Infostealer credential exposure meets ransomware targeting across Telegram and the dark web.
Most targeted attacks don’t begin with a sophisticated zero-day. They begin with a username and a password that an employee doesn’t know has already been stolen. In the Indian pharmaceutical sector, that isn’t a hypothetical, it’s the current state of play.
Bolster AI Research Labs recently ran a focused research effort across Telegram channels and dark web platforms, examining threat activity directed at Indian pharmaceutical organizations. Two distinct threat tracks emerged, operating concurrently: a mass credential exposure pipeline fed by infostealer malware campaigns, and active ransomware operations run by two separate groups against major pharmaceutical manufacturers.
The convergence of those two tracks is the central finding of this research, and the reason the threat to this sector deserves immediate attention.
Key findings
- DragonForce RaaS has published 283.8 GB of exfiltrated data from a Mumbai-based Active Pharmaceutical Ingredients manufacturer. The data was actively available for download on the group’s dark web leak blog at the time of research.
- Employee credentials from three major Indian pharmaceutical organizations are confirmed present in the ALIEN TXTBASE infostealer dataset, accessible in plaintext through active Telegram bots running a freemium commercial model.
- ALIEN TXTBASE contains 2.8 billion unique records sourced from infostealer malware, and it is actively redistributed through a Telegram channel with more than 5,500 subscribers and hosted for torrent download on a companion dark web forum.
- INC Ransom claimed an attack on a second major Indian pharmaceutical company in February 2026, within the same window as the first incident. Two independent RaaS operations hitting the same sector in the same month warrants attention.
- A dark web forum listing advertises 500,000 records on Indian pharmacy managers and business owners, a targeted intelligence product that would enable social engineering or spear-phishing against sector leadership.
Track one: the credential pipeline
ALIEN TXTBASE is among the largest infostealer credential compilations ever to surface publicly. It was published to a dedicated Telegram channel at the start of 2025, initially containing 23 billion lines of credential data. After deduplication and the removal of records already known from earlier compilations, 2.8 billion unique records remained.
Those records include email addresses, plaintext passwords, IP addresses, phone numbers, and the site or application URLs each credential was used on. The data was harvested by infostealer families including RedLine, Raccoon, and Vidar, which strip everything stored in a browser’s credential manager within seconds of infection.
How the distribution works
The dataset is actively redistributed through a Telegram channel with 5,505 subscribers, which posted a 500 GB torrent link pointing to a companion dark web forum. The forum hosts that torrent thread publicly. Any threat actor with a torrent client and the forum URL has access to 2.8 billion credential records, with no vetting and no technical barrier.
The commercial access layer sitting on top of the raw data is the more concerning part. Two Telegram bots operate as automated credential lookup services, returning plaintext passwords in response to a domain query in under a second. Both run a freemium model, so a basic query costs nothing at all. When our researchers queried Indian pharmaceutical company domains against these bots, they came back with confirmed credential records.
Mass aggregation, open torrent distribution, and a retail bot layer add up to a fully operational credential marketplace. For any threat actor who wants in, the barrier to exploitation is effectively zero.
What we found
Credential exposure was confirmed for three organizations in the Indian pharmaceutical sector across the ALIEN TXTBASE ecosystem, and one of the three appeared in four separate breach datasets. The exposed records pair employee email addresses with plaintext passwords, which means any password that has not been rotated since collection should be treated as compromised.
We also found that several exposed employee emails appeared in a separate breach that included home addresses. That incident targeted consumers rather than corporate systems, but the overlap creates a secondary spear-phishing and physical targeting risk for the employees caught in both.
Track two: active ransomware operations
While the credential pipeline runs at scale and without discrimination, a second and far more targeted track was operating in parallel. Two separate ransomware groups hit specific Indian pharmaceutical manufacturers inside the same calendar window.
DragonForce and the API manufacturer
DragonForce is a Ransomware-as-a-Service syndicate that emerged in late 2023 and scaled aggressively through 2025 and 2026. Some security firms track it as Water Tambanakua. The group runs a structured affiliate program in which verified affiliates acquire network access and deploy the ransomware in exchange for a revenue share, supported by dark web infrastructure spread across multiple onion addresses covering a news blog, a victim leak portal, and affiliate registration.
