Weekly Intelligence Report – 25 Sep 2026

Published On : 2026-09-28
Share :
Weekly Intelligence Report – 25 Sep 2026

Ransomware In Focus

CYFIRMA Research and Advisory Team would like to highlight ransomware trends and insights gathered while monitoring various forums. This includes multiple industries, geographies, and technologies that could be relevant to your organization.

Type: Ransomware
Target Technologies: Windows OS

Introduction:

CYFIRMA Research and Advisory Team has found Altair Ransomware while monitoring various underground forums as part of our Threat Discovery Process.

Altair Ransomware

Altair is a file-encrypting ransomware that compromises systems and encrypts accessible user data, making affected files unavailable to the victim. After encryption, it modifies the filenames by adding a variant-specific .altair extension, such as .altair19, and generates an HTML ransom note named RANSOM_NOTE.html. The malware follows a double-extortion model: besides denying access to files, the attackers claim to have copied confidential information from the compromised environment. They use the alleged data theft as additional leverage, threatening to disclose or sell the information if the victim does not meet their financial demands.

Screenshot: File encrypted by the ransomware (Source: Surface Web)

The ransom note informs the victim that the network has been compromised and provides instructions for communicating with the attackers through specified email accounts or a Tor-based channel. It offers limited test decryption of a few non-sensitive files to demonstrate that the attackers possess a working recovery mechanism. The message also warns victims against renaming or altering encrypted files and attempts to discourage them from using external recovery services. A 72-hour deadline is given for initiating communication, with the attackers threatening to increase the ransom afterward. Overall, the note combines file-recovery pressure with the threat of data exposure to increase the likelihood of ransom payment.

Screenshot: The appearance of Altair’s ransom note (RANSOM_NOTE.html) (Source: Surface Web)

The following are the TTPs based on the MITRE ATT&CK framework

Tactic Technique ID Technique Name
Execution T1047 Windows Management Instrumentation
Execution T1059 Command and Scripting Interpreter
Execution T1129 Shared Modules
Execution T1574 Hijack Execution Flow
Privilege Escalation  

T1055

 

Process Injection

Privilege Escalation  

T1134

 

Access Token Manipulation

Discovery T1012 Query Registry
Discovery T1033 System Owner/User Discovery
Discovery T1057 Process Discovery
Discovery T1082 System Information Discovery
Discovery T1083 File and Directory Discovery
Discovery T1135 Network Share Discovery
Collection T1074 Data Staged
Collection T1560 Archive Collected Data
Command and Control  

T1071

 

Application Layer Protocol

Impact T1486 Data Encrypted for Impact
Stealth T1027 Obfuscated Files or Information
Stealth T1055 Process Injection
Stealth T1134 Access Token Manipulation
Stealth T1202 Indirect Command Execution
Stealth T1564.003 Hide Artifacts: Hidden Window
Stealth T1574 Hijack Execution Flow

Relevancy and Insights:

  • The ransomware primarily targets Windows environments, utilizing Windows services, command-line utilities, registry configurations, system APIs, and filesystem operations to perform encryption, system modification, and recovery-inhibition activities.
  • calls-wmi: The ransomware leverages Windows Management Instrumentation (WMI), a versatile Windows feature that enables it to discreetly collect system information, control processes, or execute commands. This technique is commonly used to avoid detection and carry out reconnaissance activities within the system.
  • The ransomware terminates processes such as exe Delete Shadows /all /quiet and wmic shadowcopy delete /nointeractive to delete Volume Shadow Copies, which are used by Windows for backup and restore. By removing these shadow copies, the malware ensures that victims cannot recover their files via system restore points or backup utilities.
  • Detect-debug-environment: The ransomware technique is used to determine if it is being monitored in environments such as sandboxes, virtual machines, or under debugging tools. To perform this check, the malware may look for specific processes, drivers, or artifacts linked to analysis tools, measure timing to spot inconsistencies, or scan for system traits uncommon in real user When such conditions are identified, the malicious program can modify its behavior, such as pausing execution, shutting down, or withholding key payload actions to avoid detection and make detailed analysis more difficult.

ETLM Assessment:

Altair ransomware may evolve by improving its ability to identify valuable systems and data before initiating encryption. Future variants could incorporate stronger defense-evasion mechanisms, more extensive discovery of network resources, and improved privilege-abuse techniques to reach additional endpoints and shared storage. The malware may also become more selective in its encryption behavior, prioritizing business-critical documents, databases, backups, and virtual-machine resources to maximize operational disruption while avoiding files that are unnecessary for extortion. Changes to file extensions, ransom-note formats, communication infrastructure, and encryption implementation could further complicate automated detection and recovery efforts.

Future versions may also place greater emphasis on data theft and multi-stage extortion rather than relying solely on file encryption. Attackers could combine stolen information with threats of public disclosure, targeted pressure against affected organizations, and increasingly automated negotiation processes. Ransomware operators may additionally adapt their techniques to exploit cloud environments, remote-access infrastructure, and interconnected enterprise networks. As defensive technologies improve, the malware is likely to evolve through more sophisticated evasion and deployment techniques, making behavioral monitoring, network segmentation, offline backups, least-privilege controls, and rapid incident response increasingly important for limiting its impact.

