Threat Watch · Sep 20, 2026
What ShinyHunters hit was Clop's leak site, and both trackers ingested it as an ordinary victim claim — an extortion crew filed under "victim". The trackers record who was posted on whose leak site; they do not distinguish a company from another gang.
Groups and claims
shinyhunters — a post addressed to Cl0p
ShinyHunters breached the data leak site of the Clop (Cl0p) ransomware operation, defaced its Tor site, and claims to have taken server data and the private keys for the onion service. Both trackers logged it under a victim name, "Note to Cl0p-_-". If the key claim holds, the gang no longer controls the address its own leak site answers on.
Sources: Bleeping Computer · RansomLook · ransomware.live
zawoo — 3 claims, and the two trackers did not capture the same fields
ransomware.live recorded three named victims (ambpvc, FRANCARETRAD, HEOLIS). RansomLook recorded three entries over the same window carrying only opaque company identifier strings. Same batch of posts, names resolved on one side and not the other — checking this group's victim list against a single tracker will miss entries.
Sources: ransomware.live · ransomware.live · ransomware.live
emperador — Electrolux
This group's recent set has run to Latin American public bodies; this claim names a Swedish listed appliance manufacturer. No data volume was stated.
Sources: ransomware.live
n0n — Fanatics
The entry carries its own descriptor, "global sports commerce platform". This group's previous appearance was a batch of nine victims posted as a data inventory.
Sources: ransomware.live
arcus media — AKAZZO and Schneider's Computing, posted forty seconds apart
Sources: ransomware.live · ransomware.live
rhysida — Kreishandwerkerschaft Borken, a German district trades guild
Sources: ransomware.live
nightspire — Great Bay Bio
Sources: ransomware.live
Four more groups posted one claim each: bravox named TOWILL in the US, cry0 named the law firm Young Injury Law, unsafe named voltgames.io, and auditteam posted a redacted name given only as td***up. The full table is on Threat Actors.
Campaigns and activity
WaterPlum — a joint law enforcement advisory: 30,000 devices, $10.7 million moved to North Korea
The advisory states that the North Korean group compromised at least 30,000 devices worldwide between December 2025 and July 2026 and transferred more than $10.7 million in stolen cryptocurrency back to North Korea. These are cumulative figures as the advisory states them, not the scale of a single operation.
Sources: Bleeping Computer
Check Point: the July–August AI threat digest treats "the model as attack operator" as something that has already happened
Check Point Research gives the period's defining development not to attackers but to the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. On the criminal and state side it continues the trajectory of earlier editions: models now act as attack operators, with an underground supply forming around them. This is a two-month roundup rather than a single incident.
Sources: Check Point Research
N0va — a phishing kit impersonating trusted services, aimed at North America and Europe
The kit impersonates widely used services and abuses legitimate authentication flows, so a successful run leaves the attacker holding valid accounts rather than a foothold that needs malware on disk. That is what makes it quiet on the endpoint.
Sources: The Hacker News
Infrastructure and indicators
270 new C2 and malware-distribution addresses in 24 hours — the lowest of the last six issues, and Cobalt Strike is back ahead of VShell
Of the 270, 164 carry only the malware_download delivery tag and still have no family attribution. Among named families Cobalt Strike leads with 24 against VShell's 23, reversing the previous issue. The rest run Aisuru 12, PureRAT 10, AsyncRAT 7, DanaBot and DCRat 5 each. Across the last six issues the daily additions were 637 (September 15), 361, 379, 372, 365 and 270 — today is the low.
Sources: C2 Infrastructure
Hosting: the largest block is still not the best-evidenced one, and a scanning vendor sits seventh
China Unicom China169 (AS4837) leads with 1,946 hosts, of which only 416 return a Shodan record (21%). Seychelles-registered AROSSCLOUD (AS400619) holds 244 with 235 recorded (96%), carrying VShell, PureRAT and suspected Cobalt Strike. Seventh in the top ten is Censys's own AS398324, 158 hosts with 5 records — a reminder that this column counts which lists an address appeared on, not a verdict about the address.
Sources: C2 Infrastructure