The Underground Economist: Volume 6, Issue 18
by ZeroFox Intelligence
Dark Web Hacking Research Article Competition
On August 22, 2026, vetted threat actor “caustic” posted on the dark web forum Exploit announcing a hacking-focused article competition offering a USD 10,000 prize in Bitcoin (BTC). The contest seeks original, research-oriented submissions of at least 7,000 characters. Acceptable subject matter includes phishing, malware development, web exploitation, artificial intelligence (AI)-driven cyberattacks, botnet operations, operational security (OPSEC), and illicit monetization strategies. Submissions are due by September 6, 2026, and will undergo community voting followed by a final assessment from forum administrators.
- Caustic explicitly bans plagiarism, the use of AI to generate content, redundant entries, and any attempt to manipulate voting outcomes.
- Furthermore, participants must have accounts in good standing.
ZeroFox assesses that analogous hacking competitions that have emerged on dark web forums such as XSS, ReHub, and T1erOne indicate an established underground trend aimed at incentivizing and uncovering sophisticated technical intelligence. This initiative likely encourages forum participants to develop and share innovative cybercrime research, which will very likely facilitate the spread of advanced offensive methodologies throughout the deep and dark web (DDW) ecosystem.
Ransomware Group Recruiting Affiliates to Target Latin America
On August 19, 2026, untested threat actor "Straightonumberone" announced that they were recruiting affiliates for their new ransomware-as-a-service (RaaS) operation, Moondancer, on the predominantly English-language dark web forum DarkForums. According to Straightonumberone, the group is targeting Latin American critical infrastructure entities, excluding healthcare services.
Straightonumberone joined DarkForums in December 2025 and has made 54 posts so far; however, ZeroFox did not observe any activity indicative of the actor’s credibility within the forum. As of writing, the post has received 35 responses, most of which are generic comments such as “Ty” and “wow,” while some users expressed interest in joining the operation.
Straightonumberone is allegedly recruiting affiliates who can provide:
- Initial access of a varied kind, likely for multiple targets
- Pentesting knowledge in certain hybrid operating system environments and major cloud platforms for reconnaissance
- Expertise in C, Assembly, or Rust; cryptography; and reverse engineering
Straightonumberone claims that affiliation is free and that they offer affiliates ransomware tools designed to encrypt and decrypt files in return, along with capabilities allegedly intended to evade or disable security software used to detect and block cyberattacks. The actor also claims they will provide real-time operational guidance during reconnaissance, lateral movement, and execution, and that affiliates will receive a percentage of recovered ransom payments.
- This affiliate-based model, combined with the recruitment of initial access brokers and technically skilled operators, likely suggests an effort to build a more capable and scalable operation rather than conduct attacks independently.
Mexico is likely to remain a key area of interest given Straightonumberone’s reported history of targeting Mexican organizations, while the group’s claimed focus on critical infrastructure indicates potential expansion across other Latin American countries and sectors. The immediate threat level remains uncertain, as Moondancer's claims about its capabilities remain unverified, and there is no clear evidence yet of successful attacks under the new RaaS brand. However, ZeroFox assesses that the recruitment activity warrants continued monitoring for new affiliates, initial access sales, and reported victims, particularly among Latin American critical infrastructure organizations.
Initial Access to Research Company for Sale on ReHub
On August 15, 2026, untested threat actor “corestrike” announced unauthorized access to a U.S.-based scientific research company for sale on the dark web forum ReHub. The actor described the target company as operating in the industrial, manufacturing, and biological research sectors and allegedly generating more than USD 3 billion in annual revenue. Further, the actor partially disclosed the company's name (“b**ker[.]com”).
- Based on the available information, ZeroFox assesses that the target is likely Bruker Corporation, headquartered in Billerica, Massachusetts.
- Bruker provides scientific instruments and analytical solutions for life science, clinical, and materials research, with an annual revenue reportedly in the range of USD 3.4–3.5 billion.
Corestrike stated that the buyer would receive Remote Desktop Protocol (RDP) access to the company's network environment with administrative privileges. The actor indicated that offers below USD 20,000 would not be accepted.
- This very likely represents an unusual initial access offering, as the seller disclosed sufficient information about the target for the company to be readily identifiable.
- There is currently no information indicating whether the actor has successfully sold the access.
Although the target will almost certainly be able to identify and investigate the advertised access, this does not necessarily eliminate the underlying risk. If the access is legitimate and remains active, threat actors would very likely use it as an initial foothold for network intrusion, data exfiltration, or ransomware deployment. Awareness of the advertised access also does not guarantee that the affected access path or vulnerable network segment will be identified and remediated.
New Ransomware Section for VIP Members on ReHub
On July 28, 2026, actor “Nowheretogo”, who is a member of the ReHub forum’s moderator team, announced that the forum had created a new section entirely dedicated to RaaS and Partnership Programs (PP) accessible only to VIP members.
- To gain access to this section, Nowheretogo stated that applicants must provide their blog name, their profiles on other forums, and vouches from established forum members.
ZeroFox assesses that the purpose of this action is to limit the presence of researchers and law enforcement, as well as to protect vetted RaaS collectives and other members from unverified scammers. There is a roughly even chance the ReHub community already has enough trusted actors capable of conducting illicit RaaS activity to support this closed section. Such a move from public to private activity represents a serious shift in the conventional DDW RaaS environment.
Recommendations
- Develop a comprehensive incident response strategy.
- Deploy a holistic patch management process, and ensure all IT assets are patched with the latest software updates as quickly as possible.
- Adopt a Zero-Trust cybersecurity architecture based upon a principle of least privilege.
- Implement network segmentation to separate resources by sensitivity and/or function.
- Ensure critical, proprietary, or sensitive data is always backed up to secure, off-site, or cloud servers at least once per year—and ideally more frequently.
- Implement secure password policies, phishing-resistant multi-factor authentication (MFA), and unique credentials.
- Configure email servers to block emails with malicious indicators, and deploy authentication protocols to prevent spoofed emails.
- Proactively monitor for compromised accounts and credentials being brokered in DDW forums.
- Leverage cyber threat intelligence to inform the detection of relevant cyber threats and associated tactics, techniques, and procedures (TTPs).
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 7:00 AM (EDT) on August 27, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
ZeroFox Intelligence Probability Scale
All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.
ZeroFox Intelligence Threat Actor Reputation Scale