Threat Watch · Sep 25, 2026
Microsoft this week collapsed the deployments of four ransomware brands into one affiliate: Storm-2570 uses the same post-compromise tools and techniques whether it lands Qilin, DragonForce, Anubis or BERT. In this issue's 36-hour window, the two highest-volume posters are exactly Qilin (6 claims) and DragonForce (5). That does not make these 11 claims Storm-2570's — under the affiliate model brands and operators are many-to-many — but it does mean that counting claims by brand has never been counting one thing.
Groups and claims
qilin — 6 claims, six sectors
Dao Group (software), All Tech Machine & Engineering (industrial machinery), Inversiones Bolívar (insurance), Zig Inge Group (real estate), GDM Pipelines (software) and Agora coopérative agricole (a French agricultural cooperative). No sector concentration and no publication date on any of them. All six appear on both RansomLook and ransomware.live, making Qilin the only group this issue whose entire set is independently recorded by both trackers.
Sources: RansomLook · ransomware.live
dragonforce — 5 claims, two in Taiwan, one of them already self-disclosed
winfashion (a B2B ERP platform for the fashion industry, posted with its own "data leak analysis"), Arizona Vascular Medical Equipment (compression therapy and vascular care devices, Mesa, Arizona), BMGP Groupe (a French manufacturer of synthetic resins and technical polymers), Elite Industech (a Class-A waste treatment plant in Kaohsiung) and HEC Group. HEC Group is worth separating out: the post quotes the company's own August 30 statement to TPE:3032 shareholders and stakeholders confirming it had been targeted — so the victim confirmed the attack before the leak site published, which is the minority case in this table.
Sources: RansomLook · ransomware.live
krybit — 3 claims, one of them a national airline
airtanzania.co.tz / airtanzania.com (Air Tanzania Company Limited, the national flag carrier, established 1977), efada.sa, and jonesthegrocer.com (a premium gourmet food retail and cafe brand founded in Sydney in 1996). The airline is the only claim this issue against a state-owned infrastructure operator.
Sources: RansomLook · ransomware.live
imnotavillain — 2 claims, one named after a bank and one named after a country
One advertises Revolut data for sale, including 680 high-net-worth users. The other is titled simply "Italy" and asserts the country failed to follow data protection law, citing 85,000-plus files at 150 GB with "top departments, units, offices affected". Both are sale listings with no sample description and no named entity or system. The name does not match anything in our actors table — this morning's collection log recorded it, along with Booba project, Medusalocker, Silentransomgroup and Threea, as an unmatched group and skipped it, so it has no profile page on the site.
Sources: ransomware.live · ransomware.live
storm — 2 claims, aerospace and litigation support
Applied Composites (Lake Forest, California; advanced composite components, assemblies, engineering and tooling for aerospace and defense) and Magna Legal Services (Philadelphia; nationwide litigation support for law firms, corporations and insurers). What the two share is data density rather than size: one holds engineering drawings for defense subcontract parts, the other holds case files.
Sources: RansomLook
the gentlemen — 3 claims, three countries
ENKEI's U.S. production entity (factory light-alloy aluminium wheels supplied to automakers, not retail), Charles & Keith (the Singapore fashion brand) and Ligue-se Grupo (an IT and business-services group in Funchal, Madeira). The group posted 18 claims at once in the last issue; this is a return to routine volume.
Sources: RansomLook
The remaining eleven
inc ransom posted 4 (including the Brazilian insurance group Grupo Caberj and the domain of a Macau law firm), pear 3 (all in the U.S.: two healthcare providers and a fine art gallery), zawoo 3 (all in France: accounting advisory, technical supply, PVC joinery manufacturing), akira 2 (a Minnesota construction contractor and a carbonation equipment maker), wallstreet 2 (a Texas law firm and the Catholic University of El Salvador), and one each from rhysida, lockbit5, barracuda, spirals and n0n. Two worth noting: spirals named Armada Credit Bureau, a licensed credit reporting and analytics company, and n0n's TapClicks claim asserts the complete platform source code including 97,000-plus commits of full history. The full table is at Threat Actors.
Sources: RansomLook · ransomware.live
Campaigns and activity
Storm-2570 — four ransomware brands, one post-compromise toolset
Microsoft Threat Intelligence attributes deployments of Qilin, DragonForce, Anubis and BERT to a single affiliate, on the basis of consistent post-compromise tools and techniques before the ransomware lands rather than the encryptor itself. That is Microsoft's attribution. The defensive consequence is more immediately useful than the naming: if one toolset spans four brands, detection written around the encryptor family misses the longest stretch of dwell time, which is the only part still early enough to interrupt. Microsoft's write-up is guidance for disrupting the activity before deployment.
