// Signal InterceptMONITORING 6 CHANNELS
INTERCEPTING LIVE
FORUMS: 4 | X ACCOUNTS: 43
◆ 12 CORRELATED SIGNALS
■ Underground Forums
4 NEW // LAST SWEEPPwnForums / DarkForums
~09:00Z TODAYADDED 2026-07-12◆ CORRELATED
ACTOR: ███
Accenture Data Breach — 35GB Source Code + Cloud Credentials (One Time Sale)
In July 2026, █████████ suffered a data breach which resulted in just over 35GB of source codes getting stolen. Dataset includes source code, RSA keys, SSH keys, ████████████, and configuration files. Proof screenshot shows clone of Azure DevOps repo ████████████. One Time Sale — payment in XMR only.
Undisclosed XMR
data-salesource-codecloud-credentialsazure-devopssupply-chain-risk
◆ CORRELATED WITH X SIGNAL
Exploit.in / DarkForums
~06:00Z TODAYADDED 2026-07-12◆ CORRELATED
ACTOR: ███████
Prinz Eugen Ransomware — New Go-based Encryptor, Victims Listed, Data Available
Advertising Prinz Eugen ransomware operation. Go-based encryptor first deployed May 11, 2026. Uses ChaCha20-Poly1305, prioritizes newest files first, leaves no on-disk ransom note. Out-of-band extortion via leak portal ████████████. Current victims: ████████████. Prior actor history as avtokz on XSS and GERMANIA alias. C2 previously at ███████████ (now dismantled). Initial access via compromised RDP credentials.
ransomwaredouble-extortiongo-encryptorrdp-iabanti-forensicdarkforums
◆ CORRELATED WITH X SIGNAL
XSS / DarkForums (PolinRider-linked credential sales)
~07:30Z TODAYADDED 2026-07-12◆ CORRELATED
ACTOR: ███████████████████████████
Developer Credential Logs + Crypto Wallet Keys — OmniStealer Harvested Batch
Stealer logs from PolinRider supply-chain campaign. OmniStealer harvested credentials from developer machines infected via compromised npm, Packagist, and Go packages. Data includes Git credentials, browser cookies, ████████████. Blockchain C2 drop points: ████████████. Loader signature: rmcej%otb%. Packages compromised include ████████████ among 108 total artifacts.
stealer-logssupply-chainnorth-koreadprknpmgo-modulesdeveloper-targetingcrypto-theft
◆ CORRELATED WITH X SIGNAL
Exploit.in
~05:00Z TODAYADDED 2026-07-12◆ CORRELATED
ACTOR: ████████████████████████████
CVE-2026-8037 Progress Kemp LoadMaster — Pre-Auth RCE PoC + Scanning Activity
Working PoC for CVE-2026-8037 (CVSS 9.6/9.8) in Progress Kemp LoadMaster being shared. Targets /accessv2 API endpoint — pre-auth OS command injection via escape_quotes() uninitialized heap bug. Affects GA v7.2.63.1 and earlier, LTSF v7.2.54.17 and earlier when API is enabled. ████████████. Exploitation attempts began June 29, 2026 same day watchTowr published full PoC. Full RCE as root achievable. High-value target: LoadMaster sits at enterprise network edge.
exploitrcepre-authedge-deviceload-balancercve-2026-8037iab-potential
✕ Signal Intercept
43 MONITORED ACCOUNTSAD
@AlvieriDRESEARCHER
~08:15Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code, Azure PATs, SSH keys, RSA keys for sale in XMR. Forum post dated July 6. Accenture has confirmed an 'isolated matter' and says source has been remediated. Screenshot shows Azure DevOps clone activity. Watch for downstream client exposure — Accenture serves Fortune 500. cc @DarkWebInformer @FalconFeedsio
↺ 312♥ 1.4K⚠ HIGH SIGNAL
DW
@DarkWebInformerRESEARCHER
~07:00Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA) advertising via Exploit.in and DarkForums. Go-based encryptor, no on-disk ransom note (anti-forensic), extorts via dedicated leak portals. Confirmed victims include a major South African financial institution (1.2TB exfil). RDP initial access, RemotePC abuse for lateral movement. Flag in your threat hunts: admin account named 'germania', RDP → PowerShell chain.
