Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists

Dark Web Data-Leak Roundup (June 2026) (TL-2026-0803), also tracked as Iran Hajj Organization Leak, is a high-severity data breach, first published 2026-06-15. It is attributed to Everest ransomware group (North Korea) with low confidence, affects Iran Hajj and Pilgrimage Organization Pilgrim records / Hajj, maps to 21 MITRE ATT&CK techniques (T1014, T1027, T1048), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0803

Threat ID
TL-2026-0803
Also known as
Iran Hajj Organization Leak, AdressFakta Sweden Leak, Chrysler Salesforce Breach, Crypto Platform Lead Lists
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-06-15
Last reviewed
2026-06-15
Attribution
Everest ransomware group
Attribution confidence
LOW
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
government, religious-pilgrimage, automotive, retail-consumer, cryptocurrency, financial, marketing-data
Target regions
Middle East, Iran, Europe, Sweden, North America
Detection rules
9
Indicators of compromise
16

Malware and tooling in Dark Web Data-Leak Roundup (June 2026)

Malware and tooling: APT43 C++ backdoor (claimed), BabyShark / LATEOP, Everest ransomware (C# dual-encryption), XenoRAT, Crypto checker tool, rclone.exe, winscp.exe

SOCRadar DarkMirror dark-web monitoring surfaced multiple high-volume data-leak and breach claims in June 2026: ~168M records (1984-2024) allegedly from Iran's Hajj and Pilgrimage Organization sold for $80,000, 5,452,000+ unique records from Swedish contact-data service AdressFakta (operated by SUPEReROI AB) offered for $3,800, over 1 TB of Chrysler data including 105+ GB of Salesforce records (2021-2025) claimed by the Everest ransomware group, and aggregated cryptocurrency-platform lead lists. Accompanying APT43/Kimsuky malware and zero-day claims are reported as unverified actor boasts.

How Dark Web Data-Leak Roundup (June 2026) works

This threat record tracks a SOCRadar dark-web monitoring roundup published 2026-06-15 documenting four distinct high-volume data-exposure events plus a set of unverified advanced-persistent-threat tooling claims. It is a DATA_BREACH intelligence aggregation, not a single CVE-bound vulnerability; no CVE or CVSS is stated by the source.

1) IRAN HAJJ AND PILGRIMAGE ORGANIZATION (~168M records, 1984-2024). An unnamed actor advertised a dataset spanning four decades of pilgrim records. Exposed fields reportedly include full names, birth dates and places, national ID numbers, national codes, passport details, contact information, travel/pilgrimage records, insurance data, banking and payment information, and security-deposit documents. The seller additionally claimed possession of Hajj-application source code and asserted the records include government officials, NAJA (police) forces, Basij paramilitary forces, and clerics. Asking price: $80,000 USD payable in Bitcoin. Primary SOC risk: large-scale identity theft, targeted phishing/spear-phishing of named officials, financial fraud, and foreign-intelligence collection against a sensitive population.

2) ADRESSFAKTA / SUPEReROI AB, SWEDEN (5,452,000+ unique users). A contact/marketing dataset from the Swedish service AdressFakta (operator SUPEReROI AB) was offered for a $3,800 base-plus-access price. Exposed fields include names, gender, mobile and landline numbers, street addresses, ZIP codes, towns, birthdates, and housing-type information. Primary SOC risk: smishing, vishing, identity profiling, and social-engineering of Swedish consumers.

3) CHRYSLER / SALESFORCE (1+ TB; 105+ GB Salesforce records, 2021-2025) - EVEREST RANSOMWARE. The Everest extortion group claimed exfiltration of more than 1 TB of Chrysler (Stellantis) data, including over 105 GB of Salesforce CRM records covering 2021-2025. Exposed data reportedly includes customer, dealer, and agent records; interaction/call logs; names, phone numbers, emails, and addresses; vehicle details; recall notes; and call outcomes. Everest (active since December 2020) has evolved into a hybrid ransomware/initial-access-broker operation; documented TTPs include initial access via exposed RDP, purchased credentials, and an insider-recruitment program (running since October 2023), lateral movement over RDP with valid accounts, and data exfiltration using rclone.exe, winscp.exe, and custom PowerShell scripts to bulletproof C2 infrastructure. Primary SOC risk: dealer-impersonation phishing, recall scams, and double-extortion.

4) CRYPTOCURRENCY-PLATFORM LEAD LISTS (millions aggregated). Combined lead lists referencing users of Binance.US, Coinbase, Crypto.com (1.8M lines), Gemini (930k+ lines), Kraken, Robinhood, Ledger, and Paxful were advertised. Exposed fields are names, emails, and phone numbers, reportedly aggregated using a 'crypto checker' tool. Primary SOC risk: targeted phishing, SIM-swapping, and credential stuffing against crypto holders.

