Threat Watch · Sep 21, 2026
514 new C2 and malware-distribution addresses in 24 hours, against 270, 365, 372, 379 and 361 in the previous five issues. The increase is not broad-based: 356 of the 514 carry only the
malware_downloadlabel, and all named families together account for fewer than 70. What grew is distribution infrastructure, not named command and control.
Groups and claims
qilin — 4 new claims across four countries and four sectors
Zorlu Holding (a Turkish conglomerate), ShopDunk (Vietnam), KMLS (construction) and Touring Club Suisse (the Swiss motoring association). All four are recorded on both trackers, with timestamps less than a minute apart. This group's recent listings have kept the same shape: no two victims in the same sector.
Sources: ransomware.live · ransomware.live
bravox — TOWILL, a firm that has surveyed for US federal agencies since 1955
The listing describes the victim's business as surveying, LiDAR, photogrammetry and GIS, primarily for US federal agencies, and names the Army Corps of Engineers and the Department of Defense. Contractors like this do not themselves hold classified systems, but their deliverables — geospatial baselines, facility surveys — are tied to specific physical locations. No data volume is claimed yet.
Sources: ransomware.live
auditteam — 2 claims, targets still entirely Russian-speaking
TEK SPB, a St Petersburg heat-engineering company that designs ITP/CTP heat points, manufactures ZEVS-brand equipment and handles commissioning and maintenance; plus an entry redacted to st***co. This group writes its victims up as "audit entries" carrying an AUDIT ID and a discovery date, a format no other leak site uses.
Sources: ransomware.live · ransomware.live
emperador — 2 claims, both with a publication date announced
Alabama Woman's Health Care in Huntsville, said to hold several thousand employee and client documents plus an archive of photos, and a notary's office in Follina, Italy, said to include a large volume of customer documents and employee data. Medical practices and notaries share a profile: high document density, high per-document sensitivity, small organisation.
Sources: ransomware.live · ransomware.live
inc ransom and orova — 2 each
inc ransom listed Second House, a Barcelona real estate company, and an orthodontic practice. orova listed Siddhi Green Excellence in India (environmental testing and chemical consultancy) and Euramex Management Group in Atlanta, whose entry text actually describes the affiliated Avila Real Estate and its 25 multifamily developments.
Sources: ransomware.live · ransomware.live
Four more: an Ethiopian bank, and one claim filed under two different group names
lockbit5 listed Siinqee Bank, a licensed Ethiopian financial institution; dragonforce listed ARS Renacer, a Dominican health risk administrator; krybit listed Ahluwalia Contracts (ACIL), one of India's largest civil construction firms. Newman Tractor, a Kentucky heavy equipment dealer, appears on both trackers — but RansomLook records it under 3am and ransomware.live under Threeam. One claim, two group names, and any count keyed on group name treats it as two.
Sources: ransomware.live · RansomLook
Campaigns and activity
[Added detail] Jade Sleet — the victim is an Indian IT services provider, and the backdoors are named FLATROOF and ROOFDECK
The North Korean intrusion SentinelOne described now has a victim profile and tool names: the compromised organisation is an India-based IT services company, which SentinelOne calls "a much smaller organization," and the backdoors deployed are FLATROOF and ROOFDECK. The entry point remains developers — the route this adversary returns to repeatedly: not attacking the target network, but the people who write code for it.
Sources: The Hacker News · SentinelOne
indexed-btree — an npm campaign moves its logic out of install scripts
An ongoing npm malware campaign around the indexed-btree package hides its malicious code in the package's normal runtime behaviour rather than in installation scripts. The move targets where the checkpoint sits: supply chain tooling generally watches preinstall and postinstall, because that is where the overwhelming majority of npm malware has historically acted. Defer the action until after require, and install-time observation sees nothing at all.
Sources: Bleeping Computer
[Added detail] ShinyHunters breached Cl0p's leak site and claims the private keys for its onion service
The extortion note seen on the leak site corresponds to an actual intrusion: ShinyHunters compromised the Cl0p ransomware operation's data leak site, defaced its Tor page, and claims to have taken server data along with the private keys for the onion service. Those keys are not like other stolen data — whoever holds them can stand up a site at the same address, and a visitor cannot tell the difference from the address alone.
Sources: Bleeping Computer
Mass scanning against Vite development servers — the target is cloud credentials and infrastructure state files
F5 Labs documented an automated campaign against internet-exposed Vite development servers that steals AWS and Azure cloud credentials, configurations, and infrastructure state files. What it takes explains the intent: a development server holds little worth extorting, but the state file and credential sitting next to it lead to production. This campaign has not appeared in earlier issues; it was reported on September 15.
Sources: The Hacker News
Infrastructure and indicators
514 new C2 and distribution addresses in 24 hours — the highest across the last six issues, and the growth is on the distribution side
By label: 356 malware_download, 69 unlabelled "Unknown malware" — 83% between them. Among named families, VShell has 20 and Cobalt Strike 16. Cobalt Strike had just retaken the lead in the previous issue and the order flips back here, but both sit around twenty, and at that magnitude the ordering is not a trend. The rest: Aisuru 10, AsyncRAT 10, Vidar 6, PureRAT 5, Jackskid 4, AdaptixC2 4.
Sources: C2 Infrastructure
Hosting: the largest block is still not the densest one, and the scanning vendor is still seventh
CHINA169 leads with 2,024 hosts, but only 441 of them return any port or service record. The densest is third-placed AROSSCLOUD in the Seychelles: 235 of 244 hosts carry a record, labelled VShell, PureRAT and possible Cobalt Strike. Censys remains seventh (158 hosts, 5 with a record) — a scanning vendor's probe nodes swept into indicator lists by various feeds, in the same position as the previous issue. Tenth is Globe Telecom's mobile network in the Philippines (97 hosts, 93 with a record, every one labelled malware_download): carrier mobile address space used as a distribution landing point, which is a different kind of block from the cloud and hosting networks above it.
Sources: C2 Infrastructure