↺ 287♥ 1.2K⚠ HIGH SIGNAL
MH
@MalwareHunterTeamRESEARCHER
~06:30Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain campaign now confirmed across npm, Packagist, Go modules, Chrome extensions — 108 packages, 162 malicious artifacts. Payloads: DEV#POPPER RAT + OmniStealer. C2 via TRON and Aptos blockchain dead-drops. Loader sig: rmcej%otb%. Git history rewritten to backdate commits. Still ACTIVE as of today. Rotate ALL developer secrets if you pulled deps in past 30 days.
↺ 541♥ 2.8K⚠ HIGH SIGNAL
GD
@GossiTheDogRESEARCHER
~09:45Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts confirmed in the wild by eSentire TRU starting June 29, same day watchTowr dropped full heap-spray PoC. CVSS 9.6-9.8. Edge device with auth flows and TLS termination = full pivot potential. If your LoadMaster API is internet-exposed and unpatched, treat as compromised. Patch to GA 7.2.63.2 / LTSF 7.2.54.18 NOW. This is the second critical pre-auth RCE on this product in under 2 years.
↺ 403♥ 1.9K⚠ HIGH SIGNAL
FF
@FalconFeedsioRESEARCHER
~08:50Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset: source code, RSA/SSH keys, Azure PATs, Azure Storage access keys, config files — XMR-only sale framed as 'One Time.' Same actor previously claimed Decathlon, Credit Suisse, Shell, Heineken, UNICEF breaches. Accenture confirmed intrusion — scope unverified. Downstream clients with Accenture-managed Azure DevOps repos should rotate PATs immediately.
↺ 198♥ 876⚠ HIGH SIGNAL
MS
@MsftSecIntelVENDOR
~10:00Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | We are aware of the reported forum activity referencing Azure DevOps repository access associated with the Accenture incident. Organizations should audit Azure PAT scopes and expiry, review Azure DevOps audit logs for unexpected clone/read operations, and rotate Azure Storage access keys. MFA on all Azure DevOps identities is critical. Guidance: aka.ms/azdevops-security
↺ 622♥ 3.1K⚠ HIGH SIGNAL
TS
@TalosSecurityVENDOR
~07:45Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | PolinRider DPRK supply chain: Talos is tracking follow-on stealer log sales linked to OmniStealer infections from compromised npm/Go packages. Developer credential dumps from this campaign are appearing in underground markets. Key IOCs: TRON/Aptos blockchain C2, .woff2 hidden payloads, VS Code tasks with runOn:folderOpen. Hunt for postcss.config.js modifications and unexpected outbound to public blockchain RPC nodes.
↺ 389♥ 1.7K⚠ HIGH SIGNAL
VX
@vxundergroundRESEARCHER
~05:15Z TODAYADDED 2026-07-12◆ CORRELATED
CORRELATED | Prinz Eugen ransomware technical deep-dive: written in Go, ChaCha20-Poly1305 per-file encryption with integrity check before original deletion, recursive dir walk sorted by mtime (newest first), self-zeroes key from memory on exit, no on-disk ransom note. Attribution to ROOTBOY/avtokz/GERMANIA via forum history on Exploit.in, DarkForums, XSS (shared TOX ID). Sample hash posted for community analysis.
↺ 476♥ 2.3K⚠ HIGH SIGNAL
■ Threat Actor — Last Seen Tracker
12 MONITORED ACTORS████████Data broker. Healthcare PII. 14 listings since Jan 2025.4H AGO
BF
XSS
████████████PHANTOM CIRCUIT RaaS operator. Active since Mar 2025.2H AGO
RM
X
██████████Suspected Lazarus Group front. npm supply chain ops.YESTERDAY
BF
X
██████████Initial Access Broker. High-value corporate targets.YESTERDAY
XS
BF
█████████Independent researcher / grey-hat. PoC drops.18H AGO
EX
X