Sigma rules:

title: Shadow Copies Deletion Using Operating Systems Utilities tags:

  • impact
  • stealth logsource:

category: process_creation product: windows

detection: selection1_img:

  • Image|endswith:
    • ‘\powershell.exe’
    • ‘\pwsh.exe’
    • ‘\wmic.exe’
    • ‘\vssadmin.exe’
    • ‘\diskshadow.exe’
  • OriginalFileName:
    • ‘PowerShell.EXE’
    • ‘pwsh.dll’
    • ‘wmic.exe’
    • ‘VSSADMIN.EXE’
    • ‘diskshadow.exe’ selection1_cli:

CommandLine|contains|all:

  • ‘shadow’ # will match “delete shadows” and “shadowcopy delete” and “shadowstorage”
  • ‘delete’

selection2_img:

  • Image|endswith: ‘\wbadmin.exe’
  • OriginalFileName: ‘WBADMIN.EXE’ selection2_cli:

CommandLine|contains|all:

  • ‘delete’
  • ‘catalog’
  • ‘quiet’ # will match -quiet or /quiet selection3_img:
  • Image|endswith: ‘\vssadmin.exe’
  • OriginalFileName: ‘VSSADMIN.EXE’ selection3_cli:

CommandLine|contains|all:

  • ‘resize’
  • ‘shadowstorage’ CommandLine|contains:
  • ‘unbounded’
  • ‘/MaxSize=’

condition: (all of selection1*) or (all of selection2*) or (all of selection3*) falsepositives:

  • Legitimate Administrator deletes Shadow Copies using operating systems utilities for legitimate reason
  • LANDesk LDClient Ivanti-PSModule (PS EncodedCommand) level: high
    (Source: Surface Web)

IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)

RECOMMENDATIONS

STRATEGIC RECOMMENDATIONS

  • Implement competent security protocols and encryption, authentication, or access credential configurations to access critical systems in your cloud and local environments.
  • Ensure that backups of critical systems are maintained, which can be used to restore data in case a need arises.

MANAGEMENT RECOMMENDATIONS

  • A data breach prevention plan must be developed considering (a) the type of data being managed by the company; (b) the remediation process; (c) where and how the data is stored; (d) if there is an obligation to notify the local
  • Implement a zero-trust security model alongside multifactor authentication (MFA) to reduce the risk of credential compromise.
  • Foster a culture of cybersecurity, where you encourage and invest in employee training so that security is an integral part of your organization.

TACTICAL RECOMMENDATIONS

  • Update all applications/software regularly with the latest versions and security patches alike.
  • Add the Sigma rules for threat detection and monitoring, which will help to detect anomalies in log events and identify and monitor suspicious activities.
  • Establish and implement protective controls by actively monitoring and blocking identified indicators of compromise (IoCs) and reinforcing defensive measures based on the provided tactical intelligence.

Active Malware of the Week

Type: Downloader / Dropper | Objectives: Payload Delivery and System Compromise | Target Technology: Windows | Target Geography: Global

CYFIRMA collects data from various forums based on which the trend is ascertained. We identified a few popular malwares that were found to be distributed in the wild to launch cyberattacks on organizations or individuals.

Active Malware of the Week
This week, WailsLoader Malware is in focus.

Overview of Operation WailsLoader Malware

The sample analyzed, identified as WailsLoader, was observed to function primarily as a malware delivery component rather than as a conventional application. Its main purpose is to establish an initial foothold and facilitate the introduction of additional malicious software into a compromised environment. Although its direct activity may appear limited, its role in enabling subsequent stages makes its presence significant.The sample acts as an intermediary between the initial compromise and the activity that follows. Rather than focusing heavily on collecting information from the affected system itself, it communicates with external infrastructure to obtain additional content. Consequently, the potential impact of an infection extends beyond the activity directly attributed to the initial component and depends largely on what is delivered and executed afterward.

During the analyzed session, there was limited evidence of mechanisms designed to maintain a long-term presence on the system. The observed activity appeared relatively short-lived, although this does not indicate that the threat is harmless or necessarily temporary. Its execution may form part of a broader attack sequence in which further activity is initiated through subsequent delivery or user interaction. Overall, the presence of this component should be considered a security concern because it provides a pathway for additional malicious activity and maintains communication with external infrastructure. Its significance therefore lies not only in its immediate behavior, but also in the access and follow-on activity that it can enable within an affected environment.

Attack Method

On execution on a Windows host, the sample begins with an initial system-orientation phase to determine the environment in which it is operating. It collects basic host and operating-system information that can help establish whether the execution environment is suitable for subsequent activity. This stage appears focused on environmental awareness rather than extensive host reconnaissance or broad data collection, allowing the component to proceed with its primary delivery function. The observed execution sequence did not show a dedicated mechanism for maintaining long-term persistence or a clearly defined defense-evasion routine during the analysis period. Its activity remained relatively limited after the initial execution and environmental checks. However, the absence of these behaviors within the captured session does not necessarily indicate that the broader attack lacks persistence or evasion capabilities, as these functions may be provided by another component or initiated during a subsequent stage of the infection chain.

The primary functional behavior observed was the retrieval of an additional payload from external infrastructure. After establishing its execution environment, the sample communicates externally to obtain follow-on content and prepares that payload for subsequent execution. This positions the component as an initial delivery mechanism within a larger infection chain rather than as the final malicious payload. Its limited local activity is therefore consistent with a design intended to transfer execution to a more capable component.

The overall execution flow demonstrates a staged approach in which the initial component performs only the activity required to establish execution, assess the host, and facilitate delivery of the next-stage payload. This separation of responsibilities can reduce the visible footprint of the initial component while allowing more extensive malicious activity to occur through subsequently delivered software. The observed behavior therefore indicates that the principal purpose of the sample is to enable the next phase of the compromise rather than independently perform extensive collection or system manipulation.

