Threat Watch · Sep 8, 2026
Leak-site claims today total 47, of which 19 came from a single Gentlemen batch posted between 16:12 and 21:56 UTC on September 7 — both trackers independently recorded the same 19 names. The targets span South Africa, Argentina, Brazil, Turkey, Peru, Colombia, Portugal, Denmark, Australia, Georgia, Egypt, Chile, Spain and India, with only LA Metro and the University of San Francisco on the US side.
Groups and claims
The Gentlemen — 19 claims in one batch
By the group's own postings, the targets worth naming include the Los Angeles County Metropolitan Transportation Authority (metro.net, the second-busiest transit system in the US), the University of San Francisco (a private Jesuit institution of about 10,200 students), Hollard, South Africa's largest independent privately-owned insurance group, the century-old Argentine pharmaceutical wholesaler and manufacturer Droguería Saporiti (100 GB claimed), the Latin American CX and AI firm Mutant (4,000+ employees), Turkey's Yapı Merkezi, the Spanish automotive wheel trim maker Zanini, Peru's Comin, and Portugal's Chip7. On the Georgian retailer Superstore, the group claims to hold emails, passwords, passports, driving licenses, dates and places of birth, client bank names, tax IDs and payment cards. This group posted only 2 claims on September 5; today's volume is an outlier for it.
Sources: RansomLook · ransomware.live
Metaencryptor — 4 claims, clustered in aerospace, defence and medical devices
Singapore's defence and engineering group ST Engineering; SIFCO Industries, which supplies flight-critical forged components and machined assemblies to aerospace, energy and defence; Hologic, the US medical technology company focused on women's health; and EllisDon, the Canadian construction and infrastructure services firm. All four appear only on ransomware.live; RansomLook has no matching entries.
Sources: ransomware.live
ShinyHunters — State of Florida DMV, deadline September 11
The entry is marked "final warning" and demands contact by September 11, 2026 before files are released, with a download button for purported samples. Both trackers recorded it.
Sources: RansomLook · ransomware.live
Dark Project — 3 claims, each with a stated data volume
San Francisco architecture firm MEI Architects (340 GB and roughly 130,000 files claimed, including Social Security numbers, passports, green cards, invoices and HR documents), custom metal stamping firm Master Manufacturing (36 GB), and glass wall systems maker Alurwalls (17 GB).
Sources: ransomware.live
Interlock — NFM Lending, 2.5 TB claimed
A national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages over the past 12 months. Both trackers recorded it.
Sources: ransomware.live
Ten other groups — 19 claims between them
Direwolf 4 (Lightcast, Precision Vehicle Logistics, Semper Laser, TrainMe); Everest 3 (the German technology group Körber, the Polish bioinformatics company GeneSilico, and GGS); Rhysida 2 (Rug & Home, with 50,193 customer records claimed, and France's SAD'S Interim); Aurora 2 (Benshaw, with corporate purchasing-card records claimed to carry full PANs, Social Security numbers and dates of birth, and Jinny Beauty Supply); Qilin 2; Vexy 2; LockBit5 1; AuditTeam 1. Two more on the healthcare side: Insomnia posted NorthShore Health Centers in Indiana, and Inc Ransom posted Community Wellness Partners in Clinton, New York. All of the above are one-sided claims, not confirmed intrusions.
Sources: RansomLook · ransomware.live
Campaigns and activity
PEEP — turning Chrome and Edge into post-compromise backdoors
A Chromium-based post-exploitation toolkit that masquerades as a bookmarks extension. Its installer injects the extension directly into Chrome and Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences. The precondition is stated in the report: prior administrative or code execution access is required — this is persistence and host command execution after the break-in, not the way in.
Sources: The Hacker News
BigBear 2.0 — a phishing-as-a-service framework that bypassed MFA at 258 organizations
The framework was used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.
Sources: Bleeping Computer
[Added detail] The IT help desk impersonation cluster — targeting directors and vice presidents
Threat hunters give more structure to this cluster: it targets Microsoft 365 and other SaaS offerings, entry comes through IT help desk vishing, followed by adversary-in-the-middle token theft, with sign-ins routed through residential proxies. The people singled out are mainly directors, vice presidents and other executive staff rather than ordinary employees.
Sources: The Hacker News
Rogue ScreenConnect clients — a four-stage VBScript chain pushed to newly connected hosts
Huntress documented three unrelated incidents with different initial access methods: a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake installer. What they share is abuse of ConnectWise ScreenConnect to distribute a malicious VBScript payload to newly connected systems, spreading in a worm-like fashion.
Sources: The Hacker News
JSCeal — a compiled-V8 JavaScript stealer that bypasses Google authentication with stolen session cookies
Check Point Research unpacked the payloads: protected with javascript-obfuscator using RC4-protected strings, control-flow flattening, proxy functions and operation wrappers. Capabilities cover credential harvesting, surveillance and traffic interception.
Sources: The Hacker News
ClickFix — payloads stored in BNB Smart Chain contracts, served from over 5,400 compromised sites
A large criminal operation is using thousands of compromised small-business websites to deliver ClickFix payloads that live in smart contracts on the BNB Smart Chain. On-chain hosting means there is no distribution domain to take down. (September 5)
Sources: Bleeping Computer
ASCII smuggling — crossing over from AI prompt injection to phishing filter evasion
Microsoft Threat Intelligence documented a "high-volume phishing campaign" using invisible Unicode tag characters to split financial lure words such as "funding" so email filters cannot parse them. These characters were popularized for hiding instructions from people while exposing them to models; here the direction is reversed — hidden from the filter, visible to the reader. (September 3 to 6)
Sources: Microsoft · The Hacker News · Bleeping Computer
BraZetsu — turning compromised Windows hosts into criminal marketplace inventory
A Python-based Windows malware framework built for initial access brokers. The researchers' distinction is that it does not follow the standard infostealer model of grabbing credentials and leaving: it packages compromised systems into commercial access listings that can be priced and sold on underground markets. (September 3)
Sources: The Hacker News
Infrastructure and indicators
350 new C2 and malware-distribution addresses in 24 hours — malware_download and VShell account for 87%
By label: malware_download 204, VShell 99, Cobalt Strike 11, PureRAT 9, AdaptixC2 8, AsyncRAT 7, and Remcos, Aisuru and unnamed families 3 each. The two preceding 24-hour windows were 285 and 328, making today the highest of the three. The hosting order is unchanged: China Unicom's CHINA169 backbone (AS4837) rose from 718 to 783 hosts, Google Cloud (AS396982) sits at exactly 370 with no movement, and Seychelles-registered AROSSCLOUD (AS400619) went from 150 to 165, of which 158 have an exposure record, still composed of VShell, PureRAT and possible Cobalt Strike. Fourth place needs a caveat: Censys (AS398324) contributes 158 addresses to this list, all labelled as an unnamed family, and only 5 of them have an exposure record — these are a public scanning provider's probe nodes that an upstream feed collected as C2 candidates. Filter them out before using this list for blocking.
Sources: C2 Infrastructure