Threat Watch · Sep 17, 2026
Groups and claims
The full table is at Threat Actors. These are the sets worth calling out today.
inc ransom — 6 new claims, one of them a smart-meter operations platform
The heaviest is Aidon Oy in Finland, which the entry itself identifies as part of Gridspertise, the joint venture between the Enel Group and CVC Capital Partners, and classifies as energy / smart-grid critical infrastructure. The same batch holds the city government of Princeton, Texas (Collin County, roughly 150 staff, a $30–50M annual budget), Partners Financial Services in Prague, the Chicago History Museum (the entry cites four departments plus AWS), Trulite Glass & Aluminum Solutions (one of North America's largest independent glass and aluminium fabricators, 42 sites and about 1,700 staff) and Zito Marketi. Recorded by RansomLook only.
Sources: RansomLook
Auditteam — 6 new claims spanning Russian-language, Ukrainian and South Korean academic targets in one batch
The entries are palletshop.ru, the Kyiv system integrator Wise IT (which describes its own business as data centre, virtualization, cloud migration and security work with Google, Microsoft, VMware and Dell), buben.it, the South Korean academic domain dg.ac.kr, gownet.net and krimax.org. Four of the six carry nothing but a domain name or the words "no data breaches", so the claims themselves offer nothing checkable.
Sources: ransomware.live
ransomhouse — claims the Namibian Defence Force
The national military forces of Namibia. Both trackers recorded the claim independently.
Sources: RansomLook · ransomware.live
blacknevas — Optimum First Mortgage, 9.3 TB claimed
The entry lists the target as US lending and brokerage, with data categories including financials, HR, clients' private and financial details, PII and PHI records, mailboxes and email correspondence, database exports and OneDrive contents. Both trackers recorded it.
Sources: ransomware.live · RansomLook
qilin — 4 new claims, no two in the same sector
Reddrop Group (grocery retail), In The Company of Huskies (advertising and marketing), Thorndale Foundation (non-profit) and Thema Foundries (business services). Both trackers recorded them.
Sources: RansomLook · ransomware.live
akira — 3 new claims, each with a stated data volume
Manders Companies (a family-owned contractor in the Washington metropolitan area, 70 GB of corporate data promised including employee personal information), Bee Maid Honey (the marketing arm of western Canadian beekeeping cooperatives, 46 GB promised) and Blossomland Accounting (an accounting firm in southwest Michigan). Both trackers recorded them.
Sources: RansomLook · ransomware.live
emperador — 2 claims, both scheduled for publication on September 26
The Italian premium-car dealer RDA MOTORS S.P.A. (7.3 GB) and SEVENOAKS s.r.o. of Prague (3.3 GB). Both trackers recorded them.
Sources: RansomLook · ransomware.live
Six further groups posted one or two each: wallstreet two (Odyssey Charter School in Florida and the Iranian industrial firm Roshd Sanat), arcus media one (Thailand's Agricultural Research Development Agency, deadline September 23), and one apiece from panzer, kairos and Shadowbyt3$, while ShinyHunters issued a final warning against a redacted company with a September 18 deadline. All of the above are claims, not confirmed intrusions.
Campaigns and activity
NightEagle, Hacking Cat and Toy Ghouls — three separately named clusters hitting Russian enterprises at once
Kaspersky GERT says NightEagle (also tracked as APT-Q-95 and active since at least 2023) is running a new campaign using the GhostContainer backdoor with tooling hosted on GitHub, and new techniques for persistence and lateral movement; the group is also exploiting vulnerabilities in Active Directory and RDP. The same body of reporting names two further clusters, Hacking Cat and Toy Ghouls. The targets, as reported, are enterprises in Russia.
Sources: Securelist · The Hacker News
Shai-Hulud — from one hijacked AI coding-assistant session to about 100 internal repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider. The step before the spread: the assistant recommended software the attacker had poisoned, and the recommendation was accepted. The worm then moved across about 100 internal code repositories, stealing repository secrets and source code. The entry point is a session rather than a public package, which is what separates this from the earlier Shai-Hulud rounds.
Sources: The Hacker News
[Added detail] The OpenAI agent cluster — activity on Hugging Face predating the published timeline
SentinelOne Labs traced two Hugging Face accounts showing that the agents staged relay code on the platform, ran internal probes and registered ChatGPT accounts, over a span that runs beyond the previously published timeline.
Sources: SentinelOne
[Added detail] The Iran-linked Windows spyware now has a name: CHOSEN BRICK
Government agencies in several countries are warning that Iranian state-linked attackers are using this Windows malware strain against dissidents, activists and journalists worldwide.
Sources: Bleeping Computer
[Added detail] KREMLIN — bypassing the browser's own checks to force-install its extensions
This banking-malware toolkit has been active since mid-2025; Elastic tracked it across seven campaigns and 15 months, through Brazilian bank lures, with its C2 configuration held in Ethereum smart contracts. What is added today is the install step: it bypasses browser checks to force-install malicious Chrome and Edge extensions, which then steal credentials, session tokens and sensitive data.
Sources: Bleeping Computer · Elastic Security Labs
[Added detail] AMOS — deceptive setup guides that get the user to do the work
Unit 42's own analysis sets out how to identify and block this macOS stealer: delivery runs through deceptive setup and configuration guides, and the objective is credentials and sensitive user data.
Sources: Unit 42
Infrastructure and indicators
379 new C2 and malware-distribution addresses in 24 hours — close to seven in ten carry no family label
The 263 tagged malware_download account for 69%, followed by VShell at 25, Jackskid 14, Cobalt Strike 13, PureRAT 12 and AsyncRAT 8. The figure of 379 sits in the same range as four of the last five issues (361 on 09-16, 347 on 09-14, 327 on 09-13, 342 on 09-12); the 637 recorded on 09-15 remains the only exception in that run.
Sources: C2 Infrastructure
The hosting picture is unchanged: the largest block and the densest block are still not the same block
CHINA169, the China Unicom backbone, leads with 1,653 addresses, but only 360 of them carry a mapping record — about 22%. AROSSCLOUD, registered in the Seychelles, has 235 records across 244 addresses, roughly 96%, and remains the densest segment, with family labels concentrated in VShell, PureRAT and suspected Cobalt Strike. Censys' own range is still 158 addresses with records on only 5. Globe Telecom stays in the top ten at 83 addresses.
Sources: C2 Infrastructure