skytfall
11 posts


🚨New #Ransomware Group: Sicari
Onion:
sicariifoucvhyqg54smi3esg5sfcyw5z65t6yigqu4loyuoz62bb2id[.]onion
sicarilxx2br6esqnhad4w26bcgb5j2snbbnhyo4b6t7kby2oy4x3jad[.]onion
sicari7m63wlggfxajiuonfsk72fgencne5ztzakyuhfxzq5rnbkjead[.]onion
sicariktdbhjtrk6f2pwdh6wlequw7pcjva25skkzz4m3zz3opyox3qd[.]onion
sicari7zpu3mtxqggde7mu3ywppntdqg22arcukvlaihjbfcb2rnktid[.]onion
sicarinb4ktqcdpubjifzw3vixvzgtwacjmc5ks56kev52gxitegigad[.]onion

Suomi

🚨 Possible Reactivation of BreachForums & ShinyHunters
The domain https://breachforums(.)bf/
continues to show signs of restoration, despite critical errors in MyBB detected in the logs on November 24, 2025, at 12:19:30 GMT.
Exposed configurations, public IPs, visible VPSs, and potential access to Adminer 5.4.1 panels were identified.
🔍 Among the findings are possible authentication keys linked to VECERT, along with patterns consistent with lateral movement and recurring system failures.
Some indicators suggest a possible reappearance of activity related to ShinyHunters.
📌 Observed IOCs:
• 45.134.26.22
• 169.254.71.72
• 45.134.26.184
👀 Recent Activity: 14 users connected in the last hour.
#ShinyHunters #IOC #CyberSecurity #ThreatIntel #BreachForums #MyBB


English


@JAMESWT_WT @guelfoweb @marsomx_ @AndreaDraghetti @signorina37H @securityaffairs @c_APT_ure @0xToxin @pr0xylife Are you guys reselling this ?
English