The Following are the TTPs based on the MITRE ATT&CK Framework for Enterprises

INSIGHTS

The activity indicates that the initial compromise should be viewed in the context of a broader operation rather than as an isolated malware event. The limited role of the observed component suggests that its significance comes from how it fits into a larger sequence of activity. This distinction is important when assessing the incident, as the visible behavior of the first-stage component may not represent the full scope of the underlying operation.

Another notable aspect is the separation between the initial access stage and the activity that follows. By keeping the first stage relatively focused, the operation can maintain a smaller visible footprint while allowing subsequent components to perform different functions. This separation also makes the individual stages less representative of the overall activity when examined independently, highlighting the importance of considering the complete sequence rather than judging the threat from a single component.

The observed characteristics also suggest that the activity is not necessarily tied to a narrowly defined victim profile. Its usefulness appears to come from its ability to operate as part of a broader delivery process, allowing the subsequent stages to determine what activity takes place on an affected system. This makes the campaign’s significance more closely associated with the opportunities presented by compromised environments than with a specific type of organization or user.

ETLM ASSESSMENT

From an ETLM perspective, this type of activity could increasingly affect organizations by turning seemingly limited compromises into broader operational concerns. In the future, employees may encounter greater disruption to routine activities as compromised systems become connected to wider security incidents, potentially affecting access to business resources, productivity, and the handling of organizational information. Organizations could also face increasing difficulty in determining the full scope of an incident when initial activity appears limited but later develops into more extensive compromise. Over time, repeated incidents of this nature may place greater pressure on business operations, incident-response efforts, recovery processes, and overall organizational resilience, making the consequences extend beyond the initially affected systems.

IOCs:

Kindly refer to the IOCs below to exercise controls on your security systems. (Source: Open Surface)

YARA Rules

rule WailsLoader_Malware

{

meta:

description = “Detection rule for the analyzed Wails Loader malware sample” author = “CYFIRMA Research”

date = “2026-09-22”

strings:

$hash1 = “f1711b816466428b20ece9ebaa81ca377fd758771a33c959f46be582b1f4404d” ascii

$s1 = “\\Device\\KsecDD” ascii wide

$s2 = “KsecDD” ascii wide

$s3 = “WailsLoader” ascii wide

condition:

any of ($hash*) or 2 of ($s*)

}

Recommendations

Strategic Recommendations

  • Establish an organization-wide endpoint security strategy covering malware prevention, detection, and response.
  • Prioritize protection of sensitive credentials and business information stored or accessed from employee endpoints.
  • Adopt layered security controls so that a single compromised endpoint does not provide prolonged access to organizational resources.
  • Conduct periodic threat assessments to identify exposure to multi-purpose malware and similar information-stealing threats.

Management Recommendations

  • Prioritize egress-log retention so payload-delivery requests can be reconstructed during investigations.
  • Ensure endpoint protection and security monitoring capabilities are consistently deployed across employee systems.
  • Establish clear incident-response procedures for suspected malware infections, including isolation, investigation, and recovery.
  • Provide regular security-awareness training focused on suspicious files, links, downloads, and unexpected system activity.
  • Maintain appropriate controls over access to sensitive corporate information and user accounts.

Tactical Recommendations

  • Monitor endpoints for unusual PowerShell activity, unexpected process trees, and unauthorized changes to security settings.
  • Block and monitor the infrastructure listed in the IOC section at DNS, proxy, and perimeter controls.
  • Isolate confirmed cases promptly, then reset credentials and review autostart locations before restoration.

CYFIRMA’s Weekly Insights

1. Weekly Attack Types and Trends

Key Intelligence Signals:

  • Attack Type: Ransomware Attacks, Vulnerabilities & Exploits, Data
  • Objective: Unauthorized Access,   Data Theft,                  Data                            Encryption, Financial     Gains, Espionage.
  • Business Impact: Data Loss, Financial Loss, Reputational Damage, Loss of Intellectual Property, Operational Disruption.
  • Ransomware – ArcusMedia Ransomware, The Gentlemen Ransomware| Malware – WailsLoader
  • ArcusMedia Ransomware– One of the ransomware
  • The Gentlemen Ransomware – One of the ransomware
    Please refer to the trending malware advisory for details on the following.
  • Malware – WailsLoader
  • Behavior – Most of these malwares use phishing and social engineering techniques as their initial attack vectors. Apart from these techniques, exploitation of vulnerabilities, defense evasion, and persistence tactics are being observed.

2. Threat Actor in Focus

Transparent Tribe (APT36): Evolving Cyber-Espionage Capabilities and Operational Tradecraft

  • Threat Actor: Transparent Tribe aka APT36
  • Attack Type: Spear-phishing, Malware Implant, Exploitation of Vulnerabilities, ClickFix Technique, Watering-hole Attacks.
  • Objective: Espionage, Data and Information Theft
  • Target Technology: Removable Media, Windows, Linux, Android, Web Browsers, Credential Stores, Mobile Applications, Desktop Applications, Microsoft Office
  • Target Geography: Afghanistan, Australia, Austria, Azerbaijan, Belgium, Botswana, Bulgaria, Canada, China, Czech Republic, Germany, India, Iran, Japan, Kazakhstan, Kenya, Malaysia, Mongolia, Nepal, Netherlands, Oman, Pakistan, Romania, Saudi Arabia, Spain, Sweden, Thailand, Turkey, UAE, UK,
  • Target Industries: Aerospace & Defense, Commercial Services & Supplies, Oil, Gas & Consumable Fuels, Information Technology, Government, Transportation, Education Services, Energy, Media & Entertainment, Professional Services, Airlines, Construction & Engineering, Banks, Telecommunication Services, Health Care Providers & Services, Entertainment, Legal Services, Utilities
  • Business Impact: Data Theft, Operational Disruption, Reputational Damage

About the Threat Actor

Transparent Tribe, also known as APT36, is a suspected Pakistan-linked, state-sponsored threat actor believed to have been active since 2016. The group primarily targets military organizations, embassies, and government entities, conducting cyber-espionage operations to collect sensitive information that aligns with Pakistan’s military and diplomatic interests. Its targeting extends to neighboring and foreign countries. Transparent Tribe (APT36) primarily relies on spear-phishing and watering-hole attacks to gain initial access, using phishing emails containing malicious macros or vulnerability-based RTF files to compromise targeted victims.

