Threat Watch · Sep 14, 2026
Groups and claims
ShinyHunters — Kimberly-Clark, final notice, deadline Sep 16
The listed consumer goods company Kimberly-Clark has been posted, and the note is a final warning: reach out by Sep 16 or the data is leaked, along with "several annoying (digital) problems." Both trackers record the claim independently. The name has been busy lately — AdaptHealth's confirmed 4.1 million people affected and Florida's DAVID DMV platform sit under it too. These are claims, not confirmed intrusions.
Sources: RansomLook · ransomware.live
Barracuda — i2i-systems, 693 GB, 44 GB of it source code
The note is unusually detailed. Beyond claiming a week of free movement inside the network and 693 GB exfiltrated, it names the repositories and packaged artefacts taken one by one: Caplan, DataGov-Dev-Docker, DDR and DDR-Veriskop, Kangal, SDD, plus datagov.war, smartdq.war and Copycat.zip among others — by the note's own accounting, 44 GB of source code alone. If accurate, the exposure does not stop at one company: product source and .war build artefacts in outside hands carry risk downstream to that product's customers. The note also spends several lines mocking the target's security configuration and IT department. (The Barracuda here is the group's name and is unrelated to the security vendor of the same name.)
Sources: ransomware.live
Qilin — two claims, construction and business services
Gilco Scaffolding (construction) and CARIDRO VAL DE LOIRE (business services), both carrying only a sector label with no data volume or deadline. The name was cited last week among the clusters exploiting Cisco Secure Firewall Management Center; this issue it is back to routine volume.
Sources: ransomware.live · ransomware.live
Emperador — Navitrans, 223.2 MB, publication scheduled for Sep 23
By the note's description, Navitrans is a Colombian distributor and service provider for commercial trucks and heavy machinery with a nationwide workshop network; the post claims the data covers prices, financing and other operational information, and tags the sectors as manufacturing and transportation. This one carries an explicit publication time: Sep 23 at 13:01 UTC. Posting a countdown rather than the data is a sign negotiation is still live.
Sources: ransomware.live
Audit Team — three claims, entity names redacted, two of them marked as paid
None of the three gives a full entity name, leaving only a hash-style audit ID and a masked name such as vi***in. The detail worth recording is that two of them are titled Paid Victim followed by a hex identifier — the payment outcome itself published as content. The leak site is not being used for pressure here; it is a credit record for future victims to read.
Sources: ransomware.live
Three more groups, one claim each
krybit posted kashkha.com (by the note's description a multinational modest fashion brand headquartered in Dubai), Panzer posted Cerámicas Kantu (a Peruvian decorative tile manufacturer), and Vexy posted Strad Solutions (a cloud hosting and managed IT provider). Today's new claims total 11 across 8 groups. The full table is at Threat Actors.
Sources: ransomware.live · ransomware.live
Campaigns and activity
[Added detail] UNC3569 — the Sogou Input Method flaw is now CVE-2026-51990
The Sogou Input Method for Windows flaw used to deploy the GRAYRABBIT backdoor now carries a CVE number and a critical rating. The attack starts with a crafted link and ends with the attacker able to do anything the logged-in user can do. The CVE is not in the CISA KEV catalog, which means remediation rides on Tencent's own update with no federal deadline pushing it.
Sources: Bleeping Computer
[Added detail] The executive-impersonation campaign Microsoft disclosed — over a million scam emails between Aug 3 and 5
The scale figure has landed: more than a million messages in three days, masquerading as chief executive officers and sent through third-party email delivery infrastructure. Renting delivery services instead of standing up their own sending infrastructure means borrowing sender reputation — what the recipient's filters see is a domain with standing. The same disclosure also covers the passkey-themed social engineering activity.
Sources: The Hacker News
Infrastructure and indicators
347 new C2 and malware-distribution addresses in 24 hours — the top two labels are 68.6%
The previous 24 hours held 306. malware_download alone accounts for 210 (60.5%), followed by Jackskid at 28, Cobalt Strike and VShell at 20 each, and PureRAT at 14, with a tail of Aisuru 7, Remcos 6, CECbot 6, DCRat 4, AsyncRAT 4 and AdaptixC2 3. None of the 28 addresses under Jackskid has a hosting record yet — they are too new for the enrichment queue to have reached them.
Sources: C2 Infrastructure
Hosting distribution — the largest block is unchanged, Globe Telecom enters the top ten
CHINA169 remains the largest block at 1,358 addresses, but only 297 of them carry a hosting record; the densest evidence is on AROSSCLOUD (Seychelles, 234 of 243 addresses with a record, families concentrated in VShell, PureRAT and suspected Cobalt Strike). Google Cloud holds 373, CHINANET 150, DigitalOcean 136 and Tencent 116, with the two Alibaba Cloud ASNs at 209 between them. Globe Telecom (Philippines) enters the top ten with 70 addresses, 66 of them with a record and carrying only one family label, malware_download. The Censys netblock still shows 158 addresses with 5 records — a measurement vendor's own scanning nodes labelled malicious, a figure unchanged from the previous issue.
Sources: C2 Infrastructure