Weekly Intelligence Report – 9 Oct 2026 | #ransomware | #cybercrime


Published On : 2026-10-09

Ransomware In Focus

CYFIRMA Research and Advisory Team would like to highlight ransomware trends andinsights gathered while monitoring various forums. This includes multiple industries,geographies, and technologies that could be relevant to your organisation.

Type: Ransomware
Target Technologies: Windows OS

Introduction:
CYFIRMA Research and Advisory Team has identified Main Ransomware while monitoring various underground forums as part of our Threat Discovery Process.

Main Ransomware

MAIN is a ransomware infection that encrypts files on an affected system and modifiestheir filenames by adding a unique victim identifier, an attacker-controlled emailaddress, and a ransomware-specific file extension(.MAIN). After encryption, it displaysa pop-up ransom message and creates a text-based ransom note. The pop-upexplains that the victim’s files have been encrypted and provides instructions forcontacting the attackers. It requests the victim’s unique ID, which follows a formatsimilar to [ID-XXXXXXXX], along with an attacker email address using a format such as[username]@[email-domain] and with extension .MAIN. A secondary contact addressmay also be provided if the primary communication channel does not respond withina specified period. The message further offers free decryption of a limited number offiles as supposed proof that recovery is possible, subject to restrictions on file size andfile type. Victims are also warned against renaming encrypted files or attemptingrecovery with unauthorized decryption utilities, with claims that these actions couldcause permanent damage or increase the ransom demand.

Screenshot: File encrypted by the ransomware
(Source: Surface Web)

The accompanying text ransom note is considerably shorter than the pop-up messagebut serves the same overall purpose of establishing communication with the ransomwareoperators. Rather than explaining the encryption process or providing extensive recoveryinstructions, the note briefly asks the victim to initiate contact regarding the encrypteddata. It provides several communication channels so that the attackers can still bereached if one method becomes unavailable. The primary contact is represented in theform [username]@[domain], while an alternative address follows the same[username]@[backup-domain] structure. The note may also include an instant-messagingcontact in the format @[handle], giving the victim another way to communicate with theoperators. Unlike the pop-up window, the text note does not contain detailedinformation about free file decryption, file-size restrictions, or warnings concerningrecovery attempts. Its main function is to direct the victim toward the attackers’communication channels and encourage further negotiation over file recovery. Thepresence of multiple contact methods also provides redundancy for the operators,allowing communication to continue if the primary address or service becomesinaccessible. Technically, this note acts as a secondary ransom-demand artifactgenerated after the encryption routine has completed, complementing the graphicalransom message and ensuring that recovery instructions remain available as astandalone text file. Together, these ransom artifacts communicate the attackers’demands while providing the victim with the information necessary to begin theattempted recovery process.

Screenshot: The appearance of Main’s ransom note (INFO.txt)
(Source: Surface Web)

Screenshot: The appearance of Main’s Pop-up Window
(Source: Surface Web)

The following are the TTPs based on the MITRE ATT&CK framework

TacticTechnique IDTechnique Name
ExecutionT1129Shared Modules
PersistenceT1112Modify Registry
PersistenceT1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege EscalationT1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
DiscoveryT1033System Owner/User Discovery
DiscoveryT1057Process Discovery
DiscoveryT1082System Information Discovery
DiscoveryT1083File and Directory Discovery
DiscoveryT1497Virtualization/Sandbox Evasion
CollectionT1074Data Staged
Command and ControlT1071Application Layer Protocol
ImpactT1485Data Destruction
ImpactT1486Data Encrypted for Impact
StealthT1027.002Obfuscated Files or Information: Software Packing
StealthT1036Masquerading
StealthT1070.004Indicator Removal: File Deletion
StealthT1202Indirect Command Execution
StealthT1497Virtualization/Sandbox Evasion
StealthT1564.001Hide Artifacts: Hidden Files and Directories
Defense ImpairmentT1112Modify Registry

Relevancy and Insights:

  • The ransomware primarily targets Windows environments, utilizing Windows services,command-line utilities, registry configurations, system APIs, and filesystem operations toperform encryption, system modification, and recovery-inhibition activities.
  • The ransomware terminates processes such as vssadmin.exe Delete Shadows /all /quietand wmic shadowcopy delete /nointeractive to delete Volume Shadow Copies, whichare used by Windows for backup and restore. By removing these shadow copies, themalware ensures that victims cannot recover their files via system restore points orbackup utilities.
  • Detect-debug-environment: The ransomware technique is used to determine if it isbeing monitored in environments such as sandboxes, virtual machines, or underdebugging tools. To perform this check, the malware may look for specific processes,drivers, or artifacts linked to analysis tools, measure timing to spot inconsistencies, orscan for system traits uncommon in real user machines. When such conditions areidentified, the malicious program can modify its behavior, such as pausing execution,shutting down, or withholding key payload actions to avoid detection and makedetailed analysis more difficult.
  • Persistence: The ransomware exhibits continuity mechanisms to ensure its survival andongoing vicious conditioning within the compromised terrain. This could involvecreating autostart entries or modifying system settings to maintain a base and greaseunborn attacks.

ETLM Assessment:
Main ransomware could evolve through changes to its encryption routine, file-extensionpatterns, ransom-note content, and communication mechanisms. Future variants may usedifferent victim identifiers and attacker-controlled contact addresses for each campaign,making individual samples harder to correlate. The malware could also become moreselective in the files it targets, prioritizing documents, databases, backups, and other highvalue data while attempting to avoid system-critical files that could prevent the infectedmachine from operating. Additional evasion techniques may also be introduced, such asimproved process checks, altered execution methods, or modifications intended to reducedetection by security software. Changes to the ransom note and payment instructions arealso likely as operators adjust their social-engineering approach.

The threat could further develop toward a more flexible and resilient ransomware model inwhich attackers modify their distribution and communication infrastructure frequently. Futureversions may incorporate stronger anti-analysis mechanisms, improved persistence, oradditional techniques for disabling security and backup mechanisms before encryptionbegins. Attackers could also expand the extortion component by combining file encryptionwith data theft and threatening to publish stolen information if payment is refused. However,these developments are predictions rather than confirmed capabilities of the currentsample. The exact evolution will depend on how the malware’s operators modify their code,infrastructure, and intrusion methods in subsequent campaigns.

