Threat Watch · Sep 7, 2026
Today's claims concentrate hard on healthcare: 11 of the 17 victims in kazu's batch are hospitals, imaging centres or telemedicine platforms, all three of Direwolf's are dental, eldercare and veterinary, and chaos posted a regenerative-medicine CDMO. Most of what was hit is the SaaS platform holding a clinic's data rather than the clinic.
All of the below are one-sided claims by the groups, not confirmed intrusions. The two trackers each mirror the groups' own leak sites; where both independently recorded a claim it is noted, which is the only cross-check available here.
Groups and claims
kazu — 17 new claims
Posted as one batch, mostly healthcare and health-tech platforms: Dr Akbar Niazi Teaching Hospital in Islamabad (a 500-bed tertiary teaching hospital), Spanish imaging provider HT Médica, Natclar and Centro Médico Especializado OSI in Peru, Instituto Ferrero de Neurología y Sueño in Argentina, and a run of platforms that hold data on clinics' behalf — Brazilian cloud PACS provider Mobilemed, Indian practice-management platform PappyJoe, Meducar and ConsultorioMovil in Latin America, healthcare staffing platform HealthDaq and veterinary platform PawlyClinic. Three South African government bodies also appear: Statistics South Africa, the Gauteng Provincial Government portal and the Gauteng City Region Academy. The rest are Canadian appointment platform Yocale, education platform MSM Unify and Spirit Cultural Exchange in the US. MSM Unify and Spirit Cultural Exchange are recorded on both trackers.
Sources: RansomLook · ransomware.live
Direwolf — 3 new claims, all healthcare
Dental billing outsourcer eAssist Dental Solutions, home-based eldercare provider myLaurel, and Mission Pet Health. All three are recorded on both trackers.
Sources: RansomLook · ransomware.live
DragonForce — 3 new claims
Rubber products OEM Rubbermill, electrical equipment supplier Homewood Sales (automatic voltage regulators and control gear), and Norwood Law, a firm in Tulsa, Oklahoma. All three currently have ransomware.live as their only source.
Sources: ransomware.live
Dysphor1a — Myanmar's Road Transport Administration Department
Claims a full database dump, stated as 1.08 GB, from the Road Transport Administration Department under Myanmar's transport ministry. The agency handles driving licence issuance and vehicle registration — a national motor-vehicle identity register. Recorded on both trackers.
Sources: RansomLook · ransomware.live
ShinyHunters — Medela, with a September 8 deadline
Posted Swiss medical device manufacturer Medela with a note giving until September 8 to make contact before the data is leaked, alongside a threat of other "digital problems". Recorded on both trackers.
Sources: RansomLook · ransomware.live
Vexy — 3 new claims
Ecuadorian McDonald's franchise operator McDonalds Ecuador, real-estate and construction firm Sancity, and New Delhi software company Mega Velocity. Sancity is recorded on both trackers.
Sources: RansomLook · ransomware.live
Panzer — 2 new claims
Saudi engineering consultancy Khaled Alfagih, which specialises in healthcare design and planning, and German electronics design research network edacentrum. Both are recorded on both trackers.
Sources: RansomLook · ransomware.live
One claim each from the rest
chaos posted regenerative-medicine CDMO Evergen (recorded on both trackers), Shadowbyt3$ posted US property manager Ben Leeds Properties, leaknet posted medical device maker Katecho with HIPAA-themed pressure tags, and blacklocks posted South Korean automotive parts manufacturer Kwangmyung Industry.
Sources: ransomware.live
Campaigns and activity
REVSTEALER — four modules stay behind after the stealer deletes itself
Elastic Security Labs documented four previously unreported programs tied to REVSTEALER, an emerging Windows infostealer: ProManager, WinUpdate, SoftManager and one more. Their job is to remain on the machine after the stealer removes itself, and one of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The design choice worth noting is splitting persistence and monetisation out of the stealer payload — a stealer that deletes itself reads to detection watching only for it as an incident that has ended.
Sources: The Hacker News
Toy Ghouls — command and control moved into HiveMQ and Element
Kaspersky GERT found two versions of the group's new backdoor: one uses the HiveMQ MQTT broker as its command-and-control server, the other the Matrix-based Element messenger. Both are legitimate messaging infrastructure — MQTT is ordinary traffic anywhere industrial IoT is deployed, and Matrix traffic is end-to-end encrypted. Detection built around domains or around attacker-run C2 infrastructure does not hold against either channel.
Sources: Securelist
[Added detail] Ted backdoor — Rapid7 attributes it to DPRK and names a second family, curlRAT
Rapid7 Labs attributes the Linux toolkit compiled into victims' own HAProxy builds to DPRK APT activity, targeting South Korea's automotive and media sectors. HAProxy is not the only host binary involved: trojanized versions of crond, agetty, atd, sshd and polkitd are part of the same toolkit, which supports remote command execution, script injection into web traffic, credential harvesting and long-term surveillance. A second family, curlRAT, appears in the same activity. This is not a HAProxy vulnerability — installing the implant presupposes code execution on the host.
Sources: Rapid7 · The Hacker News
Impersonating IT support — one Teams external collaboration to enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration to impersonate IT support, obtain remote access, and deploy a Node.js-based implant before moving laterally with legitimate built-in tooling. The entry point is a collaboration feature that is on by default, not a vulnerability.
Sources: Microsoft
Attackers targeting Latin American organisations are using AI tooling, and it exposed them
Unit 42 documented ongoing AI tool use by attackers targeting Latin American entities, principally in the data exfiltration stage. The more useful half of the report is the other one: basic operational security errors by these operators let defenders observe and disrupt the activity.
Sources: Unit 42
Infrastructure and indicators
285 new C2 and malware-distribution addresses in 24 hours — malware_download and VShell are 80% of it
By label: malware_download 162, VShell 65, PureRAT 15, Aisuru 9, AdaptixC2 and Remcos 7 each, Cobalt Strike 5. The preceding 24 hours produced 328, so the volume is comparable. On the hosting side China Unicom's 169 backbone still leads (AS4837, 718 hosts), followed by Google Cloud (AS396982, 370). The one worth looking at separately is Seychelles-registered AROSSCLOUD (AS400619, 150 hosts), whose family mix is exactly what led today's new additions — VShell, PureRAT and Cobalt Strike — with exposure records available for 143 of its 150 hosts.
Sources: C2 Infrastructure