Sources: Microsoft Threat Intelligence
UNK_CondorFiltration — TeamFiltration against Chilean retail and finance, with a hit rate of 7 in 5,700
Proofpoint disclosed an active campaign using the public TeamFiltration tool across 28 Microsoft 365 tenants and more than 5,700 accounts, focused primarily on Chilean retail and financial institutions, originating from 1,487 unique AWS EC2 source IP addresses. Seven accounts were compromised, via default passwords. The tool is public, the infrastructure is rented, and the way in was an initial password nobody changed — none of the three required capability.
Sources: The Hacker News
Psychedelic — fake Cloudflare verification pages on legitimate Ukrainian sites
The campaign compromises working Ukrainian business websites and injects bogus Cloudflare verification pages that deliver a previously undocumented information stealer called Psychedelic. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs them to paste and run it. In the same week CTM360 published a ClickFix report saying it has collected 17,000 related URLs and describing the technique as a productized subscription service with on-chain infrastructure and a state-sponsored user base — the vendor's own framing, not independently reproduced.
Sources: The Hacker News · The Hacker News
Carbonato — take the Docker daemon, then make an AI agent framework the control plane
A new botnet malware called Carbonato targets insecure hosts running Docker daemons and installs the Hermes Agent AI framework on compromised hosts to take control. The notable part is that the agent framework goes on the victim rather than on the operator's side: the control logic then runs on the victim's compute, and the traffic looks like that host making ordinary calls to a model API.
Sources: Bleeping Computer
MacSync — delivery moves to public iCloud calendar events, plus a new backdoor module
Kaspersky and Bleeping Computer recorded a new version of the macOS stealer MacSync the same day: it uses public iCloud calendar events to deliver new native payloads and adds a backdoor module, targeting crypto users and developers. The point of calendar events as a delivery channel is that they are ordinary sync traffic under Apple's own domains, so egress controls written around domains see no difference.
Sources: Securelist · Bleeping Computer
Corp MDM — Android spyware wearing freight brands, aimed at logistics
The campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an APK dressed up as a system service, package name com.corp.mdm, which steals newly received SMS and redirects incoming calls. Recorded by Have I Been Squatted. Taking both SMS and calls says the objective is account verification codes and outbound contact, not the device.
Sources: The Hacker News
Compiling the miner on the endpoint — Samsung MagicINFO to AnyDesk to a locally built Monero miner
An intrusion recorded by Huntress: the actor exploited Samsung MagicINFO to install AnyDesk, disabled Defender, and then compiled a Monero miner directly on the victim endpoint. Building on the target instead of dropping a finished binary evades everything keyed to file hashes and known malicious binaries — at the cost of leaving a much louder behavioural trace in the compiler invocation.
Sources: Huntress
Rogue RMM and the management plane — two surface observations from this week
Huntress's SOC recorded phishing attacks that trick employees into installing remote management tools such as ScreenConnect themselves, giving persistent access; a legitimate RMM tool's signature and traffic are both normal, so that access is hard to separate from outsourced IT in the logs. Separately, an InfraTrust report says attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities exploited in the wild before or shortly after vendor disclosure.
Sources: Huntress · Bleeping Computer
Infrastructure and indicators
355 new C2 and malware-distribution addresses in 24 hours — the lowest in six issues, and Remcos tops the named families for the first time
By label: malware distribution 277, Remcos 15, unlabelled 12, PureRAT 12, Cobalt Strike 11, AsyncRAT 10, then AdaptixC2 4 and VShell 3. The total of 355 is below the previous four issues (406 on September 24, 435 on the 23rd, 430 on the 22nd, 514 on the 21st) and above only September 20's 270. The structural change is at the head of the named families: recent issues have seen Cobalt Strike, VShell and PureRAT take that position, and this is the first time Remcos has. This is a count, not a trend.
Sources: C2 Infrastructure
Hosting: the largest block is still not the best-evidenced one, and AROSSCLOUD has the highest density in the top ten
China Unicom's China169 backbone (AS4837) leads with 2,582 hosts, of which only 550 have a Shodan record. Google Cloud (AS396982) has 334 records across 401 hosts. Seychelles-registered AROSSCLOUD (AS400619) has 236 records across 245 hosts — 96%, the highest ratio in the top ten — with family labels concentrated in VShell, PureRAT and suspected Cobalt Strike. The contrast holds from previous issues: the networks with the most addresses are showing broadband and cloud scale, while the ones with dense evidence are the ones rented specifically to stand infrastructure up. Scanning vendor Censys (AS398324) sits eighth this issue, with 5 records across 158 hosts.
Sources: C2 Infrastructure