
CYFIRMA Research and Advisory Team would like to highlight ransomware trends and insights gathered while monitoring various forums. This includes multiple industries, geographies, and technologies that could be relevant to your organization.
Type: Ransomware
Target Technologies: Windows OS
Introduction:
CYFIRMA Research and Advisory Team has found Ried Ransomware while monitoring various underground forums as part of our Threat Discovery Process.
Ried Ransomware
RIED is a ransomware infection designed to encrypt files on a compromised computer and prevent the victim from accessing their data. Once executed, the ransomware encrypts targeted files and changes their filenames by appending a distinctive naming pattern in the format [original filename].[victim-specific identifier].[attacker contact].RIED. For example, a file such as 1.jpg would be renamed in this general format:1.jpg.[identifier].[contact].RIED. It also changes the desktop wallpaper to display a warning that the files have been encrypted and creates a ransom note named+README-WARNING+.txt. The ransom note explains that the attackers claim to possess the private key required for decryption and demand payment in exchange for a decryption program and instructions. They also offer to decrypt a small number of simple files as proof that their recovery process works.

Screenshot: File encrypted by the ransomware
(Source: Surface Web)
The ransom note is presented as a short FAQ covering what happened, how victims can supposedly recover their files, how to contact the attackers, and what happens after payment. It warns victims not to rename or modify encrypted files and discourages the use of third-party recovery software or security tools, claiming that such actions could damage the encrypted data and make recovery impossible. The ransomware generally relies on encryption that cannot be practically reversed without the corresponding private key, although a free decryptor could become available if researchers discover a weakness in the ransomware’s implementation. Paying the ransom is risky because there is no guarantee that the attackers will provide a functional decryption solution. The ransomware should be removed from an infected system to prevent further encryption, but removing the malware does not restore files that have already been encrypted. If no legitimate decryptor is available, recovery typically depends on clean backups made before the infection and stored separately from the compromised system.

Screenshot: The appearance of Ried’s ransom note (+README-WARNING+.txt)
(Source: Surface Web)
The following are the TTPs based on the MITRE ATT&CK framework
| Tactic | Techniq ue ID | Technique Name |
| Execution | T1059.00 3 | Command and Scripting Interpreter: Windows Command Shell |
| Execution | T1106 | Native API |
| Execution | T1129 | Shared Modules |
| Privilege Escalation | T1055 | Process Injection |
| Credential Access | T1539 | Steal Web Session Cookie |
| Discovery | T1012 | Query Registry |
| Discovery | T1033 | System Owner/User Discovery |
| Discovery | T1057 | Process Discovery |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1083 | File and Directory Discovery |
| Discovery | T1135 | Network Share Discovery |
| Discovery | T1518 | Software Discovery |
| Discovery | T1614 | System Location Discovery |
| Collection | T1115 | Clipboard Data |
| Command and Control | T1071 | Application Layer Protocol |
| Command and Control | T1105 | Ingress Tool Transfer |
| Impact | T1485 | Data Destruction |
| Stealth | T1027.00 2 | Obfuscated Files or Information: Software Packing |
| Stealth | T1027.00 5 | Obfuscated Files or Information: Indicator Removal from Tools |
| Stealth | T1027.00 9 | Obfuscated Files or Information: Embedded Payloads |
| Stealth | T1055 | Process Injection |
| Stealth | T1070.00 4 | Indicator Removal: File Deletion |
| Defense Impairment | T1222 | File and Directory Permissions Modification |
| Stealth | T1564.00 3 | Hide Artifacts: Hidden Window |
Relevancy and Insights:
ETLM Assessment:
RIED is likely to evolve toward a more evasive and destructive ransomware operation rather than remaining limited to straightforward file encryption. Its current behavior already indicates several capabilities that could support this progression, including process injection, code obfuscation and packing, anti-analysis checks, system and software discovery, file and directory discovery, and attempts to interfere with recovery mechanisms. The observed deletion of shadow copies and backup catalogs is particularly significant because it can reduce the victim’s ability to restore encrypted data without paying the ransom. Future variants may therefore place greater emphasis on disabling or bypassing security controls, detecting analysis environments, concealing malicious activity, and systematically removing recovery options before or during encryption.
