Ransomware claims, intrusion campaigns, malware families and the infrastructure behind them.
Microsoft names Storm-3168 for agent-driven Azure reconnaissance and resource deletion carried out through compromised service principals, linking the activity to JADEPUFFER. Mandiant records a new wave of UNC6240 mass exploitation against Oracle PeopleSoft, where the WAF bypass is one URL-encoded character. Clop confirms its leak site was taken through an unauthenticated Grav CMS path traversal and has moved to a new Tor address. On the trackers, Everest posted six claims in one afternoon across four continents.
Microsoft attributes deployments of Qilin, DragonForce, Anubis and BERT to one affiliate, Storm-2570, on the basis of a consistent pre-encryption toolset. A TeamFiltration campaign works Chilean retail and finance, compromised Ukrainian business sites serve fake Cloudflare pages for the Psychedelic stealer, and Carbonato installs an AI agent framework on the Docker hosts it takes.
Cl0p posted 23 victims in a single batch, among them an international law firm, an Australian state transport agency, a US regional bank and a security product distributor; Emperador claims data from Brazil's federal tax authority. On the campaign side, the China-nexus actor UTA0565 chained Chrome and Windows zero-days to deploy CLEANGULP, and a separate actor used open-source AI agent frameworks as the automation behind card skimming at scale.
ShinyHunters posted an open letter to the FBI on its leak site and, the same day, put Fresenius Medical Care on a two-day countdown; Silent Ransom Group listed four US and UK law firms in one night. In campaigns: Talos documents CLOSEDQUORUM, the first reported fully autonomous AI command-and-control implant, and releases the CAIRN toolkit, while Microsoft's Digital Crimes Unit and partners dismantle the EvilTokens device-code phishing platform.
the gentlemen posted 18 claims in one batch — about a third of the day's total — across thirteen countries, and metaencryptor named six manufacturing and supply-chain firms at once. On the activity side: PAYLOAD ransomware encrypts nothing and drops no binary, working through Active Directory Group Policy instead; Vidar's string obfuscation is now a per-build virtual machine; and ClickFix lures deliver a RAT that rotates its C2 through the Polygon blockchain. Indicators: 430 new addresses in 24 hours, the highest of the last six issues.
A batch of four qilin victims spanning four countries and four sectors, a bravox listing naming a surveying contractor to the US Army Corps of Engineers and the Department of Defense, and auditteam still working only Russian-speaking targets. An npm campaign moves its malicious logic out of install scripts and into runtime, past defenses that check installation hooks. On the indicator side: 514 new addresses in 24 hours, the highest across the last six issues, with almost all of the increase in one category.
ShinyHunters breached Clop's leak site and left an extortion note, which both trackers ingested as an ordinary victim entry. A joint law enforcement advisory ties North Korea's WaterPlum to 30,000 devices and $10.7 million in cryptocurrency. 270 new C2 addresses in 24 hours, the lowest of the last six issues, with Cobalt Strike back ahead of VShell.
n0n posted nine victims at once, writing the entries as data inventories rather than company names: 86.7M connection records from PayPal's outsourced support operation, 15.3M subscriber records from Venezuela's largest ISP, the network-security configuration of Argentina's education ministry. North Korea's TraderTraitor backdoors turned up on a DevOps engineer's Mac with no crypto ties, and two new stealers arrived through npm and impersonated GitHub repositories. In the indicators, VShell displaces Cobalt Strike as the largest named family.
Two unrelated groups claimed AECOM on the same day, and storm posted four US community banks and wealth managers at once. ESET documents FamousSparrow deploying a new SparroWocky backdoor across Latin America, Zscaler details APT36's new Rust-based toolset, and Handala Hack is tied to the HEAVYGRAM Telegram backdoor. The FBI seized NightmareStresser.
Kaspersky separates three clusters hitting Russian enterprises: NightEagle with the GhostContainer backdoor and tooling hosted on GitHub, alongside Hacking Cat and Toy Ghouls. Mandiant documents an attacker hijacking an AI coding-assistant session and spreading the Shai-Hulud worm across about 100 internal repositories. On the leak sites, inc ransom and Auditteam each posted six claims, and ransomhouse claims the Namibian Defence Force.
safepay posted nine victims in one batch, among them Peru's national government portal and a Swiss wastewater treatment operator, while metaencryptor listed Nippon Steel and South Korea's SFA Engineering on the same day. Elastic tracked the KREMLIN banking extension across seven campaigns and fifteen months: it forges Chrome's own integrity checks and keeps its C2 configuration in Ethereum smart contracts. 361 new C2 and malware-distribution addresses in 24 hours.
the gentlemen posted 30 victims at once, close to half of the 66 claims both trackers recorded today, with no country or sector in common. Three China-linked operations surface: UTA0560 delivering the GRIMWEDGE backdoor through patched Chrome and Windows flaws, and Red Heron scanning 1,386 Gitea instances while keeping a separate list of 477 Taiwan-based systems. The indicator mirror took 637 new C2 addresses in 24 hours, roughly double the last five issues.
