// Signal InterceptMONITORING 6 CHANNELS
■ Underground Forums
8 NEW // LAST 24H◆ CORRELATED WITH X SIGNAL
RAMP
02:44Z TODAY
ACTOR: ████████████
AFFILIATE RECRUITMENT — PHANTOM CIRCUIT RaaS [Healthcare Focus]
Seeking experienced affiliates for new RaaS operation. Custom Go encryptor, ████% split. Target vertical: healthcare, pharma, insurance. Contact via ████████████. KYC required.
raasransomwarerecruitment
◆ CORRELATED WITH X SIGNAL
XSS.is
YESTERDAY 21:05Z
ACTOR: ██████████
INITIAL ACCESS: Fortune 500 Manufacturing — Domain Admin, EDR: ████
Selling persistent access to ████████████ Corp. Domain admin credentials. Revenue: ████. Minimum bid $15,000 XMR.
$15,000+ XMR
initial-accessdomain-adminauction
✕ Signal Intercept
24 MONITORED ACCOUNTSGS
@GossiTheDogRESEARCHER
03:12Z TODAY
Cisco IOS XE situation is getting worse. Shodan now showing ~41,200 exposed mgmt interfaces, up from 38K yesterday. Some orgs have HTTP server enabled on external IPs. Disable it. Now. #CiscoIOSXE CVE-2025-1337
SO
@SwiftOnSecurityRESEARCHER
00:44Z TODAY
Reminder that "patch Tuesday" isn't a suggestion. The Windows CLFS driver vuln (CVE-2025-2201) is being used in post-exploitation by at least two ransomware groups we track. Patch is available. There's no good reason not to have deployed it already.
CI
@CISAgovVENDOR
YESTERDAY 17:00Z
CISA has added CVE-2025-0449, CVE-2025-1337, and CVE-2025-0813 to the Known Exploited Vulnerabilities catalog. Federal agencies must remediate by 2025-04-17. All organizations strongly encouraged to prioritize patching. #CISA #KEV
■ Threat Actor — Last Seen Tracker
12 MONITORED ACTORS████████Data broker. Healthcare PII. 14 listings since Jan 2025.4H AGO
BF
XSS
████████████PHANTOM CIRCUIT RaaS operator. Active since Mar 2025.2H AGO
RM
X
██████████Suspected Lazarus Group front. npm supply chain ops.YESTERDAY
BF
X
██████████Initial Access Broker. High-value corporate targets.YESTERDAY
XS
BF
█████████Independent researcher / grey-hat. PoC drops.18H AGO
EX
X