Threat Watch · Sep 12, 2026
Qilin appears twice today from opposite directions: Cisco Talos names it as one of three clusters working the Secure FMC authentication bypass, and its own leak site posted a healthcare provider overnight. One name, one end of it the initial-access detail and the other the victim list.
Groups and claims
nightspire — 4 new claims, none of them in North America or Western Europe
Four posts in one batch: DiamondLease, a Bogotá road concession (Perimetral Oriental de Bogotá S.A.S.), an Amazon-region pipe manufacturer (Tuboaços da Amazônia Ltda.) and a Turkish law office (Ozel & Ozel Laws Office). Both trackers record the same four. Where the posts describe the data at all, it is customer designs and internal departmental documents rather than credentials.
Sources: RansomLook · ransomware.live
direwolf — Port of Tanjung Pelepas
The group's only claim of the period is a container port, filed under marine shipping and transportation. Its recent sets have run to healthcare and business services; port logistics is a departure.
Sources: RansomLook · ransomware.live
securotrop — Shelco Filters, 191 GB, deadline September 20
Both trackers carry the claim. ransomware.live records 191 GB and a status of AWAITING; the post itself sets September 20 as the date the data is published if the company does not make contact.
Sources: RansomLook · ransomware.live
qilin — Imperial Healthcare Solutions
The same name Cisco Talos put on one of the three clusters exploiting the Secure FMC authentication bypass. The leak-site claim is a healthcare services provider, with no data volume stated.
Sources: ransomware.live
safepay — Compunnel
A firm offering talent acquisition, IT consulting, digital engineering, artificial intelligence, cybersecurity and workforce management — a claimed victim whose own service list includes cybersecurity.
Sources: ransomware.live
fulcrumsec — Dustin Group
By the tracker's own description, a Nordic technology reseller and IT solutions provider headquartered in Stockholm, operating across the Nordics and Benelux.
Sources: ransomware.live
The remaining groups
Panzer posted Konica Minolta Bulgaria, dragonforce a US medical equipment retailer, pear an energy-sector installation and maintenance provider, global secret group an Indian co-operative bank, beast the communications platform M800 and CINNOX, play two industrial suppliers, and audit team two entries with masked entity names.
Sources: ransomware.live · RansomLook
Campaigns and activity
The Generative Threat Groups — Anthropic's own record of Claude being abused
The account covers December 2025 to August 2026 and spans state-sponsored actors, financially motivated criminals and commercial vendors, with uses running to cyber attacks, weapons design, propaganda and mass surveillance. One operation extracted secrets from 1.8 million Android applications. A separate thread is a Russian state-sponsored cluster Anthropic tracks as GTG-20006, which built an AI-assisted workflow specifically to rebuild malware ahead of the detection curve; Anthropic says the cluster aligns with broader reporting on a known Russian espionage group. Attribution here is as the source states it.
Sources: The Hacker News · The Hacker News · Bleeping Computer
UNC3569 — a Sogou Input Method flaw to the GRAYRABBIT backdoor
Gen Digital published the research on Thursday. The China-linked group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows and owned by Tencent. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do.
Sources: The Hacker News
[Added detail] ShinyHunters and Helix — passkey and single sign-on themed social engineering into Microsoft 365
Microsoft attributes the activity to actors linked to ShinyHunters, Helix and other extortion gangs, aimed at compromising corporate Microsoft accounts and stealing data from Microsoft 365 services.
Sources: Bleeping Computer
The Artifactory operator — a Rust backdoor in the registry build servers pull from
Wiz saw the activity between August 15 and September 8: CVE-2026-42016 and CVE-2026-42018 chained for administrator control of self-hosted Artifactory, then a Rust backdoor. Both patches predated the window, so what was reachable was build-pipeline infrastructure that had not kept up — not a zero-day.
Sources: The Hacker News · Bleeping Computer
Weaponized Claude Artifacts and shared conversations — Huntress
Threat actors are hosting malicious content on trusted AI platforms, poisoning search results, buying sponsored placements and running ClickFix-style lures. The campaigns Huntress examines target AI users specifically, with weaponized Claude Artifacts and shared AI conversations as the carriers.
Sources: Bleeping Computer
One X direct message, two chains — AMOS on Mac, NetSupport Manager on Windows
A Huntress SOC breakdown of a single case: one X DM leads to a Google Doc sidebar that then splits by operating system, delivering the AMOS stealer on macOS and NetSupport Manager on Windows.
Sources: Huntress
The fraud supply chain is fragmenting — Rapid7
Instead of a handful of known marketplaces, specialized supply storefronts are proliferating across social media platforms, dark web channels and smaller niche markets, in data formats running from documents and imagery to video and unformatted text. MITRE has introduced a Fraud framework. The practical consequence for defenders is that monitoring channels have to be re-chosen rather than maintained.
Sources: Rapid7
Metasploit adds sixteen modules, five of them for KEV entries — Rapid7
Of the ten exploit modules, Cisco, PaperCut, SonicWall, JetBrains and Langflow each get one. Once a KEV entry has a public exploit module, the interval between catalogue entry and commodity exploitation gets shorter.
Sources: Rapid7
Infrastructure and indicators
342 new C2 and malware-distribution addresses in 24 hours — the top two labels are 75% of it
Of 342 distinct new IP addresses, 204 are malware_download and 53 are VShell. The share held by those two across the last six issues runs 80%, 87%, 78%, 69%, 78%, 75%; the composition beneath them has barely moved — Aisuru and Cobalt Strike tie at 13, then Unknown malware at 11, PureRAT at 9, and Havoc and DCRat at 5 each.
Sources: C2 Infrastructure
158 addresses inside a scanning vendor's own network, filed as malware
AS398324 (Censys, Inc.) now sits fourth in our hosting table at 158 hosts, above CHINANET-BACKBONE. All 158 came from ThreatFox, all labelled "Unknown malware", all submitted inside the ninety minutes between 22:48 on September 4 and 00:19 on September 5, and only five of them have any Shodan record at all. Censys runs internet-wide scanning, and from a single host's logs a scanning probe and a C2 callback look much the same. Treat that block as label noise until something else corroborates it.
Sources: C2 Infrastructure