Weekly Intelligence Report – 1 Oct 2026

Published On : 2026-10-02
Share :
Weekly Intelligence Report – 1 Oct 2026

Ransomware In Focus

CYFIRMA Research and Advisory Team would like to highlight ransomware trends and insights gathered while monitoring various forums. This includes multiple industries, geographies, and technologies that could be relevant to your organization.

Type: Ransomware
Target Technologies: Windows OS

Introduction:

CYFIRMA Research and Advisory Team has found Ried Ransomware while monitoring various underground forums as part of our Threat Discovery Process.

Ried Ransomware

RIED is a ransomware infection designed to encrypt files on a compromised computer and prevent the victim from accessing their data. Once executed, the ransomware encrypts targeted files and changes their filenames by appending a distinctive naming pattern in the format [original filename].[victim-specific identifier].[attacker contact].RIED. For example, a file such  as 1.jpg  would  be renamed in  this  general  format:1.jpg.[identifier].[contact].RIED. It also changes the desktop wallpaper to display a warning that the files have been encrypted and creates a ransom note named+README-WARNING+.txt. The ransom note explains that the attackers claim to possess the private key required for decryption and demand payment in exchange for a decryption program and instructions. They also offer to decrypt a small number of simple files as proof that their recovery process works.

Screenshot: File encrypted by the ransomware
(Source: Surface Web)

The ransom note is presented as a short FAQ covering what happened, how victims can supposedly recover their files, how to contact the attackers, and what happens after payment. It warns victims not to rename or modify encrypted files and discourages the use of third-party recovery software or security tools, claiming that such actions could damage the encrypted data and make recovery impossible. The ransomware generally relies on encryption that cannot be practically reversed without the corresponding private key, although a free decryptor could become available if researchers discover a weakness in the ransomware’s implementation. Paying the ransom is risky because there is no guarantee that the attackers will provide a functional decryption solution. The ransomware should be removed from an infected system to prevent further encryption, but removing the malware does not restore files that have already been encrypted. If no legitimate decryptor is available, recovery typically depends on clean backups made before the infection and stored separately from the compromised system.

Screenshot: The appearance of Ried’s ransom note (+README-WARNING+.txt)
(Source: Surface Web)

The following are the TTPs based on the MITRE ATT&CK framework

Tactic Techniq ue ID Technique Name
Execution T1059.00 3 Command and Scripting Interpreter: Windows Command Shell
Execution T1106 Native API
Execution T1129 Shared Modules
Privilege Escalation T1055 Process Injection
Credential Access T1539 Steal Web Session Cookie
Discovery T1012 Query Registry
Discovery T1033 System Owner/User Discovery
Discovery T1057 Process Discovery
Discovery T1082 System Information Discovery
Discovery T1083 File and Directory Discovery
Discovery T1135 Network Share Discovery
Discovery T1518 Software Discovery
Discovery T1614 System Location Discovery
Collection T1115 Clipboard Data
Command and Control T1071 Application Layer Protocol
Command and Control T1105 Ingress Tool Transfer
Impact T1485 Data Destruction
Stealth T1027.00 2 Obfuscated Files or Information: Software Packing
Stealth T1027.00 5 Obfuscated Files or Information: Indicator Removal from Tools
Stealth T1027.00 9 Obfuscated Files or Information: Embedded Payloads
Stealth T1055 Process Injection
Stealth T1070.00 4 Indicator Removal: File Deletion
Defense Impairment T1222 File and Directory Permissions Modification
Stealth T1564.00 3 Hide Artifacts: Hidden Window

Relevancy and Insights:

  • The ransomware primarily targets Windows environments, utilizing Windows services, command-line utilities, registry configurations, system APIs, and filesystem operations to perform encryption, system modification, and recovery-inhibition activities.
  • The ransomware terminates processes such as exe Delete Shadows /all/quiet and wmic shadowcopy delete /nointeractive to delete Volume Shadow Copies, which are used by Windows for backup and restore. By removing these shadow copies, the malware ensures that victims cannot recover their files via system restore points or backup utilities.
  • The malware performs extensive system and environment discovery, including identifying the operating system, logged-in user, running processes, installed software, available files and directories, network shares, registry configurations, and system location information. This behavior can help the ransomware determine the characteristics of the infected environment before carrying out destructive operations.
  • The sample exhibits defense-evasion capabilities, including obfuscation, software packing, anti-debugging checks, process injection, artifact hiding, and file deletion. These techniques can make the malware more difficult to analyze and may help it avoid detection by security products and automated analysis
  • The malware creates or interacts with scheduled-task and temporary-file locations and modifies filesystem artifacts during execution. Such behavior may assist with execution, operational activity, or concealment, although the observed data alone does not establish a persistent scheduled-task mechanism.

