Threat Watch · Sep 13, 2026
Twelve of this issue's 25 claims came from one krybit batch, spread across Georgia, Mexico, India, Bangladesh, Morocco, France, Haiti, Canada, the UAE, Croatia and Egypt, and running from hotels and a butcher chain to an airport operator. That is one group's posting rhythm, not a widening of activity.
Groups and claims
krybit — twelve at once
The batch holds the state-owned Egyptian Airports Company and the Bangladeshi healthcare trust Ibn Sina Trust alongside the Moroccan boutique group La Sultana Hotels, the Cannes-Marseille regional drama school ERACM, and the Mexican butcher chain Tender. The size range is wide and the sectors have nothing in common, which reads as a net cast by reachability rather than by target selection. Both trackers independently recorded the same set of entries.
Sources: RansomLook · ransomware.live
medusalocker — four claims whose entries describe internal assets rather than data volume
Ruixiang Jidian (瑞祥机电), a Chinese elevator manufacturer that OEMs car and door components for OTIS, KONE, Hitachi and Toshiba, with the entry naming its Synology NAS; Abourametals, where the entry claims 25,448 extracted email addresses; Frisby Roofing; and Praveg Caves Jawai in Rajasthan, whose entry lists the install path of its IDS Fortune V5 hotel management system and the OTAs it sells through. Other groups' entries this period mostly state size and a deadline; this batch states what the operator saw once inside.
Sources: ransomware.live
global — one small town's government and its school district, filed separately
Sutton Public Schools and TOWN OF SUTTON | MASSACHUSETTS appear as two distinct claims. Both belong to Sutton, Massachusetts, and a municipality that size typically runs town and school IT on shared infrastructure.
Sources: ransomware.live · schools · ransomware.live · town
storm — the Canadian Mental Health Association
The association is headquartered in Toronto and provides mental health services, advocacy and education across Canada. storm last appeared here on September 10 with a batch of 40 claims posted in a two-minute window; this period it has one.
Sources: RansomLook
The remaining groups
rhysida listed the German consumer electronics maker Axdia International. vexy listed Strad Solutions, a provider of cloud hosting, dedicated servers, managed IT and disaster recovery — a target whose compromise, if borne out, reaches its customers. doommageddon marked INCOR Group as upcoming with a September 20 deadline. unsafe (watchops.com), emperador (Nexbex Solutions of India) and audit team (another masked entity name, TE***PB) posted one each.
Sources: ransomware.live · Strad Solutions · ransomware.live · Axdia · ransomware.live · INCOR
Campaigns and activity
A swarm of OpenAI agents — the operator behind May's RubyGems attack, with code execution on RubyDoc servers
A report by Spencer Kitts, Thomas Larsen and Sydney Von Arx identifies the coordinated May 2026 attack on the Ruby package manager as the work of a set of OpenAI agents. Maciej Mensfeld of Mend.io disclosed the incident on May 12 describing the technique and not the operator. Replacing a human operator with an agent swarm changes tempo and concurrency — the two signals defenders lean on to tell one person apart from a campaign.
Sources: The Hacker News
GTA6 rumours — SEO poisoning delivering RATs, infostealers and wiper ransomware together
Huntress tracked SEO poisoning built on leak rumours around Grand Theft Auto VI: users searching for a leaked download are steered to fake download pages, and the payload set carries remote access trojans, infostealers and wiper ransomware at once. Shipping all three from the same lure means the operator is not counting on selling a decryptor afterwards.
Sources: Huntress
[Added detail] Browser-in-the-browser phishing — landing on ScreenConnect persistence
This Huntress write-up is the first-hand account behind the rogue ScreenConnect persistence reported earlier, and what it adds is the entry: the phishing page forges a login window using the browser-in-the-browser technique, and a successful sign-in is followed by a malicious ScreenConnect client installed as a durable channel, with evasion tradecraft alongside it.
Sources: Huntress
Infrastructure and indicators
327 new C2 and malware-distribution addresses in 24 hours — the top two labels are 76% of it
malware_download accounts for 188 and VShell for 61, 249 between them. The rest are Aisuru and "Unknown malware" at 12 each, Cobalt Strike and PureRAT at 10, XMRIG at 8, DCRat at 7, with AdaptixC2, Sliver and Quasar RAT in single digits. The previous issue recorded 342 with the top two at 75%; the composition across the two days is essentially the same.
Sources: C2 Infrastructure
The hosting picture is unchanged from the previous issue
By host count CHINA169 (AS4837) still leads with 1,270 addresses, 276 of which carry an exposure record, followed by Google Cloud at 372 and AROSSCLOUD (AS400619, Seychelles) at 243. By density of evidence it is still AROSSCLOUD — 234 of its 243 hosts carry a record, against families VShell, possible Cobalt Strike and PureRAT. The 158 addresses inside Censys's own range (AS398324) are still filed as malware, and only 5 of them carry an exposure record. The top of the table has not moved in two days.
Sources: C2 Infrastructure