Threat Watch · Sep 10, 2026
Ninety leak-site claims in 36 hours, of which storm posted 40 in a two-minute burst, against 50 from the other seventeen groups combined. The black nevas batch is worth reading for how it is written: a Canadian MSP is listed as a victim itself, and four other claims state in the title that the victim is "serviced by an IT company Computer Country and Networks."
Groups and claims
storm — 40 new claims, posted in a single two-minute window
The timestamps cluster at 10:38–10:39 UTC on September 9, so this is one dump rather than a day's accumulation. Targets span the United States, Canada, Australia and Germany, with no sectoral pattern: aerospace and defense includes Technology Dynamics, Star Aviation and Valor Defense Solutions (a woman-owned small business defense contractor); healthcare includes Pinnacle Hospital, Our Hospice of South Central Indiana, WindRose Health Network and SITES Medical. Also on the list are the FDIC-insured Cecilian Bank, the city government of Mitchell, South Dakota, and the law firms Hinman Straub and Tapper Cuddy. Dozens of unrelated organizations posted at once usually means the victims were not individually selected.
Sources: RansomLook
black nevas — 14 claims, listing an MSP alongside its clients
Several titles say outright that the victim is "serviced by an IT company Computer Country and Networks" — Westbrook Greenhouse Systems, Enteroptyx, Portable Intelligence, The Rutherford Group — and that IT company, based in Stratford, Ontario, appears in the same batch as a victim in its own right. A separate Italian victim, ASCOM S.p.A., is annotated as serviced by Emilcom S.r.l. Publishing a provider and its downstream customers together amounts to telling the reader where the entry point was. Other targets include Arkın Group in Northern Cyprus, the Saudi jeweler L'azurde, OTE Group in Oman and Speed Group in France.
Sources: RansomLook
the gentlemen — Air Canada and PharmaEssentia
The Air Canada claim states "We have taken 51409 critical files!" The other is the Taiwanese biopharmaceutical company PharmaEssentia. Both fit the direction of this group's recent listings: large, geographically dispersed, with no sector restriction.
Sources: RansomLook
clop — Harley-Davidson and Henry Pratt
Both claims give only a domain, with no data volume or deadline attached. Clop's historical pattern is to release victims in batches built on mass exploitation of one file-transfer product, so these two are better read as an early indicator of whether another such round is underway than as two isolated incidents.
Sources: RansomLook
The remaining groups
safepay posted 10, spread across Spain, Portugal, Italy, Austria, Canada, the Philippines and the United States, including the municipal portal of Reichenau, Austria and the Seattle nonprofit Recovery Café. emperador posted 3, among them the Bosnia and Herzegovina Mine Action Center (1.7 GB, publication scheduled for September 19). dark project listed Specchem LLC, claiming roughly 500 GB across about 700,000 files. audit team's 5 claims again redact every entity name. qilin, play and direwolf posted 2 each; akira, vexy, inc ransom, chaos, anubis, embargo and global secret group one each. Of these, anubis on Gellibrand Support Services and play on Red Star Oil and GT Distributors were recorded independently by both trackers — the only cross-check available in this section.
Sources: RansomLook · ransomware.live
Campaigns and activity
BlueMoon — four espionage groups picked up the same Chrome and Windows exploit chain within a week
The previously undocumented exploit kit chains multiple vulnerabilities in Microsoft Windows and Google Chrome. Its first in-the-wild use is attributed to the China-aligned state-sponsored group tracked as APT31 (also Bronze Vinewood, Judgement Panda, JungleBamboo), and within a week it appeared in the hands of multiple espionage-motivated activity clusters. One zero-day toolkit moving that fast between separate clusters points to a shared supplier rather than independent development in each — which, for defenders, means detection written per group will miss the later users.
Sources: The Hacker News
Passkey-themed social engineering — from one identity deception to SharePoint, OneDrive and mail
Microsoft Threat Intelligence has observed attackers running social engineering built around passkeys, then establishing persistence at the MFA layer, using Microsoft Graph for reconnaissance, and reaching SharePoint, OneDrive and email data. What is being exploited is not passkey cryptography but the enrollment and recovery flow around it — users are simultaneously unfamiliar with "set up a passkey" and actively encouraged to do it, which is exactly the condition a social engineering pretext needs.
Sources: Microsoft Threat Intelligence
AI service tokens in infostealer logs — replayable "stolen keys"
Criminals are pulling AI-account credentials, session tokens and API keys out of the logs produced by stealers such as Lumma Stealer and Vidar, and turning them into working access. The reporting names affected model providers including Google and Anthropic. The point of this one is that token replay goes around multi-factor authentication entirely — MFA protects the act of signing in, and what was stolen is the artifact produced after it. Few organizations yet treat AI services as an identity boundary to be governed, and stealers have been collecting this data all along.
Sources: The Hacker News
Unit 42 — a multi-payload delivery network hiding behind commodity infrastructure
Unit 42 dissected a criminal chain combining YouTube gaming lures with SEO poisoning to deliver multiple payloads into enterprise networks. They characterize this activity as "untracked" precisely because the infrastructure is a generic pay-per-install network rather than any one group's own — which is what makes it invisible to tracking organized around adversary names.
Sources: Unit 42
ShinyHunters — AdaptHealth confirms 4.1 million people affected
AdaptHealth, a home medical equipment and care provider, confirmed that data on 4.1 million people was exposed in the attack discovered in July, and attributed the attack to ShinyHunters. The same group recently claimed it took over 200,000 driver records from the Florida DMV's DAVID platform, with a September 11 deadline attached.
Sources: Bleeping Computer
[Added detail] The Gentlemen — Veradigm confirms a patient data breach
Veradigm has disclosed the exposure of patients' personal data following a cybersecurity incident, and states the incident occurred at one of its third-party vendors. The disclosure does not confirm the 3.5 million patient records the group claimed, and does not name the vendor — the vendor being the entry point is the new information; the scale is still only the attacker's assertion.
Sources: Bleeping Computer
Xinbi Guarantee — DoJ dismantles a guarantee marketplace, freezes $52.8 million in crypto
The U.S. Department of Justice announced coordinated actions: seizing the Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime. Guarantee marketplaces are the settlement layer of this ecosystem — they escrow funds between parties who do not trust each other, and without one, both the laundering upstream and the service procurement downstream have to find a new intermediary.
Sources: The Hacker News
Infrastructure and indicators
340 new C2 and malware-distribution addresses in 24 hours — the top two labels drop to 69%
malware_download accounts for 188 and VShell for 47, together 235. The total is up from yesterday's 307, but the combined share of those two labels fell to 69%, from 78% yesterday and 87% the day before. Today's growth sits further down the tail: Aisuru 12, PureRAT 11, Vidar 10, Remcos 10, AsyncRAT 9, Cobalt Strike 8, AdaptixC2 8, XWorm 5. This is the first time in three issues that top-label concentration has fallen on consecutive days.
Sources: C2 Infrastructure
Hosting: AROSSCLOUD is the densest block by evidence, not by size
By host count, China Unicom's China169 backbone leads with 981 and Google Cloud follows with 371, with Seychelles-registered AROSSCLOUD (AS400619) third at 236. The first two carry mostly malware_download and "Unknown malware" labels, while 227 of AROSSCLOUD's 236 hosts have a Shodan record and are labelled VShell, possible Cobalt Strike C2 and PureRAT — a comparable host count with a completely different evidence density. Fourth on the list is Censys (AS398324, 158 hosts): that is scanning infrastructure appearing in an indicator set, not C2.
Sources: C2 Infrastructure