ETLM Assessment:

RIED is likely to evolve toward a more evasive and destructive ransomware operation rather than remaining limited to straightforward file encryption. Its current behavior already indicates several capabilities that could support this progression, including process injection, code obfuscation and packing, anti-analysis checks, system and software discovery, file and directory discovery, and attempts to interfere with recovery mechanisms. The observed deletion of shadow copies and backup catalogs is particularly significant because it can reduce the victim’s ability to restore encrypted data without paying the ransom. Future variants may therefore place greater emphasis on disabling or bypassing security controls, detecting analysis environments, concealing malicious activity, and systematically removing recovery options before or during encryption.

The ransomware could also become more targeted in how it selects and processes files and environments. Its observed discovery activity includes identifying the host, user, installed software, network shares, and system information, which could provide a foundation for broader impact in future versions. The presence of credential- and session-related collection behavior, clipboard access, and application-layer communication suggests that later variants could potentially combine encryption with information theft or other forms of data collection, increasing pressure on victims. The file-renaming behavior is also likely to remain a useful indicator, with encrypted files following a pattern similar to original_filename.[identifier].[contact].RIED. Overall, the observed capabilities suggest that future RIED variants may focus on stronger defense evasion, broader environmental discovery, recovery inhibition, and potentially data theft alongside encryption, although these developments are predictions based on current observed behavior rather than confirmed features of future samples.

Sigma rules:

title: Shadow Copies Deletion Using Operating Systems Utilities tags:

  • impact
  • stealth
  • t1070 logsource:

category: process_creation product: windows

detection: selection1_img:

  • Image|endswith:
    • ‘\powershell.exe’
    • ‘\pwsh.exe’
    • ‘\wmic.exe’
    • ‘\vssadmin.exe’
    • ‘\diskshadow.exe’
  • OriginalFileName:
    • ‘PowerShell.EXE’
    • ‘pwsh.dll’
    • ‘wmic.exe’
    • ‘VSSADMIN.EXE’
    • ‘diskshadow.exe’ selection1_cli:

CommandLine|contains|all:

  • ‘shadow’ # will match “delete shadows” and “shadowcopy delete” and “shadowstorage”
  • ‘delete’ selection2_img:
  • Image|endswith: ‘\wbadmin.exe’
    • OriginalFileName: ‘WBADMIN.EXE’ selection2_cli:

CommandLine|contains|all:

  • ‘delete’
  • ‘catalog’
  • ‘quiet’ # will match -quiet or /quiet selection3_img:
  • Image|endswith: ‘\vssadmin.exe’
  • OriginalFileName: ‘VSSADMIN.EXE’ selection3_cli:

CommandLine|contains|all:

  • ‘resize’
  • ‘shadowstorage’ CommandLine|contains:
  • ‘unbounded’
  • ‘/MaxSize=’

condition: (all of selection1*) or (all of selection2*) or (all of selection3*) falsepositives:

  • Legitimate Administrator deletes Shadow Copies using operating systems utilities for legitimate reason
  • LANDesk LDClient Ivanti-PSModule (PS EncodedCommand) level: high
    (Source: Surface Web)

IOCs:
Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)

RECOMMENDATIONS

STRATEGIC RECOMMENDATIONS

  • Implement competent security protocols and encryption, authentication, or access credential configurations to access critical systems in your cloud and local environments.
  • Ensure that backups of critical systems are maintained, which can be used to restore data in case a need arises.

MANAGEMENT RECOMMENDATIONS

  • A data breach prevention plan must be developed considering (a) the type of data being managed by the company; (b) the remediation process; (c) where and how the data is stored; (d) if there is an obligation to notify the local
  • Implement a zero-trust security model alongside multifactor authentication (MFA) to reduce the risk of credential compromise.
  • Foster a culture of cybersecurity, where you encourage and invest in employee training so that security is an integral part of your organization.