Sigma rules:

title: Shadow Copies Deletion Using Operating
Systems Utilities
tags:
– attack.impact
– attack.stealth
– attack.t1070
logsource:
category: process_creation
product: windows
detection:
selection1_img:
– Image|endswith:
– ‘\powershell.exe’
– ‘\pwsh.exe’
– ‘\wmic.exe’
– ‘\vssadmin.exe’
– ‘\diskshadow.exe’
– OriginalFileName:
– ‘PowerShell.EXE’
– ‘pwsh.dll’
– ‘wmic.exe’
– ‘VSSADMIN.EXE’
– ‘diskshadow.exe’
selection1_cli:
CommandLine|contains|all:
– ‘shadow’ # will match “delete shadows”
and “shadowcopy delete” and “shadowstorage”
‘delete’
selection2_img:
– Image|endswith: ‘\wbadmin.exe’
– OriginalFileName: ‘WBADMIN.EXE’
selection2_cli:
CommandLine|contains|all:
– ‘delete’
– ‘catalog’
– ‘quiet’ # will match -quiet or /quiet
selection3_img:
– Image|endswith: ‘\vssadmin.exe’
– OriginalFileName: ‘VSSADMIN.EXE’
selection3_cli:
CommandLine|contains|all:
– ‘resize’
– ‘shadowstorage’
CommandLine|contains:
– ‘unbounded’
– ‘/MaxSize=’
condition: (all of selection1*) or (all of
selection2*) or (all of selection3*)
falsepositives:
– Legitimate Administrator deletes Shadow
Copies using operating systems utilities for
legitimate reason
– LANDesk LDClient Ivanti-PSModule (PS
EncodedCommand)
level: high
(Source: Surface Web)

IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)

RECOMMENDATIONS

STRATEGIC RECOMMENDATIONS

  • Implement competent security protocols and encryption, authentication, or access credential configurations to access critical systems in your cloudand local environments.
  • Ensure that backups of critical systems are maintained, which can be usedto restore data in case a need arises.

MANAGEMENT RECOMMENDATIONS

  • A data breach prevention plan must be developed considering (a) thetype of data being managed by the company; (b) the remediationprocess; (c) where and how the data is stored; (d) if there is an obligationto notify the local authority.
  • Implement a zero-trust security model alongside multifactor authentication(MFA) to reduce the risk of credential compromise.
  • Foster a culture of cybersecurity, where you encourage and invest inemployee training so that security is an integral part of your organisation.

TACTICAL RECOMMENDATIONS

  • Update all applications/software regularly with the latest versions andsecurity patches alike.
  • Add the Sigma rule for threat detection and monitoring, which will help todetect anomalies in log events and identify and monitor suspiciousactivities.
  • Establish and implement protective controls by actively monitoring andblocking identified indicators of compromise (IoCs) and reinforcingdefensive measures based on the provided tactical intelligence.

Active Malware of the Week

Type: Infostealer / Stealer | Objectives: Credential Theft and Data Exfiltration | Target Technology: Windows | Target Geography: Global

CYFIRMA collects data from various forums based on which the trend is ascertained. Weidentified a few popular malwares that were found to be distributed in the wild to launchcyberattacks on organizations or individuals

Active Malware of the Week

This week, VorishkaStealer Malware is in focus.

Overview of Operation VorishkaStealer Malware

Assessment of “VorishkaStealer” shows software whose behavior, once active, is directedtoward a specific operational goal. What sets it apart from an innocuous program is thedeliberate set of actions it takes on the host it infects. It is built to monitor copied content,including account details. Taken together, these behaviors describe an operationallypurposeful threat rather than an inert file.

Observed activity includes clipboard monitoring, and the sample takes an active interest inregistry configuration and local files. For a manager, the key point is that the sample is notidle; it is actively engaging with the machine and with the information held on or near it, soits presence signals a direct interest in the organization’s data rather than a benign oraccidental installation.

Little indicates that the sample makes a determined effort to remain resident over time;within the recorded sessions, its activity looked short-lived. That is not proof it is benign, sincesome variants rely on being delivered afresh or on user action to run again, but it doessuggest the observed program was not centered on a deep self-sustaining routine.
Stepping back, the broader picture is that the sample supports more than a single one-offaction: only limited outward traffic was captured in the session, so the sample’s immediateeffect seems limited to the machine it ran on. For an organization, this is a real securityconcern, because it shows an attacker with a deliberate interest in these systems and thedata they contain.

Attack Method

On a Windows host, the sample begins with anti-analysis checks designed to detect amonitored or virtualized environment before any real activity unfolds. Only basicenvironment details are gathered at this stage, enough for the component to orient itselfbut not enough to betray a heavy information gathering routine of its own. Where suchconditions are detected, it can alter its behavior or exit early rather than hand analysts afaithful trace. The combined effect is that the execution phase establishes a workingfoothold, confirms the sample is running under favorable conditions, and prepares theground for the persistence and collection routines that follow.

No durable persistence or explicit defense-evasion behavior was recorded within theobservation window. This absence should be read with care: if the operator retains access,survival is likely maintained outside the activity captured here, whether through loaderchains that deliver the component again, through re-infection by other means, or throughthe operator relying on user interaction to set it running once more. The lack of an obviousself-sustaining routine therefore does not reduce the threat posed.

The heart of this sample’s purpose is gathering data: recorded behaviors cover systematicreading of local files, gathering documents, configuration, and other sensitive material fromthe workstation, and clipboard monitoring that intercepts copy-paste content such aspasswords, wallet addresses, and confidential text. These actions work alongsidereconnaissance of processes, system state, and security controls, so the implant builds acomplete view of the victim before any data leaves the network.

