Rosetta Intel
Briefings/Daily BriefAI FrontierThreat Watch
Rosetta Lab ↗contact@rosettalab.devclick to copy
© 2026 BlurHorizon, LLC
Threat Watch

Threat Watch

Adversary activity

Ransomware claims, intrusion campaigns, malware families and the infrastructure behind them.

112 Issues · Page 1 / 4

2026-09-26
Threat Watch · Sep 26, 2026

Microsoft names Storm-3168 for agent-driven Azure reconnaissance and resource deletion carried out through compromised service principals, linking the activity to JADEPUFFER. Mandiant records a new wave of UNC6240 mass exploitation against Oracle PeopleSoft, where the WAF bypass is one URL-encoded character. Clop confirms its leak site was taken through an unauthenticated Grav CMS path traversal and has moved to a new Tor address. On the trackers, Everest posted six claims in one afternoon across four continents.

16 Items
2026-09-25
Threat Watch · Sep 25, 2026

Microsoft attributes deployments of Qilin, DragonForce, Anubis and BERT to one affiliate, Storm-2570, on the basis of a consistent pre-encryption toolset. A TeamFiltration campaign works Chilean retail and finance, compromised Ukrainian business sites serve fake Cloudflare pages for the Psychedelic stealer, and Carbonato installs an AI agent framework on the Docker hosts it takes.

17 Items
2026-09-24
Threat Watch · Sep 24, 2026

Cl0p posted 23 victims in a single batch, among them an international law firm, an Australian state transport agency, a US regional bank and a security product distributor; Emperador claims data from Brazil's federal tax authority. On the campaign side, the China-nexus actor UTA0565 chained Chrome and Windows zero-days to deploy CLEANGULP, and a separate actor used open-source AI agent frameworks as the automation behind card skimming at scale.

17 Items
2026-09-23
Threat Watch · Sep 23, 2026

ShinyHunters posted an open letter to the FBI on its leak site and, the same day, put Fresenius Medical Care on a two-day countdown; Silent Ransom Group listed four US and UK law firms in one night. In campaigns: Talos documents CLOSEDQUORUM, the first reported fully autonomous AI command-and-control implant, and releases the CAIRN toolkit, while Microsoft's Digital Crimes Unit and partners dismantle the EvilTokens device-code phishing platform.

18 Items
2026-09-22
Threat Watch · Sep 22, 2026

the gentlemen posted 18 claims in one batch — about a third of the day's total — across thirteen countries, and metaencryptor named six manufacturing and supply-chain firms at once. On the activity side: PAYLOAD ransomware encrypts nothing and drops no binary, working through Active Directory Group Policy instead; Vidar's string obfuscation is now a per-build virtual machine; and ClickFix lures deliver a RAT that rotates its C2 through the Polygon blockchain. Indicators: 430 new addresses in 24 hours, the highest of the last six issues.

17 Items
2026-09-21
Threat Watch · Sep 21, 2026

A batch of four qilin victims spanning four countries and four sectors, a bravox listing naming a surveying contractor to the US Army Corps of Engineers and the Department of Defense, and auditteam still working only Russian-speaking targets. An npm campaign moves its malicious logic out of install scripts and into runtime, past defenses that check installation hooks. On the indicator side: 514 new addresses in 24 hours, the highest across the last six issues, with almost all of the increase in one category.

12 Items
2026-09-20
Threat Watch · Sep 20, 2026

ShinyHunters breached Clop's leak site and left an extortion note, which both trackers ingested as an ordinary victim entry. A joint law enforcement advisory ties North Korea's WaterPlum to 30,000 devices and $10.7 million in cryptocurrency. 270 new C2 addresses in 24 hours, the lowest of the last six issues, with Cobalt Strike back ahead of VShell.

13 Items
2026-09-19
Threat Watch · Sep 19, 2026

n0n posted nine victims at once, writing the entries as data inventories rather than company names: 86.7M connection records from PayPal's outsourced support operation, 15.3M subscriber records from Venezuela's largest ISP, the network-security configuration of Argentina's education ministry. North Korea's TraderTraitor backdoors turned up on a DevOps engineer's Mac with no crypto ties, and two new stealers arrived through npm and impersonated GitHub repositories. In the indicators, VShell displaces Cobalt Strike as the largest named family.

