. The threat actors targeted Barix network audio devices and reconfigured them to capture attacker-controlled streams. The FCC reports that the incidents stemmed from unsecured equipment, noting that some stations did not discover the compromise until after the attacks and were seemingly unaware as they unfolded. Read here.

5. CISA warns of Chinese “BrickStorm” malware attacks on VMware servers – Bleeping Computer

U.S. Cybersecurity and Infrastructure Security Agency (CISA) warn of Chinese hackers backdooring VMware vSphere servers with BrickStorm. Malware samples analyzed by the National Security Agency (NSA) and Canada’s Cyber Security Centre were found on victim networks in which the attackers had specifically targeted VMware vSphere environments. One of the incidents showed the threat actors compromising a web server in an organization’s demilitarized zone (DMZ) in April 2024, then moved laterally to an internal VMware vCenter server and deployed malware. Learn more.

6. Glassworm malware returns in third wave of malicious VS Code packages – Bleeping Computer

First emerging in October, the Glassworm campaign, has released 24 new packages distributing malware to OpenVSX and Microsoft Visual Studio. According to Koi Security, Glassworm malwares uses “invisible Unicode characters to hit its code”. Following previous detection, Glassworm evolved technically, using Rust-based implants packaged inside extensions as well as invisible Unicode. Once the malware is installed it attempts to steal GitHub, npm, and OpenVSX accounts, as well as cryptocurrency wallet data from 49 extensions. Additionally, the malware deploys a SOCKS proxy to route malicious traffic and give operators stealthy remote access. Read full article.

7. React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable – Bleeping Computer

On December 03, React disclosed the vulnerability, CVE-2025-55182 aka React2Shell, detailing “that unsafe deserialization of client-controlled data inside React Server Components enables attackers to trigger remote, unauthenticated execution of arbitrary commands.” React2Shell is a security flaw that allows attackers to run code on a server without logging in. It can be triggered with just one HTTP request and affects any framework that uses React Server Components, including Next.js. Over 77K internet exposed IP addresses are vulnerable to React2Shell and researchers believe 30 organizations are already compromised. Read full article.

8. RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware – The Hacker News

The malware group RomCom has been observed using the JavaScript loader, SocGholish, to target U.S. based civil engineering company. By targeting poorly secured websites, the group injects fake Google Chrome or Mozilla Firefox update alerts into otherwise legitimate but compromised pages. These alerts trick users into downloading malicious JavaScript that installs a loader, which then retrieves additional malware. According to Arctic Wolf researchers, this allowed the threat actors to execute commands on the compromised host through a reverse shell connected to the command-and-control (C2) server, enabling activities such as system reconnaissance and deployment of a custom Python backdoor known as VIPERTUNNEL. Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.