DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
MONITORING 6 CHANNELS
INTERCEPTING LIVE
FORUMS: 6  |  X ACCOUNTS: 43
◆ 12 CORRELATED SIGNALS
■ Underground Forums
6 NEW // LAST SWEEP
BreachForums
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
ACTOR: █████████████
VECT RaaS x BreachForums Partnership — Affiliate Keys Now Active for TeamPCP Victim Pool
We are formalizing our operational partnership with ███████. All 300,000 members of this forum are eligible for a personal affiliate key. ████████████. Together we are ready to deploy ransomware across all affected companies. We will chain these compromises into devastating follow-on campaigns. Escrow handled via forum infrastructure. Monero only. Tiered commission structure active. CIS orgs excluded.
null — affiliate revenue split 80-85% to affiliates
RaaSsupply-chainBreachForums-partnershipVECTTeamPCPCI/CDcredential-archive
◆ CORRELATED WITH X SIGNAL
BreachForums / DarkForums
00:00Z TODAYADDED 2026-08-02
ACTOR: ███████████
FATETRAFFIC 2070 MIX — Infostealer Log Dump [5,777 logs / 2,070 creds]
Releasing 5,777 individual infostealer logs harvested as recently as ████████████. Dataset contains 2,070 unique email/password combos. Distributed via ████████████. Mix includes browser-saved passwords, session cookies, and sensitive config files scraped by infostealer malware. Suitable for ATO, financial fraud, and initial access operations.
stealer-logsinfostealercredential-dumpATOcombolistMaaS
Niflheim dark web forum
00:00Z TODAYADDED 2026-08-02
ACTOR: ███████████
125,000 Outlook Credential Pairs — Targeted Combolist Drop
Dropping a targeted combolist of ████████████. Dataset appeared ████████████ and is explicitly marketed for credential-stuffing and enterprise phishing pre-positioning. Logs sourced from infostealer campaigns.
combolistOutlookcredential-stuffingstealer-logsenterprise-targeting
DarkForums / Exploit.in ecosystem
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
ACTOR: █████████████████
Qilin Affiliate Recruitment — CVE-2026-0257 GlobalProtect Initial Access for RaaS Deployments
Qilin affiliate program openly recruiting on Russian-language cybercrime forums. Initial access method currently leveraged: ████████████. Exploitation yields direct VPN sessions without valid credentials. Targeting unpatched ████████████. 167,000+ exposed GlobalProtect instances currently visible on Shadowserver. Affiliate split: 80-85%. Rust-based payload, ESXi/Linux/Windows builders available.
null — affiliate commission 80-85% of ransom
QilinRaaSCVE-2026-0257PAN-OSGlobalProtectinitial-accessaffiliate-recruitment
◆ CORRELATED WITH X SIGNAL
Russian Market / DarkForums
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
ACTOR: █████████████
FIFA World Cup 2026 Credential Bundle — Ticketing Platform Accounts + Cash-Out Services
Selling FIFA-related individual account credentials harvested via phishing and infostealer campaigns. Accounts linked to ████████████. Cash-out services advertised. Over ████████████ now circulating across dark web marketplaces. Credential stuffing ready. Premium hospitality phishing transactions priced ████████████.
null — per-account pricing varies
FIFA2026credential-theftticketing-fraudcash-outinfostealerRussian-Market
◆ CORRELATED WITH X SIGNAL
Russian-speaking forums (post-RAMP ecosystem: T1erOne, Rehub)
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
ACTOR: █████████████████████
ACR Stealer (Amatera) MaaS — ClickFix Delivery, $199/mo — Active Enterprise Campaigns
ACR Stealer (rebranded from Amatera Stealer / GrMsk) actively marketed on Russian-speaking forums. Pricing from ████████████. Delivery via ClickFix social engineering lures (malvertising / SEO-poisoned search / fake CAPTCHA). Steals browser credentials, session tokens, M365 docs, OneDrive/SharePoint content. Two confirmed active enterprise intrusion chains documented by Microsoft Defender Experts late April through mid-June 2026. Logs exfiltrated to operator C2.
$199/month
ACR-stealerAmateraClickFixMaaSinfostealerenterprisesession-tokens
✕ Signal Intercept
43 MONITORED ACCOUNTS
MS
@MsftSecIntelVENDOR
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Microsoft Defender Experts tracked increased ACR Stealer activity from late April through mid-June 2026. Two distinct ClickFix intrusion chains observed across customer environments — both end in exfiltration of browser credentials, session tokens, and sensitive enterprise documents including M365 and SharePoint files. Blog: ACR Stealer: Two observed intrusion chains amid increased threat activity. Rotate credentials and revoke exposed session tokens immediately if ClickFix prompt was executed.
