Threat Watch · Sep 18, 2026
AECOM was posted to two separate leak sites on the same day, by Brain Cipher and by Metaencryptor, two groups with no known relationship and claims that do not agree on volume. This is not corroboration — it is one victim appearing in two unrelated claims, and for anyone reading this data it marks the distance between a claim and an intrusion.
Groups and claims
storm — 5 new claims, four of them US midwestern banks and wealth managers
First Secure Community Bank (Sugar Grove, Illinois), The State Bank Group (Wonder Lake, Illinois, comprising six branch banks), First Secure Bank and Trust (Palos Hills, Illinois) and Johnson Investment Counsel (Cincinnati, Ohio, an employee-owned wealth management firm). The fifth is American Casting Company, an investment casting foundry in Hollister, California. The first four are all small and geographically clustered — the shape of one target class posted in sequence.
Sources: RansomLook
Brain Cipher and Metaencryptor — separate claims on AECOM, same day
Metaencryptor posted AECOM at 13:05 on 17 September. Brain Cipher posted aecom.com at 18:36 the same day, stating it had obtained 670 GB of data that "most likely belongs to a Fortune 500 company" without naming it directly. The two groups have no known relationship. Metaencryptor's same batch also carried Beckman Coulter, the Danaher clinical diagnostics manufacturer, and ProMantra.
Sources: ransomware.live · ransomware.live
Endzone — AT&T and Accela, both entries describing the access path
The AT&T entry claims initial access came through a customer-experience contractor doing business with AT&T, mentions VPN and HVD as the two channels, and says the access was originally used for equipment changes and call forwarding. The Accela entry claims over 50 GB extracted; that company runs the cloud platform state and local governments use to manage internal agency operations. Both rest on the group's own account, with no second-party confirmation.
Sources: ransomware.live · ransomware.live
Settra — 6 at once, written as narrative rather than inventory
rottner-tresor.at, naturesplus.com, pacificabs.com, fchhotels.com, budgetms.com and sym.com.mx. Unlike most leak-site entries, these carry a "PROLOGUE" heading and an ironic opening written at the victim, several naming specific individuals and business details.
Sources: ransomware.live
Panzer — 3 claims, including the University of Hamburg
Universität Hamburg is the largest research and teaching institution in northern Germany, with over 42,000 students. The other two are Inovapy, a Latin American software company, and Stim, a French video surveillance integrator.
Sources: ransomware.live
inc ransom — 3 claims, one a Taiwanese IC design house
Silicon Integrated Systems (SiS, Taiwan, analog and mixed-signal IC design), Diarco in Argentina, and Appliance Factory in the United States.
Sources: ransomware.live
ransomhouse — Pertamina
Indonesia's state oil and gas company. The group claimed the Namibian Defence Force the previous day.
Sources: ransomware.live
akira and qilin — 3 to 4 each, no repeated sector
akira: Vetta, a Brazilian energy-management software firm; Javep Chevrolet, a car dealership; and Practice Management, which does medical billing for Federally Qualified Health Centers. qilin: Vigatec, Invincible GG, Techwise and The Gran Hotel Ingles — the first three filed under business services, the last hospitality. Routine volume for both.
Sources: RansomLook · RansomLook
Another twelve or so claims across the remaining groups
krybit posted 2 (a Turkish property developer and a German social welfare organization); emperador 2 (Westbridge Institute of Technology in the Philippines and RDA Motors in Italy); brain cipher a further 2; chaos 1 (Express Employment Professionals, entering its public release phase); Spirals 1 (ANYTHINGIT, which does IT asset disposition for federal agencies and defense contractors); and lockbit5, vexy, Killsec, Silentransomgroup, Shadowbyt3$ and leakeddata one each. shinyhunters issued a final warning against a company whose name is masked, with an 18 September deadline.
