Threat Watch · Sep 19, 2026
The nine claims n0n posted at once are written not as "who we hit" but as "what gets published if there is no settlement": 86.7M connection records from PayPal's outsourced support operation, 15.3M subscriber records from Venezuela's largest ISP, a KYC investor register from a Luxembourg securities platform. The leverage being advertised is the specificity of what comes next, not the volume.
Groups and claims
n0n — nine victims in one batch, written as data inventories
The nine claims span eight countries and seven sectors, each following one template: the victim's sector and country, then what will be published if no settlement is reached. The most itemised: PayPal support operations run by Transcom WorldWide (Netherlands / Tunisia), claimed as 86.7 million connection records covering support agents' daily sessions into PayPal corporate Citrix/AAA systems; Inter, Venezuela's largest internet provider, claimed as over 15.3 million subscriber connection records with tens of thousands of subscriber addresses and the services they contacted; Argentina's Ministry of Education, claimed as the complete network-security configuration of the ministry network plus 1.08 million connection records touching the national library (BNM) and the school-book selection platform; and AstraZeneca Türkiye, claimed as 940 MB holding the internal network-security configuration of all three sites — every rule, device definition and remote-access mapping. The rest: a KYC investor register from the Luxembourg digital securities platform STOKR (names, emails, nationalities, wallet addresses and tax IDs), roughly 181,420 legal case documents from the United Federation of Teachers in New York (grievance and arbitration files, disciplinary appeal decisions), 2,021,011 registered bettors from the Vietnamese GC789 betting network, 152,044 CRM lead records from BeLi Teacher / FSC education centres in Vietnam, and an application database with password hashes from the Brazilian legal services firm Konnatus. Eight of the nine were recorded independently by both trackers.
Sources: RansomLook · ransomware.live
qilin — 7 new victims, four of the seven with Spanish-language names
Ascend Com, Ceres Tolvas, Futuro Forestal, Grupo Juste, Inland and Offshore Contractors, Vigatec and Invincible GG. RansomLook records the sectors as business services, business services, agriculture, manufacturing, civil engineering construction, business services and business services. The group has posted new victims in each of the last five issues, and the sector spread has stayed wide throughout.
Sources: RansomLook
spirals — two victims, one an IT asset disposal provider for federal agencies and defence contractors
ANYTHINGIT describes itself as a certified IT asset disposition (ITAD) and e-waste management provider for federal agencies, defence contractors and enterprises demanding the highest chain-of-custody standards — a business that by definition handles clients' decommissioned equipment and whatever remained on it. The second is PITTSRAD, a radiology and health imaging provider, where the post claims client personal and health data.
Sources: RansomLook · ransomware.live
play — 3 victims across Ireland and Canada
Barrett Mahony Consulting Engineers (Ireland), Inglewood Golf (Canada) and Vista Plastic Solutions (Canada). The three entries give no detail beyond the country.
Sources: ransomware.live
inc ransom and lockbit5 — two each, no two in the same sector
inc ransom posted Kendall Hunt Publishing (a US publisher founded in 1944, producing inquiry-based science and mathematics curricula for grades PreK-12) and Roan Luxury Camping Holidays (a Dutch tour operator). lockbit5 posted forus.cl (a Chilean apparel company founded in 1980, headquartered in Santiago) and hygear.com (on-site and on-demand hydrogen and industrial gases).
Sources: ransomware.live · ransomware.live
Another dozen or so claims
securotrop posted Prefix Corp, claiming 1,135 GB with a publication deadline of 30 September; rhysida posted the German pharmaceutical importer MPA Pharma; akira posted the US engineering and manufacturing firm Anderson Industries; anubis posted Quest Group; auditteam posted two, one the Japanese kit-e.jp and one identified only by a code and marked as paid; krybit posted two, the German welfare organisation Diakoniewerk Apolda and the Istanbul property developer Harput Yapı; panzer posted the Brazilian telecom and IT consultancy K3G Solutions; chaos posted Express Employment Professionals, stating it had entered the public release phase; gammax and killsec posted one each, and two further entries withhold the company name pending disclosure.
Sources: RansomLook · ransomware.live
Campaigns and activity
TraderTraitor — backdoors on a DevOps engineer's Mac with no crypto ties
SentinelOne Labs reports North Korean operators building a foothold on a DevOps engineer's Mac in a campaign whose job-interview lures deliver malware via Terraform lock files. The victim profile is the part worth keeping: TraderTraitor has been tracked as a cluster aimed at the cryptocurrency industry, and this victim has no crypto connection — the selection criterion looks like the infrastructure the engineer could reach, not the sector their employer sits in.
Sources: SentinelOne Labs
WeaselBiscuit — a JavaScript stealer in 13 npm packages, overlapping with Contagious Interview tooling
Researchers found a cluster of 13 npm packages delivering a previously undocumented JavaScript stealer, WeaselBiscuit, which harvests Chrome extension storage. Per OpenSourceMalware, the family shows functional overlap with two strains associated with North Korea's Contagious Interview campaign, BeaverTail among them.
Sources: The Hacker News
Rapuncel — search ranking as the distribution channel
An ongoing campaign uses SEO-optimized GitHub repositories impersonating well-known software firms to push a previously undocumented information stealer called Rapuncel; one observed disguise is a fake LastPass Authenticator. The distribution surface is neither an app store nor a phishing message but the organic result ordering developers and users see when they search for software.
Sources: Bleeping Computer
[Added detail] Transparent Tribe (APT36) — tool names and target scope
The four previously undocumented tools in the operation Zscaler ThreatLabz attributes are RUSTYSHADE, RUSTYMOVE, PSNATCH and BASHNATCH, and the targets are government and defence entities in India and Afghanistan. The Pakistan-aligned group is also tracked as Earth Karkaddan. The new Rust backdoor uses private GitHub repositories as its command-and-control channel.
Sources: The Hacker News · Zscaler ThreatLabz
[Added detail] PhantomRaven — the developer is assessed to have written the malware with an LLM
Researchers assess with high confidence that the JavaScript stealer was written using a large language model, citing verbose comments, placeholder code left in place, and statistical token-analysis patterns. It is distributed through the npm package registry and linked to a financially motivated actor.
Sources: The Hacker News
Infrastructure and indicators
365 new C2 and malware-distribution addresses in 24 hours — VShell displaces Cobalt Strike as the largest named family
224 of them (61%) carry only the generic malware_download tag, which states a distribution role rather than a family; that share is in line with recent issues. Among the named families VShell leads with 76, then PureRAT at 14, CECbot and Unknown malware at 7 each, XWorm at 6, DCRat at 5, and Remcos and Cobalt Strike at 4 each. Cobalt Strike falling to eighth is the one change in ordering: it recorded 55 addresses on 14 September and held between 12 and 16 a day since.
Sources: C2 Infrastructure
The hosting picture is unchanged, and the densest network is where VShell lives
The largest block is still AS4837 (China Unicom China169 Backbone) with 1,850 hosts, of which only 394 (21%) have a Shodan record. The densest is still AS400619 (AROSSCLOUD INC., Seychelles), where 235 of 244 hosts (96%) carry a record — and the three families recorded on that network are VShell, PureRAT and possible Cobalt Strike C2, the first two of which are also the top two named families among today's new addresses. Third by size is AS396982 (Google Cloud) at 388 hosts. The difference between the top two blocks is visibility rather than scale: more than three quarters of China Unicom's 1,850 hosts return no port or service record at all.
Sources: C2 Infrastructure