We had a Windows laptop that looked completely normal at first.
Defender was quiet, there was nothing suspicious sitting in Downloads, and Task Manager did not show anything that immediately looked wrong.
But one thing kept happening.
Any time the user logged in, PowerShell would start in the background.
That was what made me check the persistence locations.
I went through the user’s Run key in the registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
and found an entry called:
Windows Security Health
The name looked normal enough, but the command behind it was not.
It was launching PowerShell with the window hidden and running this script:
C:\Users\ola\AppData\Roaming\Microsoft\Windows\cache.ps1
At that point, I checked the file timestamps and saw that the script had been created the previous afternoon around 4:22 PM.
Then I went into the Sysmon logs.
Event ID 13 showed the registry Run key being modified around the same time the script was created.
Event ID 1 also showed PowerShell starting again the next morning after the user logged in.
So now the timeline was starting to make sense.
The user logs in.
Windows processes the Run key.
PowerShell starts quietly in the background.
The script runs.
I checked the network connections from the PowerShell process and found an active HTTPS connection to an external address on port 443.
That was enough for us to isolate the laptop and start preserving the evidence before removing anything.
When we spoke to the user later, he remembered opening what he thought was a company document the previous day.
He said nothing happened when he opened it, so he assumed the file was bad and forgot about it.
Meanwhile, the persistence had already been created.
What made this case interesting for me was how normal everything looked.
There was no malware.exe.
No strange folder sitting on the desktop.
The attacker used PowerShell, the Windows registry, AppData and a name that looked like it belonged to Windows Security.
If you were checking the machine quickly, you could easily pass over it.
Sometimes malware does not hide by looking strange.
It hides by looking like something you have seen a hundred times before.
❗🇫🇷 🇨🇳
Présenté la semaine dernière à un juge d'instruction après une garde à vue à la DGSI, Pierre-Henri Chuet, ancien pilote de Rafale au sein de l'aéronavale française, a été mis en examen, notamment pour « intelligence avec une puissance étrangère » et « livraison d'informations à une puissance étrangère ». Il a également été placé sous contrôle judiciaire.
⚠️ Alleged Windows Kernel Exploit Framework Leaked by Orcinus Orca
A threat actor linked to Orcinus Orca has published what they claim is the full source code of "OrcaHunter Kernel Framework v1.0" alongside a purported pre-auth remote RCE/DoS proof-of-concept targeting Windows 11 24H2.
According to the post, the leak allegedly includes:
* Full OrcaHunter Framework v1.0 source code
* 1,300+ lines of claimed exploit framework code
* A pre-auth remote packet exploit targeting tcpip.sys
* Windows 11 24H2 build 26100.8655 and below listed as targets
* Core driver-related components
* Automation modules for reverse engineering and kernel vulnerability research
The actor claims the framework is designed to support low-level kernel research, dynamic emulation, constraint solving, and automated analysis of Windows .sys binaries.
If authentic, the claimed capability could be highly significant due to the alleged targeting of the Windows networking stack. Pre-authentication vulnerabilities in network-facing components can create serious enterprise risk if weaponized.
Potential impact if validated:
* Remote code execution
* Denial-of-service conditions
* Kernel-level compromise
* Pre-authentication attack surface exposure
* Rapid weaponization by ransomware and intrusion groups
* Increased targeting of Windows 11 enterprise environments
At this stage, the claim remains unverified. The existence of source code does not confirm a working zero-day or reliable exploit chain. Technical validation is required to determine whether the release contains a real vulnerability, a crash-only PoC, incomplete research code, or fabricated material.
Analyst Note: Exploit claims involving tcpip.sys and pre-auth remote execution should be treated as high-priority intelligence leads, but not as confirmed exploitation until independently reproduced. The most important next step is controlled technical validation in an isolated lab environment.
#DDW #Intelligence #DarkWeb #Windows
🇫🇷 French Transport & Mobility Platform Data Allegedly Exposed
A threat actor is claiming to have breached https://t.co/i5VwsbpOgd and is advertising a dataset allegedly containing information associated with more than 435,000 users.