Sources: RansomLook · ransomware.live
Campaigns and activity
FamousSparrow — deploying the previously unreported SparroWocky backdoor across Latin America
ESET researchers Alexandre Côté Cyr and Romain Dumont document activity by this China-aligned state-sponsored actor against multiple Latin American countries since at least August 2025, including government organizations. SparroWocky is described as a modular C++ backdoor and the group's new flagship tool. ESET's technical report and two outlets published the same day.
Sources: ESET · The Hacker News · Bleeping Computer
APT36 — Operation RapidRust, a whole toolset rewritten in Rust
Zscaler ThreatLabz says it observed new activity by this Pakistan-nexus actor in August 2026, still targeting government and defense organizations in India and Afghanistan. Since the team's previous publication in January, APT36 has maintained a high operational tempo and updated its tactics and techniques. The new tools are the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and two file-stealing utilities, PSNATCH and BASHNATCH.
Sources: Zscaler ThreatLabz
Handala Hack — tied to the HEAVYGRAM Telegram backdoor
This Iran-linked "hacktivist" persona has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. HEAVYGRAM's built-in commands support remote command execution, system, network and process discovery, exfiltration of data and Telegram session files, screenshot capture, and DLL sideloading.
Sources: The Hacker News
RatHat — Android malware abusing ADB to keep shell access after uninstall
Researchers assess this malware to be operated by China-based threat actors, with an AI-powered subsystem that helps operators navigate and control compromised devices remotely. Distribution runs primarily through targeted smishing and malvertising leading to deceptive third-party download portals. The detail worth recording separately is its abuse of ADB — shell access survives uninstallation of the app.
Sources: The Hacker News · Bleeping Computer
MovieReaper — distributed through movie torrents, C2 hidden on the Solana blockchain
A new campaign found by Kaspersky. The multi-stage Trojan spreads through movie torrents such as "The Odyssey" and uses the Solana blockchain to hide its command-and-control infrastructure — on-chain data cannot be taken down, and does not depend on a domain that can be seized.
Sources: Securelist
The Gentlemen and Qilin — Talos counts Japan's first half and reports evidence of Qilin using AI
Cisco Talos finds ransomware incidents in Japan rose 4.7% year over year in the first half of 2026. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July; Qilin ranked second, and Talos says the group appeared to be using AI. The victim profile is worth noting: SMEs with capital under JPY 1 billion made up 80% of victims. The report also analyses The Gentlemen's infrastructure.
Sources: Cisco Talos
NightmareStresser — domains seized by the US Department of Justice
The FBI seized nightmare-stresser[.]com and nightmarestresser[.]org. The platform was one of the longest-running DDoS-for-hire services and is linked to hundreds of thousands of attacks. Visitors now see a seizure banner.
Sources: Bleeping Computer · The Hacker News
One X DM, two chains — AMOS on Mac, NetSupport on Windows
Huntress SOC analysts documented a delivery run using a Google Doc sidebar as the lure: a single direct message split by operating system, handing macOS users the AMOS stealer and Windows users the abused remote management tool NetSupport Manager.
Sources: Huntress
Infrastructure and indicators
372 new C2 and malware-distribution addresses in 24 hours — 62% still carry no usable family label
232 of the 372 fall under malware_download, Unknown malware or no label at all, which is 62%, in line with 379 on 17 September and 361 on 16 September. Among the roughly 140 that are labelled, the leaders are Jackskid at 22, Cobalt Strike at 17 and PureRAT at 15, followed by VShell and ValleyRAT at 14 each, Remcos and XWorm at 7, DCRat at 6, and AsyncRAT and AdaptixC2 at 5.
Sources: C2 Infrastructure
Hosting unchanged: the largest block and the densest block are still not the same block
CHINA169 (AS4837) leads with 1,766 hosts, but only 381 of those have a port or service record. AROSSCLOUD (AS400619, Seychelles) holds just 244 hosts, 235 of them with records, and concentrates VShell, PureRAT and suspected Cobalt Strike. Google Cloud is second at 388 hosts, 326 with records, including Sliver and Evilginx. Globe Telecom remains in the top ten since entering it on 14 September.
Sources: C2 Infrastructure