Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale8
- Ransomware31
- Leak85
- Stealer0
- Other1
Window
Category
Severity
Servicio de búsqueda de credenciales filtradas LeakZero ofrece acceso masivo a cuentas
Global
This service aggregates URL:LOG:PASS (ULP) data from multiple breaches and lets subscribers search by domain, making credential stuffing and account takeover trivially easy. It affects organizations worldwide, and the scale (15KKK rows) means many corporate and personal accounts are exposed. Defenders should treat any leaked credential as compromised, enforce MFA, and monitor for anomalous logins.
Venta de acceso total a la red corporativa de Kido Group (kdc.vn)
Kido Group (kdc.vn)
An exclusive bidding thread advertises a complete network compromise of Kido Group (kdc.vn), including executive archives, SharePoint databases and file server repositories. This is a serious initial access sale that could enable ransomware or large-scale data theft. The breadth of access makes it a high-value lead even outside Latin America.
Venta de 74.000 accesos a correos electrónicos
A seller is offering 74,000 valid email access credentials, likely obtained from data breaches or stealer malware. These are complete accesses to email accounts, which can be used for account recovery, financial fraud, and further phishing campaigns. The freshness of the data (dated August 28) makes it an immediate threat for email account owners.
Venta de acceso a API de RENAPER y bases de datos gubernamentales de Argentina
RENAPER (Registro Nacional de las Personas, Argentina)
A seller is offering access to an API service tied to RENAPER, Argentina's national identity registry, along with other government databases. This would allow doxing, identity theft, and large-scale fraud against Argentine citizens. It is a direct threat to critical government infrastructure and must be treated as a high-priority incident.
Venta de acceso VMware Horizon a empresa tecnológica sueca
Access to a VMware Horizon environment of a Swedish technology/SaaS company ($100M-$250M revenue) is being sold. VMware Horizon is a known initial attack vector for ransomware. This access could give the buyer a foothold in the corporate network and is a credible threat.
Venta de acceso VPN a red corporativa de EE.UU. con 600+ hosts
A seller is offering VPN access to a US corporate network with full internal visibility across more than 600 hosts and revenue above $1B. This is a confirmed initial access that could lead to ransomware or large-scale data theft. The access is recent and priced at $2,000, indicating an active threat.
Venta de base de datos y acceso de ardecora.it (Italia)
ardecora.it
This fresh post offers a 15K-record database and access for the Italian e-commerce site ardecora.it. The inclusion of access makes it a potential initial access vector. Even though the dataset is small, the breach is recent and could enable further attacks.
Venta de acceso admin a TeamCity de Steelseries
Steelseries
A threat actor is selling admin access to Steelseries' TeamCity server, a build and release management system. Such access can lead to source code theft, supply chain attacks, or further lateral movement into corporate networks. Defenders should treat this as a critical initial access risk and check for any related IOCs.