According to the post, the actor attributes the exposure to:
* Insecure Direct Object Reference (IDOR)
* Sequential identifier enumeration
* Lack of rate limiting
* Insufficient access controls
The advertised dataset allegedly contains:
* User profiles
* Contact information
* Email addresses
* Appointment and scheduling records
* Enterprise-related data
* Internal identifiers
* Administrative records
* JSON database exports
The screenshots suggest multiple exposed datasets and API responses containing structured user and organizational information.
Potential risks include:
* Large-scale privacy violations
* Targeted phishing campaigns
* Identity fraud attempts
* Business impersonation attacks
* Enumeration of organizational contacts
* Follow-on attacks against associated entities
The actor claims to have extracted hundreds of thousands of records through application-level weaknesses rather than traditional malware or ransomware activity.
At the time of writing, the authenticity, scope, and current availability of the advertised dataset have not been independently verified.
Analyst Note: IDOR vulnerabilities remain one of the most common and damaging web application security flaws. When combined with predictable object identifiers and missing rate limiting, threat actors can automate the extraction of large datasets without requiring privileged access.
#DDW #Intelligence #DarkWeb #France
🤯 ANZOR MET PAUL DENA KOOOOOOOOOO !!
🔥 C’est complètement dingue, Anzor Baybatyrov fait dormir Paul Dena dès le début du premier round ! Il lui inflige sa première défaite et son premier KO en carrière !
📺 ON EST EN DIRECT sur la chaîne RMC Sport 1 !
🇫🇷 https://t.co/k57j6ADjj8 Healthcare Provider Registry Allegedly Exposed
A threat actor has published an alleged dataset associated with https://t.co/k57j6ADjj8, France's national health insurance platform.
* According to the advertisement, the dataset allegedly contains:
* More than 12 million records
* Approximately 2.29 GB of data
* Structured healthcare provider and administrative registry information
* The actor claims the exposed data includes:
* Healthcare professional identifiers
* National and professional registration numbers
* First and last names
* Professional titles and specialties
* Organization and clinic information
* SIRET, SIREN, and FINESS identifiers
* Full workplace addresses
* Geographic location data
* Telephone and fax numbers
* Email addresses (where available)
* Administrative and regulatory classification codes
* Activity and role categorization information
* Based on the advertised contents, the dataset appears to primarily consist of healthcare provider and organizational registry information rather than patient medical records.
* At the time of publication, Daily Dark Web could not independently verify:
* The authenticity of the dataset
* Whether the information originated from a breach
* Whether the records were obtained from publicly accessible registries
* The recency of the data
* Whether any non-public information is included
* No evidence of patient health records, medical histories, prescriptions, or reimbursement data was presented in the advertisement.
Analyst Note:
Healthcare provider registries are valuable for threat actors conducting phishing, business email compromise, credential harvesting, and healthcare-focused social engineering campaigns. Even when patient data is absent, large-scale collections of provider identities and organizational details can be leveraged to target hospitals, clinics, insurers, and healthcare professionals across the sector.
#DDW #Intelligence #DarkWeb #France
🇫🇷 France - https://t.co/ZJb2L4nEST Customer Dataset Allegedly Exposed
A threat actor is advertising an alleged customer database associated with French telecommunications provider https://t.co/ZJb2L4nEST.
According to the listing, the dataset reportedly contains more than 19 million customer records and includes:
* Full names
* Email addresses
* Mobile phone numbers
* Postal addresses
* Dates of birth
* Customer account identifiers
* Subscription and service details
* Account activation information
* Internal account references
If authentic, the exposure could increase the risk of identity theft, phishing, SIM-swapping attempts, and telecom-related account takeover attacks.
Daily Dark Web has not independently verified the authenticity of the dataset or the claims made by the seller.
Analyst Note: Telecommunications providers remain prime targets for threat actors due to the value of subscriber data and its potential use in social engineering, credential attacks, and identity fraud operations.
#DDW #Intelligence #DarkWeb #France
🇫🇷 France: Alleged Exposure of Tchap Government Messaging Platform Data
A threat actor claims to have accessed data from Tchap, the French government's official secure messaging platform used across multiple ministries and public sector organizations.
