ACTOR: █████████████
VECT RaaS x BreachForums Partnership — Affiliate Keys Now Active for TeamPCP Victim Pool
We are formalizing our operational partnership with ███████. All 300,000 members of this forum are eligible for a personal affiliate key. ████████████. Together we are ready to deploy ransomware across all affected companies. We will chain these compromises into devastating follow-on campaigns. Escrow handled via forum infrastructure. Monero only. Tiered commission structure active. CIS orgs excluded.
null — affiliate revenue split 80-85% to affiliates
RaaSsupply-chainBreachForums-partnershipVECTTeamPCPCI/CDcredential-archive
◆ CORRELATED WITH X SIGNAL ACTOR: ███████████
FATETRAFFIC 2070 MIX — Infostealer Log Dump [5,777 logs / 2,070 creds]
Releasing 5,777 individual infostealer logs harvested as recently as ████████████. Dataset contains 2,070 unique email/password combos. Distributed via ████████████. Mix includes browser-saved passwords, session cookies, and sensitive config files scraped by infostealer malware. Suitable for ATO, financial fraud, and initial access operations.
stealer-logsinfostealercredential-dumpATOcombolistMaaS
ACTOR: ███████████
125,000 Outlook Credential Pairs — Targeted Combolist Drop
Dropping a targeted combolist of ████████████. Dataset appeared ████████████ and is explicitly marketed for credential-stuffing and enterprise phishing pre-positioning. Logs sourced from infostealer campaigns.
combolistOutlookcredential-stuffingstealer-logsenterprise-targeting
ACTOR: █████████████████
Qilin Affiliate Recruitment — CVE-2026-0257 GlobalProtect Initial Access for RaaS Deployments
Qilin affiliate program openly recruiting on Russian-language cybercrime forums. Initial access method currently leveraged: ████████████. Exploitation yields direct VPN sessions without valid credentials. Targeting unpatched ████████████. 167,000+ exposed GlobalProtect instances currently visible on Shadowserver. Affiliate split: 80-85%. Rust-based payload, ESXi/Linux/Windows builders available.
null — affiliate commission 80-85% of ransom
QilinRaaSCVE-2026-0257PAN-OSGlobalProtectinitial-accessaffiliate-recruitment
◆ CORRELATED WITH X SIGNAL ACTOR: █████████████
FIFA World Cup 2026 Credential Bundle — Ticketing Platform Accounts + Cash-Out Services
Selling FIFA-related individual account credentials harvested via phishing and infostealer campaigns. Accounts linked to ████████████. Cash-out services advertised. Over ████████████ now circulating across dark web marketplaces. Credential stuffing ready. Premium hospitality phishing transactions priced ████████████.
null — per-account pricing varies
FIFA2026credential-theftticketing-fraudcash-outinfostealerRussian-Market
◆ CORRELATED WITH X SIGNAL ACTOR: █████████████████████
ACR Stealer (Amatera) MaaS — ClickFix Delivery, $199/mo — Active Enterprise Campaigns
ACR Stealer (rebranded from Amatera Stealer / GrMsk) actively marketed on Russian-speaking forums. Pricing from ████████████. Delivery via ClickFix social engineering lures (malvertising / SEO-poisoned search / fake CAPTCHA). Steals browser credentials, session tokens, M365 docs, OneDrive/SharePoint content. Two confirmed active enterprise intrusion chains documented by Microsoft Defender Experts late April through mid-June 2026. Logs exfiltrated to operator C2.
$199/month
ACR-stealerAmateraClickFixMaaSinfostealerenterprisesession-tokens
Microsoft Defender Experts tracked increased ACR Stealer activity from late April through mid-June 2026. Two distinct ClickFix intrusion chains observed across customer environments — both end in exfiltration of browser credentials, session tokens, and sensitive enterprise documents including M365 and SharePoint files. Blog: ACR Stealer: Two observed intrusion chains amid increased threat activity. Rotate credentials and revoke exposed session tokens immediately if ClickFix prompt was executed.
Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+ victims posted this year alone. Arctic Wolf confirmed multiple June 2026 intrusions all originating from CVE-2026-0257 (PAN-OS GlobalProtect auth bypass) leading to domain-wide Qilin encryption. CISA KEV listed. Shadowserver tracking 167,000+ exposed GlobalProtect instances. Patch now — affected versions: PAN-OS 12.1, 11.2, 11.1, 10.2.
VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate mobilization = unprecedented industrialized RaaS model. FBI IC3 FLASH-20260702-001 documents the campaign. If your CI/CD pipeline ran LiteLLM v1.82.8, any poisoned Trivy GitHub Action, or Checkmarx KICS between March–May 2026, treat all pipeline cloud credentials as compromised. Sophos CTU has confirmed at least one VECT deployment traced to TeamPCP-sourced credentials.
Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums (post-RAMP fragmentation). Actors migrating to T1erOne and Rehub. CVE-2026-0257 exploitation confirmed as primary initial access vector in June 2026 Qilin intrusions. Once inside, playbook: registry Run key persistence (asterisk + 6 random chars), AnyDesk/Ngrok/LogMeIn for redundant access, then domain-wide encryption. Hunt for these TTPs now.
Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on Russian Market and criminal forums. 1.5M+ compromised credentials circulating. 300 Chinese-speaking TA cloned FIFA domains for credential harvesting. Cash-out services for Ticketmaster/StubHub/SeatGeek accounts being openly advertised. Over 13,000 FIFA-themed malicious domains registered since Jan 2026. Organizations in sports, travel, hospitality — monitor for brand abuse and combolists NOW.
Qilin just posted Kean University to their DLS (discovered 2026-07-24). Group is leveraging CVE-2026-0257 for initial access at scale — 2,000+ total victims on leak site. Recruitment still active on underground forums post-RAMP seizure. Double extortion model: steal data, encrypt, publish on Tor DLS and WikiLeaksV2 clearnet site if no payment. Ransom demands $50K–$800K. No signs of slowing down into August 2026.
FATETRAFFIC infostealer log dump spotted: 5,777 logs / 2,070 unique creds, harvested as recently as July 15 2026, distributed via Pixeldrain. Separately: Niflheim forum actor 'DAISY CLOUD' dropped 125,000 Outlook credential pairs July 7. Both typical of the log-as-a-service ecosystem dominating fresh credential compromise in 2026. Credential reuse risk is critical — these will fuel ATO and ransomware pre-positioning within hours.
ACR Stealer (aka Amatera Stealer) — originally marketed on Russian-speaking forums by SheldIO, shut down July 2024, source code sold, rebranded. Now priced $199/mo–$1,499/yr. ClickFix delivery confirmed as primary vector in 2026 enterprise campaigns. Microsoft documented two distinct intrusion chains July 16. This is the same MaaS family behind surging enterprise credential exfiltration. Correlated with ACR/Amatera listings still circulating on underground forums.
Post-RAMP underground fragmentation update (Jan 2026 FBI seizure): ransomware actors and IABs have migrated to T1erOne (gated) and Rehub (open). VECT/TeamPCP BreachForums partnership represents a new model — forum as operational infrastructure, not just marketplace. Escrow, affiliate support, key distribution all integrated. This is the first documented case of a ransomware group formally partnering with a forum at this scale. Defenders: visibility into centralized coordination is shrinking.