The Following are the TTPs based on the MITRE ATT&CK Framework for Enterprises

TacticTechnique IDTechnique Name
ExecutionT1059Command and Scripting Interpreter
ExecutionT1129Shared Modules
PersistenceT1112Modify Registry
PersistenceT1547.009Boot or Logon Autostart Execution: Shortcut Modification
Privilege EscalationT1134Access Token Manipulation
StealthT1027.002Obfuscated Files or Information: Software Packing
StealthT1027.009Obfuscated Files or Information: Embedded Payloads
StealthT1140Deobfuscate/Decode Files or Information
StealthT1564.003Hide Artifacts: Hidden Window
StealthT1622Debugger Evasion
Defense ImpairmentT1222File and Directory Permissions Modification
DiscoveryT1010Application Window Discovery
DiscoveryT1012Query Registry
DiscoveryT1057Process Discovery
DiscoveryT1082System Information Discovery
DiscoveryT1083File and Directory Discovery
DiscoveryT1124System Time Discovery
CollectionT1115Clipboard Data
CollectionT1125Video Capture
ImpactT1529System Shutdown/Reboot

INSIGHTS

  • Looked at as a tool rather than a file, VorishkaStealer exists to do one job well: the sample’s whole reason to exist is the quiet removal of data; the moment it executes, it begins collecting login material, browsing history, and on-machine files that can later be monetized or used to pivot into other systems. That objective colors every other behavior the sample displays, giving the whole component a coherent focus that is easy to lose when it is examined piece by piece.
  • This is not a crude or experimental piece of code. The sequence of actions it takes once running, how carefully it hides, and how it sustains itself all suggest a builder who thought deliberately about how the sample should operate inside a network. Taken as a whole, this is the profile of a threat refined through use rather than thrown together, with behaviors that overlap and support one another.
  • The pattern of interaction with the host itself reveals targeting intent: the emphasis on credential material indicates the operator values accounts over specific files, which points toward theft that can be resold or reused later. In combination, these details describe a threat that is selective in what it makes use of and unhurried in how it operates.

ETLM ASSESSMENT

Viewed from an ETLM perspective, what VorishkaStealer does today points to a sharper, more automated class of intrusion ahead, and its future effect on organizations and employees merits serious attention: credential-harvesting operations of this class are sliding toward automated, always-on pipelines that will make stolen accounts tradable minutes after a compromise, turning a single workstation breach into a recurring source of business compromise. As this family and its descendants mature, organizations will increasingly find themselves responding to incidents that reach further into day-to-day operations, while employees become the primary human exposure point – their daily clicks, logins, and communications quietly feeding a growing digital economy built on what these samples quietly collect. The cumulative consequence may therefore be felt most in how organizations absorb exposure over time: as intrusions of this class become more common, the overall effect could reach well beyond any single machine into broader operational disruption that is difficult to isolate and even harder to unwind.

IOCs

Kindly refer to the IOCs below to exercise controls on your security systems. (Source: Open Surface)

YARA Rules

rule VorishkaStealer_Malware
{
meta:
description = “Detection rule for the analyzed malware sample”
author = “CYFIRMA Research”
strings:
$hash1 =
“b312ef44bca34f2186177d9a6c8da06834d2748586ed5aa757d300c36d37acf2″$hash2 = “dd350eac76d1157772889dc21d0ae2e85b2ddf2f”
$hash3 = “56b34de84f4950c4364e693877b640c6”
$s1 =
“C:\\Users\\A4148~1.MON\\AppData\\Local\\Temp\\fajZCxur\\\\AutoIt3.exe\” \”C:\\Users\\A4148~1.MON\\AppData\\Local\\Temp\\fajZCxur\\\\AutoStart_f34691.au3″
$s2 = “c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur”
$s3 = “fajzcxur”
$s4 = “c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\nsg5b38.tmp”$s5 = “nsg5b38.tmp”
$s6 =
“c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur\\autoit3.exe”
$s7 = “autoit3.exe”
$s8 =
“c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur\\autostart_f34691.au3”
$s9 = “autostart_f34691.au3”
$s10 = “VorishkaStealer”
condition:
any of ($hash*) or
2 of ($s*)
}

Recommendations

Strategic Recommendations

  • Establish an organization-wide endpoint security strategy covering malware prevention, detection, and response.
  • Prioritize protection of sensitive credentials and business information stored or accessed from employee endpoints.
  • Adopt layered security controls so that a single compromised endpoint does not provide prolonged access to organizational resources.
  • Conduct periodic threat assessments to identify exposure to multi-purpose malware and similar information-stealing threats.

Management Recommendations

  • Direct affected users to rotate passwords and confirm multi-factor enrolment as part of the response checklist.
  • Ensure endpoint protection and security monitoring capabilities are consistently deployed across employee systems.
  • Establish clear incident-response procedures for suspected malware infections, including isolation, investigation, and recovery.
  • Provide regular security-awareness training focused on suspicious files, links, downloads, and unexpected system activity.
  • Maintain appropriate controls over access to sensitive corporate information and user accounts.

Tactical Recommendations

  • Monitor endpoints for unusual PowerShell activity, unexpected process trees, and unauthorized changes to security settings.
  • Block and monitor the infrastructure listed in the IOC section at DNS, proxy, and perimeter controls.
  • Isolate confirmed cases promptly, then reset credentials and review AutoStart locations before restoration.

CYFIRMA’s Weekly Insights

1. Weekly Attack Types and Trends

Key Intelligence Signals

  • Attack Type: Ransomware Attacks, Vulnerabilities & Exploits, Data Leaks.
  • Objective: Unauthorized Access, Data Theft, Data Encryption, Financial Gains, Espionage.
  • Business Impact: Data Loss, Financial Loss, Reputational Damage, Loss of Intellectual Property, Operational Disruption.
  • Ransomware – Everest Ransomware, The Gentlemen Ransomware | Malware – VorishkaStealer
  • Everest Ransomware – One of the ransomware groups.
  • The Gentlemen Ransomware – One of the ransomware groups. Please refer to the trending malware advisory for details on the following: Malware – VorishkaStealer
  • Behavior – Most of these malwares use phishing and social engineering techniques as their initial attack vectors. Apart from these techniques, exploitation of vulnerabilities, defense evasion, and persistence tactics are being observed.

