Threat Watch · Sep 23, 2026
Silent Ransom Group listed four US and UK law firms in a single night, and the two trackers file the same batch under two different group names — leakeddata on RansomLook, SilentRansomGroup on ransomware.live. Anyone counting by group name tonight counts this batch twice.
Groups and claims
shinyhunters — an open letter to the FBI, and a dialysis provider on a two-day clock
The group posted an entry titled "PSA - READ THIS NOW" whose body is an open letter to FBI Cyber Division Assistant Director Brett Leatherman and Director Kash Patel, claiming it entered the agency's systems during the second quarter of this year. A second entry the same day lists Fresenius Medical Care with a 48-hour deadline expiring September 25. These are claims, not confirmed intrusions; the FBI has not responded and there is no vendor advisory for the Oracle PeopleSoft zero-day said to be involved.
Sources: RansomLook · ransomware.live
silent ransom group — four law firms in one night
Clark Hill (Detroit, full-service), Cozen O'Connor (Philadelphia), an entry written as "Hogan Lovells Cadwalader", and two redacted pending disclosure. That third name does not correspond to a single entity — Hogan Lovells and Cadwalader, Wickersham & Taft are two firms, and the tracker notes this itself; merged entries like it usually get split or withdrawn on a later pass. The choice of sector carries its own logic: one intrusion at a law firm reaches privileged communications belonging to many clients.
Sources: ransomware.live · RansomLook
settra — 6 claims, still written as narrative rather than inventory
Nam Theun 2 (the large Lao hydropower project, 1.2 TB claimed), ASM Global as operator of the Moscone Center, Lake Beverage (a beer distributor in Rochester, New York, 165 GB claimed), Universal Auto Group, the law firm Greg Jones & Associates, and Quantum Technology Marketing Group in Reading, UK. Each entry carries a headed write-up with a prologue, which is how this group presents everything, out of proportion to its volume.
Sources: ransomware.live · ransomware.live
termite — 3 claims, all US money and property
theLender (wholesale mortgage), TruAmerica Multifamily (multifamily real estate investment and asset management), and Sealcon (cable management components, Colorado).
Sources: ransomware.live · ransomware.live
qilin — 4 claims, four sectors
Columbus Informatica (software), Textile City (home improvement and hardware retail), The Fifty/50 (hospitality) and Telrad Networks (manufacturing). The group has held this no-repeated-sector spread for several issues running.
Sources: ransomware.live · ransomware.live
akira — 3 claims, all manufacturers
Coe Press Equipment (US, coil handling and servo roll feed equipment), DI.C.S.EL. S.R.L. (Milan) and TDMI. Both trackers record the same three.
Sources: RansomLook · ransomware.live
auditteam — the target set leaves the Russian-speaking world for the first time
vit.ac.in, the Indian private university Vellore Institute of Technology, plus a redacted Pr***IT. In recent issues every victim this group posted was a Russian-speaking organisation.
Sources: ransomware.live
booba team — a US public high school, 35 GB
Tulare Western High School in the Tulare Joint Union district, California, and the healthcare practice GOTTHELF (2 GB claimed).
Sources: RansomLook · ransomware.live
Anubis, kairos, lockbit5, nightspire, play, secp0, titan, n0n and unsafe each posted one to three claims with no notable target; the full table is at Threat Actors.
Campaigns and activity
CLOSEDQUORUM — the first publicly documented fully autonomous AI command-and-control implant
Cisco Talos found the Windows binary through its CAIRN project. It decides its own post-compromise actions with no operator involvement. Talos frames this as effort displacement for attackers: an expanding portion of the attack chain executes without anyone present. Bleeping Computer's reporting adds that it calls Google Gemini, DeepSeek, Qwen and Mistral models to make those decisions — no single provider it depends on, so cutting off one API does not stop it. Talos released CAIRN the same day, a research toolkit for hunting, classifying and tracking AI-integrated malware.
Sources: Cisco Talos · Cisco Talos · Bleeping Computer
EvilTokens — a device-code phishing platform dismantled after 12,000 account compromises
Microsoft's Digital Crimes Unit, with authorization from the US District Court for the Eastern District of Virginia, acted with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud and The Shadowserver Foundation to take down the platform's infrastructure and operations. Microsoft says it used AI at every step of the attack chain: lure generation, automated infrastructure, token theft. More than 12,000 Microsoft accounts at over 10,000 organisations were compromised. Device code phishing abuses the legitimate OAuth device authorization flow, so it needs no fake login page and defeats detection that only inspects the domain.
Sources: Microsoft · The Hacker News · Bleeping Computer
A Chinese-speaking actor — a switch and a CMS chained into a data pipeline
A Chinese-speaking threat actor exploited Zyxel GS1900 Smart Managed Switches (CVE-2026-7273) and WordPress flaws to take government data from 996 devices and more than 18,500 records in backend databases. The switch is not the objective in this chain; it is the hop that gets inside and stays there. CISA has added the Zyxel flaw to its exploited catalogue and given federal agencies until Thursday to patch.
Sources: Bleeping Computer
ShinyHunters — from extorting data holders to addressing law enforcement
The group says it reached internal FBI services through an Oracle PeopleSoft zero-day and holds data on current and former employees and on job applicants. Writing the claim as an open letter to the agency's leadership is a departure: the pressure it usually applies to a victim company is being applied here to a party that will not pay. All of this is the group's own account, unverified.
Sources: The Hacker News · Bleeping Computer
SideCopy — from government bodies to Indian academia, still delivering ReverseRAT
Trellix researchers observed spear-phishing against academic institutions in India, beyond the group's usual focus on government entities. The opening move is unchanged: abuse of mshta.exe to execute scripts and get past standard protections.
Sources: The Hacker News
tw-pkgprobe-7731 — an npm package posing as a Twilio bug-bounty probe
Researchers disclosed a malicious package masquerading as a security tool for developers integrating Twilio, while harvesting sensitive data. It was uploaded in mid-August 2026 by an npm account named twdepprobe7731. Dressing the payload as a security testing tool aims it at exactly the people who go and install such things.
Sources: The Hacker News
NightEagle — the GhostContainer backdoor and tooling hosted on GitHub
Kaspersky GERT documented a new campaign by this APT against Russian companies, using the GhostContainer backdoor with tools hosted on GitHub, and exploiting flaws in Active Directory and RDP. The report was published on September 16.
Sources: Securelist
Infrastructure and indicators
435 new C2 and malware-distribution addresses in 24 hours — still driven by the distribution side
318 of them are labelled malware_download, over seven in ten. Among the named families: Cobalt Strike 19, PureRAT 17, VShell 16, Remcos 12, AdaptixC2 8. The total is flat against the previous issue's 430 and well below the 514 of September 21. A further 17 carry only "Unknown malware".
Sources: C2 Infrastructure
Hosting unchanged: the largest block is still not the best-evidenced one
CHINA169, the China Unicom backbone, leads with 2,327 hosts but only 503 of them return a host record. Google Cloud is second at 400 hosts with 334 records. The densest is fourth-placed AROSSCLOUD, registered in the Seychelles, at 245 hosts and 236 records, labelled VShell, PureRAT and possible Cobalt Strike. The scanning vendor Censys still sits seventh (158 hosts, 5 records), as in recent issues — it appears in this table because it scans, not because it is being used.
Sources: C2 Infrastructure