Threat Watch · Sep 15, 2026
the gentlemen's 30 claims share no country and no sector — a primary school, a Swedish technical gymnasium, an Indian listed power-equipment maker, an eye clinic, a Bulgarian pharmacy chain. That is the shape of a backlog published at once, not a campaign.
Groups and claims
the gentlemen — 30 victims in one batch, recorded independently by both trackers
The two trackers together recorded 66 claims from 16 groups today; this one group accounts for 30 of them. The named victims run across Europe, the Americas, the Middle East and Asia with no sector in common: High Oakham Primary School, Göteborgsregionens Tekniska Gymnasium, BGR Energy Systems, Dome Gold Mines, Hattiesburg Eye Clinic, Apteki Mareshki, Medskin Solutions Dr. Suwelack AG, Librería Santa Fe, Sarku Japan, Wada Farms, Downrite Engineering and ACA Pescara among them. RansomLook and ransomware.live each recorded the same 30 names, which is the only cross-check available here. The group was previously tied to the Veradigm patient data breach confirmed on September 9.
Sources: RansomLook · ransomware.live
qilin — 7 claims across transport, manufacturing and construction
Alicotrans, Foremost Mfg, GEIEG, Minmer Global, Roadex America, Vitar Group and Winston Contracting LLC, all on both trackers. Cisco named this group on September 12 as one of the three clusters exploiting the Secure FMC flaw CVE-2026-20079.
Sources: RansomLook · ransomware.live
panzer — 6 claims, two of them local entities of multinational brands
Honda (Peru) and Konica Minolta Bulgaria are the only multinational-brand entities in the set; the rest are Cerámicas Kantu, Aqualogus and Financière d'Uzès.
Sources: RansomLook · ransomware.live
lockbit5 — 3 claims, one an Italian municipality
comune.robeccosulnaviglio.mi.it, httoy.fi and tpi.tw, one in each of three countries.
Sources: RansomLook · ransomware.live
storm — 3 claims, on one tracker only
Insight Credit Union, McCarthy Tire Service and PantherX Rare. These appear only on RansomLook, with no matching record on ransomware.live, so there is no cross-check for them.
Sources: RansomLook
Another eleven groups, 18 claims between them
direwolf (Hazel Health, Little Otter), eclipse (Dublin City Schools GA, Rosello et Fils), genesis, insomnia, chaos and booba filed two each; anubis, audit team, unsafe, iah6477 (Veritiv) and shadowbyt3$ one each. Of these, direwolf appears only on RansomLook, while iah6477 and shadowbyt3$ appear only on ransomware.live. The full table is on Threat Actors.
Sources: RansomLook · ransomware.live
Campaigns and activity
UTA0560 — patched Chrome and Windows flaws used to deliver the GRIMWEDGE backdoor
Volexity attributes this cluster to a Chinese threat actor and says it ran a spear-phishing campaign against multiple non-governmental organizations on September 1, 2026, exploiting recently patched Google Chrome and Microsoft Windows flaws to deliver a JavaScript backdoor called GRIMWEDGE. This is a different cluster and a different payload from the BlueMoon exploit kit reported on September 10, whose first in-the-wild use was attributed to APT31 — but it works the same browser-plus-operating-system path.
Sources: The Hacker News
Red Heron — rapid exploitation of a Gitea RCE, 13 organizations across six countries
Acronis Threat Research Unit attributes the rapid exploitation of a recently disclosed Gitea vulnerability to this suspected Chinese threat actor, targeting internet-facing instances. TRU says Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. The attribution is stated by the source as suspected.
Sources: The Hacker News
The 3BB intruder — MeshCentral, a legitimate management tool, held root on a Thai broadband provider's internal machines
Threat intelligence firm Hunt.io says an attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, using the legitimate remote management tool MeshCentral to keep control of internal machines with root access. Hunt.io found the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of subscriber credentials.
Sources: The Hacker News
HBO Max's Reddit account hijacked to run ClickFix ads
Attackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks, installing information-stealing malware on Windows and macOS. The account was the brand's own, so there is no suspicious-domain step anywhere in this chain.
Sources: Bleeping Computer
The JeetBot extension — OAuth tokens for nearly 31,000 Twitch users sent to a Russian commercial bot service
The extension, "Twitch Enhanced Viewer | JeetBot", is listed on both the Chrome Web Store and the Mozilla Firefox Add-ons store with HISHIMIRO/jeetbot.cc as its developer, and sends users' Twitch OAuth session tokens to proxy servers operated by that commercial bot service. Neither store's review caught it.
Sources: The Hacker News · Bleeping Computer
Mass scanning of internet-exposed Vite development servers, aimed at cloud credentials
A mass-scanning campaign is hunting internet-exposed Vite development servers and attempting to steal cloud credentials and configurations from AWS and Azure deployments. Dev servers are not built for the public internet, so this activity turns a "localhost only" default assumption into an attack surface.
Sources: Bleeping Computer
Volume Shadow Copy abuse for credential theft and pre-ransomware defense evasion
Huntress breaks down how attackers exploit Volume Shadow Copy to steal credentials and to evade defenses before deploying ransomware, and gives the markers that separate it from routine IT activity — the two look much alike in telemetry, which is exactly why it is chosen.
Sources: Huntress
Infrastructure and indicators
637 new C2 and malware-distribution addresses in 24 hours — roughly double the last five issues
The previous five issues recorded 347, 327, 342, 369 and 340; today is 637. The top two labels, malware_download (243) and Unknown malware (159), total 402 or 63%, down from the 69%–78% range of those issues — the volume doubled while concentration fell. The post-exploitation frameworks are worth reading separately: Cobalt Strike 60, Sliver 49, VShell 14, AdaptixC2 9.
Sources: C2 Infrastructure
Hosting unchanged: the largest block and the densest block are still not the same block
CHINA169 (AS4837) still leads at 1,457 hosts, but only 314 of them return a port or service record. AROSSCLOUD (AS400619, Seychelles) has 234 records across 243 hosts and remains the densest block by evidence, labelled VShell, possible Cobalt Strike and PureRAT. Google Cloud is second at 373 hosts with 312 records. Globe Telecom, which entered the top ten on September 14, is still there at 75 hosts and 71 records, every one labelled malware_download.
Sources: C2 Infrastructure