2. Threat Actor in Focus

Star Blizzard: Evolution of Phishing and Malware Delivery

  • Threat Actor: Star Blizzard aka SEABORGIUM
  • Attack Type: Credential Stealing, Impersonation, Malware Implant, Spear-phishing.
  • Objective: Espionage, Information Theft.
  • Suspected Target Technology: Windows, Microsoft Office, cPanel, WordPress
  • Suspected Target Geography: Brazil, Canada, Chile, Estonia, France, Germany, Greece, India, Israel, Italy, Latvia, Lebanon, Lithuania, Norway, Poland, Russian Federation, Singapore, South Africa, Sweden, Switzerland, Ukraine, United Arab Emirates, United Kingdom, United States.
  • Suspected Target Industries: Commercial Services & Supplies, Automobiles, Education Services, Civic and Social Organizations, IT Services, Aerospace & Defense, Electric Utilities, Professional Services, Energy, Utilities, Financials, Air Freight & Logistics, Retail, Grantmaking and Giving Services, Health Care, Human Rights Organizations, Information Technology, Insurance, IGOs, Media, Justice & Safety Activities, Management, Scientific, Manufacturing, Metals & Mining, Entertainment, National Security & International Affairs, Non-Profit, Oil, Gas & Consumable Fuels, Personal Care Services, Public Administration, Research and Development in the Social Sciences and Humanities, Software, Telecommunications, Think Tanks, NGOs, Transportation.
  • Business Impact: Data Theft, Operational Disruption, Reputational Damage.

About the Threat Actor

Star Blizzard, also known as SEABORGIUM, is a highly persistent threat actor known for repeatedly targeting the same organizations over extended periods. Following initial compromise, Star Blizzard gradually expands its access by infiltrating victims’ social networks through persistent impersonation, relationship building, and phishing. The group has consistently compromised organizations and individuals of interest over several years, while largely maintaining the same established tactics and methodologies.

Details on Exploited Vulnerabilities

CVE IDAffected ProductsCVSS ScoreExploit Links
CVE-2024-4947Google Chrome prior to 125.0.6422.609.6–
CVE-2023-38831RARLAB WinRAR7.8Link1
CVE-2023-36884Windows7.5Link1
CVE-2022-30190Microsoft Support Diagnostic Tool (MSDT), Windows7.8–
CVE-2023-36884Windows7.5–

TTPs based on the MITRE ATT&CK Framework

TacticIDTechnique
ReconnaissanceT1589Gather Victim Identity Information
ReconnaissanceT1598.002Phishing for Information: Spearphishing Attachment
ReconnaissanceT1598.003Phishing for Information: Spearphishing Link
ReconnaissanceT1593Search Open Websites/Domains
Resource DevelopmentT1583Acquire Infrastructure
Resource DevelopmentT1583.001Acquire Infrastructure: Domains
Resource DevelopmentT1586.002Compromise Accounts: Email Accounts
Resource DevelopmentT1585.001Establish Accounts: Social Media Accounts
Resource DevelopmentT1585.002Establish Accounts: Email Accounts
Resource DevelopmentT1588.002Obtain Capabilities: Tool
Resource DevelopmentT1608.001Stage Capabilities: Upload Malware
Initial AccessT1566.001Phishing: Spear phishing Attachment
Initial AccessT1078Valid Accounts
ExecutionT1059.007Command and Scripting Interpreter: JavaScript
ExecutionT1204.002User Execution: Malicious File
PersistenceT1078Valid Accounts
Privilege EscalationT1078Valid Accounts
StealthT1078Valid Accounts
StealthT1684.001Social Engineering: Impersonation
Credential AccessT1539Steal Web Session Cookie
Lateral MovementT1550.004Use Alternate Authentication Material: Web Session Cookie
CollectionT1114.002Email Collection: Remote Email Collection
CollectionT1114.003Email Collection: Email Forwarding Rule

Latest Developments Observed

The threat actor Star Blizzard is suspected of expanding its phishing operations fromtargeted spear-phishing to large-scale campaigns targeting Ukrainian individuals andorganizations, NGOs, think tanks, governments, and financial institutions. The threat actorhas introduced the RedFlick malware delivery technique, using malicious VHDX files,password-protected archives, compromised websites, scheduled tasks, and payloadsconcealed within PDF files to deploy the CosmicPulse backdoor. The activity appearsaimed at improving malware delivery, reducing required user interaction, evadingdetection, and supporting ongoing cyberespionage operations.

ETLM Insights

Star Blizzard, a Russian state-sponsored cyber-espionage actor, is demonstratingcontinued operational evolution through the expansion of its phishing operations,adoption of new malware delivery mechanisms, and increased use of compromisedinfrastructure to support scalable targeting. The actor’s 2026 activity reflects a shift fromhighly targeted spear-phishing toward larger-scale operations while continuing to refineits ability to evade detection and streamline malware deployment against organizationsaligned with Ukraine-related political and policy interests.

The threat actor’s operations reflect:

  • Scaled phishing operations, expanding from targeted spear-phishing to campaignsinvolving tens to hundreds of messages across multiple targets.
  • Compromised infrastructure, using cPanel- and WordPress-hosted websites tosupport higher-volume phishing.
  • Evolving delivery and persistence, with RedFlick using VHDX files and scheduledtasks to deploy CosmicPulse with reduced user interaction.
  • Enhanced defense evasion, including PDF payload concealment andmasquerading malicious components as legitimate system tasks.

Looking ahead, Star Blizzard is likely to further refine its large-scale phishing and malwaredelivery capabilities to improve operational scalability, reduce user interaction, andstrengthen its ability to evade detection. The continued adoption of compromisedinfrastructure, scheduled-task persistence, and concealed payload delivery suggests thatthe actor will remain focused on developing more resilient and efficient intrusion chainsto support sustained cyberespionage operations against strategically relevant targets.

IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source:Surface Web)

YARA Rules

rule CVE_2024_4947_Proton_Decrypter_Indicators
{
meta:
description = “Indicators associated with CVE-2024-4947 and Proton Decrypter”author = “CYFIRMA”
reference = “CVE-2024-4947”
strings:
// CVEs
$cve1 = “CVE-2022-30190” ascii nocase
$cve2 = “CVE-2023-39831” ascii nocase
$cve3 = “CVE-2023-36884” ascii nocase
$cve4 = “CVE-2018-0798” ascii nocase
$cve5 = “CVE-2024-4947” ascii nocase
// IP Addresses
$ip1 = “165.227.148.68” ascii
$ip2 = “192.236.193.194” ascii
$ip3 = “142.11.209.180” ascii
$ip4 = “142.11.209.171” ascii
$ip5 = “185.164.172.128” ascii
// Domains
$domain1 = “cloudmediaportal.com” ascii nocase
$domain2 = “aerofluidthermo.org” ascii nocase
$domain3 = “civilstructgeo.org” ascii nocase
$domain4 = “docs-info.com” ascii nocase
// File indicators
$file1 = “proton-decrypter.exe” ascii nocase
$hash1 =
“37c52481711631a5c73a6341bd8bea302ad57f02199db7624b580058547fb5a9.bin” ascii nocase
condition:
any of them
}

Recommendations

Strategic Recommendations

  • Deploy an Extended Detection and Response (XDR) solution as part of the organization’s layered security strategy that provides detection/prevention for malware and malicious activities that do not rely on signature-based detection methods.
  • Incorporate Digital Risk Protection (DRP) as part of the overall security posture to proactively defend against impersonations and phishing attacks.

Management Recommendations

  • Regularly reinforce awareness of unauthorized attempts with end-users across the environment and emphasize the human weakness in mandatory information security training sessions.
  • Look for email security solutions that use ML- and AI-based anti-phishing technology for BEC protection to analyze conversation history to detect anomalies, as well as computer vision to analyze suspect links within emails.

Tactical Recommendations

  • Take advantage of emerging APIs to integrate email events into a broader XDR or security information and event management (SIEM)/security orchestration, analytics, and reporting (SOAR) strategy.
  • For better protection coverage against email attacks (like spear phishing, business email compromise, or credential phishing attacks), organizations should augment built-in email security with layers that take a materially different approach to threat detection.
  • Patch software/applications as soon as updates are available. Where feasible, automated remediation should be deployed because vulnerabilities are one of the top attack vectors.
  • Add the YARA rule for threat detection and monitoring, which will help to detect anomalies in log events, identify and monitor suspicious activities.
  • Build and undertake safeguarding measures by monitoring/blocking the IOCs and strengthening defence based on the tactical intelligence provided.

3. Major Geopolitical Developments in Cybersecurity

South Korean Banks Under Intense Hacking Campaign

The South Korean Financial Services Commission (FSC) convened an emergency meeting with top financial executives and regulators following a coordinated wave of cyberattacks targeting major South Korean banks, including Shinhan, KB Kookmin, Hana, and Woori. The regulatory body warned that the intrusions may have utilized advanced artificial intelligence to broadly scan multiple financial institutions for system vulnerabilities rather than focusing on a single target. Malicious attack traffic has been traced back to IP addresses across several countries, with political figures urging authorities to investigate potential connections to North Korean state-sponsored threat groups known for targeting South Korean financial infrastructure.

The breaches have already compromised sensitive consumer data across multiple lenders, reportedly exposing personal and financial records for roughly 25,000 customers at Shinhan Bank, alongside smaller affected numbers at KB Kookmin and Hana Bank. Cybersecurity experts cited by local media suggest that attackers likely deployed sophisticated AI agents to probe for weaknesses and breach services tied to loan recruiters, laying bare the double-edged sword of advanced technologies where defensive-oriented source codes are increasingly weaponized for automated cybercrime. Although these customer figures are modest compared to historical mega-breaches in the country, such as massive historical leaks at Lotte Card and Coupang, security analysts warn that the exposure of detailed financial parameters makes victims highly vulnerable to hyper-personalized, generative AI-driven scams.

ETLM Assessment:

South Korean financial institutions have long been prime targets for Pyongyang’s state-backed threat actors, who have historically relied on sophisticated cyberheists and cryptocurrency scams to launder billions of dollars to fund the regime’s illicit programs. Cyberespionage groups like the Lazarus cyber syndicate have systematically attacked banks, exchanges, and financial networks across the globe, shifting from traditional malware deployments to highly coordinated, multi-stage social engineering and infrastructure compromises. In recent months, threat intelligence agencies and security researchers have identified an alarming evolution in these operations: North Korean hackers are increasingly integrating artificial intelligence and automated agents into their attack lifecycles. By weaponizing generative AI and machine learning tools to rapidly scan for system vulnerabilities, automate phishing campaigns, and synthesize convincing multilingual pretexts for financial fraud, these state-sponsored operators are scaling up the speed and efficiency of their multi-million-dollar digital campaigns.

Chinese Hackers Impersonate US Officials

Chinese-aligned threat actor TA419 impersonated US policymakers this summer in adversary-in-the-middle phishing campaigns targeting AI experts at think tanks, universities, and law firms. Researchers revealed the campaign is part of broader espionage efforts to gather intelligence on US AI policy amid intense tech competition and export controls.

Rather than launching immediate attacks, TA419 first builds credibility. The group poses as legitimate contacts – such as former White House officials or economists – inviting targets to join fictitious advisory committees or contribute to Senate reports on AI. Once trust is established, attackers send a shortened URL leading to a customized, browser-in-the-browser OneDrive phishing page.

This technique captures authenticated sessions, bypassing standard multifactor authentication because victims unwittingly approve logins themselves. Experts note that traditional training falls short against these relationship-building pretexts, urging organizations to adopt phishing-resistant passkeys and verify unexpected outreach through independent channels.

ETLM Assessment:

Such operations represent standard operating procedure for state-backed intelligence collection, reflecting how modern nations gather critical insights to shape their own strategic policymaking. Rather than targeting immediate financial or tactical assets, state-aligned actors systematically map foreign regulatory landscapes, research breakthroughs, and diplomatic positioning to anticipate geopolitical moves, counter export controls, and inform their own national technology strategies.