TACTICAL RECOMMENDATIONS

  • Update all applications/software regularly with the latest versions and security patches alike.
  • Add the Sigma rules for threat detection and monitoring, which will help to detect anomalies in log events and identify and monitor suspicious activities.
  • Establish and implement protective controls by actively monitoring and blocking identified indicators of compromise (IoCs) and reinforcing defensive measures based on the provided tactical intelligence.

Active Malware of the Week

Type: Downloader / Dropper | Objectives: Payload Delivery and System Compromise | Target Technology: Windows | Target Geography: Global

CYFIRMA collects data from various forums based on which the trend is ascertained. We identified a few popular malwares that were found to be distributed in the wild to launch cyberattacks on organizations or individuals.

Active Malware of the Week
This week, ShellterLoader Malware is in focus.

Overview of Operation ShellterLoader Malware

ShellterLoader is a malware delivery component designed to establish an initial presence on a Windows system and facilitate the introduction of additional malicious software. Its primary role is not extensive data theft on its own, but to create a pathway through which more capable malware can subsequently reach the compromised environment. This makes it an enabling component within a broader attack chain.From an organizational perspective, the key concern is the potential consequences that may follow its deployment. Although the initial component maintains a relatively limited footprint, the additional payloads it delivers can introduce significantly greater capabilities, including unauthorized access, information theft, or other malicious activity. Therefore, the apparent simplicity of the initial infection should not be considered an indication of limited risk.

The malware also demonstrates behavior intended to reduce visibility and maintain its presence on an affected system. Such characteristics can allow an infection to remain unnoticed for longer periods and provide additional opportunities for subsequent malicious activity. This increases the importance of identifying the initial compromise before further components are introduced.

Overall, the activity associated with ShellterLoader reflects a delivery-focused threat in which the initial malware serves as a steppingstone toward a potentially broader compromise. Organizations encountering this type of activity should consider the possibility of additional malicious components being present and assess the affected environment for related activity rather than treating the detected file as an isolated incident.

Attack Method

ShellterLoader begins execution by verifying whether the required runtime conditions are present on the Windows host. It creates named mutex objects, including ChromeProcessSingletonStartup! and  OMADM_NAMED_MUTEX , to regulate execution and prevent multiple instances from running simultaneously. It also performs basic environment checks to determine whether the host is suitable for continued execution. Depending on the conditions identified, it may modify its behavior or terminate, potentially complicating analysis.

The execution chain incorporates memory-based techniques designed to reduce the visibility of malicious functionality. Reflective loading and in-memory execution allow payload components to be prepared and executed without relying entirely on conventional file-based mechanisms. Memory and thread manipulation consistent with code injection also enable malicious code to operate within the context of another process. These techniques can complicate static analysis and limit the effectiveness of detection mechanisms that primarily rely on identifying suspicious files on disk.

A primary function of the component is to retrieve and stage an additional payload. During execution, it communicates with external infrastructure masquerading as or abusing traffic to sb.scorecardresearch.com to obtain the next-stage component. This establishes a multi-stage infection process in which the initial loader facilitates the delivery of additional malicious functionality. Its observed behavior is therefore primarily focused on payload delivery rather than extensive data collection.

The execution process also incorporates mechanisms intended to conceal malicious activity and sustain the infection. The combination of environment checks, mutex-based execution control, memory-resident payload handling, process-level manipulation, and external communication creates an execution chain that can complicate detection and behavioral analysis. Consequently, examining the initial component alone may not reveal the full scope of the compromise, as the capabilities and potential impact depend on the additional payload delivered to the affected system.

