Threat Watch · Sep 24, 2026
Cl0p posted 23 claims inside roughly one minute around 17:32 on September 23 — the largest single batch in recent issues. Four days earlier, on September 19, ShinyHunters claimed it had breached Cl0p's leak site and taken the private keys to its onion service. The relationship between the two is, so far, sequence only: neither party has stated a causal one.
Groups and claims
clop — 23 claims inside a minute
The batch spans law, government, finance, retail and the security industry itself: Kirkland & Ellis (international law firm), Transport for NSW (the Australian state transport agency), Columbia Bank / Umpqua Bank (US regional banking), Brinks New Zealand, Infinigate (European security product distribution), Aldo Group, Suunto, E-Land Retail (South Korea), Amey (UK infrastructure services), Palig, SAUL (UK pensions), UniSalle (Colombia), CCED (Oman) and DAD-CO (Thailand). Entries carry domains and no descriptions, the usual shape of a Cl0p batch. The Infinigate entry is worth separating out: a security product distributor holds deployment records for its downstream integrators and end customers.
Sources: RansomLook
emperador — Brazil's federal tax authority, and a US last-mile carrier
Emperador claims archives from Receita Federal do Brasil, the federal revenue service under the Ministry of Finance, describing several thousand documents of personnel and customer data along with all user data and passwords on gov.br — 6.3 GB, with publication scheduled for October 13, 2026. The same group posted OnTrac, the US last-mile e-commerce delivery company formed by the 2021 LaserShip–OnTrac merger, which reaches over 75% of the US population. A claim against a national tax authority is uncommon on leak sites; these remain claims, not confirmed intrusions.
Sources: ransomware.live · ransomware.live
booba team — 4 claims, two of them US county governments
Merrimack County, New Hampshire (3 GB) and Washington County, Maine (2 GB), alongside COSEF, the economic development consortium for Italy's Friuli region (200 GB), and US optometry provider Smart Eye Care (7 GB). Neither county set is large, but county government holds voter registration, tax and court records — identity data that cannot be reissued. Both trackers independently recorded the same batch.
Sources: RansomLook · ransomware.live
akira — 3 claims: two US professional services firms and a Slovenian gaming group
Apex Litigation Support (litigation services for attorneys and law firms, with 77 GB of corporate data said to be coming), Urban Engineering (engineering services, headquartered in Annandale, Virginia), and HIT d.d. (hotel and casino group in Nova Gorica, Slovenia, operating multiple resorts). Both trackers record the three consistently.
Sources: RansomLook · ransomware.live
endzone — Trump Mobile and eTeam
Endzone posted Trump Mobile, the US mobile virtual network operator that licenses the Trump Organization brand and was launched by Donald Trump Jr. and Eric Trump, stating the held data includes eSIM QR codes and user PII, with a jibe about the operator having only around 4,000 users. The same batch carries eTeam Inc., a global workforce solutions and business transformation firm with roughly $229 million in revenue.
Sources: ransomware.live · ransomware.live
[Added detail] shinyhunters — a second statement to the press, alongside the Fresenius clock
The two-day deadline against Fresenius Medical Care is still running, expiring September 25. The group separately posted a "PRESS RELEASE RE PSA" setting out a sample distribution policy: it is not currently distributing samples to any media agency, it had provided samples to a select group of prominent US media organizations solely to verify its claims, and it restricts sharing to established mainstream agencies.
Sources: RansomLook
the gentlemen — a Singapore fashion brand and a Portuguese IT group
Charles & Keith, the Singapore-based women's footwear and accessories brand founded in 1996 on a vertically integrated model, and Ligue-se Grupo, a Portuguese IT and business-services group founded in 2009 in Funchal, Madeira, which runs the Chip7 computer retail chain.
Sources: RansomLook
Around ten further groups posted one or two claims each in the same window, among them Barracuda, rhysida (the Latin American legal publisher Legis), spirals (Oman's Asyad Group), brain cipher, space bears, titan, inc ransom, lockbit5, arcus media, medusalocker and blacklocks. The full table is on Threat Actors.
