Welcome

Join the leading Carding Forum for carders worldwide. Connect, discuss, and explore carding topics and free carding stuff like cc, dumps with pin, leaked deatabse, bank accounts and much more in a trusted community hub for beginners and pros.

  • Contact : for Purchasing Advertisement and TELEGRAM : @Cardersforum_Admin
adv ex on 22 February 2024

Search results

  1. CarderBoss

    Fake LastPass Support Email Threads try to steal Vault Passwords

    Password management software provider LastPass is warning users of a phishing campaign targeting its users with fake unauthorized account access alerts. The emails impersonate a LastPass representative by spoofing the display name and use subject lines crafted to mimic forwarded internal...
  2. CarderBoss

    Wikipedia hit by self-propagating JavaScript Worm that vandalized Pages

    The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis. Editors first reported the incident on Wikipedia's Village Pump (technical), where users noticed a large number of...
  3. CarderBoss

    Termite Ransomware Breaches linked to ClickFix CastleRAT Attacks

    Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor. Researchers at cyber-deception threat intelligence firm MalBeacon observed the hackers' actions in an emulated...
  4. CarderBoss

    Microsoft Teams Phishing Targets Employees with A0Backdoor Malware

    Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor. The attacker relies on social engineering to gain the employee's trust by first flooding...
  5. CarderBoss

    New BeatBanker Android Malware poses as Starlink App to hijack Devices

    A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. The malware combines banking trojan functions with Monero mining, and can steal credentials, as well as tamper...
  6. CarderBoss

    England Hockey investigating Ransomware Data Breach

    England Hockey, the governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware gang listed it as a victim on its data leak site. The threat actor allegedly stole 129GB of data from the organization’s systems and announced that it will soon...
  7. CarderBoss

    Fake Enterprise VPN Sites used to steal Company Credentials

    A threat actor tracked as Storm-2561 is distributing fake enterprise VPN clients from Ivanti, Cisco, and Fortinet to steal VPN credentials from unsuspecting users. The attackers manipulate search results (SEO poisoning) for common queries like “Pulse VPN download” or “Pulse Secure client” to...
  8. CarderBoss

    New Infinity Stealer Malware grabs macOS Data via ClickFix Lures

    A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler. The attack uses the ClickFix technique, presenting a fake CAPTCHA that mimics Cloudflare’s human verification check to trick users...
  9. CarderBoss

    European Police dismantles €50M Crypto Investment Fraud Ring

    Austrian and Albanian authorities dismantled a criminal ring accused of running a large-scale cryptocurrency investment fraud operation that caused estimated losses of over €50 million ($58.5 million) to victims worldwide. The joint action, which started in June 2023 and was supported by Europol...
  10. CarderBoss

    European Commission confirms Data Breach after Europa.eu Hack

    The European Commission has confirmed a data breach after its Europa.eu web platform was hacked in a cyberattack claimed by the ShinyHunters extortion gang. That this breach affects at least one of the Commission's AWS (Amazon Web Services) accounts. The Commission says the attack didn't disrupt...
  11. CarderBoss

    Device Code Phishing Attacks surge 37x as New Kits spread Online

    Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. In this type of attack, the threat actor sends a device authorization request to a service provider and receives a code, which is sent to the victim...
  12. CarderBoss

    US Ransomware Negotiators get 4 Years in Prison over BlackCat Attacks

    Two former employees of cybersecurity incident response companies Sygnia and DigitalMint were sentenced to four years in prison each for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. 40-year-old Ryan Clifford Goldberg (a former Sygnia incident response manager) and 36-year-old...
  13. CarderBoss

    ADT confirms Data Breach after ShinyHunters Leak Threat

    Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. In a statement shared today, the company said it detected unauthorized access to customer and prospective customer data on April 20, after which it...
  14. CarderBoss

    NVIDIA confirms GeForce NOW Data Breach affecting Armenian Users

    NVIDIA has confirmed that GeForce NOW user information has been exposed in a data breach. The gaming and hardware giant has clarified that the impact is limited to Armenia, and was caused by a compromise of the infrastructure operated by a regional partner. The company added that its own network...
  15. CarderBoss

    Police shut down Reboot of Crimenetwork Marketplace, arrest Admin

    German authorities have shut down a relaunch version of the criminal marketplace 'Crimenetwork' that generated more than 3.6 million euros, and arrested its operator. Crimenetwork was the largest online cybercrime marketplace in Germany, operating since 2012 and with 100,000 registered users...
  16. CarderBoss

    New Pack2TheRoot Flaw gives Hackers Root Linux Access

    A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions. The flaw is identified as CVE-2026-41651 and received a high-severity rating of 8.8 out of 10. It has persisted for...
  17. CarderBoss

    Instructure confirms Hackers used Canvas Flaw to deface Portals

    Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message. The second hack was to draw attention and to pressure Instructure into entering negotiations to pay a ransom following an initial...
  18. CarderBoss

    Russian Hackers turn Kazuar Backdoor into Modular P2P Botnet

    The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. Secret Blizzard, whose activity overlaps that of Turla, Uroburos, and Venomous Bear, has been...
  19. CarderBoss

    Alleged Scattered Spider Hacker extradited to the United States

    A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. 19-year-old Peter Stokes (who used the online handles "Bouquet," "Spencer," and "Jordan") was arrested in Finland on April 10 while...
  20. CarderBoss

    Malicious PyPI Packages give Hackers Control of Telegram Bot Servers

    A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. At least eight packages have been published on the Python Package Index (PyPI) with a hidden...
Top