Threat Watch · Sep 26, 2026
Everest posted six claims in one afternoon across four continents: Securitas Group, the Swedish multinational security services firm; CENELEC, the European electrotechnical standardization committee in Brussels; UNIRITA, a Tokyo IT operations software vendor; and Morula IVF, an Indonesian fertility clinic network. Two more — Reliance Audit and ETS — carry names too generic for the trackers themselves to resolve. There is no shared sector in the batch and no shared region.
Groups and claims
everest — 6 claims, four continents, no shared sector
Two of them are not the commercial firms that usually fill a leak site: Securitas Group is a Stockholm-headquartered multinational security services company, and CENELEC is the Brussels-based European Committee for Electrotechnical Standardization. The others are UNIRITA in Tokyo and Morula IVF in Indonesia. For the remaining two, Reliance Audit and ETS, the tracker's own note is that the names are too generic to identify which organization is meant. All are claims, not confirmed intrusions.
Sources: RansomLook · ransomware.live
wallstreet — 5 claims, all small organizations
Tobin & Company, a Harrison, New York accounting firm working largely with nonprofits; AR Valve Resources, an industrial valve distributor in Kent, UK; Beatus Cartons, a UK folding-carton manufacturer founded in 1940; Breast Implant Center of Hawaii, a plastic surgery clinic in Kailua-Kona; and GTFM, about which little is public. Both trackers recorded the same set independently.
Sources: RansomLook · ransomware.live
metaencryptor — 3 claims, one of them a listed energy equipment maker
GE Vernova is the global energy equipment and services company formed from General Electric's energy businesses, headquartered in Cambridge, Massachusetts. The other two are PKF Hadiwinata, a top-ten Indonesian accounting and professional services firm, and Platinum Healthcare Staffing, a Louisiana healthcare staffing agency.
Sources: ransomware.live
lockbit5 — 3 claims, one each in Indonesia, Brazil and Italy
Indonesian insurer Taspen Life, Brazilian home care provider Anery Home Care, and Italy's CO.R.I.S. All three entries give a domain and a short company description and nothing else.
Sources: ransomware.live
pear — 3 claims, two healthcare providers and an art gallery
Ambulatory endoscopy center Westside GI, Indroj Medical Group, and US fine art dealer Martin Lawrence Galleries.
Sources: ransomware.live
[Added detail] emperador — the follow-up post on Electrolux and OnTrac describes a pretext call to the helpdesk
The new post says the group phoned the victim's IT helpdesk posing as threat researchers to ask about the breach, and was told "We cannot talk about it." The post sets a new deadline. Writing a social engineering attempt into the extortion notice itself is an unusual form of pressure. This is the group's own account and is unverified.
Sources: ransomware.live
Another eleven claims
Silent Ransom Group posted two with the company names redacted and a "full data timer" running; the gentlemen listed FTAPI Software, a Munich platform for compliant exchange of sensitive business data; n0n claims the complete platform source code of marketing analytics vendor TapClicks, said to include 97,000-plus commits of history and the multi-tenant instance management system; inc ransom claims 50GB from Moroccan pharmaceutical manufacturer Pharma5. One each from qilin (Iberia Compositech Manufacturing), vexy (Majani Insurance Brokers), spirals (Armada Credit Bureau), krybit (efada.sa) and termite (US petroleum transporter Crossett).
Sources: RansomLook · ransomware.live
Campaigns and activity
Storm-3168 — Azure reconnaissance and resource deletion run through compromised service principals
Microsoft Threat Intelligence names Storm-3168 for a set of Azure-directed activity it associates with JADEPUFFER. The entry point is compromised service principals — application identities rather than human accounts — and the observed actions are environment reconnaissance, resource deletion and credential access. Microsoft's term for it is agentic-driven, meaning a degree of automation beyond the hands-on-keyboard cloud intrusions it has previously documented, and the write-up carries detection and defender guidance.