Campaigns and activity
UTA0565 — a Chrome and Windows zero-day chain delivering CLEANGULP
A Chinese threat actor codenamed UTA0565 used fake websites to chain two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows Advanced Local Procedure Call flaw (CVE-2026-85880), breaking out of the sandbox while all three were still zero-days and deploying the CLEANGULP malware. The activity was observed on September 3 and 4, 2026. All three CVEs are now in the KEV catalogue — CVE-2026-85046 added September 4, the other two on September 8 and 9 — so exploitation preceded cataloguing.
Sources: The Hacker News
Open-source AI agent frameworks as skimming automation — 600,000 cards, more than 100 sites
A financially motivated actor used open-source AI agent frameworks to attack hundreds of online retailers at scale, planting skimmers on more than 100 sites and stealing over 600,000 credit card records. The role is worth separating: the agent framework is not the target here, it is the attacker's means of scaling manual work. This is not the same category as the other AI thread this week — Talos's CLOSEDQUORUM, an implant that puts its next move to a vote of models. CLOSEDQUORUM delegates the decision; this case only automates the execution.
Sources: Bleeping Computer
The HashiCorp Registry becomes a delivery surface — two Terraform providers and two Go modules
Aikido disclosed Go-based malware distributed through HashiCorp's centralized registry, across two Terraform providers and two Go modules, including gocommunity-io/dockerd with 222 downloads. Package-registry delivery has until now concentrated on npm and PyPI. What makes Terraform providers distinct is that they execute with high privilege inside CI and infrastructure pipelines, and generally fall outside the coverage of application dependency scanning.
Sources: The Hacker News
DarkMe — an APT-linked RAT known for zero-days turns up as a plain infostealer
Huntress encountered DarkMe, a VB6 remote access trojan linked to APT activity and known for using zero-day exploits, in two incidents. In both it was stripped down to a plain .pif infostealer with no exploitation stage at all. Huntress's reading is that the family has abandoned its previous delivery; a tool separating from its delivery method suggests the code itself may have moved beyond its original operators.
Sources: Huntress
OAuth token theft through a Microsoft-signed binary
Huntress documented a technique in which a sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. There is no phishing domain, no spoofed interface and no browser involved — which means detection keyed on domain reputation, interface anomalies or browser behaviour misses this path entirely. Huntress published detection guidance.
Sources: Huntress
third-party.com — a placeholder domain from developer documentation now serves ClickFix
The third-party.com domain, long used as a placeholder in developer documentation and code examples, now returns a fake Cloudflare verification page that tries to get Windows users to run PowerShell commands. The value of a placeholder domain is exactly its provenance: it appears across tutorials, sample code and copy-pasted configuration, so visitors arrive expecting an address from the docs.
Sources: Bleeping Computer
RemControl — Android banking malware-as-a-service aimed at Europe and Canada
A new Android malware-as-a-service platform called RemControl is reaching users through malvertising campaigns that impersonate the TVTap IPTV application, targeting Europe and Canada.
Sources: Bleeping Computer
Ryuk — a member sentenced to 24 months
An Armenian man was sentenced to 24 months in prison and three years of supervised release for hacking US companies and encrypting their systems in Ryuk ransomware attacks.
Sources: Bleeping Computer
Infrastructure and indicators
406 new C2 and malware-distribution addresses in 24 hours — PureRAT enters the top five for the first time
By label, malware_download accounts for 304 and remains the bulk, followed by Cobalt Strike at 15, VShell at 14, PureRAT at 12, AsyncRAT at 11, Aisuru at 8 and Remcos at 8. The total sits mid-range across the last six issues (514 on September 21, 435 on the 23rd, 430 on the 22nd, 365 on the 19th, 270 on the 20th) and is still driven by the distribution side rather than by C2. PureRAT's 12 addresses put it fourth among named families; it has not appeared in the named list of previous issues.
Sources: C2 Infrastructure
Hosting: the largest block is still not the best-evidenced one
CHINA169, the China Unicom backbone, leads with 2,447 hosts but only 524 carry a hosting record; Google Cloud has records for 334 of its 401. The densest evidence remains AROSSCLOUD (AS400619, registered in the Seychelles), with records on 236 of 245 hosts and families listed as VShell, PureRAT and possible Cobalt Strike — the same two families that rose in today's new-indicator labels. Seventh place is Censys (158 hosts, 5 with a record), a scanning vendor rather than attack infrastructure, a position unchanged across several issues. Globe Telecom in the Philippines sits tenth with 105 hosts, 101 of them with records, all labelled malware_download.
Sources: C2 Infrastructure