๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ

682 posts

๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ banner
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ

๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ

@intelrat

Independent OSINT/threat intel research. Content is for informational purposes only and does not endorse or promote any referenced services or activity.

Deep Underground Se uniรณ Ocak 2026
267 Siguiendo294 Seguidores
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
Ransomware group DragonForce listed another two alleged victims on their leak site earlier today. Post details: Threat actor: DragonForce Victim 1: vatractor[.]com Data size: 22.4 GB Leak deadline: 4 days 18 hours Post date: 19 March 2026 Victim 2: Mercedes-Benz of Arlington Data size: 93.07 GB Leak deadline: 4 days 17 hours Post date: 19 March 2026
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media
English
0
0
1
62
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ retuiteado
DarkFeed
DarkFeed@ido_cohen2ยท
๐Ÿšจ BREAKING: FBI seizes primary infrastructure of #Handala, the #Ransomware group linked to Iranโ€™s IRGC! Court-authorized warrant leads to the takedown of domains used for state-sponsored cyber operations and network intrusions. Major blow to Iranian proxy activities. ๐Ÿ“‰ Full CTI update & analysis: ๐Ÿ›ก๏ธDarkfeed.io #Handala #IRGC #Iran #FBI #CyberSecurity #ThreatIntel #InfoSec
DarkFeed tweet media
English
0
9
24
1.7K
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
Threat actor group KittyKatKrew claim to have breached The Government Ayurved College and Hospital Nagpur Threat actor claim: "We encourage someone at The Government Ayurved College and Hospital Nagpur to reach out to us either on Session (Redacted) or X (Redacted) to resolve this issue. You have 72 hours or this entire database will be leaked publicly." - KittyKatKrew
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media
English
0
0
1
107
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
Ransom extortion group ShinyHunters have listed Berkadia Commercial Mortgage LLC as a new alleged victim on their leak site. Post details: Threat actor: ShinyHunters Victim: Berkadia Commercial Mortgage LLC 5M+ Records Leak deadline: 20 Mar 2026 Post date: 19 Mar 2026 Threat actor claim: "Over 5M Salesforce records containing PII and other internal corporate data have been compromised." - ShinyHunters
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media
English
0
2
2
279
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ retuiteado
Crypto Tea
Crypto Tea@Cryptoteaยท
North Korean hacker group Lazarus allegedly hacked Bitrefill they drained hot wallets and stole 18,500 customers information
Crypto Tea tweet mediaCrypto Tea tweet media
English
34
29
256
72.7K
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
This is particularly noteworthy. The SCADA-related fires, allegedly attributed to a cyberattack, have been widely speculated to involve threat actor Pryx. However, responsibility has also reportedly been claimed by the threat actor group Devman. Please note that this is a highly speculative topic at this stage.
GangExposed RU@GangExposed_RU

@IntCyberDigest I canโ€™t yet name the source from which this correspondence was taken.

English
0
0
7
627
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ retuiteado
International Cyber Digest
International Cyber Digest@IntCyberDigestยท
โ—๏ธCybersecurity company Aura suffered a data breach after a phone phishing attack by ShinyHunters. The attackers gained access to an employee account. Most of the stolen data came from a company Aura acquired in 2021: over 900,000 names and email addresses stored in Salesforce. Additionally, data of fewer than 20,000 current and 15,000 former Aura customers was stolen, including names, emails, addresses, and phone numbers.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
14
26
136
18.1K
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ retuiteado
StarPlatinum
StarPlatinum@StarPlatinum_ยท
This is how one of the biggest Bitcoin whales was actually a hacker - โ€œLoadedโ€ on Bitcointalk - anonymous user since 2012 - called himself a Bitcoin multimillionaire - claimed to be a broker and asset manager - posted only ~135 times - rumors of 182,000 BTC 2017 - signs a message with 40,000 BTC - offers a swap to Roger Ver - later moves it all to SegWit - pays ~$1 in fees for years - holds through every crash - disappears from the forum 2021 - US authorities raid a house in Georgia - find 50,000+ BTC hidden - inside a safe and a popcorn tin real identity - James Zhong - hacked Silk Road in 2012 - exploited a withdrawal bug - stole 50,680 BTC after - funds seized by the government - pleads guilty - sentenced in 2023
StarPlatinum tweet mediaStarPlatinum tweet media
English
21
10
106
11.1K
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
Ransomware group DragonForce have just listed another 5 new alleged victims on their leak site. Post details: Threat actor: DragonForce Victim 1: Dynex/Rivett Data size: 58.49 GB Leak deadline: Published Post date: 18 March 2026 Victim 2: Flexform Data size: 29.51 GB Leak deadline: Published Post date: 18 March 2026 Victim 3: HARTMANN BAU Data size: 166.59 GB Leak deadline: Published Post date: 18 March 2026 Victim 4: gasteiger[.]design Data size: 37.47 GB Leak deadline: 21 hours Post date: 18 March 2026 Victim 5: Construction Equipment Parts Data size: 21.91 GB Leak deadline: 2 days 17 hours Post date: 18 March 2026
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media
English
0
0
2
157
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ
The threat actor group Hellcat has now reportedly had 2 of its members de-anonymized, those members being Rey & Pryx. IntelBroker, Hellcat's most notorious alleged member in terms of publicity, was reportedly arrested in 2025 and is believed to be in custody. The current state of Hellcat is shown in the image of alleged members below.
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ tweet media
English
11
32
204
14.1K
๐™ž๐™ฃ๐™ฉ๐™š๐™ก๐™ง๐™–๐™ฉ retuiteado