Skip to content Dark Web Informer - Cyber Threat Intelligence

Alleged Sale of Database and Shell Access – Government of Nepal

💡 Subscribe to DarkWebInformer.com for Unmatched Cyber Threat Intelligence 💡

Why Subscribe? Let me do the work and save you time.

Stay ahead of cyber threats and safeguard your digital assets while enhancing your cybersecurity awareness with just some of these exclusive subscriber-only features:

  • 📜
    Exclusive Threat Feeds: Access the latest ransomware victim disclosures, breaches, leaks, and other critical updates. You will receive approximately 100-200 alerts daily.
  • 📡
    Detailed Threat Posts: Stay updated on breaches, leaks, ransomware, DDoS attacks, and more.
  • 📤
    On-Demand Data Export: Export all 14,000+ alerts to JSON, CSV, or XML at any time for deeper analysis.
  • 🖼️
    Instant Insight with Unredacted Screenshots: Gain immediate visibility into leaked data with high-resolution, watermark-free images. Seeing unredacted details helps you quickly assess whether your sensitive information has been compromised—without delays.
  • 🔗
    Direct Claim URLs: Instantly access claims with direct links for fast verification.
Subscribe Now Pay with Crypto

Disclaimer
This report includes actual screenshots and/or text containing unredacted cybersecurity intelligence gathered from publicly available sources. The information presented within this report is intended solely for cybersecurity awareness and threat intelligence purposes. Dark Web Informer explicitly condemns unauthorized access, distribution, or misuse of the compromised data. Users must treat exposed data responsibly and ethically.


📌 Overview

A threat actor operating under the alias Ghudra, affiliated with the APT28 group (Fancy Bears), has listed both full database access and web shell access to the Government of Nepal – Office of the Prime Minister and Council of Ministers.

According to the post, the breach took place in March 2025, and the actor is offering:

  • The entire database of government user data
  • Remote shell access to the compromised server
  • A file manager preview showing internal server structure

🔑 Key Details

AttributeInformation
📅 Date2025-03-26 08:09:21
🕵️‍♂️ Threat ActorGhudra (Fancy Bears – APT28)
🌎 Victim CountryNepal
🏭 Victim IndustryGovernment Administration
🏢 Victim OrganizationGovernment of Nepal – Office of the Prime Minister
🌐 Victim Sitenepal.gov.np
📜 CategoryData Breach
🌍 NetworkOpen Web

This post is for subscribers on the Plus and Pro tiers

Subscribe

Already have an account? Sign In

Latest