The Following are the TTPs based on the MITRE ATT&CK Framework for Enterprises

Tactic Technique Technique Name
 

 

 

 

Execution

 

T1047

Windows Management Instrumentation
 

T1059

Command and Scripting Interpreter
T1129 Shared Modules
 

 

 

 

 

Stealth

 

T1027.002

Obfuscated Files or Information: Software Packing
T1218 System Binary Proxy Execution
 

T1497

Virtualization/Sandbox Evasion
T1564 Hide Artifacts
 

 

 

 

 

 

Discovery

T1012 Query Registry
T1033 System Owner/User Discovery
T1057 Process Discovery
T1082 System Information Discovery
T1083 File and Directory Discovery
 

T1518.001

Software Discovery: Security Software Discovery
Collection T1185 Browser Session Hijacking
 

Command and control

T1071

 

T1573

Application Layer Protocol

 

Encrypted Channel

 

Impact

T1485

 

T1486

Data Destruction

 

Data Encrypted for Impact

INSIGHTS

A key insight from the observed activity is the deliberate separation between the initial compromise and the eventual malicious objective. The component itself performs a relatively narrow role, indicating that the intrusion is structured in stages rather than relying on a single piece of malware to perform every task. This separation allows the activity associated with the initial foothold to remain less conspicuous while other capabilities are introduced independently.

The behavior also reflects a level of operational discipline in how the compromise is maintained. Multiple elements work together to limit visibility and preserve control, suggesting that the activity was designed with the realities of endpoint monitoring and investigation in mind. The overall behavior is therefore better characterized as a coordinated intrusion component than as an isolated or opportunistic program.

A further insight concerns the value placed on access obtained through the compromised environment. The activity indicates that maintaining a usable presence on a system is itself an important objective, rather than simply performing an immediate action and terminating. This places greater significance on the compromised account and system context, as continued access can provide a basis for subsequent activity without requiring the same initial entry process again.

ETLM ASSESSMENT

From an ETLM perspective, ShellterLoader-type activity is likely to contribute to a shift toward more modular and persistent intrusion campaigns, where the initial compromise serves as a controlled entry point for progressively more capable payloads. Organizations may increasingly face incidents in which the visible malware represents only one stage of a wider compromise, making incident scope and business impact more difficult to determine quickly. Employees could become more directly exposed to these campaigns as attackers seek to blend malicious activity into normal workplace processes, potentially increasing the risk of account misuse, disruption to business applications, and unauthorized access to corporate resources. In the longer term, repeated incidents of this nature could result in extended recovery periods, greater operational costs, and increased disruption across interconnected business functions rather than remaining confined to individual endpoints.

IOCs:

Kindly refer to the IOCs below to exercise controls on your security systems. (Source: Open Surface)

YARA Rules

rule ShellterLoader_Malware

{meta: description = “Detection rule for the analyzed malware sample” author = “CYFIRMA Research”

date = “2026-09-29”

strings:

$hash1 = “594033ed58e27b42bb1bef7e5b21eac87f0d660c7cc3d48881a2e5575e3ac811”

$hash2  =  “dd39fafbdba994169991cea092c6428e1d3b1539”

$hash3  =  “d3cea61538aa5030e90a1d38cca762b4”

$s1 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\Application\\chrome.exe\”  –

-no-first-run –no-default-browser-check”

$s2  =  “C:\\Program Files  (x86)\\Microsoft\\Edge\\Application\\msedge.exe\”

–no-first-run –no-default-browser-check”

$s3 = “C:\\Windows\\system32\\BackgroundTaskHost.exe\” – ServerName:BackgroundTaskHost.WebAccountProvider”

$s4 = “C:\\Windows\\System32\\RuntimeBroker.exe -Embedding”

$s5  =  “ChromeProcessSingletonStartup!”

$s6 = “  OMADM_NAMED_MUTEX  ”

$s7 = “_app_container_profile_lock_0278d671-c445-4dfa-a8b4-d5ccf66d4cc3”

$s8 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\Crashpad\\settings.dat”

$s9 = “settings.dat”

$s10 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\BrowserMetrics\\BrowserMetrics-6AB8F3B2-122C.pma”

$s11 = “BrowserMetrics-6AB8F3B2-122C.pma”

$s12 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\lockfile”

$s13 = “lockfile”

$s14 = “C:\\Users\\<USER>\\AppData\\Local\\Chromium\\User Data\\Variations”

$s15 = “wss.scriptlab.cc/”

$s16   =   “wss.scriptlab.cc/api/splitChanges/850ec405”

condition:

any of ($hash*) or 2 of ($s*)

}

Recommendations

Strategic Recommendations

  • Establish an organization-wide endpoint security strategy covering malware prevention, detection, and response.
  • Prioritize protection of sensitive credentials and business information stored or accessed from employee endpoints.
  • Adopt layered security controls so that a single compromised endpoint does not provide prolonged access to organizational resources.
  • Conduct periodic threat assessments to identify exposure to multi-purpose malware and similar information-stealing threats.

