Threat Watch · Sep 11, 2026
Five unrelated groups each posted a healthcare victim inside 36 hours: Rhysida (a Philippine hospital, 2.44 TB claimed), Chaos (Mankato Clinic in Minnesota), LockBit5 (the AmorSaúde clinic chain in Brazil), DragonForce (Medical Department Store) and Wallstreet (an occupational medicine practice in Ohio). None of them claims shared tooling or access; what overlaps is the sector, not the operator.
Groups and claims
Rhysida — 2 new claims, one of them a hospital with 2.44 TB claimed
General Santos Doctors Hospital in the Philippines is listed with 3,502,636 files totalling roughly 2.44 TB, and the posting states it includes name-tagged scans across department shares — surgical pathology, hemodialysis charts, admission records. The second, Professional Retail Services, is listed as the owner's and CFO's personal documents: employee evaluations, salary rates, client credit reports, bankruptcy records, tax documents.
Sources: ransomware.live · ransomware.live
Panzer — 2 new claims, one of them Spain's national weather agency
Agencia Estatal de Meteorología (AEMET) is a governmental agency of Spain providing weather observation, forecasting and climate analytics. The other is Aqualogus, an engineering consultancy working on hydraulic projects. Both claims are recorded independently by the two trackers.
Sources: ransomware.live · ransomware.live
Akira — 3 new claims, all North American physical trades
AK Stamping (precision metal stamping), Eagle Construction (Virginia homebuilding) and George Cameron Nash (high-end furniture and lighting showrooms in Dallas and Houston). All three appear on both trackers.
Sources: RansomLook · ransomware.live
Wallstreet — 3 new claims with nothing in common between the sectors
New Covenant Believers' Church, On Demand Occupational Medicine in Austintown, Ohio (occupational health and drug testing), and Goldston Oil Corporation, a Houston oil and gas explorer operating in Texas and Louisiana. All three were posted in one batch.
Sources: RansomLook · ransomware.live
Vexy — one claim, against an Indian cloud and hosting provider
i2k2 Networks, founded in 1999, sells cloud computing, web hosting, managed IT, data centre, backup and disaster recovery services. When a hosting provider is listed, the downstream customer exposure depends entirely on what the claim actually covers, and the claim itself does not say.
Sources: RansomLook · ransomware.live
The remaining groups
Another fifteen groups posted 24 claims between them in the same window. Audit Team's three continue to carry only masked entity names and an "audit ID"; Global Secret Group listed an Indian co-operative bank and a Florida machinery firm with stated data volumes; one Embargo posting names five domains at once. The full table is on Threat Actors.
Sources: RansomLook · ransomware.live
Campaigns and activity
The PaperCut operator — hundreds of AI agents building and launching the exploitation, 395 organizations compromised
Blackpoint Cyber and GreyNoise published independently, assessing the actor as Russian-speaking and describing a global exploitation campaign built against the two recently disclosed PaperCut NG/MF flaws (CVE-2026-81578, CVE-2026-82078) across more than 440 exposed instances. Both trace the activity to one address, 45.142.193[.]132, which already carried prior associations. The detail worth holding onto is where the automation sits: the AI was applied to developing and launching the exploit, not to lateral movement or negotiation.
Sources: Bleeping Computer · The Hacker News
Cisco Secure FMC — three independent clusters working the same pair of flaws
Talos says two recently patched Secure Firewall Management Center vulnerabilities have been exploited by three separate activity clusters, attributed across both ransomware operations and state-sponsored actors (CVE-2026-20079, CVSS 10). That a single authentication bypass on a perimeter management plane draws both categories at once is the point of this entry. CISA's deadline for federal agencies is September 12.
Sources: Bleeping Computer · The Hacker News
SloppyRAT — a new family delivered by ClickFix that resolves its C2 on the Polygon blockchain
Zscaler ThreatLabz identified the family in June 2026 and assesses it is used by a ransomware-related actor, delivered through a multi-stage ClickFix infection chain. It carries a large set of built-in PowerShell-like commands, encrypted code blocks, several anti-analysis techniques, and uses EtherHiding to resolve command-and-control through the Polygon JSON-RPC protocol. ThreatLabz also notes the codebase contains numerous software flaws, which it reads as a sign the tool is still under development.
Sources: Zscaler ThreatLabz
AI-assisted executive impersonation — ACH payment fraud aimed at finance teams
Microsoft examined a business email compromise campaign that paired AI-generated executive impersonation with fake invoices, targeting the ACH payment process in finance departments.
Sources: Microsoft Threat Intelligence
Gigabud — hiding its tampered banking app inside an Android work profile
In a report published September 9, Group-IB says the banking trojan now installs a second app that creates a work profile on the infected phone and drops a tampered banking app inside it. A work profile is the separated space Android normally reserves for employer apps, and what sits inside it is kept apart from everything in the personal space — which is exactly the position that evades the banking app's own malware checks.
Sources: The Hacker News
Mantax Otax — ransomware, spyware and harassment in one Android family
A new Android strain that encrypts files, steals sensitive data, and spams and harasses the victim.
Sources: Bleeping Computer
Conti — a member sentenced to four years
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
Sources: Bleeping Computer
Infrastructure and indicators
369 new C2 and malware-distribution addresses in 24 hours — the top two labels are 78% of it
malware_download accounts for 193 and VShell for 95, together 288. At 369 this is the highest single day across the last five issues (September 10: 340; September 9: 307; September 8: 350; September 7: 285), and the concentration in the top two labels is back to 78%. Everything else is in single or low double digits: AsyncRAT 12, PureRAT 11, AdaptixC2 9, Remcos 9, XWorm 8, Cobalt Strike 7.
Sources: C2 Infrastructure
Hosting: the largest block and the densest block are not the same block
By host count, CHINA169 (AS4837, China Unicom) leads with 1,062, but only 227 of those have a hosting record — 21%. Google Cloud (AS396982) holds 372 with 311 recorded. AROSSCLOUD (AS400619, Seychelles) carries only 242 hosts but 233 of them have records, 96%, and its labels cluster on VShell, possible Cobalt Strike and PureRAT — consistent with the previous issue's reading that it remains the standout by density of evidence rather than by size.
Sources: C2 Infrastructure