Threat Watch · Sep 16, 2026
Six of today's 30 new claims land on public-service operators, and they come from five unrelated groups: Peru's national government portal gob.pe, a Swiss wastewater treatment operator, a Costa Rican water utility, Massachusetts' third-largest school district, and the city government of Fort Smith, Arkansas.
Groups and claims
safepay — 9 new victims
The largest batch of the day. It includes gob.pe, Peru's national government portal and the primary online point of contact between public institutions and citizens; ARA Lyss, a Swiss wastewater treatment operator; Ryomo Systems, a publicly listed Japanese systems integrator; La Concepción, a private healthcare provider in Coahuila, Mexico; and Trinity Caring, a US senior services organization. The rest are German and Swiss manufacturers and retailers plus a US HVAC contractor. Both trackers recorded the same batch independently.
Sources: RansomLook · ransomware.live
qilin — 7 new victims, no two in the same sector
ADM (food and beverage), Bravo Group (freight and logistics), Aarsleff and Montana Civil Contractors (construction), Taurus Ibérica (real estate), Resolve Law Group (legal services) and Incrys (business services). The group posted a comparably scattered set the previous day. Both trackers carry them.
Sources: RansomLook · ransomware.live
metaencryptor — 2 victims, both East Asian heavy industry
Nippon Steel Corporation, Japan's largest steelmaker and one of the world's leading steel producers, and SFA Engineering Corporation, a South Korean industrial automation, robotics and manufacturing equipment maker. Both claims were posted within the same minute. Only ransomware.live records them; RansomLook has no matching entries.
Sources: ransomware.live
interlock — 2 US public bodies
Springfield Public Schools, the third-largest district in Massachusetts with over 23,500 students and more than 4,200 full-time employees, and the city government of Fort Smith, Arkansas. Both leak-site pages carry disparaging text aimed at the victim.
Sources: RansomLook · ransomware.live
akira — 3 new victims
Southern California Telephone Company, a US telecom provider; Pilot Precision, an industrial cutting-tool and machining firm; and Lazy Boyz, a Harley-Davidson dealership and workshop in Oslo. Both trackers carry them.
Sources: RansomLook · ransomware.live
dragonforce — 2 victims, both with large volume claims
Community Property Management, a US common-interest-development management firm, claimed at 200 GB or more, and Owen Leigh Optometry, claimed at 400 GB or more. These are the latest posts in this issue's window.
Sources: RansomLook · ransomware.live
Five more groups, one claim each
insomnia listed Wiggins, Childs, Pantazis, Fisher & Goldfarb, a large US plaintiffs firm; ransomhouse listed the California School Employees Association; dark project claimed 489 GB taken from Cumar Marble & Granite; arcus media listed Asada Sarapiquí, a Costa Rican water supply organization, with a September 22 deadline; and vexy listed Hashimoto Jimuki, a Japanese office and IT equipment supplier.
Sources: ransomware.live · RansomLook
Campaigns and activity
KREMLIN — forging Chrome's own integrity checks, with C2 configuration held in Ethereum smart contracts
Elastic Security Labs tracks this previously undocumented Brazilian banking operation as REF9334, active since at least May 2025. The lures impersonate a dozen Brazilian banks and install a malicious browser extension on Chrome and Edge; Elastic describes the extension as forging Chrome's own integrity checks, which is why it presents as something the user never installed. Elastic followed it across seven campaigns over fifteen months and analysed the Ethereum smart contracts holding its C2 configuration.
Sources: Elastic Security Labs · The Hacker News
BambooToken — MQTT as the command-and-control channel for both Windows and Linux
Researchers disclosed a multi-platform framework assessed as active since at least February 2023 and used against organizations across Asia and South America. It uses Message Queuing Telemetry Transport as its channel to controlled hosts — a protocol common in IoT deployments, and not necessarily treated as suspicious traffic on an enterprise network.
Sources: The Hacker News · Bleeping Computer
Iran's intelligence service — Telegram-controlled Windows spyware aimed at dissidents and journalists
Cybersecurity agencies in the United States, the United Kingdom and the Netherlands jointly detailed Windows malware they say Iran's intelligence service uses to spy on dissidents, journalists and activists worldwide. It can copy a target's emails and chat messages, take screenshots and activate the microphone to record. The control channel is Telegram.
Sources: The Hacker News
Marimo notebook to SSH bastion — eight seconds
In an intrusion Sysdig documented, the operator moved from a vulnerable Marimo notebook to an SSH bastion within eight seconds of gaining initial access. Sysdig's point is that the speed came from a skilled human operator, which is a separate matter from AI compressing the window between disclosure and exploitation.
Sources: The Hacker News
Black Axe — five alleged leaders extradited to the United States
Five alleged leaders of the syndicate, known for cyber-enabled financial fraud at global scale, have been extradited to the US to face wire fraud and money laundering charges.
Sources: Bleeping Computer
PhantomRaven — an information stealer developed for bug bounty hunting
CrowdStrike disclosed a malware family it describes as an LLM-generated information stealer developed for bug bounty hunting. The feed entry carries a title only, with no body text to quote.
Sources: CrowdStrike
Infrastructure and indicators
361 new C2 and malware-distribution addresses in 24 hours — two thirds carry no family label
239 of them, 66%, are labelled malware_download. The named families behind the rest are Cobalt Strike at 16, PureRAT at 10, then Remcos, Aisuru, VShell and Jackskid at 9 each, and AsyncRAT and XWorm at 7. The 361 brings the count back into the band of the five issues before the previous one (347, 327, 342, 369) after that issue's 637, so yesterday's doubling did not carry over.
Sources: C2 Infrastructure
Hosting unchanged: the largest block and the densest block are still not the same block
China Unicom's China169 backbone (AS4837) remains the largest at 1,551 addresses, but only 336 of them have an exposure record. AROSSCLOUD in the Seychelles (AS400619) is the densest at 244 addresses with 235 records, its families concentrated in VShell and PureRAT. Globe Telecom in the Philippines (AS132199) holds a top-ten place at 80 addresses, all labelled malware_download. The scanning vendor Censys's own range (AS398324) still carries 158 addresses filed as malware with records for only 5.
Sources: C2 Infrastructure