Details on Exploited Vulnerabilities

 

CVE ID

 

Affected Products

 

CVSS Score

 

Exploit Links

 

CVE-2026-21509

 

Microsoft Office

 

7.8

 

–

 

 

CVE-2018-14041

 

 

Bootstrap before 4.1.2

 

 

6.1

 

 

Link1, Link2

 

CVE-2025-64496

 

Open WebUI

 

8.0

 

–

 

CVE-2022-41034

 

Visual Studio Code

 

7.8

 

–

 

 

CVE-2025-10035

 

 

Fortra’s GoAnywhere MFT

 

 

9.8

 

 

–

 

 

CVE-2017-8759

 

 

Microsoft .NET Framework

 

 

7.8

 

 

link

 

CVE-2023-39234

 

TKWave 3.3.115

 

7.8

 

–

 

CVE-2021-40539

 

Zoho ManageEngine

 

9.8

 

link

TTPs based on the MITRE ATT&CK Framework

Tactic ID Technique
Resource Development T1583.001 Acquire Infrastructure: Domains
Resource Development T1584.001 Compromise Infrastructure: Domains
Resource Development T1608.001 Stage Capabilities: Upload Malware
Resource Development T1587.003 Develop Capabilities: Digital Certificates
Resource Development T1608.004 Stage Capabilities: Drive-by Target
Initial Access T1566.001 Phishing: Spear phishing Attachment
Initial Access T1189 Drive-by Compromise
Initial Access T1566.002 Phishing: Spear-phishing Link
Execution T1203 Exploitation for Client Execution
Execution T1204.001 User Execution: Malicious Link
Execution T1059.005 Command and Scripting Interpreter: Visual Basic
Execution T1204.002 User Execution: Malicious File
Stealth T1036.005 Masquerading: Match Legitimate Name or Location
Stealth T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
Stealth T1564.001 Hide Artifacts: Hidden Files and Directories
Command and Control T1568 Dynamic Resolution

Latest Developments Observed

Transparent Tribe (APT36) is suspected of conducting Operation RapidRust, targeting government and defense organizations in India and Afghanistan. The campaign introduced new malware and post-compromise tools, including the Rust-based RUSTYSHADE backdoor, RUSTYMOVE USB propagation tool, and PSNATCH and BASHNATCH file stealers targeting Windows and Linux environments. APT36 leveraged typosquatted domains impersonating Indian news outlets and private GitHub repositories for payload staging, command-and-control, and data exfiltration. The activity appears aimed at stealing sensitive information, maintaining persistent access, and facilitating malware propagation to air-gapped networks.

ETLM Insights

Transparent Tribe (APT36), a Pakistan-nexus threat actor, continues to demonstrate an adaptive cyber-espionage model focused on government and defense organizations in India and Afghanistan. The threat group’s campaigns highlight the group’s evolving malware capabilities, cross-platform file theft, and use of legitimate cloud services to support persistent access and sensitive information collection.

Looking ahead, Transparent Tribe is likely to continue evolving its malware ecosystem to enhance operational flexibility and evade conventional security controls. Trusted platforms and impersonation infrastructure, including typosquatted domains, legitimate code-hosting services, and compromised infrastructure, are likely to remain important enablers for payload delivery and C2 operations. Future activity may increasingly focus on credential theft, persistent access, and targeted intelligence collection against government, defense, and other high-value targets.

IOCs:

Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)

YARA Rules

rule Threat_Activity_IOC_Detection

{

meta:

description = “Detects files containing supplied threat activity IOCs” author = “CYFIRMA”

date = “2026-09-22”

category = “Threat Intelligence IOC Detection”

 

strings:

// Domains

$domain1 = “defence.cdga.site” ascii wide nocase

$domain2 = “appstoore.duckdns.org” ascii wide nocase

$domain3 = “nic-support.site” ascii wide nocase

$domain4 = “www.nicservice.org” ascii wide nocase

 

// IP addresses

$ip1 = “2.56.10.86” ascii wide

$ip2 = “46.30.188.13” ascii wide

$ip3 = “172.217.16.227” ascii wide

$ip4 = “64.227.133.141” ascii wide

$ip5 = “173.194.45.95” ascii wide

 

// File names

$file1 = “uvj3lwj.exe” ascii wide nocase

$file2 = “jitsimeet-setup.exe” ascii wide nocase

 

// File path indicators

$path1 = “C:\\Windows\\uvj3lwj.exe” ascii wide nocase

$path2 = “C:\\Users\\user\\AppData\\Local\\Temp\\susmnw.xdj\\jitsimeet-setup.exe” ascii wide nocase

 

condition:

1 of ($domain*) or 1 of ($ip*) or

1 of ($file*) or 1 of ($path*)

}

Recommendations

Strategic Recommendations

  • Incorporate Digital Risk Protection (DRP) as part of the overall security posture to proactively defend against impersonations and phishing attacks.
  • Deploy a Zero Trust Policy that leverages tools like security information management, advanced security analytics platforms, security user behaviour analytics, and other analytics systems to help the organization’s security personnel observe in real-time what is happening within their networks so they can orient defences more intelligently.
  • Block exploit-like behaviour. Monitor endpoints memory to find behavioural patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new. This will be able to provide effective protection against zero-day/critical exploits and more by identifying such patterns.