* According to the post, the actor allegedly obtained access through social engineering of an account associated with the education shard of the platform.
* The actor claims the exposed data includes:
* 73,467 user accounts
* 643,459 messages
* 876 chat rooms with message history
* 59,386 media files (13.51 GB)
* References to documents marked with "Diffusion Restreinte" (French restricted distribution classification)
* The post further alleges that user enumeration was possible through a directory search endpoint that returned users across multiple platform shards.
* No independent verification has been conducted, and the claims remain those of the threat actor at the time of reporting.
* If validated, the incident could expose sensitive government communications, organizational structures, contact directories, media files, and operational discussions across multiple French ministries.
Analyst Note:
Tchap was developed as France's sovereign alternative to commercial messaging platforms for government communications. Any confirmed compromise affecting user directories, message histories, or media repositories would represent a significant security and intelligence concern due to the platform's use by public sector personnel and government agencies.
#DDW #Intelligence #DarkWeb #France
🇫🇷 France: Alleged Exposure of Tchap Government Messaging Platform Data
A threat actor claims to have accessed data from Tchap, the French government's official secure messaging platform used across multiple ministries and public sector organizations.
* According to the post, the actor allegedly obtained access through social engineering of an account associated with the education shard of the platform.
* The actor claims the exposed data includes:
* 73,467 user accounts
* 643,459 messages
* 876 chat rooms with message history
* 59,386 media files (13.51 GB)
* References to documents marked with "Diffusion Restreinte" (French restricted distribution classification)
* The post further alleges that user enumeration was possible through a directory search endpoint that returned users across multiple platform shards.
* No independent verification has been conducted, and the claims remain those of the threat actor at the time of reporting.
* If validated, the incident could expose sensitive government communications, organizational structures, contact directories, media files, and operational discussions across multiple French ministries.
Analyst Note:
Tchap was developed as France's sovereign alternative to commercial messaging platforms for government communications. Any confirmed compromise affecting user directories, message histories, or media repositories would represent a significant security and intelligence concern due to the platform's use by public sector personnel and government agencies.
#DDW #Intelligence #DarkWeb #France
🇫🇷 France: Carrefour User Database Reposted on Underground Forum
* A threat actor has reposted an alleged Carrefour database containing approximately 64,000 user accounts.
* The forum post appears to be a redistribution of previously leaked data rather than a newly claimed compromise.
* No detailed technical information, breach date, or affected systems were disclosed in the listing.
* Based on the advertisement, the dataset is being shared through an external file-hosting service and promoted as a Carrefour user database dump.
* At this stage, the authenticity, age, and origin of the dataset remain unverified.
* Organizations should treat reposted datasets seriously, as older breaches frequently resurface in underground communities and may still contain valid credentials or personal information.
Analyst Note:
Reposted databases are common across cybercrime forums. Even when a breach is not recent, recycled datasets can fuel credential stuffing, phishing, and identity-based attacks against individuals who have not updated their credentials following the original exposure.
#DDW #Intelligence #DarkWeb #Carrefour
🌐 BreachForums Announces Domain Migration Following Takedown
* BreachForums claims its clearnet domains were suspended following what it describes as competitor-driven complaints
* Forum operators announced plans to migrate to a new primary domain and deploy additional mirror sites
* The statement references continued collaboration with ShinyHunters and ongoing development of related leak infrastructure
* Administrators claim new services and updates will be deployed within the coming days
* BreachForums states operations will continue despite recent disruptions and domain seizures
Analyst Note:
* The continued resilience of major cybercrime forums highlights the challenges of disrupting illicit ecosystems through domain takedowns alone
* Threat actors frequently leverage mirror sites, alternative TLDs, bulletproof hosting, and darknet infrastructure to maintain operational continuity after enforcement or infrastructure disruptions
Daily Dark Web cannot independently verify the claims made in the statement and is monitoring the situation for further developments.
#DDW #Intelligence #DarkWeb #BreachForums