Sources: Microsoft Threat Intelligence
[Added detail] UNC6240 (ShinyHunters) — a new wave of PeopleSoft mass exploitation, and a WAF rule that falls to one character
Mandiant and the Google Threat Intelligence Group record renewed mass exploitation of CVE-2026-35273 by the group. In June it was exploited as a zero-day, predominantly against academic institutions; Mandiant describes this wave as expanded targeting across multiple sectors and regions. What had been stopping it was a string-matching WAF rule blocking the vulnerable PSEMHUB endpoint, and the actor got past it by URL-encoding a single character in the request. Attribution is Mandiant's.
Sources: Mandiant
[Added detail] Clop — the leak site was taken through an unauthenticated Grav CMS path traversal, and has moved to a new Tor address
The group confirmed its previous server was compromised and defaced through an unpatched Grav CMS flaw; Bleeping Computer has learned that flaw is an unauthenticated path traversal. The data leak site now runs at a new Tor address.
Sources: Bleeping Computer
Ledger phishing — Google ads into Google Cloud Storage into Vercel into an iframe on Google Sites
Zscaler ThreatLabz analyzed an August 2026 campaign in which fraudulent Google ads redirected users through Google Cloud Storage and Vercel to a Google Sites page carrying a Ledger-impersonating phishing page inside an iframe. During analysis the Vercel redirect changed every 15 to 20 minutes. A fake device-verification flow prompted victims for their secret recovery phrases, which give wallet access without the physical device. Every hop in the chain sits on a legitimate cloud or site-building service.
Sources: Zscaler ThreatLabz
PamStealer — the macOS stealer moves payload decryption server-side, so the body only exists online
The new version flagged by Jamf Threat Labs keeps the same JavaScript for Automation (JXA) dropper mechanism but changes the lure and the delivery method. The change that matters is in the keys: earlier variants embedded the payload key material in the artifact, while the main payload in this version can only be recovered through a server-side decryption chain. For analysts that means a sample without a live C2 does not yield the thing that would have run.
Sources: The Hacker News
Mini Shai-Hulud — two compromised GitHub Actions came back online and resumed executing their payload
actions-cool/issues-helper and actions-cool/maintain-one-comment were compromised during the May 2026 Mini Shai-Hulud campaign. Last week both repositories became accessible again and went back to executing malicious code, so they were disabled a second time. Visiting either now returns an access-restricted message. A compromised CI component that is taken down but still referenced starts executing again the moment it becomes reachable.
Sources: The Hacker News
Rydox — the operator pleads guilty and faces 22 years
A Kosovar national pleaded guilty to running Rydox, a marketplace that sold stolen personal information, login credentials, credit card details and cybercrime tools.
Sources: Bleeping Computer
Infrastructure and indicators
384 new C2 and malware-distribution addresses in 24 hours — distribution still dominates
Of the 384, 303 are labelled malware_download. The named families behind the rest: AsyncRAT 10, Potassium 8, Aisuru, Remcos and Cobalt Strike 7 each, Drifter 6, PureRAT 5, and AdaptixC2, Quasar RAT and VShell 4 each. Against the same query in the last five issues (514 on September 21, 430 on the 22nd, 435 on the 23rd, 406 on the 24th, 355 on the 25th), today's 384 halts a four-issue slide while staying below the first half of the week. The top of the named-family list keeps rotating among the same four RATs; no new name entered the top five.
Sources: C2 Infrastructure
Hosting picture: the largest block is still not the best-evidenced one
The CHINA169 backbone leads with 2,702 hosts, but only 566 of them carry a host record. The densest is Seychelles-registered AROSSCLOUD: 236 of 245 hosts have records, 96%, tagged VShell, PureRAT and possible Cobalt Strike. Google Cloud is second with 401 hosts and 334 records, tagged Sliver and Evilginx. Eighth on the list is Censys with 158 hosts and just 5 records — that is a scanning vendor's address space, not C2, and it appears here because of what the indicator feeds choose to list.
Sources: C2 Infrastructure