13 Items
2026-09-18
Threat Watch · Sep 18, 2026

Two unrelated groups claimed AECOM on the same day, and storm posted four US community banks and wealth managers at once. ESET documents FamousSparrow deploying a new SparroWocky backdoor across Latin America, Zscaler details APT36's new Rust-based toolset, and Handala Hack is tied to the HEAVYGRAM Telegram backdoor. The FBI seized NightmareStresser.

19 Items
2026-09-17
Threat Watch · Sep 17, 2026

Kaspersky separates three clusters hitting Russian enterprises: NightEagle with the GhostContainer backdoor and tooling hosted on GitHub, alongside Hacking Cat and Toy Ghouls. Mandiant documents an attacker hijacking an AI coding-assistant session and spreading the Shai-Hulud worm across about 100 internal repositories. On the leak sites, inc ransom and Auditteam each posted six claims, and ransomhouse claims the Namibian Defence Force.

15 Items
2026-09-16
Threat Watch · Sep 16, 2026

safepay posted nine victims in one batch, among them Peru's national government portal and a Swiss wastewater treatment operator, while metaencryptor listed Nippon Steel and South Korea's SFA Engineering on the same day. Elastic tracked the KREMLIN banking extension across seven campaigns and fifteen months: it forges Chrome's own integrity checks and keeps its C2 configuration in Ethereum smart contracts. 361 new C2 and malware-distribution addresses in 24 hours.

14 Items
2026-09-15
Threat Watch · Sep 15, 2026

the gentlemen posted 30 victims at once, close to half of the 66 claims both trackers recorded today, with no country or sector in common. Three China-linked operations surface: UTA0560 delivering the GRIMWEDGE backdoor through patched Chrome and Windows flaws, and Red Heron scanning 1,386 Gitea instances while keeping a separate list of 477 Taiwan-based systems. The indicator mirror took 637 new C2 addresses in 24 hours, roughly double the last five issues.

15 Items
2026-09-14
Threat Watch · Sep 14, 2026

ShinyHunters has put Kimberly-Clark under a final notice expiring Sep 16, and Barracuda claims 693 GB taken from i2i-systems, 44 GB of it product source code and build artefacts. The exploited Sogou Input Method flaw now carries a CVE number, and the executive-impersonation campaign Microsoft disclosed sent over a million emails in three days. 347 new C2 and malware-distribution addresses in 24 hours.

10 Items
2026-09-13
Threat Watch · Sep 13, 2026

krybit posted twelve claims in one batch, close to half of this issue's total, across eleven countries with no sector in common. global listed one small Massachusetts town's government and its school district as separate claims. Researchers attribute May's RubyGems supply-chain attack to a swarm of OpenAI agents, and Huntress tracks GTA6 rumour SEO poisoning that delivers stealers and wiper ransomware together.

10 Items
2026-09-12
Threat Watch · Sep 12, 2026

Anthropic publishes its first systematic account of threat groups using Claude — secrets pulled from 1.8 million Android apps, and a Russian state-sponsored cluster rebuilding malware faster than detection catches up. The Artifactory pair became a delivery path, planting a Rust backdoor in the registry build servers pull from, and UNC3569 used a Sogou Input Method flaw to drop the GRAYRABBIT backdoor. On the indicator side: 342 new C2 and malware-distribution addresses in 24 hours, plus 158 addresses inside a scanning vendor's own network filed as malware.

17 Items
2026-09-11
Threat Watch · Sep 11, 2026

Five unrelated groups each posted a healthcare victim within 36 hours, with Rhysida claiming 2.44 TB of patient records from a Philippine hospital. The PaperCut operator used hundreds of AI agents to build its exploitation and reached 395 organizations; Zscaler documents SloppyRAT, a new family delivered by ClickFix that resolves its command and control through the Polygon blockchain. Microsoft details an ACH payment fraud campaign built on AI-generated executive impersonation.

14 Items
2026-09-10
Threat Watch · Sep 10, 2026

storm posted 40 claims in a two-minute burst, 44% of the day's 90, spanning hospitals, hospice care, municipal government and defense manufacturing across four countries. black nevas listed a Canadian MSP and four of its clients in the same batch. The BlueMoon exploit chain appeared in four espionage groups' hands within a week, its first in-the-wild use attributed to APT31, and AI service tokens pulled from infostealer logs are replayable with MFA playing no part.