Management Recommendations

  • Regularly reinforce awareness related to different cyberattacks using impersonated domains/spoofed webpages with end-users across the environment and emphasize the human weakness in mandatory information security training sessions.
  • Look for email security solutions that use ML- and AI-based anti-phishing technology for BEC protection to analyze conversation history to detect anomalies, as well as computer vision to analyze suspect links within emails.

Tactical Recommendations

  • Protect accounts with multi-factor authentication. Exert caution when opening email attachments or clicking on embedded links supplied via email communications, SMS, or messaging.
  • Set up DMARC (Domain-based Message Authentication, Reporting & Conformance) to stop phishers from spoofing your domain (that is, making their emails look like they come from your organization).
  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs and strengthening defence based on the tactical intelligence provided.
  • Add the YARA rules for threat detection and monitoring, which will help to detect anomalies in log events, identify and monitor suspicious activities.

3. Major Geopolitical Developments in Cybersecurity

Hackers Targeting Global Shipping

Ships are increasingly becoming targets of cyberattacks, and the incidents are no longer isolated. In late August, the US Coast Guard and FBI boarded two foreign-flagged oil tankers in the Gulf of Mexico after both vessels showed signs of network compromise while transiting the Strait of Gibraltar. One, the VL Prosperity – a South Korean-managed tanker carrying two million barrels of Gulf crude – lost communications for more than thirty hours. US officials are investigating potential Iranian involvement, though no formal attribution has been made. Iranian state media amplified the story, sharing unconfirmed details about the breach’s extent – opportunistic reporting that itself falls short of evidence.

The incidents are part of a broader pattern. A third vessel, the LNG carrier Vivit Africa, suffered a suspected cyberattack in early September while sailing toward Italy, leaving its crew unable to access internal control systems. The ship turned away from its destination and is currently near Tunisia with its cargo undelivered. US agencies are now monitoring nearly twenty vessels worldwide for similar threats, and the Coast Guard has requested advance notice from any of those ships before they enter American ports.

What makes ships particularly exposed is their growing connectivity. Every major system — navigation, engines, cargo monitoring — is now linked via satellite to shore-based control centres, creating what one maritime cybersecurity executive described as “a floating attack surface.” Attacks infiltrating vessels through satellite-linking edge devices jumped from 3% of all incidents in 2024 to 22% in 2025. Shipowners have also increasingly adopted Starlink to improve crew connectivity, adding another entry point. Once inside the satellite connection, an attacker can potentially cross over into onboard operational systems — controlling speed, temperature, propulsion.

ETLM Assessment:

The underlying vulnerability is structural. Much of the equipment running ships’ operational systems is decades old, built long before cyberattacks were a realistic threat and difficult to update without taking vessels out of service. The boundary between operational technology and standard IT is blurring as ships become more automated — and ransomware is no longer the only concern. Shipping executives now rank cyber threats as the second-highest operational risk to the industry, yet cybersecurity ranks only fifth in terms of the industry’s readiness to handle it. That gap is becoming dangerous.

As an upcoming CYFIRMA report on chokepoints and attacks on shipping concludes, shipping and logistics operators should treat periods of chokepoint pressure – in which we currently find ourselves – as periods of heightened cyber exposure rather than as purely physical supply-chain events, with particular emphasis on identity security and third-party access, internet-facing infrastructure, the resilience of manual fallback processes, and the segmentation that keeps an IT compromise from becoming an operational one. This assessment is based on the intelligence available at the time of writing and is subject to change as the situation develops.

Port of LA Targeted By 120 Million Cyberattacks Last Month Alone

Amid evolving tariff policies, the Port of Los Angeles—the nation’s busiest container port—faced a relentless digital onslaught in August, successfully blocking over 120 million cyberattack attempts.

During an interview with Bloomberg Television, Executive Director Gene Seroka revealed that the port detected a broad spectrum of threats, including network exploitation, intrusion attempts, credential harvesting, and malware. He credited their resilience to a multi-layered defense strategy featuring a seven-tier digital shield forged through a public-private coalition between the port’s cybersecurity team and private businesses.

Seroka’s disclosures follow recent warnings from U.S. officials tracking active cyber threats targeting approximately 20 vessels globally. These incidents highlight a broader, escalating trend of digital vulnerability across the maritime sector as modern shipping operations grow increasingly dependent on automated navigation and communication networks.

ETLM Assessment:

CYFIRMA assesses that the defining vulnerability of the next phase of the global economy will not be any single chokepoint’s physical closure, but the convergence of cyber, kinetic, and political pressure applied to several chokepoints like maritime straits and ports at once. The pattern is already visible: digital reconnaissance and pre-positioning inside energy and port infrastructure regularly precede or accompany physical strikes and diplomatic coercion rather than substituting for them, blurring the line between espionage, sabotage and statecraft.

