Head of Cyber Threat Intelligence @ WΓΌrth Group, GCTI/CPENT/CEH/CND/CSA/ECSA/ECIH/CTIA, owner of SATAYO CTI platform & deepdarkCTI - member of @Curatedintel
π’A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #NoName057 threat actor
β’οΈThe pro-Russia hacktivist collective emerged in March 2022 following the Russian invasion of Ukraine
π You can read the interview at deepdarkcti.com/interview-11β¦
π’ A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #BreachForums, interviewing the forum owner, diencracked
π΅οΈββοΈ The interview, which we publish in full, was conducted in May 2026.
π You can read the interview at deepdarkcti.com/interview-10β¦
π’ A new interview is available on #deepdarkCTI. This time, we wanted to delve deeper into the #MedusaLocker ransomware gang.
π΅οΈββοΈ The interview, which we publish in full, was conducted in May 2026 by Erez.
π You can read the interview at deepdarkcti.com/interview-9-β¦
βοΈ The #SATAYO TIP becomes a key element in the continuous #threat#hunting process thanks to seamless integration with long-standing benchmark tools like Elastic Security and #MISP.
ππΌ Read the full article at the link neteye-blog.com/2026/03/fromβ¦
β’οΈ In recent days, the pro-Iran group #Handala has publicly released information regarding more than 180 profiles associated to the #Israeli#Air#Force and other strategic organizations/sectors.
ππΌ Full article at deepdarkcti.com/handala-and-β¦
π’ New #Insomnia ransomware gang.
β’οΈ Active since October 2025, 17 victims published on their data leak site.
ππΌ Onion link and TOX ID already available on #deepdarkCTIgithub.com/fastfire/deepdarkβ¦
π How is the ransomware gang landscape evolving after the #RAMP forum seizure?
π΄ Another well-known forum seems to be becoming a point of reference in this field.
ππΌ We discuss it in the article you can read at this link neteye-blog.com/2026/02/fromβ¦
With 2025 now behind us, we can make some observations regarding the landscape of double-extortion #ransomware#attacks.
β Which ransomware gangs were the most active?
β Which sectors and countries were most affected?
ππ» Read the full article here neteye-blog.com/2026/01/ransβ¦
π’ Recap of what happened in #deepdarkCTI in 2025:
β 586 commits
β 35 contributors
β 6,400 stars on GitHub
β 8 articles on deepdarkcti.com
β 129 active users within the Telegram channel
β a total of 2,465 sources
π Many thanks to the #deepdarkCTI community!
#Ransomware π£ NEW FEATURE
La nuova sezione RF Domain Monitor permette il monitoraggio costante dei domini sotto controllo #Ransomfeed e di deepdarkCTI project (@fastfire), alla ricerca di variazioni DNS e law enforcement.
1/2
π’ On October 23rd, I will have the pleasure of participating in the #NetEye#Conference 2025 as a speaker with the talk "From Intelligence to Action: Embedding TI into Your Security Operations".
ππΌ You can register here wuerth-phoenix.com/neteye-coβ¦
π’ We interviewed Gabi, a member of the #Cyber ββ#Toufan group. This group, active since October 2024, has carried out several attacks against #Israeli targets.
The full interview is available at the link deepdarkcti.com/interview-7-β¦
π’ At deepdarkcti.com/details-of-tβ¦, you can find a detailed timeline of the main events related to the alleged seizure of the #XSS forum.
β° The timeline is constantly updated, taking into account relevant events that are also occurring in recent days.
#deepdarkCTI
π’ A new interview is available on the #deepdarkCTI website. This time, community member #Erez interviewed the founder of the #Devman ransomware gang.
ππ» You can read the full interview at this link deepdarkcti.com/interview-6-β¦
If you want to contribute, I created this project where I'm cataloging the Telegram channels of the various groups related to the Israel-Iran conflict, shared by @Cyberknow20github.com/fastfire/IsraelIrβ¦
π’ Hey #community!
βοΈ βοΈ βοΈ βοΈ βοΈ We have reached 5000 stars on #deepdarkCTI!
βοΈ 99 contributors
βοΈ 119 people within Telegram channel
βοΈ more than 2000 sources added!
βοΈ official website deepdarkcti.com
π€ A huge thank you goes to the whole community!