13 Items
2026-09-09
Threat Watch · Sep 9, 2026

Google Threat Intelligence Group puts a clock on adversarial agent use: under six hours from compromising a cloud resource to completing a mass credential harvest. The same day, Talos documents a ClickFix variant running command and control out of a Google Sheets document. Leak sites added 30 claims, ten of them from Safepay alone; a Linux rootkit turns up in F5 BIG-IP environments and Slim Spider targets Brazilian finance.

15 Items
2026-09-08
Threat Watch · Sep 8, 2026

The Gentlemen posted 19 claims in a single batch, recorded independently by both trackers, with targets across four continents and only LA Metro and the University of San Francisco on the US side. Metaencryptor's four cluster in aerospace and medical devices. On tooling: PEEP turns Chrome and Edge into post-compromise backdoors, and ClickFix now stores its payloads in BNB Smart Chain contracts.

15 Items
2026-09-07
Threat Watch · Sep 7, 2026

kazu posted 17 victims in a single batch, almost all healthcare and health-tech platforms across Latin America and South Asia, plus three South African government bodies. Kaspersky documents Toy Ghouls running command and control over HiveMQ and Element, and Elastic details the four REVSTEALER modules that stay behind after the stealer deletes itself.

14 Items
2026-09-06
Threat Watch · Sep 6, 2026

Qilin alone accounts for half of today's new claims, its seven victims spread across six unrelated sectors and including the Philippine Ports Authority. Aurora listed a pair of US defence contractors, and The Gentlemen listed Latin America's largest business aviation company.

7 Items
2026-09-05
Threat Watch · Sep 5, 2026

The Gentlemen claim 3.5 million patient records from healthcare data network Veradigm; Direwolf listed Wolfram Research; and Dysphor1a put 209,970 subscriber records from Myanmar ISP MBT Telecom up for sale. ShinyHunters used a leak-site slot for a purchase offer rather than a victim notice.

14 Items
2026-09-04
Threat Watch · Sep 4, 2026

Settra and Storm together account for nearly half the claims in this window. Law and accounting firms are unusually dense in the victim list — Katten Muchin Rosenman, Hagelgans & Veronis, Blanco & Etcheverry, SGLA and Maglin Miskiv were all posted within it. Also claimed: the listed Italian diagnostics firm DiaSorin, Guatemala's INCAN cancer hospital, Heilbronn University in Germany, and the Central Java provincial communications agency in Indonesia.

15 Items
2026-09-03
Threat Watch · Sep 3, 2026

Two more law firms appear on the leak sites, one of them posted by the same operation that listed Holland & Knight a day earlier. Inc Ransom leads the day's volume with seven claims reaching a US public school district and an Italian hospital network, and municipal and healthcare bodies are unusually dense in this window.

11 Items
2026-09-02
Threat Watch · Sep 2, 2026

Thegentlemen, Qilin, Akira, Direwolf, and Everest each claimed 3-4 new victims; Qilin hit a U.S. rural electric cooperative and Quebec's construction regulator, a departure from its usual small-business targets. Also claimed: German electronics distributor Chip 1 Exchange and major U.S. law firm Holland & Knight.

8 Items
2026-09-01
Threat Watch · Sep 1, 2026

Krybit leads this window with 14 new claims, almost entirely against low-profile small businesses; Brain Cipher and Settra follow with 8 each. The Gentlemen added Malaysia-listed EP Manufacturing Bhd, while LockBit5 and Wallstreet each named a credit union and a hospital respectively.

9 Items
2026-08-31
Threat Watch · Aug 31, 2026

111 distinct victim claims from 16 ransomware groups in 36 hours; Orova and Zawoo led on volume with small, low-profile targets, while Direwolf, Falcon and Shinyhunters claimed notable targets including two hospitals, a game publisher, and two NYSE-listed companies.

111 Items
2026-08-30
Threat Watch · Aug 30, 2026

115 victim claims in 36 hours; the gentlemen (16) and Qilin (13) led activity, with ShinyHunters' McKesson claim corroborated by today's breach disclosure.

6 Items
2026-08-29
Threat Watch · Aug 29, 2026

36-hour scan of 103 ransomware items across roughly 60 new victim claims from ~20 groups: Qilin led with 14, Akira and Storm claimed 6 each. Notable targets include a US healthcare network (9M+ files), a Berlin municipal target, and Australia's NSW Health.

20 Items
2026-08-28
Threat Watch · Aug 28, 2026

34 new victim claims in 36 hours across 10 groups, krybit the most active (12); headline: Aurora leaked SAP integrator ERPIS/ShipERP's full source code and financial data.

34 Items
Next →