↺ 1.2K♥ 3.8K⚠ HIGH SIGNAL
TS
@TalosSecurityVENDOR
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+ victims posted this year alone. Arctic Wolf confirmed multiple June 2026 intrusions all originating from CVE-2026-0257 (PAN-OS GlobalProtect auth bypass) leading to domain-wide Qilin encryption. CISA KEV listed. Shadowserver tracking 167,000+ exposed GlobalProtect instances. Patch now — affected versions: PAN-OS 12.1, 11.2, 11.1, 10.2.
↺ 987♥ 2.9K⚠ HIGH SIGNAL
CS
@CrowdStrikeVENDOR
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate mobilization = unprecedented industrialized RaaS model. FBI IC3 FLASH-20260702-001 documents the campaign. If your CI/CD pipeline ran LiteLLM v1.82.8, any poisoned Trivy GitHub Action, or Checkmarx KICS between March–May 2026, treat all pipeline cloud credentials as compromised. Sophos CTU has confirmed at least one VECT deployment traced to TeamPCP-sourced credentials.
↺ 1.4K♥ 4.1K⚠ HIGH SIGNAL
MT
@MandiantThreatsVENDOR
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums (post-RAMP fragmentation). Actors migrating to T1erOne and Rehub. CVE-2026-0257 exploitation confirmed as primary initial access vector in June 2026 Qilin intrusions. Once inside, playbook: registry Run key persistence (asterisk + 6 random chars), AnyDesk/Ngrok/LogMeIn for redundant access, then domain-wide encryption. Hunt for these TTPs now.
↺ 743♥ 2.1K⚠ HIGH SIGNAL
FF
@FalconFeedsioRESEARCHER
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on Russian Market and criminal forums. 1.5M+ compromised credentials circulating. 300 Chinese-speaking TA cloned FIFA domains for credential harvesting. Cash-out services for Ticketmaster/StubHub/SeatGeek accounts being openly advertised. Over 13,000 FIFA-themed malicious domains registered since Jan 2026. Organizations in sports, travel, hospitality — monitor for brand abuse and combolists NOW.
↺ 612♥ 1.8K⚠ HIGH SIGNAL
AD
@AlvieriDRESEARCHER
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Qilin just posted Kean University to their DLS (discovered 2026-07-24). Group is leveraging CVE-2026-0257 for initial access at scale — 2,000+ total victims on leak site. Recruitment still active on underground forums post-RAMP seizure. Double extortion model: steal data, encrypt, publish on Tor DLS and WikiLeaksV2 clearnet site if no payment. Ransom demands $50K–$800K. No signs of slowing down into August 2026.
↺ 534♥ 1.6K⚠ HIGH SIGNAL
DW
@DarkWebInformerRESEARCHER
00:00Z TODAYADDED 2026-08-02
FATETRAFFIC infostealer log dump spotted: 5,777 logs / 2,070 unique creds, harvested as recently as July 15 2026, distributed via Pixeldrain. Separately: Niflheim forum actor 'DAISY CLOUD' dropped 125,000 Outlook credential pairs July 7. Both typical of the log-as-a-service ecosystem dominating fresh credential compromise in 2026. Credential reuse risk is critical — these will fuel ATO and ransomware pre-positioning within hours.
↺ 389♥ 1.1K
VX
@vxundergroundRESEARCHER
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
ACR Stealer (aka Amatera Stealer) — originally marketed on Russian-speaking forums by SheldIO, shut down July 2024, source code sold, rebranded. Now priced $199/mo–$1,499/yr. ClickFix delivery confirmed as primary vector in 2026 enterprise campaigns. Microsoft documented two distinct intrusion chains July 16. This is the same MaaS family behind surging enterprise credential exfiltration. Correlated with ACR/Amatera listings still circulating on underground forums.
↺ 901♥ 3.2K⚠ HIGH SIGNAL
BT
@BushidoTokenRESEARCHER
00:00Z TODAYADDED 2026-08-02◆ CORRELATED
Post-RAMP underground fragmentation update (Jan 2026 FBI seizure): ransomware actors and IABs have migrated to T1erOne (gated) and Rehub (open). VECT/TeamPCP BreachForums partnership represents a new model — forum as operational infrastructure, not just marketplace. Escrow, affiliate support, key distribution all integrated. This is the first documented case of a ransomware group formally partnering with a forum at this scale. Defenders: visibility into centralized coordination is shrinking.
↺ 678♥ 2.0K⚠ HIGH SIGNAL
■ Threat Actor — Last Seen Tracker
12 MONITORED ACTORS
████████Data broker. Healthcare PII. 14 listings since Jan 2025.
BF
XSS
4H AGO
████████████PHANTOM CIRCUIT RaaS operator. Active since Mar 2025.
RM
X
2H AGO
██████████Suspected Lazarus Group front. npm supply chain ops.
BF
X
YESTERDAY
██████████Initial Access Broker. High-value corporate targets.
XS
BF
YESTERDAY
█████████Independent researcher / grey-hat. PoC drops.
EX
X
18H AGO