The ransomware could also become more targeted in how it selects and processes files and environments. Its observed discovery activity includes identifying the host, user, installed software, network shares, and system information, which could provide a foundation for broader impact in future versions. The presence of credential- and session-related collection behavior, clipboard access, and application-layer communication suggests that later variants could potentially combine encryption with information theft or other forms of data collection, increasing pressure on victims. The file-renaming behavior is also likely to remain a useful indicator, with encrypted files following a pattern similar to original_filename.[identifier].[contact].RIED. Overall, the observed capabilities suggest that future RIED variants may focus on stronger defense evasion, broader environmental discovery, recovery inhibition, and potentially data theft alongside encryption, although these developments are predictions based on current observed behavior rather than confirmed features of future samples.
Sigma rules:
title: Shadow Copies Deletion Using Operating Systems Utilities tags:
category: process_creation product: windows
detection: selection1_img:
CommandLine|contains|all:
CommandLine|contains|all:
CommandLine|contains|all:
condition: (all of selection1*) or (all of selection2*) or (all of selection3*) falsepositives:
IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)
STRATEGIC RECOMMENDATIONS
MANAGEMENT RECOMMENDATIONS
TACTICAL RECOMMENDATIONS
Type: Downloader / Dropper | Objectives: Payload Delivery and System Compromise | Target Technology: Windows | Target Geography: Global
CYFIRMA collects data from various forums based on which the trend is ascertained. We identified a few popular malwares that were found to be distributed in the wild to launch cyberattacks on organizations or individuals.
Active Malware of the Week
This week, ShellterLoader Malware is in focus.
Overview of Operation ShellterLoader Malware
ShellterLoader is a malware delivery component designed to establish an initial presence on a Windows system and facilitate the introduction of additional malicious software. Its primary role is not extensive data theft on its own, but to create a pathway through which more capable malware can subsequently reach the compromised environment. This makes it an enabling component within a broader attack chain.From an organizational perspective, the key concern is the potential consequences that may follow its deployment. Although the initial component maintains a relatively limited footprint, the additional payloads it delivers can introduce significantly greater capabilities, including unauthorized access, information theft, or other malicious activity. Therefore, the apparent simplicity of the initial infection should not be considered an indication of limited risk.
The malware also demonstrates behavior intended to reduce visibility and maintain its presence on an affected system. Such characteristics can allow an infection to remain unnoticed for longer periods and provide additional opportunities for subsequent malicious activity. This increases the importance of identifying the initial compromise before further components are introduced.
Overall, the activity associated with ShellterLoader reflects a delivery-focused threat in which the initial malware serves as a steppingstone toward a potentially broader compromise. Organizations encountering this type of activity should consider the possibility of additional malicious components being present and assess the affected environment for related activity rather than treating the detected file as an isolated incident.
Attack Method
ShellterLoader begins execution by verifying whether the required runtime conditions are present on the Windows host. It creates named mutex objects, including ChromeProcessSingletonStartup! and OMADM_NAMED_MUTEX , to regulate execution and prevent multiple instances from running simultaneously. It also performs basic environment checks to determine whether the host is suitable for continued execution. Depending on the conditions identified, it may modify its behavior or terminate, potentially complicating analysis.
The execution chain incorporates memory-based techniques designed to reduce the visibility of malicious functionality. Reflective loading and in-memory execution allow payload components to be prepared and executed without relying entirely on conventional file-based mechanisms. Memory and thread manipulation consistent with code injection also enable malicious code to operate within the context of another process. These techniques can complicate static analysis and limit the effectiveness of detection mechanisms that primarily rely on identifying suspicious files on disk.