4. Rise in Malware/Ransomware and Phishing

Everest Ransomware Impacts an Information Technology Company from Japan

  • Attack Type: Ransomware
  • Target Industry: Information Technology
  • Target Geography: Japan
  • Ransomware: Everest Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Japan was compromised by Everest ransomware. The compromised company is a Japanese IT company headquartered in Tokyo, Japan, operating in the information technology and systems software industry. It specializes in IT operations management software, system infrastructure solutions, and IT services. The Company also provides IT consulting, systems integration, and outsourcing services primarily to enterprise clients in Japan. The compromised dataset contains 159,901 files in 22,338 folders, occupying 127.964 GB. It combines corporate records, contracts, product engineering, customer implementation material, quality assurance, personnel assessments, structured application data, and selected correspondence. The dated business material extends from historical development and company administration to internal documents prepared for September 2026.

Source: Dark Web

Relevancy & Insights:

  • The Everest Ransomware group primarily targets countries such as the United States of America, Japan, Indonesia, Germany, and India.
  • The Everest Ransomware group primarily targets industries, including Professional Goods & Services, Information Technology, Manufacturing, Healthcare, and Finance.
  • Based on the Everest Ransomware victims list from 1st Jan 2026 to 06th October 2026, the top 5 Target Countries are as follows:

  • The Top 10 Industries most affected by the Everest Ransomware group victims list from 1st Jan 2026 to 06th October 2026 are as follows:

ETLM Assessment:

According to CYFIRMA’s assessment, Everest ransomware continues to pose a persistent and evolving cyber threat. The group is actively broadening its targeting across new sectors, expanding its role as an initial access broker, and increasingly relying on data-leak extortion as its core operational tactic. Organizations are advised to remain vigilant by strengthening access controls, closely monitoring for lateral movement and Cobalt Strike–related activity, and maintaining robust incident response and detection capabilities to mitigate the risks posed by Everest’s ongoing campaigns.

The Gentlemen Ransomware Impacts a Food & Beverage Organisation from Indonesia

  • Attack Type: Ransomware
  • Target Industry: Food & Beverage
  • Target Geography: Indonesia
  • Ransomware: The Gentlemen Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that an organisation from Indonesia was compromised by The Gentlemen Ransomware. The compromised organisation is one of Indonesia’s biggest family restaurant chains — 200+ outlets in 55 cities across 31 provinces, employing thousands of people. It serves affordable Asian-Indonesian comfort food (fried rice, noodles, kwetiau, chicken and seafood dishes) famous for huge “jumbo” portions at Rp23k–55k, targeting middle-class families and mall shoppers. The data, which has been breached, has not yet appeared on the leak site, indicating that negotiations between the affected party and the ransomware group may be underway. The compromised data includes confidential and sensitive information belonging to the organization.

Source: Dark Web

Relevancy & Insights:

  • The Gentlemen is a relatively highly sophisticated ransomware-as-a-service (RaaS) group that emerged in mid-2025.
  • The Gentlemen Ransomware group primarily targets countries such as the United States of America, France, Thailand, India, and Italy.
  • The Gentlemen Ransomware group primarily targets industries, including Manufacturing, Professional Goods & Services, Consumer Goods & Services, Information Technology, and Healthcare.
  • Based on the Gentlemen Ransomware victims list from 1st Jan 2025 to 06th October 2026, the top 5 Target Countries are as follows:

  • The Top 10 Industries most affected by the Gentlemen Ransomware group victims list from 1st Jan 2025 to 06th October 2026 are as follows:

ETLM Assessment

According to CYFIRMA’s assessment, the Gentlemen Ransomware is a highly adaptive and globally active threat that leverages dual-extortion tactics, combining data theft with file encryption. The group employs advanced evasion and persistence techniques, supports cross-platform and scalable ransomware deployment, and conducts targeted attacks across multiple industries and geographic regions. This combination of capabilities makes it a significant risk to enterprise cybersecurity defenses, particularly for organizations with limited detection and incident-response maturity.

5. Vulnerabilities and Exploits

Vulnerability in Bluehood

  • Attack Type: Vulnerabilities & Exploits
  • Target Technology: Bluetooth Monitoring Software
  • Vulnerability: CVE-2026-49994
  • CVSS Base Score: 1
  • Vulnerability Type: Missing Authentication for Critical Function / Missing Authorization
  • Summary: The vulnerability allows a remote unauthenticated attacker toaccess Bluehood API routes and modify application state when webauthentication is enabled.

Relevancy & Insights:

The vulnerability exists because the /api/* handlers do notenforce session authentication when web authentication is enabled. Anetwork-reachable attacker can access Bluetooth tracking data and modifyapplication settings, device groups, and per-device notes without a validsession.

Impact: A remote unauthenticated attacker can read Bluetooth tracking dataand modify application state, including the heartbeat URL, prune retention,device groups, and per-device notes.

Affected Products: 

https[:]//github[.]com/dannymcc/bluehood/security/advisories/GHSAqj2j-wcg3-74jw

Recommendations:

Monitoring and Detection: Implement monitoring and detection mechanisms to identify unusual system behavior that might indicate an attempted exploitation of this vulnerability.

TOP 5 AFFECTED TECHNOLOGIES OF THE WEEK

This week, CYFIRMA researchers have observed significant impacts on various technologiesdue to a range of vulnerabilities. The following are the top 5 most affected technologies.

ETLM Assessment

The vulnerability in Bluehood presents a significant security risk to organizations using affected versions with web authentication enabled. The issue allows a network-reachable unauthenticated attacker to bypass authentication controls applied to the web interface and access Bluetooth tracking observations or modify application state through API endpoints. Public exploit code has been reported, increasing the potential for opportunistic exploitation, although current sources do not confirm active exploitation. Organizations using affected Bluehood versions should prioritize upgrading to version 0.7.1, restrict access to the dashboard port to trusted networks, and monitor application and network logs for suspicious requests to affected API endpoints. Prompt remediation and continuous monitoring are recommended to reduce the risk of unauthorized access to Bluetooth tracking data and application state.

