Threat Watch · Sep 9, 2026
Google Threat Intelligence Group puts a clock on adversarial agent use: under six hours from compromising a cloud resource to completing a mass credential harvest. The same day, Talos documents a ClickFix variant running command and control out of a published Google Sheets document. Both point the same way — attack infrastructure is moving into legitimate cloud services, and human-in-the-loop latency is being squeezed out.
Groups and claims
Safepay — 10 new victims across seven countries
A third of the day's claims came from one group, mostly small and mid-sized businesses spread across industries: Spanish ceramics manufacturer gayafores.es and Madrid-based gsngestion.es, Portuguese technology services firm hbpro.pt, Italian insurance broker assiprime.it, Philippine cenmar-manila.com, Argentine personal-care manufacturer cannonpuntana.com, Alberta steel company mcnishsteel.com, and a U.S. ophthalmology practice, palmettoeyeinstitute.com. Two non-commercial targets are worth noting: reichenau.at, the official website of the Austrian municipality of Reichenau, and recoverycafe.org, a Seattle non-profit. Both trackers independently recorded the same set of claims.
Sources: ransomware.live · ransomware.live
Akira — 3 new victims
Brent Electric (electrical contracting, in business since 1996), CreateASoft (process simulation software) and Brentwood Country Club in Los Angeles, all in the United States.
Sources: RansomLook · ransomware.live
Audit Team — 3 new claims with masked entity names
This group's entries carry only an AUDIT ID and a discovery date, with victim names shown masked (bu***en, Wi***IT, pa***op), so sector and geography cannot be checked.
Sources: ransomware.live
Play — 2 new victims
Red Star Oil and GT Distributors, both in the United States.
Sources: ransomware.live
Eclipse — 2 new victims, a law firm and a trade publisher
The Zhou Law Group is one of the larger family law firms in California, handling divorce, child custody and spousal support — case files of unusually sensitive content. TTG Asia Media is an Asia-Pacific travel trade publisher established in 1974.
Sources: ransomware.live
Direwolf — 2 new victims, continuing its healthcare and business-services pattern
Sales Boomerang (finance and customer relationship software) and EMS1R (corporate wellness services).
Sources: RansomLook · ransomware.live
LockBit5 — 2 new victims
Dutch mortgage and insurance advisor fdcputman.nl and Argentine contreras.com.ar.
Sources: ransomware.live
Six more groups — one claim each
Anubis claims Gellibrand Support Services, an Australian disability support provider; Qilin claims Alaska Electrical Apprenticeship; Rhysida claims French temporary staffing firm SAD'S Interim and says it holds bank statements with SEPA credit transfers; Chaos claims U.S. performance plastics distributor copeplastics.com; Panzer claims French wealth manager Financière d'Uzès; Blacknevas claims Turkey's Mefa Group. That makes 30 claims from 13 groups today.
Sources: ransomware.live · ransomware.live
Campaigns and activity
GTIG — from prompting to autonomy, a mass credential harvest completed in under six hours
Google Threat Intelligence Group observed in Q2 2026 that attackers compromised a cloud resource, then planned, built and executed an agent-enabled mass credential harvesting campaign, start to finish, in under six hours. GTIG's reading is that human-in-the-loop latency is dramatically reduced, compressing the window defenders traditionally have to respond. The same report tracks UNC6780 using multiple tactics to trick AI coding assistants and large language models. It follows GTIG's May report on adversarial misuse of AI, with the through-line moving from basic prompting to agentic workflows and AI-enabled automation.
Sources: Google Threat Intelligence · The Hacker News
Slim Spider — crypto custody secrets at Brazilian financial institutions
CrowdStrike names this previously undocumented, financially motivated adversary Slim Spider and tracks activity against Brazilian financial institutions since at least March 2026. CrowdStrike assesses that the adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including its instant payment system, and that the objective is crypto custody secrets.
Sources: The Hacker News
ClickFix — command and control moves into a Google Sheets document
Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control, retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. Putting the fetch on Google's own domains is a different hosting choice from the same family's earlier practice of storing payloads in public blockchain smart contracts, and it has a different defensive consequence: domain blocking does not apply here.
Sources: Cisco Talos
ClearFake — a WebDAV infection chain delivering Amatera stealer, ZigCryptoStealer and NetSupport Manager
Talos assesses with moderate confidence that these attacks are not aimed at any particular organization but form a cryptocurrency and credential stealing operation with Amatera as the primary payload, alongside ZigCryptoStealer and the abused commercial remote access tool NetSupport Manager.
Sources: Cisco Talos
A Linux rootkit in F5 BIG-IP APM environments — intercepting PHP file loading to inject a web shell into memory
The rootkit intercepts PHP file loading and injects a fileless web shell directly into memory, so no malicious code is written to disk — which puts it out of reach of on-disk detection and file integrity checks.
Sources: Bleeping Computer
BengalSEO — an SEO poisoning operation running since 2015, delivering MayaBot and tech support scams
The DFIR Report discovered and named the campaign in March 2026. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect, and poisons Bing search results to pave the way for malware deployment and tech support scams.
Sources: The Hacker News
Infrastructure and indicators
307 new C2 and malware-distribution addresses in 24 hours — malware_download and VShell account for 78%
By label: malware_download 164 and VShell 74, together 238; PureRAT is third at 18, followed by 11 unlabelled, AdaptixC2 and Remcos at 6 each, and Cobalt Strike at 5. The total is about 12% below the previous issue's 350; the same two labels lead, but their combined share fell from 87% to 78%. On the hosting side, the three networks carrying the most addresses are China Unicom's China169 backbone (AS4837, 892 hosts), Google Cloud (AS396982, 370) and Seychelles-registered AROSSCLOUD (AS400619, 210). Of AROSSCLOUD's 210, 201 have port and service records, with VShell, suspected Cobalt Strike and PureRAT as the leading families.
Sources: C2 Infrastructure