4. Rise in Malware/Ransomware and Phishing

ArcusMedia Ransomware Impacts an Agricultural Organisation in Thailand

  • Attack Type: Ransomware
  • Target Industry: Agriculture
  • Target Geography: Thailand
  • Ransomware: ArcusMedia Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that an organisation from Thailand was compromised by ArcusMedia ransomware. The compromised organisation serves as a central hub for agricultural research management, focusing on strengthening and sustaining the agricultural sector. It promotes, supports, and develops professional agricultural researchers while providing a comprehensive research information system. The agency aims to enhance the agricultural industry in Thailand to compete globally by facilitating the application of research outcomes in various agricultural fields. Its intended clients include agricultural professionals, researchers, and businesses seeking to utilize research for commercial development. The data, which has been breached, has not yet appeared on the leak site, indicating that negotiations between the affected party and the ransomware group may be underway. The compromised data includes confidential and sensitive information belonging to the organization.

Source: Dark Web

Relevancy & Insights:

  • ArcusMedia ransomware began operations in May 2024 and has quickly gained attention in the cybersecurity The group employs phishing emails to gain initial access, deploying custom ransomware binaries and using obfuscation techniques to evade detection.
  • The ArcusMedia Ransomware group primarily targets countries such as Brazil, Spain, France, the United States of America, and Canada.
  • The ArcusMedia Ransomware group primarily targets industries such as Information Technology, Manufacturing, Transportation & Logistics, Consumer Goods & Services, and Real Estate & Construction.
  • Based on the ArcusMedia Ransomware victims list from 1st Jan 2025 to 22nd September 2026, the top 5 Target Countries are as follows:

 

  • The Top 10 Industries most affected by the ArcusMedia Ransomware group victims list from 1stJan 2025 to 22nd September 2026 are as follows:

ETLM Assessment:

Based on recent assessments by CYFIRMA, ArcusMedia ransomware represents a significant threat in the cybersecurity landscape, characterized by its sophisticated tactics and aggressive approach to extortion. Organizations are advised to enhance their cybersecurity defenses, including employee training on phishing awareness, regular updates to systems, and comprehensive incident response plans to mitigate risks associated with this evolving threat actor. Continuous monitoring of ArcusMedia’s activities will be essential for understanding its impact on global cybersecurity efforts.

The Gentlemen Ransomware Impacts a Manufacturing Company from Japan

  • Attack Type: Ransomware
  • Target Industry: Manufacturing
  • Target Geography: Japan
  • Ransomware: The Gentlemen Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Japan was compromised by The Gentlemen Ransomware. The compromised company is a Japanese manufacturer and global supplier specializing in apparel accessories, RFID solutions, and sustainable materials. Founded in October 1972 and headquartered in Tokyo, the company operates across 29 locations worldwide with production facilities in Japan, China, Thailand, and Vietnam. The data, which has been breached, has not yet appeared on the leak site, indicating that negotiations between the affected party and the ransomware group may be underway. The compromised data includes confidential and sensitive information belonging to the organization.

Source: Dark Web

Relevancy & Insights:

  • The Gentlemen is a relatively highly sophisticated ransomware-as-a-service (RaaS) group that emerged in mid-2025.
  • The Gentlemen Ransomware group primarily targets countries such as the United States of America, France, Thailand, India, and
  • The Gentlemen Ransomware group primarily targets industries, including Manufacturing, Professional Goods & Services, Consumer Goods & Services, Information Technology, and Healthcare.
  • Based on the Gentlemen Ransomware victims list from 1st Jan 2025 to 22nd September 2026, the top 5 Target Countries are as follows:

  • The Top 10 Industries most affected by the Gentlemen Ransomware victims list from 1st Jan 2025 to 22nd September 2026 are as follows:

 

ETLM Assessment:

According to CYFIRMA’s assessment, the Gentlemen Ransomware is a highly adaptive and globally active threat that leverages dual-extortion tactics, combining data theft with file encryption. The group employs advanced evasion and persistence techniques, supports cross-platform and scalable ransomware deployment, and conducts targeted attacks across multiple industries and geographic regions. This combination of capabilities makes it a significant risk to enterprise cybersecurity defenses, particularly for organizations with limited detection and incident-response maturity.

5. Vulnerabilities and Exploits

Vulnerability in Altium Enterprise Server

  • Attack Type: Vulnerabilities & Exploits
  • Target Technology: Enterprise Server / UnifiedLogin Service
  • Vulnerability: CVE-2026-92808
  • CVSS Base Score: 10 Source
  • Vulnerability Type: Server-Side Request Forgery (SSRF) / Missing Authentication for Critical Function
  • Summary: The vulnerability allows an unauthenticated remote attacker to compromise the affected Altium Enterprise

 

Relevancy & Insights:
The vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can abuse server-side request forgery to make the server issue outbound HTTP requests to attacker-controlled destinations, including internal services that are otherwise reachable only from the server itself.

Impact:
Successful exploitation can allow an unauthenticated attacker to retrieve server configuration and stored credential material from an internal service, use the credentials to obtain an administrative session, and potentially achieve full compromise of the server and its services.

Affected Products:
https[:]//www[.]altium[.]com/platform/security-compliance/security-advisories

Recommendations:
Monitoring and Detection: Implement monitoring and detection mechanisms to identify unusual system behavior that might indicate an attempted exploitation of this vulnerability.

TOP 5 AFFECTED TECHNOLOGIES OF THE WEEK

This week, CYFIRMA researchers have observed significant impacts on various technologies due to a range of vulnerabilities. The following are the top 5 most affected technologies.