A primary function of the component is to retrieve and stage an additional payload. During execution, it communicates with external infrastructure masquerading as or abusing traffic to sb.scorecardresearch.com to obtain the next-stage component. This establishes a multi-stage infection process in which the initial loader facilitates the delivery of additional malicious functionality. Its observed behavior is therefore primarily focused on payload delivery rather than extensive data collection.
The execution process also incorporates mechanisms intended to conceal malicious activity and sustain the infection. The combination of environment checks, mutex-based execution control, memory-resident payload handling, process-level manipulation, and external communication creates an execution chain that can complicate detection and behavioral analysis. Consequently, examining the initial component alone may not reveal the full scope of the compromise, as the capabilities and potential impact depend on the additional payload delivered to the affected system.
The Following are the TTPs based on the MITRE ATT&CK Framework for Enterprises
| Tactic | Technique | Technique Name |
|
Execution |
T1047 |
Windows Management Instrumentation |
|
T1059 |
Command and Scripting Interpreter | |
| T1129 | Shared Modules | |
|
Stealth |
T1027.002 |
Obfuscated Files or Information: Software Packing |
| T1218 | System Binary Proxy Execution | |
|
T1497 |
Virtualization/Sandbox Evasion | |
| T1564 | Hide Artifacts | |
|
Discovery |
T1012 | Query Registry |
| T1033 | System Owner/User Discovery | |
| T1057 | Process Discovery | |
| T1082 | System Information Discovery | |
| T1083 | File and Directory Discovery | |
|
T1518.001 |
Software Discovery: Security Software Discovery | |
| Collection | T1185 | Browser Session Hijacking |
|
Command and control |
T1071
T1573 |
Application Layer Protocol
Encrypted Channel |
|
Impact |
T1485
T1486 |
Data Destruction
Data Encrypted for Impact |
INSIGHTS
A key insight from the observed activity is the deliberate separation between the initial compromise and the eventual malicious objective. The component itself performs a relatively narrow role, indicating that the intrusion is structured in stages rather than relying on a single piece of malware to perform every task. This separation allows the activity associated with the initial foothold to remain less conspicuous while other capabilities are introduced independently.
The behavior also reflects a level of operational discipline in how the compromise is maintained. Multiple elements work together to limit visibility and preserve control, suggesting that the activity was designed with the realities of endpoint monitoring and investigation in mind. The overall behavior is therefore better characterized as a coordinated intrusion component than as an isolated or opportunistic program.
A further insight concerns the value placed on access obtained through the compromised environment. The activity indicates that maintaining a usable presence on a system is itself an important objective, rather than simply performing an immediate action and terminating. This places greater significance on the compromised account and system context, as continued access can provide a basis for subsequent activity without requiring the same initial entry process again.
ETLM ASSESSMENT
From an ETLM perspective, ShellterLoader-type activity is likely to contribute to a shift toward more modular and persistent intrusion campaigns, where the initial compromise serves as a controlled entry point for progressively more capable payloads. Organizations may increasingly face incidents in which the visible malware represents only one stage of a wider compromise, making incident scope and business impact more difficult to determine quickly. Employees could become more directly exposed to these campaigns as attackers seek to blend malicious activity into normal workplace processes, potentially increasing the risk of account misuse, disruption to business applications, and unauthorized access to corporate resources. In the longer term, repeated incidents of this nature could result in extended recovery periods, greater operational costs, and increased disruption across interconnected business functions rather than remaining confined to individual endpoints.
IOCs:
Kindly refer to the IOCs below to exercise controls on your security systems. (Source: Open Surface)
YARA Rules
rule ShellterLoader_Malware
{meta: description = “Detection rule for the analyzed malware sample” author = “CYFIRMA Research”
date = “2026-09-29”
strings:
$hash1 = “594033ed58e27b42bb1bef7e5b21eac87f0d660c7cc3d48881a2e5575e3ac811”
$hash2 = “dd39fafbdba994169991cea092c6428e1d3b1539”
$hash3 = “d3cea61538aa5030e90a1d38cca762b4”
$s1 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\Application\\chrome.exe\” –
-no-first-run –no-default-browser-check”
$s2 = “C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\”
–no-first-run –no-default-browser-check”
$s3 = “C:\\Windows\\system32\\BackgroundTaskHost.exe\” – ServerName:BackgroundTaskHost.WebAccountProvider”
$s4 = “C:\\Windows\\System32\\RuntimeBroker.exe -Embedding”
$s5 = “ChromeProcessSingletonStartup!”
$s6 = “ OMADM_NAMED_MUTEX ”
$s7 = “_app_container_profile_lock_0278d671-c445-4dfa-a8b4-d5ccf66d4cc3”
$s8 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\Crashpad\\settings.dat”
$s9 = “settings.dat”
$s10 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\BrowserMetrics\\BrowserMetrics-6AB8F3B2-122C.pma”
$s11 = “BrowserMetrics-6AB8F3B2-122C.pma”
$s12 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\lockfile”
$s13 = “lockfile”
$s14 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\Variations”
$s15 = “wss.scriptlab.cc/”
$s16 = “wss.scriptlab.cc/api/splitChanges/850ec405”
condition:
any of ($hash*) or 2 of ($s*)
}
Strategic Recommendations
Management Recommendations
Tactical Recommendations
Key Intelligence Signals:
FamousSparrow: Evolving Malware Capabilities and Stealth-Oriented Cyber-Espionage
About the Threat Actor
Salt Typhoon is a highly sophisticated Advanced Persistent Threat (APT) group believed to be operated by China’s Ministry of State Security (MSS). The group has been linked to high-profile cyber-espionage campaigns, particularly targeting U.S. intelligence agencies and organizations holding critical corporate intellectual property. The threat actor has also been observed conducting campaigns across multiple countries globally. The group is widely regarded as a strategic asset aligned with China’s broader “100-Year Strategy” to expand its global influence and technological dominance.
Salt Typhoon is believed to have been active since at least 2020. Some of its observed Tactics, Techniques, and Procedures (TTPs) overlap with those attributed to FamousSparrow, indicating a possible connection between the threat actors. The group is assessed to possess significant resources and sophisticated cyber-espionage capabilities, supported by extensive experience in conducting illicit cyber activities. Salt Typhoon has also been suspected of having potential links to the nation-state threat actor APT41.
Details on Exploited Vulnerabilities
|
CVE ID |
Affected Products |
CVSS Score |
Exploit Links |
|
CVE-2025-7776 |
NetScaler ADC and NetScaler Gateway |
9.8 |
– |
|
CVE-2025-8424 |
NetScaler ADC and NetScaler Gateway |
– |
– |
|
CVE-2026-23760 |
SmarterTools SmarterMail versions prior to build 9511 |
9.8 |
– |
|
CVE-2025-0944 |
Tailoring Management System 1.0 |
9.8 |
– |
|
CVE-2025-12480 |
Triofox |
9.1 |
– |
| Tactic | ID | Technique |
| Reconnaissance | T1598 | Phishing for Information |
| Reconnaissance | T1598.003 | Phishing for Information: Spear phishing Link |
| Resource Development | T1583.001 | Acquire Infrastructure: Domains |
| Resource Development | T1584.008 | Compromise Infrastructure: Network Devices |
| Resource Development | T1583.006 | Acquire Infrastructure: Web Services |
| Initial Access | T1566.002 | Phishing: Spear phishing Link |
| Execution | T1204.001 | User Execution: Malicious Link |
| Execution | T1059.003 | Command and Scripting Interpreter: Windows Command Shell |
| Execution | T1059.006 | Command and Scripting Interpreter: Python |
| Persistence | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Privilege Escalation | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Stealth | T1218.007 | System Binary Proxy Execution: Msiexec |
| Stealth | T1036.004 | Masquerading: Masquerade Task or Service |
| Stealth | T1036 | Masquerading |
| Stealth | T1027.002 | Obfuscated Files or Information: Software Packing |
| Stealth | T1140 | Deobfuscate/Decode Files or Information |
| Credential Access | T1555.003 | Credentials from Password Stores: Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1012 | Query Registry |
| Discovery | T1016 | System Network Configuration Discovery |
|
Discovery |
T1033 |
System Owner/User Discovery |
|
Discovery |
T1124 |
System Time Discovery |
|
Command and Control |
T1102.002 |
Web Service: Bidirectional Communication |
|
Command and Control |
T1573.001 |
Encrypted Channel: Symmetric Cryptography |
|
Command and Control |
T1090.003 |
Proxy: Multi-hop Proxy |
|
Command and Control |
T1105 |
Ingress Tool Transfer |
|
Command and Control |
T1665 |
Hide Infrastructure |
|
Exfiltration |
T1041 |
Exfiltration Over C2 Channel |
|
Exfiltration |
T1567.002 |
Exfiltration Over Web Service: Exfiltration to Cloud Storage |
Latest Developments Observed
The threat actor is suspected of targeting government organizations across Latin America, including entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group has deployed a newly developed modular C++ backdoor, SparroWocky, using DLL sideloading and reflective in-memory execution to enable command execution, screenshot capture, and file exfiltration. The activity appears to be espionage-driven, with the likely objective of monitoring regional governments and collecting strategically valuable information aligned with China’s economic and strategic interests in the region.
ETLM Insights
FamousSparrow, a China-aligned cyber-espionage group, continues to demonstrate an evolving operational model through geographic targeting shifts and modernization of its malware capabilities. Its recent activities reflect an increasing emphasis on stealth, extensibility, and flexible post-compromise operations to support intelligence collection.
The threat actor’s recent activity highlights:
Looking ahead, FamousSparrow is likely to further refine its modular malware and defense-evasion capabilities while continuing to adapt its targeting toward strategically valuable organizations. The integration of BOF execution and offensive-security components into SparroWocky may provide greater flexibility for post-compromise operations. Continued development of stealth-oriented execution and adaptable tooling is likely to support sustained intelligence-collection activities across changing targets.
IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)
YARA Rules
rule FamousSparrow_SaltTyphoon_IOC_Detection
{
meta:
description = “Detects supplied FamousSparrow/Salt Typhoon-related IP, domain, and Win32 EXE indicators”
author = “CYFIRMA” date = “2026-09-29”
category = “Threat Intelligence IOC Detection”
strings:
// IP addresses
$ip1 = “36.106.166.96” ascii wide
$ip2 = “139.59.236.31” ascii wide
$ip3 = “137.135.178.23” ascii wide
$ip4 = “36.106.166.97” ascii wide
$ip5 = “114.119.158.36” ascii wide
// Domains
$domain1 = “5jkl8ae8ph.ucarecd.net” ascii wide nocase
$domain2 = “5jiyuz.frost-echo.in.net” ascii wide nocase
$domain3 = “altra-paris.fr” ascii wide nocase
$domain4 = “altra-chaussure.fr” ascii wide nocase
// File type
$filetype = “win32 exe” ascii wide nocase
condition:
1 of ($ip*) or
1 of ($domain*) or
$filetype
}
Recommendations
Strategic Recommendations
Management Recommendations
Tactical Recommendations
Russia hits data centres in Ukraine
Russian drone and missile strikes this week heavily targeted telecommunications facilities and data centers in Kyiv, cutting off reliable internet access for around 100,000 households across the Ukrainian capital and surrounding regions. At least four regional providers have reportedly suffered partial connectivity losses following the assault, which struck critical networking equipment, data center facilities, and a central internet traffic exchange. Individual providers detailed significant physical damage to their operations, with severe outages affecting communications lines and equipment across multiple regions.
Russia’s Defense Ministry claimed responsibility for hitting specific data centers allegedly tied to Ukrainian security agencies, though these military assertions remained unverified. The Ukrainian Foreign Ministry condemned the attacks on civilian networks, emphasizing that internet infrastructure is vital for maintaining everyday life and delivering life-saving air-raid warnings to the population. The devastating barrage, which also damaged residential areas, railway infrastructure, and a historic market, left two people dead and at least 43 injured, followed quickly by a massive strike the next day that impacted a maternity hospital, housing, and additional energy logistics.
ETLM Assessment:
In modern warfare, data centers and communications networks are just as vital as artillery factories, and Russia systematically targets this critical digital infrastructure to hobble Ukraine’s decisive advantage in integrated battlefield data collection and management systems. These telecommunications assaults form part of a broader, persistent pattern of Russian strikes targeting Ukrainian digital connectivity, following similar infrastructure hits earlier in the month involving major operator Kyivstar and a severe data center strike back in July. Complicating the regional digital landscape further, a suspicious fire broke out late Wednesday at a Starlink ground station in central Poland operated by Exatel, damaging critical power infrastructure like generators and switchboards. Coupled with suspicious incidents like the recent fire at a Polish Starlink ground station, these events highlight a broader and growing risk that critical data centers across Europe are increasingly vulnerable to an ongoing covert Russian sabotage campaign in Europe that CYFIRMA covered in this report.
North Korean hackers steal $387 million from a Singaporean exchange
A major cryptocurrency exchange experienced a significant security breach, resulting in the theft of approximately $387.5 million from its hot and warm wallet systems. During an emergency town hall meeting, the exchange’s leadership disclosed that preliminary evidence, including operational patterns and on-chain signatures, strongly indicated potential involvement by state-sponsored North Korean hackers.
The incident came to light after blockchain security firms detected sudden and substantial outflows from the platform. The exchange’s security team promptly activated emergency response protocols as unauthorized transfers began moving funds out of its wallet infrastructure. Initial findings suggest that the attackers compromised a critical backend system, manipulating transaction data to bypass authorization mechanisms and execute fraudulent withdrawals. However, private keys and offline cold storage wallets reportedly remained uncompromised and secure.
The stolen assets included multiple cryptocurrencies, such as Ethereum, XRP, USD Coin, and several other digital tokens across various blockchain networks. Attribution experts and blockchain analysts identified similarities between the incident and previous large-scale cryptocurrency thefts associated with North Korean-linked threat groups, including operations historically linked to the theft of billions of dollars from the global cryptocurrency ecosystem.
ETLM Assessment:
As noted in this CYFIRMA report, Pyongyang has spent years systematically refining an ever-expanding toolkit to generate hard currency for its nuclear and ballistic-missile programs, which run the gamut from classic diplomatic cover and ship-to-ship transfers to aggressive cyber theft and, more recently, the large-scale deployment of highly skilled IT workers operating under false identities abroad. But it is cybercrime that has rapidly become a cornerstone of North Korea’s state survival.
Qilin Ransomware Impacts an Electronics Manufacturing Company from Japan
Summary:
CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Japan was compromised by Qilin ransomware. The compromised company is a Japanese electronics manufacturer specialising in professional video and imaging technologies. The company develops and manufactures equipment used in broadcasting, medical imaging, security surveillance, video production, and industrial inspection. The ransomware attack reportedly resulted in the exposure of sensitive internal technical documents and engineering-related information, including broadcasting system design specifications, system architecture diagrams, equipment configuration details, technical drawings, operational documentation, system planning materials, and internal data tables. The leaked materials appear to contain detailed information about system infrastructure, component configurations, technical specifications, and project-related documentation, potentially exposing proprietary engineering knowledge and operational details. The total size of the compromised data is approximately 66 GB.

Source: Dark Web
Relevancy & Insights:



ETLM Assessment:
According to CYFIRMA’s assessment, Qilin ransomware poses a significant threat to organizations of all sizes. Its evolving tactics, including double extortion (data encryption and leak threats), cross-platform capabilities (Windows and Linux, including VMware ESXi), and a focus on speed and evasion, make it a particularly dangerous actor.
The Gentlemen Ransomware Impacts a Manufacturing Company from Thailand
Summary:
CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Thailand was compromised by The Gentlemen Ransomware. The compromised company is a Thai-Japanese JV (founded 1990, HQ Samut Prakan/Bangkok) — the leading engineering-plastics distributor and fabricator in Thailand & Southeast Asia, importing materials from Japan and processing them locally: UHMW-PE, MC-Nylon, POM, PA6G, HDPE, PEEK, PVC-C, PVDF, PET, PTFE — sold as cut-to-size sheets/rods/tubes and CNC-machined custom parts for automotive, food & packaging, semiconductors, chemicals, oil & gas, robotics and water treatment across SEA. The compromised data includes confidential and sensitive information belonging to the organization.

Source: Dark Web
Relevancy & Insights:



ETLM Assessment:
According to CYFIRMA’s assessment, the Gentlemen Ransomware is a highly adaptive and globally active threat that leverages dual-extortion tactics, combining data theft with file encryption. The group employs advanced evasion and persistence techniques, supports cross-platform and scalable ransomware deployment, and conducts targeted attacks across multiple industries and geographic regions. This combination of capabilities makes it a significant risk to enterprise cybersecurity defenses, particularly for organizations with limited detection and incident-response maturity.
Vulnerability in CRI-O (Kubernetes)
Relevancy & Insights: The vulnerability exists due to improper enforcement of the destination container’s security context during checkpoint restoration.
Impact: A remote user can gain elevated privileges on the system.
Affected Products:
Recommendations:
This week, CYFIRMA researchers have observed significant impacts on various technologies due to a range of vulnerabilities. The following are the top 5 most affected technologies.

ETLM Assessment:
The vulnerability in CRI-O presents a significant security risk to organizations using affected versions in Kubernetes environments. The issue allows a user with permission to create a pod from a malicious checkpointed container image to bypass Kubernetes security context enforcement during container restoration. Successful exploitation could result in processes retaining credentials, Linux capabilities, and other security settings from the original checkpoint, potentially enabling execution with elevated privileges across the container security boundary. Organizations using affected CRI-O versions should prioritize applying the security updates provided by the respective vendors. Organizations should also review Kubernetes RBAC permissions, restrict checkpoint restoration functionality where unnecessary, and monitor suspicious pod creation and container restoration activities. Prompt remediation and continuous monitoring are recommended to reduce the risk of privilege escalation and unauthorized access to containerized workloads.
Krybit Ransomware attacked and published the data of a Construction company from India
Summary:
Recently, we observed that Krybit Ransomware attacked and published the data of a construction company from India on its dark web website. The compromised company is one of India’s largest civil construction and contracting companies, incorporated on November 2, 1979, headquartered in New Delhi, India, and listed on the National Stock Exchange (NSE). The company provides a comprehensive range of construction services, including civil and structural works, composite works, and finishing works for residential buildings, IT parks, metro stations and depots, commercial office spaces, automated car parking lots, power plants, retail centers, and hospitals, also executing Engineering, Procurement and Construction (EPC) projects and real estate development. It operates across multiple Indian states, including Karnataka, West Bengal, and Maharashtra through its subsidiaries. The compromised data appears to include identity and government records, such as national identification cards, tax or income-tax documents, passport-related information, photographs, signatures, dates of birth, residential addresses, handwritten forms, financial or salary-related records, account and transaction details, invoices, purchase or sales documents, and email correspondence containing personal and business information. The exposed material also includes scanned documents with QR codes, identification numbers, contact details, and other sensitive personally identifiable information (PII), creating risks of identity theft, financial fraud, phishing, impersonation, and further targeted attacks. The Total size of the compromised data is approximately 222.48 GB.