Management Recommendations

  • Direct affected users to rotate passwords and confirm multi-factor enrollment as part of the response checklist.
  • Ensure endpoint protection and security monitoring capabilities are consistently deployed across employee systems.
  • Establish clear incident-response procedures for suspected malware infections, including isolation, investigation, and recovery.
  • Provide regular security-awareness training focused on suspicious files, links, downloads, and unexpected system activity.
  • Maintain appropriate controls over access to sensitive corporate information and user accounts.

Tactical Recommendations

  • Force password resets and revoke active sessions for users on affected systems; verify MFA coverage to blunt harvested-credential replay.
  • Monitor endpoints for unusual PowerShell activity, unexpected processes, trees, and unauthorized changes to security settings.
  • Block and monitor the infrastructure listed in the IOC section at DNS, proxy, and perimeter controls.
  • Isolate confirmed cases promptly, then reset credentials and review autostart locations before restoration.

CYFIRMA’s Weekly Insights

1. Weekly Attack Types and Trends

Key Intelligence Signals:

  • Attack Type: Ransomware Attacks, Vulnerabilities & Exploits, Data
  • Objective: Unauthorized Access, Data Theft, Data Encryption, Financial Gains,
  • Business Impact: Data Loss, Financial Loss, Reputational Damage, Loss of Intellectual Property, Operational Disruption.
  • Ransomware – Qilin Ransomware, The Gentlemen Ransomware| Malware – ShellterLoader
  • Qilin Ransomware– One of the ransomware
  • The Gentlemen Ransomware – One of the ransomware Please refer to the trending malware advisory for details on the following:
  • Malware – ShellterLoader
  • Behavior – Most of these malwares use phishing and social engineering techniques as their initial attack vectors. Apart from these techniques, exploitation of vulnerabilities, defense evasion, and persistence tactics are being observed.

2. Threat Actor in Focus

FamousSparrow: Evolving Malware Capabilities and Stealth-Oriented Cyber-Espionage

  • Threat Actor: FamousSparrow aka Salt Typhoon
  • Attack Type: DLL Sideloading, Keylogging, Living off the Land (LoTL), Malware Implant, Spear-phishing, Exploitation of
  • Objective: Espionage, Data
  • Suspected Target Technology: Internet service provider networks, Telecommunications carrier networks, Ivanti Policy Secure appliances, Sophos Firewall appliances, Linux network devices, Cisco network switches and routers, Cisco switches and routers, Linux-based network devices, Active Directory domain controllers, Ivanti Connect Secure appliances, Microsoft Exchange servers, Fortinet FortiClient EMS, Telecommunications provider infrastructure, Firewall appliances, Lawful-intercept systems, Lawful intercept systems, VPN gateways, Microsoft Exchange Server, Network edge devices, Windows servers, QLogic Fibre Channel adapter management servers.
  • Suspected Target Geography: Afghanistan, Argentina, Australia, Azerbaijan, Bangladesh, Brazil, Burkina Faso, Canada, Egypt, Eswatini, Ethiopia, Finland, France, Germany, Guatemala, India, Indonesia, Israel, Japan, Korea, Liberia, Lithuania, Macedonia, Malaysia, Mexico, Netherlands, Pakistan, Philippines, Province of China, Republic of, Saudi Arabia, Singapore, South Africa, Swaziland, Taiwan, Thailand, UK, USA, United Arab Emirates, United Kingdom, United States, Vietnam, Ecuador, Honduras, Panama, Peru, Puerto Rico, Venezuela.
  • Suspected Target Industries: Hotels, Restaurants & Leisure, Food Products, Software, Materials, Government, Commercial Services & Supplies, Chemicals, Pharmaceuticals, Manufacturing, Information Technology, Oil, Gas & Consumable Fuels, Communication Services, Government & Public Sector, Critical Infrastructure, Justice & Safety Activities, Retail, Education Services, Semiconductors & Semiconductor Equipment, Airlines, Professional Services, Construction & Engineering, Aerospace & Defense, Telecommunications, Supply Chain, Health Care, Hospitals, Civic and Social Organizations, Professional, Political, Industrials, IT Services, Legal Services, Transportation, Grantmaking and Giving Services, National Security & International Affairs, Other Personal Services, Energy, Financials, Resorts & Cruise Lines, Personal Care Services, Non-Profit, Public Administration, Rental & Leasing, Management, Scientific, Media
  • Business Impact: Data Theft, Operational Disruption, Reputational Damage.