6. Latest Cyber-Attacks, Incidents, and Breaches

SafePay Ransomware attacked and published the data of a Chemical Manufacturingcompany from Thailand

  • Threat Actor: SafePay Ransomware
  • Attack Type: Ransomware
  • Objective: Data Leak, Financial Gains
  • Target Technology: Web Applications
  • Target Industry: Chemical Manufacturing
  • Target Geography: Thailand
  • Business Impact: Operational Disruption, Data Loss, Financial Loss, Potential Reputational Damage

Summary:
Recently, we observed that SafePay Ransomware attacked and published the data of a Chemical Manufacturing company from Thailand on its dark web website. The compromised company is a Thai industrial company specializing in electroplating chemicals, surface-finishing technologies, industrial cleaning solutions, and related production systems. The company is headquartered in Samut Prakan Province and has more than five decades of experience in the surface-finishing industry. Its history traces back to 1967, when the business was established in Bangkok, and it subsequently expanded from chemical trading into manufacturing, technical services, and research and development.

The company’s products and services support a wide range of industrial applications, including automotive manufacturing, aerospace and defense, electronics and printed circuit boards, renewable energy, heavy machinery, sanitary equipment and decorative metal finishing. Its technology portfolio includes plating chemicals, industrial cleaners, plating on plastics, decorative metal coatings, electroless nickel, corrosion-resistant coatings, wear-resistant coatings, anodizing and electronic surface-finishing processes. The ransomware attack allegedly resulted in the exposure of a broad range of internal corporate data, including administrative records, business development and marketing information, commercial-office data, finance and accounting records, food-related information, human resources data, international sales and services records, laboratory and laboratory-service information, legal and logistics data, maintenance records, management-office information, material laboratory data, planning and portfolio information, procurement records, product-development data, production and production planning records, quality assurance and quality-control (QA/QC) information, quality management records, research and development (R&D) data, technical development and technical sales/service information, warehouse records, attachments, client setup information, dashboards, data-server monitoring information, documentation, emails, fax records, HTML/web content, inventory information, and other internal operational files.

Relevancy & Insights:

  • SafePay Ransomware is a rapidly emerging and sophisticated ransomwarethreat first identified in September 2024.
  •  The SafePay Ransomware group primarily targets industries, includingProfessional Goods & Services, Consumer Goods & Services, Real Estate &Construction, Manufacturing, and Information Technology.

ETLM Assessment:

According to CYFIRMA’s assessment, SafePay represents a sophisticated, fast-movingransomware threat capitalizing on VPN weaknesses and credential theft, employingeffective double extortion tactics to maximize ransom payments. Organizations,especially in highly targeted sectors and regions, must prioritize layered defenses andactive hunting for early detection.

7. Data Leaks

Unauthorized Database Advertised on a Leak Site

  • Attack Type: Data Leak
  • Target Industry: Travel & Tourism
  • Target Geography: Japan
  • Objective: Financial Gains
  • Business Impact: Exposure of Personally Identifiable Information (PII), customerprivacy risks, identity theft, fraud, regulatory compliance concerns, financial losses,and reputational damage.

Summary:

The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a large database allegedly associated with a Japanese travel and tourism organization. According to the advertisement, the dataset reportedly contains information related to customer contacts, travel bookings, and passport verification records. The seller claims that the dataset has been organized into multiple sections covering customer information, booking details, and identity-document verification data. Sample data and references were reportedly provided as proof of possession, while the complete dataset was offered for sale.

Allegedly Exposed Data
Based on the information visible in the advertisement, the dataset may contain:

1. Customer and Contact Information

  • Full names and salutations
  • Gender and date of birth
  • Email addresses
  • Primary and secondary telephone numbers
  • Mailing addresses
  • Country and region information
  • Customer and account IDs
  • Owner/user identifiers
  • Preferred language
  • Customer segment and status
  • Preferred contact method
  • Department and job title
  • Annual revenue and number of employees
  • Social-media profile information
  • Campaign and regional identifiers

2. Travel and Booking Information

  • Booking start and end dates
  • Trip-end dates
  • Booking status
  • Booking amounts
  • Booking and package IDs
  • Payment status and payment method
  • Booking channel and agency information
  • Booking pipeline information
  • Discount and cancellation information
  • Travel-insurance details
  • Special requests
  • Accommodation type
  • Transportation type
  • Seat numbers
  • Loyalty-program IDs
  • Loyalty points earned
  • Additional charges and tax amounts
  • Currency and booking notes

3.Passport and Identity-Verification Information

  • Document type
  • Document number
  • Passport/document expiry date
  • Document holder’s full name
  • Date of birth
  • Document-issuing country
  • Issuing authority
  • Place of birth
  • Verification ID and contact ID
  • Verification status and date
  • Verification method
  • Risk score
  • Compliance notes
  • Document-scan references
  • Verification comments
  • Associated booking IDs
  • Data-privacy consent information

The authenticity of the allegedly exposed dataset remains unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

 

Unauthorized Airline Database Advertised on a Leak Site

  • Attack Type: Data Leak
  • Target Industry: Aviation / Travel & Transportation
  • Target Geography: Thailand
  • Objective: Financial Gains
  • Business Impact: Exposure of passenger PII, passport and identity information, booking and ticketing data, payment-related information, loyalty-program data, operational information, privacy risks, regulatory concerns, financial losses, and reputational damage.

Summary: The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a large database allegedly originating from a Thailand-based airline organization. The advertisement claims that the dataset contains more than 200 million records associated with passenger and airline operations. According to the screenshot, the allegedly exposed information covers multiple areas, including:

  • Booking and reservation information
  • Ticketing details
  • Passenger information
  • Baggage-related information
  • Loyalty-program data
  • Payment-related information
  • Customer-service information
  • Digital activity/log data
  • Operational information

The post also displays sample database records as evidence of possession. The visible sample contains passenger-related fields and appears to demonstrate structured records from an airline reservation or customer-management environment.