ETLM Assessment:

The vulnerability in Altium Enterprise Server presents a critical security risk to organizations using affected versions of the enterprise server. The issue is caused by a server-side request forgery vulnerability in the UnifiedLogin service combined with missing authentication for an internal critical function. An unauthenticated network attacker can cause the server to make requests to internal services, potentially exposing configuration and credential material. Successful exploitation could allow the attacker to obtain an administrative session and result in full compromise of the affected server and its services. The vulnerability carries a CVSS v4.0 score of 10.0 (Critical). Organizations using affected Altium Enterprise Server versions should prioritize upgrading to version 8.1.1 or later. Security teams should also monitor outbound requests from the UnifiedLogin service, review access controls, and investigate unexpected authentication or administrative activity. Prompt remediation and continuous monitoring are recommended to reduce the risk of unauthorized access and system compromise.

6. Latest Cyber-Attacks, Incidents, and Breaches

SafePay   Ransomware  attacked   and   published   the   data   of   an Information Technology company from Japan

  • Threat Actor: SafePay Ransomware
  • Attack Type: Ransomware
  • Objective: Data Leak, Financial Gains
  • Target Technology: Web Applications
  • Target Industry: Information Technology
  • Target Geography: Japan
  • Business Impact: Operational Disruption, Data Loss, Financial Loss, Potential Reputational Damage

Summary:

Recently, we observed that SafePay Ransomware attacked and published the data of an Information Technology company from Japan on its dark web website. The compromised company is a Japanese information technology company headquartered in Kiryu, Gunma Prefecture. Established in January 1970 as a regional computer-services center, the company has developed into a publicly listed systems integrator providing software development, information-processing services, system equipment, cloud services, data-center operations and other IT solutions. Its customer base spans manufacturing, mobility, printing, retail, healthcare, education, energy, water utilities and local government. It provides consulting, system development and implementation, outsourcing, network and security services, cloud platforms, operational support and data-center services. The company operates development centers and support offices across Japan and also has overseas group operations in Vietnam and the Philippines. The compromised data appears to include database backups and database files, user-related information, application data, public-facing web/application files, disk-check or system-related data, and log files. The exposed directory listing specifically shows BAK_DB, SQL_DB, Users, data, public, and a 48 MB backup/log file, indicating that the stolen data may include database records, user information, application files, system or operational data, and backup/log information.

Source: Dark Web

Relevancy & Insights:

  • SafePay Ransomware is a rapidly emerging and sophisticated ransomware threat first identified in September
  • The SafePay Ransomware group primarily targets industries, including Professional Goods & Services, Consumer Goods & Services, Real Estate & Construction, Manufacturing, and Information Technology.

ETLM Assessment:

According to CYFIRMA’s assessment, SafePay represents a sophisticated, fast-moving ransomware threat capitalizing on VPN weaknesses and credential theft, employing effective double extortion tactics to maximize ransom payments. Organizations, especially in highly targeted sectors and regions, must prioritize layered defenses and active hunting for early detection.

7. Data Leaks

Unauthorized National Health Insurance Database Advertised on a Leak Site

  • Attack Type: Data Leak
  • Target Industry: Healthcare / Health Insurance
  • Target Geography: South Korea
  • Objective: Financial Gains
  • Reported Dataset Size: Approximately 51 million unique records
  • Reported Price: US$900
  • Business Impact: Exposure of Personally Identifiable Information (PII), sensitive health-related information, identity theft risks, privacy violations, regulatory concerns, financial loss, and reputational damage

Summary

The CYFIRMA research team identified a post on a cybercrime forum advertising the sale of a large database allegedly associated with South Korea’s national health insurance system. According to the forum advertisement, the dataset reportedly contains approximately 51 million unique records and includes extensive personal, demographic, insurance, employment, and health-screening information. The seller has also provided sample data as an indication of possession, while the complete database is reportedly being offered for sale for approximately US$900.

Allegedly Exposed Information

Based on the information visible in the advertisement, the dataset may contain:

  • Personal identification and demographic information
  • Names and gender information
  • Dates of birth and age
  • Resident/personal identification numbers
  • Telephone/contact information
  • Residential address information
  • Postal codes and geographic location details
  • Health insurance type and eligibility information
  • Insurance acquisition and related dates
  • Workplace/employer identification and workplace names
  • Income-related information
  • Health insurance premium information
  • Long-term care insurance premium information
  • Health check-up status and dates
  • Height and weight
  • Body Mass Index (BMI)
  • Left/right eyesight information
  • Left/right hearing information
  • Medical and health-screening related records
  • Administrative and insurance-related identifiers
  • Additional structured healthcare database fields

The authenticity and provenance of the advertised dataset remain unverified. This assessment is based on information displayed in the cybercrime-forum advertisement and should not be interpreted as independent confirmation that the database was legitimately obtained or that all advertised records are authentic. The accompanying screenshot shows the database advertisement, its claimed record volume, pricing information, and sample database fields.

Source: Underground Forums

Saudi Government Employee Database Advertised on a Leak Site

  • Attack Type: Database Access
  • Target Industry: Government / Public Sector
  • Target Geography: Saudi Arabia
  • Objective: Financial Gains
  • Business Impact: Exposure of Customer and Employee/Contractor Data, Privacy Risks, Financial Fraud, Identity Theft, Account Takeover, Regulatory Compliance Concerns, Reputational Damage

Summary:

The CYFIRMA research team identified a post on a cybercrime forum advertising the sale of a database allegedly originating from a Saudi Arabian government entity. According to the advertisement, the dataset reportedly contains government employee profiles encompassing personal identifiers, contact information, employment details, and residential or workplace-related information.