5) UNVERIFIED APT43 / KIMSUKY CLAIMS. A separate dark-web post attributed to APT43 (Kimsuky, North-Korea-linked) advertised a C++ backdoor with encryption/anti-forensic capabilities, Android kernel attack tools, a server-takeover rootkit, and three alleged zero-days including a Linux root privilege-escalation. SOCRadar explicitly flags these as unverified and notes such APT claims are frequently exaggerated. APT43/Kimsuky is a documented espionage actor (MITRE G0094) whose real, sourced tooling includes the BabyShark/LATEOP VBScript backdoor and off-the-shelf RATs such as XenoRAT, QuasarRAT, and Gh0st RAT; the specific tools advertised here are not independently confirmed.

Defensive priority: breach response and credential-exposure monitoring for affected populations, anti-phishing and anti-fraud controls, and Everest-ransomware hardening (RDP exposure reduction, exfil-tool detection).

MITRE ATT&CK techniques used in TL-2026-0803

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1070 Indicator Removal

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Command and Control

T1573 Encrypted Channel

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities; T1650 Acquire Access

Affected products and versions in Dark Web Data-Leak Roundup (June 2026)

  • Iran Hajj and Pilgrimage Organization — Pilgrim records / Hajj applications
    Vulnerable versions: records 1984-2024
  • SUPEReROI AB — AdressFakta contact-data service
    Vulnerable versions: 5,452,000+ user records
  • Chrysler (Stellantis) — Salesforce CRM dataset
    Vulnerable versions: records 2021-2025
  • Multiple — Cryptocurrency platform user lead lists (Binance.US, Coinbase, Crypto.com, Gemini, Kraken, Robinhood, Ledger, Paxful)
    Vulnerable versions: aggregated lead lists

Remediation for Dark Web Data-Leak Roundup (June 2026)

Immediate actions

  • Initiate breach-response and exposed-credential monitoring for any users tied to Iran Hajj Organization, AdressFakta/SUPEReROI, Chrysler/Stellantis, or the named crypto platforms
  • Force password resets and enforce phishing-resistant MFA for potentially exposed accounts; deprioritize SMS OTP given SIM-swap risk
  • Reduce external RDP exposure and block known Everest exfil tooling (rclone.exe, winscp.exe) outbound where not business-required
  • Brief SOC and fraud teams on dealer-impersonation, Hajj/official-targeted spear-phishing, and crypto-holder smishing/vishing lures

Workarounds

  • Disable or VPN-gate internet-exposed RDP
  • Restrict and log bulk CRM record exports
  • Apply SIM-swap protections (carrier port-out locks) for high-value crypto and executive accounts

Longer-term hardening

  • Deploy EDR with behavioral detection for mass data staging and exfiltration over RDP, WebDAV, and cloud-storage CLIs
  • Implement Salesforce/CRM third-party access governance, DLP, and anomalous-export alerting
  • Stand up dark-web/leak monitoring to detect re-sale of these datasets and derivative phishing infrastructure
  • Conduct supply-chain/trusted-relationship review for SaaS CRM connectors

Weaknesses (CWE) in Dark Web Data-Leak Roundup (June 2026)

CWE-200, CWE-359, CWE-522

Timeline of Dark Web Data-Leak Roundup (June 2026)

  • Earliest records in the claimed Iran Hajj and Pilgrimage Organization dataset (span 1984-2024).
  • CISA, FBI and US Cyber Command publish advisory AA20-301A profiling Kimsuky (APT43) espionage TTPs (context for the unverified APT43 dark-web claims).
  • Everest ransomware group first observed; later evolves into a hybrid ransomware / initial-access-broker operation.
  • Start of the 2021-2025 period covered by the Chrysler/Salesforce CRM data later claimed by Everest.
  • Everest begins an insider-recruitment program to obtain corporate network access (documented TTP).
  • Latest records in the claimed 168M-record Iran Hajj dataset (span ends 2024).
  • End of the 2021-2025 period of Chrysler/Salesforce records in Everest's exfiltration claim.
  • SOCRadar DarkMirror dark-web monitoring publishes the roundup detailing the Iran Hajj, AdressFakta/SUPEReROI, Chrysler/Salesforce, crypto-leads, and unverified APT43 claims.

Sources cited for Dark Web Data-Leak Roundup (June 2026)

Threats related to Dark Web Data-Leak Roundup (June 2026)

Detection coverage for TL-2026-0803

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0803 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats