
CYFIRMA Research and Advisory Team would like to highlight ransomware trends andinsights gathered while monitoring various forums. This includes multiple industries,geographies, and technologies that could be relevant to your organisation.
Type: Ransomware
Target Technologies: Windows OS
Introduction:
CYFIRMA Research and Advisory Team has identified Main Ransomware while monitoring various underground forums as part of our Threat Discovery Process.
Main Ransomware
MAIN is a ransomware infection that encrypts files on an affected system and modifiestheir filenames by adding a unique victim identifier, an attacker-controlled emailaddress, and a ransomware-specific file extension(.MAIN). After encryption, it displaysa pop-up ransom message and creates a text-based ransom note. The pop-upexplains that the victim’s files have been encrypted and provides instructions forcontacting the attackers. It requests the victim’s unique ID, which follows a formatsimilar to [ID-XXXXXXXX], along with an attacker email address using a format such as[username]@[email-domain] and with extension .MAIN. A secondary contact addressmay also be provided if the primary communication channel does not respond withina specified period. The message further offers free decryption of a limited number offiles as supposed proof that recovery is possible, subject to restrictions on file size andfile type. Victims are also warned against renaming encrypted files or attemptingrecovery with unauthorized decryption utilities, with claims that these actions couldcause permanent damage or increase the ransom demand.

Screenshot: File encrypted by the ransomware
(Source: Surface Web)
The accompanying text ransom note is considerably shorter than the pop-up messagebut serves the same overall purpose of establishing communication with the ransomwareoperators. Rather than explaining the encryption process or providing extensive recoveryinstructions, the note briefly asks the victim to initiate contact regarding the encrypteddata. It provides several communication channels so that the attackers can still bereached if one method becomes unavailable. The primary contact is represented in theform [username]@[domain], while an alternative address follows the same[username]@[backup-domain] structure. The note may also include an instant-messagingcontact in the format @[handle], giving the victim another way to communicate with theoperators. Unlike the pop-up window, the text note does not contain detailedinformation about free file decryption, file-size restrictions, or warnings concerningrecovery attempts. Its main function is to direct the victim toward the attackers’communication channels and encourage further negotiation over file recovery. Thepresence of multiple contact methods also provides redundancy for the operators,allowing communication to continue if the primary address or service becomesinaccessible. Technically, this note acts as a secondary ransom-demand artifactgenerated after the encryption routine has completed, complementing the graphicalransom message and ensuring that recovery instructions remain available as astandalone text file. Together, these ransom artifacts communicate the attackers’demands while providing the victim with the information necessary to begin theattempted recovery process.

Screenshot: The appearance of Main’s ransom note (INFO.txt)
(Source: Surface Web)

Screenshot: The appearance of Main’s Pop-up Window
(Source: Surface Web)
The following are the TTPs based on the MITRE ATT&CK framework
| Tactic | Technique ID | Technique Name |
| Execution | T1129 | Shared Modules |
| Persistence | T1112 | Modify Registry |
| Persistence | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Privilege Escalation | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Discovery | T1033 | System Owner/User Discovery |
| Discovery | T1057 | Process Discovery |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1083 | File and Directory Discovery |
| Discovery | T1497 | Virtualization/Sandbox Evasion |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| Impact | T1485 | Data Destruction |
| Impact | T1486 | Data Encrypted for Impact |
| Stealth | T1027.002 | Obfuscated Files or Information: Software Packing |
| Stealth | T1036 | Masquerading |
| Stealth | T1070.004 | Indicator Removal: File Deletion |
| Stealth | T1202 | Indirect Command Execution |
| Stealth | T1497 | Virtualization/Sandbox Evasion |
| Stealth | T1564.001 | Hide Artifacts: Hidden Files and Directories |
| Defense Impairment | T1112 | Modify Registry |
Relevancy and Insights:
ETLM Assessment:
Main ransomware could evolve through changes to its encryption routine, file-extensionpatterns, ransom-note content, and communication mechanisms. Future variants may usedifferent victim identifiers and attacker-controlled contact addresses for each campaign,making individual samples harder to correlate. The malware could also become moreselective in the files it targets, prioritizing documents, databases, backups, and other highvalue data while attempting to avoid system-critical files that could prevent the infectedmachine from operating. Additional evasion techniques may also be introduced, such asimproved process checks, altered execution methods, or modifications intended to reducedetection by security software. Changes to the ransom note and payment instructions arealso likely as operators adjust their social-engineering approach.
The threat could further develop toward a more flexible and resilient ransomware model inwhich attackers modify their distribution and communication infrastructure frequently. Futureversions may incorporate stronger anti-analysis mechanisms, improved persistence, oradditional techniques for disabling security and backup mechanisms before encryptionbegins. Attackers could also expand the extortion component by combining file encryptionwith data theft and threatening to publish stolen information if payment is refused. However,these developments are predictions rather than confirmed capabilities of the currentsample. The exact evolution will depend on how the malware’s operators modify their code,infrastructure, and intrusion methods in subsequent campaigns.
Sigma rules:
title: Shadow Copies Deletion Using Operating
Systems Utilities
tags:
– attack.impact
– attack.stealth
– attack.t1070
logsource:
category: process_creation
product: windows
detection:
selection1_img:
– Image|endswith:
– ‘\powershell.exe’
– ‘\pwsh.exe’
– ‘\wmic.exe’
– ‘\vssadmin.exe’
– ‘\diskshadow.exe’
– OriginalFileName:
– ‘PowerShell.EXE’
– ‘pwsh.dll’
– ‘wmic.exe’
– ‘VSSADMIN.EXE’
– ‘diskshadow.exe’
selection1_cli:
CommandLine|contains|all:
– ‘shadow’ # will match “delete shadows”
and “shadowcopy delete” and “shadowstorage”
‘delete’
selection2_img:
– Image|endswith: ‘\wbadmin.exe’
– OriginalFileName: ‘WBADMIN.EXE’
selection2_cli:
CommandLine|contains|all:
– ‘delete’
– ‘catalog’
– ‘quiet’ # will match -quiet or /quiet
selection3_img:
– Image|endswith: ‘\vssadmin.exe’
– OriginalFileName: ‘VSSADMIN.EXE’
selection3_cli:
CommandLine|contains|all:
– ‘resize’
– ‘shadowstorage’
CommandLine|contains:
– ‘unbounded’
– ‘/MaxSize=’
condition: (all of selection1*) or (all of
selection2*) or (all of selection3*)
falsepositives:
– Legitimate Administrator deletes Shadow
Copies using operating systems utilities for
legitimate reason
– LANDesk LDClient Ivanti-PSModule (PS
EncodedCommand)
level: high
(Source: Surface Web)
IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)
STRATEGIC RECOMMENDATIONS
MANAGEMENT RECOMMENDATIONS
TACTICAL RECOMMENDATIONS
Type: Infostealer / Stealer | Objectives: Credential Theft and Data Exfiltration | Target Technology: Windows | Target Geography: Global
CYFIRMA collects data from various forums based on which the trend is ascertained. Weidentified a few popular malwares that were found to be distributed in the wild to launchcyberattacks on organizations or individuals
Active Malware of the Week
This week, VorishkaStealer Malware is in focus.
Overview of Operation VorishkaStealer Malware
Assessment of “VorishkaStealer” shows software whose behavior, once active, is directedtoward a specific operational goal. What sets it apart from an innocuous program is thedeliberate set of actions it takes on the host it infects. It is built to monitor copied content,including account details. Taken together, these behaviors describe an operationallypurposeful threat rather than an inert file.
Observed activity includes clipboard monitoring, and the sample takes an active interest inregistry configuration and local files. For a manager, the key point is that the sample is notidle; it is actively engaging with the machine and with the information held on or near it, soits presence signals a direct interest in the organization’s data rather than a benign oraccidental installation.
Little indicates that the sample makes a determined effort to remain resident over time;within the recorded sessions, its activity looked short-lived. That is not proof it is benign, sincesome variants rely on being delivered afresh or on user action to run again, but it doessuggest the observed program was not centered on a deep self-sustaining routine.
Stepping back, the broader picture is that the sample supports more than a single one-offaction: only limited outward traffic was captured in the session, so the sample’s immediateeffect seems limited to the machine it ran on. For an organization, this is a real securityconcern, because it shows an attacker with a deliberate interest in these systems and thedata they contain.
Attack Method
On a Windows host, the sample begins with anti-analysis checks designed to detect amonitored or virtualized environment before any real activity unfolds. Only basicenvironment details are gathered at this stage, enough for the component to orient itselfbut not enough to betray a heavy information gathering routine of its own. Where suchconditions are detected, it can alter its behavior or exit early rather than hand analysts afaithful trace. The combined effect is that the execution phase establishes a workingfoothold, confirms the sample is running under favorable conditions, and prepares theground for the persistence and collection routines that follow.
No durable persistence or explicit defense-evasion behavior was recorded within theobservation window. This absence should be read with care: if the operator retains access,survival is likely maintained outside the activity captured here, whether through loaderchains that deliver the component again, through re-infection by other means, or throughthe operator relying on user interaction to set it running once more. The lack of an obviousself-sustaining routine therefore does not reduce the threat posed.
The heart of this sample’s purpose is gathering data: recorded behaviors cover systematicreading of local files, gathering documents, configuration, and other sensitive material fromthe workstation, and clipboard monitoring that intercepts copy-paste content such aspasswords, wallet addresses, and confidential text. These actions work alongsidereconnaissance of processes, system state, and security controls, so the implant builds acomplete view of the victim before any data leaves the network.
The Following are the TTPs based on the MITRE ATT&CK Framework for Enterprises
| Tactic | Technique ID | Technique Name |
| Execution | T1059 | Command and Scripting Interpreter |
| Execution | T1129 | Shared Modules |
| Persistence | T1112 | Modify Registry |
| Persistence | T1547.009 | Boot or Logon Autostart Execution: Shortcut Modification |
| Privilege Escalation | T1134 | Access Token Manipulation |
| Stealth | T1027.002 | Obfuscated Files or Information: Software Packing |
| Stealth | T1027.009 | Obfuscated Files or Information: Embedded Payloads |
| Stealth | T1140 | Deobfuscate/Decode Files or Information |
| Stealth | T1564.003 | Hide Artifacts: Hidden Window |
| Stealth | T1622 | Debugger Evasion |
| Defense Impairment | T1222 | File and Directory Permissions Modification |
| Discovery | T1010 | Application Window Discovery |
| Discovery | T1012 | Query Registry |
| Discovery | T1057 | Process Discovery |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1083 | File and Directory Discovery |
| Discovery | T1124 | System Time Discovery |
| Collection | T1115 | Clipboard Data |
| Collection | T1125 | Video Capture |
| Impact | T1529 | System Shutdown/Reboot |
INSIGHTS
ETLM ASSESSMENT
Viewed from an ETLM perspective, what VorishkaStealer does today points to a sharper, more automated class of intrusion ahead, and its future effect on organizations and employees merits serious attention: credential-harvesting operations of this class are sliding toward automated, always-on pipelines that will make stolen accounts tradable minutes after a compromise, turning a single workstation breach into a recurring source of business compromise. As this family and its descendants mature, organizations will increasingly find themselves responding to incidents that reach further into day-to-day operations, while employees become the primary human exposure point – their daily clicks, logins, and communications quietly feeding a growing digital economy built on what these samples quietly collect. The cumulative consequence may therefore be felt most in how organizations absorb exposure over time: as intrusions of this class become more common, the overall effect could reach well beyond any single machine into broader operational disruption that is difficult to isolate and even harder to unwind.
Kindly refer to the IOCs below to exercise controls on your security systems. (Source: Open Surface)
YARA Rules
rule VorishkaStealer_Malware
{
meta:
description = “Detection rule for the analyzed malware sample”
author = “CYFIRMA Research”
strings:
$hash1 =
“b312ef44bca34f2186177d9a6c8da06834d2748586ed5aa757d300c36d37acf2″$hash2 = “dd350eac76d1157772889dc21d0ae2e85b2ddf2f”
$hash3 = “56b34de84f4950c4364e693877b640c6”
$s1 =
“C:\\Users\\A4148~1.MON\\AppData\\Local\\Temp\\fajZCxur\\\\AutoIt3.exe\” \”C:\\Users\\A4148~1.MON\\AppData\\Local\\Temp\\fajZCxur\\\\AutoStart_f34691.au3″
$s2 = “c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur”
$s3 = “fajzcxur”
$s4 = “c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\nsg5b38.tmp”$s5 = “nsg5b38.tmp”
$s6 =
“c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur\\autoit3.exe”
$s7 = “autoit3.exe”
$s8 =
“c:\\users\\rdhj0cnfevzx\\appdata\\local\\temp\\fajzcxur\\autostart_f34691.au3”
$s9 = “autostart_f34691.au3”
$s10 = “VorishkaStealer”
condition:
any of ($hash*) or
2 of ($s*)
}
Strategic Recommendations
Star Blizzard: Evolution of Phishing and Malware Delivery
About the Threat Actor
Star Blizzard, also known as SEABORGIUM, is a highly persistent threat actor known for repeatedly targeting the same organizations over extended periods. Following initial compromise, Star Blizzard gradually expands its access by infiltrating victims’ social networks through persistent impersonation, relationship building, and phishing. The group has consistently compromised organizations and individuals of interest over several years, while largely maintaining the same established tactics and methodologies.
Details on Exploited Vulnerabilities
| CVE ID | Affected Products | CVSS Score | Exploit Links |
| CVE-2024-4947 | Google Chrome prior to 125.0.6422.60 | 9.6 | – |
| CVE-2023-38831 | RARLAB WinRAR | 7.8 | Link1 |
| CVE-2023-36884 | Windows | 7.5 | Link1 |
| CVE-2022-30190 | Microsoft Support Diagnostic Tool (MSDT), Windows | 7.8 | – |
| CVE-2023-36884 | Windows | 7.5 | – |
| Tactic | ID | Technique |
| Reconnaissance | T1589 | Gather Victim Identity Information |
| Reconnaissance | T1598.002 | Phishing for Information: Spearphishing Attachment |
| Reconnaissance | T1598.003 | Phishing for Information: Spearphishing Link |
| Reconnaissance | T1593 | Search Open Websites/Domains |
| Resource Development | T1583 | Acquire Infrastructure |
| Resource Development | T1583.001 | Acquire Infrastructure: Domains |
| Resource Development | T1586.002 | Compromise Accounts: Email Accounts |
| Resource Development | T1585.001 | Establish Accounts: Social Media Accounts |
| Resource Development | T1585.002 | Establish Accounts: Email Accounts |
| Resource Development | T1588.002 | Obtain Capabilities: Tool |
| Resource Development | T1608.001 | Stage Capabilities: Upload Malware |
| Initial Access | T1566.001 | Phishing: Spear phishing Attachment |
| Initial Access | T1078 | Valid Accounts |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript |
| Execution | T1204.002 | User Execution: Malicious File |
| Persistence | T1078 | Valid Accounts |
| Privilege Escalation | T1078 | Valid Accounts |
| Stealth | T1078 | Valid Accounts |
| Stealth | T1684.001 | Social Engineering: Impersonation |
| Credential Access | T1539 | Steal Web Session Cookie |
| Lateral Movement | T1550.004 | Use Alternate Authentication Material: Web Session Cookie |
| Collection | T1114.002 | Email Collection: Remote Email Collection |
| Collection | T1114.003 | Email Collection: Email Forwarding Rule |
Latest Developments Observed
The threat actor Star Blizzard is suspected of expanding its phishing operations fromtargeted spear-phishing to large-scale campaigns targeting Ukrainian individuals andorganizations, NGOs, think tanks, governments, and financial institutions. The threat actorhas introduced the RedFlick malware delivery technique, using malicious VHDX files,password-protected archives, compromised websites, scheduled tasks, and payloadsconcealed within PDF files to deploy the CosmicPulse backdoor. The activity appearsaimed at improving malware delivery, reducing required user interaction, evadingdetection, and supporting ongoing cyberespionage operations.
ETLM Insights
Star Blizzard, a Russian state-sponsored cyber-espionage actor, is demonstratingcontinued operational evolution through the expansion of its phishing operations,adoption of new malware delivery mechanisms, and increased use of compromisedinfrastructure to support scalable targeting. The actor’s 2026 activity reflects a shift fromhighly targeted spear-phishing toward larger-scale operations while continuing to refineits ability to evade detection and streamline malware deployment against organizationsaligned with Ukraine-related political and policy interests.
The threat actor’s operations reflect:
Looking ahead, Star Blizzard is likely to further refine its large-scale phishing and malwaredelivery capabilities to improve operational scalability, reduce user interaction, andstrengthen its ability to evade detection. The continued adoption of compromisedinfrastructure, scheduled-task persistence, and concealed payload delivery suggests thatthe actor will remain focused on developing more resilient and efficient intrusion chainsto support sustained cyberespionage operations against strategically relevant targets.
IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source:Surface Web)
YARA Rules
rule CVE_2024_4947_Proton_Decrypter_Indicators
{
meta:
description = “Indicators associated with CVE-2024-4947 and Proton Decrypter”author = “CYFIRMA”
reference = “CVE-2024-4947”
strings:
// CVEs
$cve1 = “CVE-2022-30190” ascii nocase
$cve2 = “CVE-2023-39831” ascii nocase
$cve3 = “CVE-2023-36884” ascii nocase
$cve4 = “CVE-2018-0798” ascii nocase
$cve5 = “CVE-2024-4947” ascii nocase
// IP Addresses
$ip1 = “165.227.148.68” ascii
$ip2 = “192.236.193.194” ascii
$ip3 = “142.11.209.180” ascii
$ip4 = “142.11.209.171” ascii
$ip5 = “185.164.172.128” ascii
// Domains
$domain1 = “cloudmediaportal.com” ascii nocase
$domain2 = “aerofluidthermo.org” ascii nocase
$domain3 = “civilstructgeo.org” ascii nocase
$domain4 = “docs-info.com” ascii nocase
// File indicators
$file1 = “proton-decrypter.exe” ascii nocase
$hash1 =
“37c52481711631a5c73a6341bd8bea302ad57f02199db7624b580058547fb5a9.bin” ascii nocase
condition:
any of them
}
Recommendations
Strategic Recommendations
South Korean Banks Under Intense Hacking Campaign
The South Korean Financial Services Commission (FSC) convened an emergency meeting with top financial executives and regulators following a coordinated wave of cyberattacks targeting major South Korean banks, including Shinhan, KB Kookmin, Hana, and Woori. The regulatory body warned that the intrusions may have utilized advanced artificial intelligence to broadly scan multiple financial institutions for system vulnerabilities rather than focusing on a single target. Malicious attack traffic has been traced back to IP addresses across several countries, with political figures urging authorities to investigate potential connections to North Korean state-sponsored threat groups known for targeting South Korean financial infrastructure.
The breaches have already compromised sensitive consumer data across multiple lenders, reportedly exposing personal and financial records for roughly 25,000 customers at Shinhan Bank, alongside smaller affected numbers at KB Kookmin and Hana Bank. Cybersecurity experts cited by local media suggest that attackers likely deployed sophisticated AI agents to probe for weaknesses and breach services tied to loan recruiters, laying bare the double-edged sword of advanced technologies where defensive-oriented source codes are increasingly weaponized for automated cybercrime. Although these customer figures are modest compared to historical mega-breaches in the country, such as massive historical leaks at Lotte Card and Coupang, security analysts warn that the exposure of detailed financial parameters makes victims highly vulnerable to hyper-personalized, generative AI-driven scams.
ETLM Assessment:
South Korean financial institutions have long been prime targets for Pyongyang’s state-backed threat actors, who have historically relied on sophisticated cyberheists and cryptocurrency scams to launder billions of dollars to fund the regime’s illicit programs. Cyberespionage groups like the Lazarus cyber syndicate have systematically attacked banks, exchanges, and financial networks across the globe, shifting from traditional malware deployments to highly coordinated, multi-stage social engineering and infrastructure compromises. In recent months, threat intelligence agencies and security researchers have identified an alarming evolution in these operations: North Korean hackers are increasingly integrating artificial intelligence and automated agents into their attack lifecycles. By weaponizing generative AI and machine learning tools to rapidly scan for system vulnerabilities, automate phishing campaigns, and synthesize convincing multilingual pretexts for financial fraud, these state-sponsored operators are scaling up the speed and efficiency of their multi-million-dollar digital campaigns.
Chinese-aligned threat actor TA419 impersonated US policymakers this summer in adversary-in-the-middle phishing campaigns targeting AI experts at think tanks, universities, and law firms. Researchers revealed the campaign is part of broader espionage efforts to gather intelligence on US AI policy amid intense tech competition and export controls.
Rather than launching immediate attacks, TA419 first builds credibility. The group poses as legitimate contacts – such as former White House officials or economists – inviting targets to join fictitious advisory committees or contribute to Senate reports on AI. Once trust is established, attackers send a shortened URL leading to a customized, browser-in-the-browser OneDrive phishing page.
This technique captures authenticated sessions, bypassing standard multifactor authentication because victims unwittingly approve logins themselves. Experts note that traditional training falls short against these relationship-building pretexts, urging organizations to adopt phishing-resistant passkeys and verify unexpected outreach through independent channels.
ETLM Assessment:
Such operations represent standard operating procedure for state-backed intelligence collection, reflecting how modern nations gather critical insights to shape their own strategic policymaking. Rather than targeting immediate financial or tactical assets, state-aligned actors systematically map foreign regulatory landscapes, research breakthroughs, and diplomatic positioning to anticipate geopolitical moves, counter export controls, and inform their own national technology strategies.
Summary:
CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Japan was compromised by Everest ransomware. The compromised company is a Japanese IT company headquartered in Tokyo, Japan, operating in the information technology and systems software industry. It specializes in IT operations management software, system infrastructure solutions, and IT services. The Company also provides IT consulting, systems integration, and outsourcing services primarily to enterprise clients in Japan. The compromised dataset contains 159,901 files in 22,338 folders, occupying 127.964 GB. It combines corporate records, contracts, product engineering, customer implementation material, quality assurance, personnel assessments, structured application data, and selected correspondence. The dated business material extends from historical development and company administration to internal documents prepared for September 2026.
Source: Dark Web
Relevancy & Insights:


ETLM Assessment:
According to CYFIRMA’s assessment, Everest ransomware continues to pose a persistent and evolving cyber threat. The group is actively broadening its targeting across new sectors, expanding its role as an initial access broker, and increasingly relying on data-leak extortion as its core operational tactic. Organizations are advised to remain vigilant by strengthening access controls, closely monitoring for lateral movement and Cobalt Strike–related activity, and maintaining robust incident response and detection capabilities to mitigate the risks posed by Everest’s ongoing campaigns.
Summary:
CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that an organisation from Indonesia was compromised by The Gentlemen Ransomware. The compromised organisation is one of Indonesia’s biggest family restaurant chains — 200+ outlets in 55 cities across 31 provinces, employing thousands of people. It serves affordable Asian-Indonesian comfort food (fried rice, noodles, kwetiau, chicken and seafood dishes) famous for huge “jumbo” portions at Rp23k–55k, targeting middle-class families and mall shoppers. The data, which has been breached, has not yet appeared on the leak site, indicating that negotiations between the affected party and the ransomware group may be underway. The compromised data includes confidential and sensitive information belonging to the organization.
Source: Dark Web
Relevancy & Insights:


ETLM Assessment
According to CYFIRMA’s assessment, the Gentlemen Ransomware is a highly adaptive and globally active threat that leverages dual-extortion tactics, combining data theft with file encryption. The group employs advanced evasion and persistence techniques, supports cross-platform and scalable ransomware deployment, and conducts targeted attacks across multiple industries and geographic regions. This combination of capabilities makes it a significant risk to enterprise cybersecurity defenses, particularly for organizations with limited detection and incident-response maturity.
Vulnerability in Bluehood
Relevancy & Insights:
The vulnerability exists because the /api/* handlers do notenforce session authentication when web authentication is enabled. Anetwork-reachable attacker can access Bluetooth tracking data and modifyapplication settings, device groups, and per-device notes without a validsession.
Impact: A remote unauthenticated attacker can read Bluetooth tracking dataand modify application state, including the heartbeat URL, prune retention,device groups, and per-device notes.
Affected Products:
https[:]//github[.]com/dannymcc/bluehood/security/advisories/GHSAqj2j-wcg3-74jw
Recommendations:
Monitoring and Detection: Implement monitoring and detection mechanisms to identify unusual system behavior that might indicate an attempted exploitation of this vulnerability.
This week, CYFIRMA researchers have observed significant impacts on various technologiesdue to a range of vulnerabilities. The following are the top 5 most affected technologies.

The vulnerability in Bluehood presents a significant security risk to organizations using affected versions with web authentication enabled. The issue allows a network-reachable unauthenticated attacker to bypass authentication controls applied to the web interface and access Bluetooth tracking observations or modify application state through API endpoints. Public exploit code has been reported, increasing the potential for opportunistic exploitation, although current sources do not confirm active exploitation. Organizations using affected Bluehood versions should prioritize upgrading to version 0.7.1, restrict access to the dashboard port to trusted networks, and monitor application and network logs for suspicious requests to affected API endpoints. Prompt remediation and continuous monitoring are recommended to reduce the risk of unauthorized access to Bluetooth tracking data and application state.
SafePay Ransomware attacked and published the data of a Chemical Manufacturingcompany from Thailand
Summary:
Recently, we observed that SafePay Ransomware attacked and published the data of a Chemical Manufacturing company from Thailand on its dark web website. The compromised company is a Thai industrial company specializing in electroplating chemicals, surface-finishing technologies, industrial cleaning solutions, and related production systems. The company is headquartered in Samut Prakan Province and has more than five decades of experience in the surface-finishing industry. Its history traces back to 1967, when the business was established in Bangkok, and it subsequently expanded from chemical trading into manufacturing, technical services, and research and development.
The company’s products and services support a wide range of industrial applications, including automotive manufacturing, aerospace and defense, electronics and printed circuit boards, renewable energy, heavy machinery, sanitary equipment and decorative metal finishing. Its technology portfolio includes plating chemicals, industrial cleaners, plating on plastics, decorative metal coatings, electroless nickel, corrosion-resistant coatings, wear-resistant coatings, anodizing and electronic surface-finishing processes. The ransomware attack allegedly resulted in the exposure of a broad range of internal corporate data, including administrative records, business development and marketing information, commercial-office data, finance and accounting records, food-related information, human resources data, international sales and services records, laboratory and laboratory-service information, legal and logistics data, maintenance records, management-office information, material laboratory data, planning and portfolio information, procurement records, product-development data, production and production planning records, quality assurance and quality-control (QA/QC) information, quality management records, research and development (R&D) data, technical development and technical sales/service information, warehouse records, attachments, client setup information, dashboards, data-server monitoring information, documentation, emails, fax records, HTML/web content, inventory information, and other internal operational files.