Allegedly Exposed Data

Based on the information visible in the advertisement, the dataset may contain:

  • Passenger type
  • Reservation IDs
  • Passenger titles
  • First and last names
  • Dates of birth
  • Mobile telephone numbers
  • Passport expiration dates
  • Nationality
  • Passenger login/account IDs
  • Passport issue dates
  • Gender
  • Document expiration dates
  • Booking and reservation information
  • Ticketing information
  • Baggage-related records
  • Loyalty-program information
  • Payment-related information
  • Customer-service records
  • Digital logs
  • Operational data

The authenticity and extent of the alleged unauthorized access remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums

Relevancy & Insights

Financially motivated cybercriminals are continuously looking for exposed and vulnerable systems and applications to exploit. A significant number of these malicious actors congregate within underground forums, where they discuss cybercrime and trade stolen digital assets. Operating discreetly, these opportunistic attackers target unpatched systems or vulnerabilities in applications to gain access and steal valuable data. Subsequently, the stolen data is advertised for sale within underground markets, where it can be acquired, repurposed, and utilized by other malicious actors in further illicit activities.

ETLM Assessment

The threat actor is assessed as an active and capable cybercriminal entity primarily involved in data-leak and information-extortion activities, with multiple indications of unauthorized access to systems and the subsequent dissemination or sale of compromised data through underground forums. Their activities demonstrate the evolving sophistication of organized cybercriminal networks and highlight the increasing risk of sensitive information being exploited for financial gain, fraud, and follow-on attacks. Organizations should strengthen their cybersecurity posture through continuous monitoring, proactive threat intelligence, robust access controls, enhanced data protection, and timely defensive measures to safeguard sensitive information and critical infrastructure.

Recommendations:

Enhance the cybersecurity posture by:

  1. Updating all software products to their latest versions is essential to mitigate the risk of vulnerabilities being exploited.
  2. Ensure proper database configuration to mitigate the risk of database-related attacks.
  3. Establish robust password management policies, incorporating multi-factor authentication and role-based access to fortify credential security and prevent unauthorized access.

8. Other Observations

The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a database allegedly belonging to an India-based digital gateway and logistics platform serving the Lakshadweep Islands. According to the advertisement, the platform primarily facilitates connectivity and logistics between the Indian mainland, including Kochi, Kerala, and the Lakshadweep Islands.

The advertisement claims that a database associated with the platform was compromised on 03 October 2026 and is being offered for sale. The seller has reportedly assigned a price of US$500, with negotiations permitted.

Allegedly Exposed Information

The advertisement does not provide a detailed list of database fields or sample records. However, based on the description of the platform and the database being offered, the exposed information may include:

  • Customer or user information
  • Logistics and transportation-related records
  • Booking or transaction information
  • Account-related information
  • Contact details
  • Service-related records
  • Operational and logistical information
  • Internal database records
  • Other information associated with the platform’s digital services

Potential Impact

If the claims are verified, unauthorized exposure of the database could create risks including:

  • Customer privacy exposure through unauthorized access to personal or account information.
  • Targeted phishing and social-engineering attacks using information associated with customers or users.
  • Identity theft and impersonation if personally identifiable information is present.
  • Fraudulent transactions or account takeover if authentication or account-related information is exposed.
  • Operational intelligence exposure, potentially revealing information about logistics and transportation activities.
  • Supply-chain risks involving connected logistics providers or service partners.
  • Further cyberattacks against exposed systems using information obtained from the database.
  • Regulatory and compliance concerns if personal information is confirmed to have been compromised.
  • Reputational damage and financial losses resulting from a confirmed data breach.

However, the authenticity of the alleged database, the actual breach, the volume ofcompromised records, and the specific information contained in the dataset have notbeen independently verified. The assessment is therefore based solely on the informationpresented in the cybercrime-forum advertisement and should be treated as an allegeddata leak pending validation.

Source: Underground Forums

RECOMMENDATIONS

 STRATEGIC RECOMMENDATIONS

  • Attack Surface Management should be adopted by organisations, ensuring that a continuous closed-loop process is created between attack surface monitoring and security testing.
  • Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes.
  • Incorporate Digital Risk Protection (DRP) in the overall security posture that acts as a proactive defence against external threats targeting unsuspecting customers.
  • Implement a holistic security strategy that includes controls for attack surface reduction, effective patch management, and active network monitoring, through next-generation security solutions and a ready-to-go incident response plan.
  • Create risk-based vulnerability management with deep knowledge about each asset. Assign a triaged risk score based on the type of vulnerability and criticality of the asset to help ensure that the most severe and dangerous vulnerabilities are dealt with first.

MANAGEMENT RECOMMENDATIONS

  • Take advantage of global Cyber Intelligence, providing valuable insights on threat actor activity, detection, and mitigation techniques.
  • Proactively monitor the effectiveness of risk-based information security strategy, the security controls applied, and the proper implementation of security technologies, followed by corrective actions, remediations, and lessons learned.
  • Consider implementing Network Traffic Analysis (NTA) and Network Detection and Response (NDR) security systems to compensate for the shortcomings of EDR and SIEM solutions.
  • Ensure that detection processes are tested to ensure awareness of anomalous events. Timely communication of anomalies should be continuously evolved to keep up with refined ransomware threats.

TACTICAL RECOMMENDATIONS

  • Patch software/applications as soon as updates are available. Where feasible, automated remediation should be deployed since vulnerabilities are one of the top attack vectors.
  • Consider using security automation to speed up threat detection, improved incident response, increased the visibility of security metrics, and rapid execution of security checklists.
  • Build and undertake safeguarding measures by monitoring/blocking the IOCs and strengthening defences based on the tactical intelligence provided.
  • Deploy detection technologies that are behavioral anomaly-based to detect ransomware attacks and help to take appropriate measures.
  • Implement a combination of security controls, such as reCAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP blacklisting, Rate-limiting, and Account lockout to thwart automated brute-force attacks.
  • Ensure email and web content filtering uses real-time blocklists, reputation services, and other similar mechanisms to avoid accepting content from known and potentially malicious sources.

Situational Awareness – Cyber News

Please find the Geography-Wise and Industry-Wise breakup of cyber news for the last 5 days as part of the situational awareness pillar.



Click Here For The Original Source.

——————————————————–

..........

.

.