ShinyHunters has put Kimberly-Clark under a final notice expiring Sep 16, and Barracuda claims 693 GB taken from i2i-systems, 44 GB of it product source code and build artefacts. The exploited Sogou Input Method flaw now carries a CVE number, and the executive-impersonation campaign Microsoft disclosed sent over a million emails in three days. 347 new C2 and malware-distribution addresses in 24 hours.
krybit posted twelve claims in one batch, close to half of this issue's total, across eleven countries with no sector in common. global listed one small Massachusetts town's government and its school district as separate claims. Researchers attribute May's RubyGems supply-chain attack to a swarm of OpenAI agents, and Huntress tracks GTA6 rumour SEO poisoning that delivers stealers and wiper ransomware together.
Anthropic publishes its first systematic account of threat groups using Claude — secrets pulled from 1.8 million Android apps, and a Russian state-sponsored cluster rebuilding malware faster than detection catches up. The Artifactory pair became a delivery path, planting a Rust backdoor in the registry build servers pull from, and UNC3569 used a Sogou Input Method flaw to drop the GRAYRABBIT backdoor. On the indicator side: 342 new C2 and malware-distribution addresses in 24 hours, plus 158 addresses inside a scanning vendor's own network filed as malware.
Five unrelated groups each posted a healthcare victim within 36 hours, with Rhysida claiming 2.44 TB of patient records from a Philippine hospital. The PaperCut operator used hundreds of AI agents to build its exploitation and reached 395 organizations; Zscaler documents SloppyRAT, a new family delivered by ClickFix that resolves its command and control through the Polygon blockchain. Microsoft details an ACH payment fraud campaign built on AI-generated executive impersonation.
storm posted 40 claims in a two-minute burst, 44% of the day's 90, spanning hospitals, hospice care, municipal government and defense manufacturing across four countries. black nevas listed a Canadian MSP and four of its clients in the same batch. The BlueMoon exploit chain appeared in four espionage groups' hands within a week, its first in-the-wild use attributed to APT31, and AI service tokens pulled from infostealer logs are replayable with MFA playing no part.
Google Threat Intelligence Group puts a clock on adversarial agent use: under six hours from compromising a cloud resource to completing a mass credential harvest. The same day, Talos documents a ClickFix variant running command and control out of a Google Sheets document. Leak sites added 30 claims, ten of them from Safepay alone; a Linux rootkit turns up in F5 BIG-IP environments and Slim Spider targets Brazilian finance.
The Gentlemen posted 19 claims in a single batch, recorded independently by both trackers, with targets across four continents and only LA Metro and the University of San Francisco on the US side. Metaencryptor's four cluster in aerospace and medical devices. On tooling: PEEP turns Chrome and Edge into post-compromise backdoors, and ClickFix now stores its payloads in BNB Smart Chain contracts.
kazu posted 17 victims in a single batch, almost all healthcare and health-tech platforms across Latin America and South Asia, plus three South African government bodies. Kaspersky documents Toy Ghouls running command and control over HiveMQ and Element, and Elastic details the four REVSTEALER modules that stay behind after the stealer deletes itself.
Qilin alone accounts for half of today's new claims, its seven victims spread across six unrelated sectors and including the Philippine Ports Authority. Aurora listed a pair of US defence contractors, and The Gentlemen listed Latin America's largest business aviation company.
The Gentlemen claim 3.5 million patient records from healthcare data network Veradigm; Direwolf listed Wolfram Research; and Dysphor1a put 209,970 subscriber records from Myanmar ISP MBT Telecom up for sale. ShinyHunters used a leak-site slot for a purchase offer rather than a victim notice.
Settra and Storm together account for nearly half the claims in this window. Law and accounting firms are unusually dense in the victim list — Katten Muchin Rosenman, Hagelgans & Veronis, Blanco & Etcheverry, SGLA and Maglin Miskiv were all posted within it. Also claimed: the listed Italian diagnostics firm DiaSorin, Guatemala's INCAN cancer hospital, Heilbronn University in Germany, and the Central Java provincial communications agency in Indonesia.
Two more law firms appear on the leak sites, one of them posted by the same operation that listed Holland & Knight a day earlier. Inc Ransom leads the day's volume with seven claims reaching a US public school district and an Italian hospital network, and municipal and healthcare bodies are unusually dense in this window.
Thegentlemen, Qilin, Akira, Direwolf, and Everest each claimed 3-4 new victims; Qilin hit a U.S. rural electric cooperative and Quebec's construction regulator, a departure from its usual small-business targets. Also claimed: German electronics distributor Chip 1 Exchange and major U.S. law firm Holland & Knight.
Krybit leads this window with 14 new claims, almost entirely against low-profile small businesses; Brain Cipher and Settra follow with 8 each. The Gentlemen added Malaysia-listed EP Manufacturing Bhd, while LockBit5 and Wallstreet each named a credit union and a hospital respectively.
111 distinct victim claims from 16 ransomware groups in 36 hours; Orova and Zawoo led on volume with small, low-profile targets, while Direwolf, Falcon and Shinyhunters claimed notable targets including two hospitals, a game publisher, and two NYSE-listed companies.
115 victim claims in 36 hours; the gentlemen (16) and Qilin (13) led activity, with ShinyHunters' McKesson claim corroborated by today's breach disclosure.
36-hour scan of 103 ransomware items across roughly 60 new victim claims from ~20 groups: Qilin led with 14, Akira and Storm claimed 6 each. Notable targets include a US healthcare network (9M+ files), a Berlin municipal target, and Australia's NSW Health.
34 new victim claims in 36 hours across 10 groups, krybit the most active (12); headline: Aurora leaked SAP integrator ERPIS/ShipERP's full source code and financial data.