Relevancy & Insights:
ETLM Assessment:
According to CYFIRMA’s assessment, SafePay represents a sophisticated, fast-movingransomware threat capitalizing on VPN weaknesses and credential theft, employingeffective double extortion tactics to maximize ransom payments. Organizations,especially in highly targeted sectors and regions, must prioritize layered defenses andactive hunting for early detection.
Unauthorized Database Advertised on a Leak Site
Summary:
The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a large database allegedly associated with a Japanese travel and tourism organization. According to the advertisement, the dataset reportedly contains information related to customer contacts, travel bookings, and passport verification records. The seller claims that the dataset has been organized into multiple sections covering customer information, booking details, and identity-document verification data. Sample data and references were reportedly provided as proof of possession, while the complete dataset was offered for sale.
Allegedly Exposed Data
Based on the information visible in the advertisement, the dataset may contain:
1. Customer and Contact Information
2. Travel and Booking Information
3.Passport and Identity-Verification Information
The authenticity of the allegedly exposed dataset remains unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Unauthorized Airline Database Advertised on a Leak Site
Summary: The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a large database allegedly originating from a Thailand-based airline organization. The advertisement claims that the dataset contains more than 200 million records associated with passenger and airline operations. According to the screenshot, the allegedly exposed information covers multiple areas, including:
The post also displays sample database records as evidence of possession. The visible sample contains passenger-related fields and appears to demonstrate structured records from an airline reservation or customer-management environment.
Allegedly Exposed Data
Based on the information visible in the advertisement, the dataset may contain:
The authenticity and extent of the alleged unauthorized access remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums
Relevancy & Insights
Financially motivated cybercriminals are continuously looking for exposed and vulnerable systems and applications to exploit. A significant number of these malicious actors congregate within underground forums, where they discuss cybercrime and trade stolen digital assets. Operating discreetly, these opportunistic attackers target unpatched systems or vulnerabilities in applications to gain access and steal valuable data. Subsequently, the stolen data is advertised for sale within underground markets, where it can be acquired, repurposed, and utilized by other malicious actors in further illicit activities.
ETLM Assessment
The threat actor is assessed as an active and capable cybercriminal entity primarily involved in data-leak and information-extortion activities, with multiple indications of unauthorized access to systems and the subsequent dissemination or sale of compromised data through underground forums. Their activities demonstrate the evolving sophistication of organized cybercriminal networks and highlight the increasing risk of sensitive information being exploited for financial gain, fraud, and follow-on attacks. Organizations should strengthen their cybersecurity posture through continuous monitoring, proactive threat intelligence, robust access controls, enhanced data protection, and timely defensive measures to safeguard sensitive information and critical infrastructure.
Recommendations:
Enhance the cybersecurity posture by:
The CYFIRMA research team identified a post observed on a cybercrime forum that advertises the sale of a database allegedly belonging to an India-based digital gateway and logistics platform serving the Lakshadweep Islands. According to the advertisement, the platform primarily facilitates connectivity and logistics between the Indian mainland, including Kochi, Kerala, and the Lakshadweep Islands.
The advertisement claims that a database associated with the platform was compromised on 03 October 2026 and is being offered for sale. The seller has reportedly assigned a price of US$500, with negotiations permitted.
Allegedly Exposed Information
The advertisement does not provide a detailed list of database fields or sample records. However, based on the description of the platform and the database being offered, the exposed information may include:
If the claims are verified, unauthorized exposure of the database could create risks including:
However, the authenticity of the alleged database, the actual breach, the volume ofcompromised records, and the specific information contained in the dataset have notbeen independently verified. The assessment is therefore based solely on the informationpresented in the cybercrime-forum advertisement and should be treated as an allegeddata leak pending validation.
Source: Underground Forums
RECOMMENDATIONS
STRATEGIC RECOMMENDATIONS
MANAGEMENT RECOMMENDATIONS
TACTICAL RECOMMENDATIONS
Please find the Geography-Wise and Industry-Wise breakup of cyber news for the last 5 days as part of the situational awareness pillar.