Source: Darkweb
Relevancy & Insights:
ETLM Assessment:
According to CYFIRMA’s assessment, Krybit represents a persistent, financially motivated Ransomware-as-a-Service (RaaS) and data extortion threat that leverages an opportunistic affiliate-driven operational model to maximize pressure on victims. Although the group functions via external threat actors incentivized by lucrative profit-sharing structures, its targeted deployment of custom malware suites across corporate environments highlights the critical importance of robust identity security, continuous network monitoring, timely vulnerability remediation, and rigorous data loss prevention measures to detect, contain, and mitigate potential ransomware extortion attacks.
Unauthorized E-Commerce Customer Database Advertised on a Leak Site
Summary
The CYFIRMA research team identified a post on a dark web forum advertising the sale of a large database allegedly originating from a South Korean e-commerce organization. According to the forum advertisement, the seller claims to possess more than 1 million unique customer records containing sensitive personally identifiable information (PII). The advertisement identifies the organization as an established online shopping platform involved in direct retail sales, third-party marketplace operations, and logistics services.
Based on the information shared in the forum post, the allegedly exposed database may contain the following information:
The authenticity of the allegedly exposed dataset remains unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums
Unauthorized Access to Philippine Government and Logistics Sector Systems Advertised on a Leak Site
Summary: The CYFIRMA research team identified a post on a dark web forum claiming unauthorized access to systems belonging to Philippine government and logistics-sector organizations. According to the forum advertisement, the seller claims to have obtained full access to multiple organizational environments, including a government institution responsible for national nutrition-related programs and a major logistics and courier service provider operating in the Philippines. The advertisement specifically highlights the availability of government documents and user credentials, suggesting potential exposure of sensitive organizational information and authentication-related data.
Based on the information shared in the forum post, the allegedly compromised information may include:
The authenticity and extent of the alleged unauthorized access remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums
Relevancy & Insights:
Financially motivated cybercriminals are continuously looking for exposed and vulnerable systems and applications to exploit. A significant number of these malicious actors congregate within underground forums, where they discuss cybercrime and trade stolen digital assets. Operating discreetly, these opportunistic attackers target unpatched systems or vulnerabilities in applications to gain access and steal valuable data. Subsequently, the stolen data is advertised for sale within underground markets, where it can be acquired, repurposed, and utilized by other malicious actors in further illicit activities.
ETLM Assessment:
The threat actor is assessed as an active and capable cybercriminal entity primarily involved in data-leak and information-extortion activities, with multiple indications of unauthorized access to systems and the subsequent dissemination or sale of compromised data through underground forums. Their activities demonstrate the evolving sophistication of organized cybercriminal networks and highlight the increasing risk of sensitive information being exploited for financial gain, fraud, and follow-on attacks. Organizations should strengthen their cybersecurity posture through continuous monitoring, proactive threat intelligence, robust access controls, enhanced data protection, and timely defensive measures to safeguard sensitive information and critical infrastructure.
Recommendations:
Enhance the cybersecurity posture by:
The CYFIRMA research team identified a post on a dark web forum advertising the alleged exposure of customer data belonging to an online financial trading and brokerage platform primarily focused on forex trading, while also offering access to commodities, indices, and cryptocurrency markets. According to the forum advertisement, the seller claims to possess a database containing sensitive customer information, including personal details and transaction-related records. The seller further alleges that the organization was involved in fraudulent activities and states that its website is currently shut down. However, these allegations have not been independently verified.
Based on the information shared in the forum post, the allegedly exposed dataset may contain the following information:
The authenticity and extent of the allegedly exposed dataset remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and the accompanying screenshots and has not been independently confirmed.

Source: Underground Forums
RECOMMENDATIONS
STRATEGIC RECOMMENDATIONS
MANAGEMENT RECOMMENDATIONS
TACTICAL RECOMMENDATIONS
Please find the Geography-Wise and Industry-Wise breakup of cyber news for the last 5 days as part of the situational awareness pillar.

Geography-Wise Graph