The advertisement identifies the alleged source as a Saudi government domain and provides database field names as evidence of the information reportedly contained in the dataset.

Source: Underground Forums

Relevancy & Insights:

Financially motivated cybercriminals are continuously looking for exposed and vulnerable systems and applications to exploit. A significant number of these malicious actors congregate within underground forums, where they discuss cybercrime and trade stolen digital assets. Operating discreetly, these opportunistic attackers target unpatched systems or vulnerabilities in applications to gain access and steal valuable data. Subsequently, the stolen data is advertised for sale within underground markets, where it can be acquired, repurposed, and utilized by other malicious actors in further illicit activities.

ETLM Assessment:

The threat actor is assessed as an active and capable cybercriminal entity primarily involved in data-leak and information-extortion activities, with multiple indications of unauthorized access to systems and the subsequent dissemination or sale of compromised data through underground forums. Their activities demonstrate the evolving sophistication of organized cybercriminal networks and highlight the increasing risk of sensitive information being exploited for financial gain, fraud, and follow-on attacks. Organizations should strengthen their cybersecurity posture through continuous monitoring, proactive threat intelligence, robust access controls, enhanced data protection, and timely defensive measures to safeguard sensitive information and critical infrastructure.

Recommendations:

Enhance the cybersecurity posture by:

  1. Updating all software products to their latest versions is essential to mitigate the risk of vulnerabilities being
  2. Ensure proper database configuration to mitigate the risk of database-related
  3. Establish robust password management policies, incorporating multi-factor authentication and role-based access to fortify credential security and prevent unauthorized access.

8. Other Observations

The CYFIRMA research team identified a post on a cybercrime forum claiming unauthorized access to and availability of private project files belonging to an Indian organization operating across the real-estate and healthcare sectors. The forum post states that the organization began operations in the real-estate sector and subsequently expanded into healthcare.

According to the advertisement, the allegedly obtained material consists of private project files and associated business documents. A download link was also included in the post, indicating that the files were being made available for unauthorized access or distribution.

Allegedly Exposed Information

Based on the information visible in the forum post, the exposed material may include:

  • Private real-estate project files
  • Project planning and development documents
  • Business and operational documentation
  • Property-related information
  • Healthcare-sector project information
  • Internal project records
  • Corporate documentation
  • Project-related correspondence and supporting files
  • Potentially sensitive commercial information
  • Other confidential files associated with ongoing or completed projects

The exact contents, volume, and sensitivity of the files could not be independently established from the screenshot alone.

Potential Impact

If the advertised files are genuine, unauthorized disclosure could potentially enable:

  • Competitive intelligence gathering through access to confidential project
  • Intellectual property exposure involving proprietary plans, documents, and business processes.
  • Targeted phishing and social-engineering attacks using information contained in internal documents.
  • Business email compromise (BEC) through knowledge of projects, employees, vendors, and business
  • Fraudulent impersonation of personnel involved in
  • Unauthorized modification or misuse of project
  • Financial fraud involving project-related transactions or commercial
  • Reputational damage resulting from the disclosure of confidential business
  • Follow-on attacks against employees, partners, contractors, or associated

The authenticity and provenance of the advertised files remain unverified. This assessment is based solely on the information displayed in the cybercrime-forum advertisement and has not been independently confirmed.

Source: Underground Forums

RECOMMENDATIONS

STRATEGIC RECOMMENDATIONS

  • Attack Surface Management should be adopted by organisations, ensuring that a continuous closed-loop process is created between attack surface monitoring and security testing.
  • Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation
  • Incorporate Digital Risk Protection (DRP) in the overall security posture that acts as a proactive defence against external threats targeting unsuspecting customers.
  • Implement a holistic security strategy that includes controls for attack surface reduction, effective patch management, and active network monitoring, through next-generation security solutions and a ready-to-go incident response
  • Create risk-based vulnerability management with deep knowledge about each asset. Assign a triaged risk score based on the type of vulnerability and criticality of the asset to help ensure that the most severe and dangerous vulnerabilities are dealt with first.

MANAGEMENT RECOMMENDATIONS

  • Take advantage of global Cyber Intelligence, providing valuable insights on threat actor activity, detection, and mitigation techniques.
  • Proactively monitor the effectiveness of risk-based information security strategy, the security controls applied, and the proper implementation of security technologies, followed by corrective actions, remediations, and lessons learned.
  • Consider implementing Network Traffic Analysis (NTA) and Network Detection and Response (NDR) security systems to compensate for the shortcomings of EDR and SIEM
  • Ensure that detection processes are tested to ensure awareness of anomalous events. Timely communication of anomalies should be continuously evolved to keep up with refined ransomware threats.

TACTICAL RECOMMENDATIONS

  • Patch software/applications as soon as updates are Where feasible, automated remediation should be deployed since vulnerabilities are one of the top attack vectors.
  • Consider using security automation to speed up threat detection, improved incident response, increased the visibility of security metrics, and rapid execution of security checklists.
  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs and strengthening defences based on the tactical intelligence provided.
  • Deploy detection technologies that are behavioral anomaly-based to detect ransomware attacks and help to take appropriate measures.
  • Implement a combination of security controls, such as reCAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP backlisting, Rate-limiting, and Account lockout to thwart automated brute-force attacks.
  • Ensure email and web content filtering uses real-time blocklists, reputation services, and other similar mechanisms to avoid accepting content from known and potentially malicious sources.

Situational Awareness – Cyber News

Please find the Geography-Wise and Industry-Wise breakup of cyber news for the last 5 days as part of the situational awareness pillar.