The group’s leak blog listed a Mumbai-based Active Pharmaceutical Ingredients manufacturer as a confirmed victim, and at the time of research 283.8 GB of exfiltrated data was marked as published with an active download link. That distinction is worth stating plainly. This is not a ransom threat with a countdown clock. It’s a completed exfiltration, and the data is already in circulation.
One caution for anyone running their own research here: a large Telegram channel operating under the DragonForce name belongs to a Malaysian hacktivist collective, not the ransomware syndicate. We found no operational link between the two, though the hacktivist group has targeted Indian organizations in the past. Conflating them will send an investigation in the wrong direction.
INC Ransom and the concurrent claim
In the same February 2026 timeframe, INC Ransom, also tracked as GOLD IONIC and Tarnished Scorpion, claimed an attack against a second major Indian pharmaceutical company. The claim surfaced on a third-party ransomware tracking service.
This one looks different from the first. No active download link was present, and extensive dark web investigation didn’t surface traded data from this victim. We assess it as a ransom pressure post rather than a confirmed exfiltration, though credible information suggests a significant volume of data was taken. The group’s infrastructure warrants continued observation.
Two independent RaaS operations landing on two Indian pharmaceutical manufacturers within weeks of each other isn’t a coincidence. It reflects sector-level targeting.
Why the convergence matters
Credential exposure and ransomware tend to get filed as separate categories of threat. In practice they aren’t separate at all.
The path from infostealer credential theft to ransomware deployment is one of the best-documented attack chains in enterprise security. An affiliate buys or simply looks up a valid VPN credential, uses it to establish access, escalates privileges, moves laterally, and deploys ransomware. Every step in that sequence can be executed with tooling available in any criminal marketplace, and the whole chain begins with a single working password.
The Indian pharmaceutical sector now sits on both ends of that chain at once. Employee credentials are exposed in bulk and queryable through commercial Telegram bots, while ransomware affiliates are demonstrably targeting manufacturers in the region. Whether these specific incidents are causally connected is almost beside the point, because the preconditions for credential-to-ransomware attacks against this sector are fully in place.
Organizations here should stop treating confirmed credential exposure as a data privacy problem and start treating it as a precursor condition for ransomware intrusion.
What security teams should do now
- Force a password reset across the organization. Prioritize accounts with external-facing access, including VPN, email, and cloud portals. Credentials in the ALIEN TXTBASE dataset may have been collected as far back as 2024, so any password unchanged since then should be considered compromised.
- Enable multi-factor authentication on every external-facing system. MFA neutralizes the immediate credential stuffing risk from stolen passwords. VPN and email access are the highest-value entry points and match common RaaS initial access patterns, so start there.
- Run a targeted threat hunt for DragonForce and INC Ransom activity. Look retrospectively across endpoint and network logs for anomalous lateral movement, unusual scheduled task creation, and large outbound transfers. A threat intelligence provider with current IOC feeds for both groups will sharpen detection considerably.
- Block the known distribution infrastructure at the DNS perimeter. Employees are unlikely to reach these domains deliberately, which is exactly why an outbound connection to one is such a strong indicator of compromise. Alert on it rather than simply dropping it.
- Watch for impersonation infrastructure built on this data. Records on pharmacy managers and executives feed directly into convincing spear-phishing, and lookalike domains are usually the next step. Continuous domain monitoring and automated takedown close that window before customers or partners are deceived.
- Move from point-in-time assessment to continuous monitoring. Research like this is a snapshot, and the landscape for this sector is actively evolving. Automated monitoring of your domains across breach aggregators and dark web sources provides early warning before attackers act on new exposure. If you are evaluating options, our comparison of dark web monitoring services is a useful starting point.
Closing thoughts
The Indian pharmaceutical sector sits at an uncomfortable intersection. It holds high-value intellectual property and regulatory data that ransomware operators know how to monetize, its workforce is subject to the same mass credential harvesting that touches every other sector, and the infrastructure for monetizing both kinds of access is mature, cheap, and running right now.
The question for security teams here is not whether the threat exists. The evidence settles that. What remains open is whether credential hygiene and threat hunting are keeping pace with the speed of exploitation, and a point-in-time assessment like this one can only tell you so much.
Bolster AI Dark Web Monitoring continuously scans criminal forums, marketplaces, paste sites, and Telegram channels for credentials and data tied to your organization, with AI-driven detection and human analysts reviewing the ambiguous and complex findings. Request a demo to see what is already exposed.