About the Threat Actor

Salt Typhoon is a highly sophisticated Advanced Persistent Threat (APT) group believed to be operated by China’s Ministry of State Security (MSS). The group has been linked to high-profile cyber-espionage campaigns, particularly targeting U.S. intelligence agencies and organizations holding critical corporate intellectual property. The threat actor has also been observed conducting campaigns across multiple countries globally. The group is widely regarded as a strategic asset aligned with China’s broader “100-Year Strategy” to expand its global influence and technological dominance.

Salt Typhoon is believed to have been active since at least 2020. Some of its observed Tactics, Techniques, and Procedures (TTPs) overlap with those attributed to FamousSparrow, indicating a possible connection between the threat actors. The group is assessed to possess significant resources and sophisticated cyber-espionage capabilities, supported by extensive experience in conducting illicit cyber activities. Salt Typhoon has also been suspected of having potential links to the nation-state threat actor APT41.

Details on Exploited Vulnerabilities

 

CVE ID

 

Affected Products

 

CVSS Score

 

Exploit Links

 

 

 

CVE-2025-7776

 

 

 

NetScaler ADC and NetScaler Gateway

 

 

 

9.8

 

 

 

–

 

 

 

CVE-2025-8424

 

 

 

NetScaler ADC and NetScaler Gateway

 

 

 

–

 

 

 

–

 

 

 

 

 

CVE-2026-23760

 

 

 

 

SmarterTools SmarterMail versions prior to build 9511

 

 

 

 

 

9.8

 

 

 

 

 

–

 

 

 

 

 

CVE-2025-0944

 

 

 

 

Tailoring Management System 1.0

 

 

 

 

 

9.8

 

 

 

 

 

–

 

CVE-2025-12480

 

Triofox

 

9.1

 

–

TTPs based on the MITRE ATT&CK Framework

Tactic ID Technique
Reconnaissance T1598 Phishing for Information
Reconnaissance T1598.003 Phishing for Information: Spear phishing Link
Resource Development T1583.001 Acquire Infrastructure: Domains
Resource Development T1584.008 Compromise Infrastructure: Network Devices
Resource Development T1583.006 Acquire Infrastructure: Web Services
Initial Access T1566.002 Phishing: Spear phishing Link
Execution T1204.001 User Execution: Malicious Link
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell
Execution T1059.006 Command and Scripting Interpreter: Python
Persistence T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation T1068 Exploitation for Privilege Escalation
Stealth T1218.007 System Binary Proxy Execution: Msiexec
Stealth T1036.004 Masquerading: Masquerade Task or Service
Stealth T1036 Masquerading
Stealth T1027.002 Obfuscated Files or Information: Software Packing
Stealth T1140 Deobfuscate/Decode Files or Information
Credential Access T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Discovery T1082 System Information Discovery
Discovery T1012 Query Registry
Discovery T1016 System Network Configuration Discovery

 

 

 

Discovery

 

 

T1033

 

 

System Owner/User Discovery

 

 

Discovery

 

 

T1124

 

 

System Time Discovery

 

 

Command and Control

 

 

T1102.002

 

Web Service: Bidirectional Communication

 

 

Command and Control

 

 

T1573.001

 

Encrypted Channel: Symmetric Cryptography

 

 

Command and Control

 

 

T1090.003

 

 

Proxy: Multi-hop Proxy

 

 

Command and Control

 

 

T1105

 

 

Ingress Tool Transfer

 

 

Command and Control

 

 

T1665

 

 

Hide Infrastructure

 

 

Exfiltration

 

 

T1041

 

 

Exfiltration Over C2 Channel

 

 

Exfiltration

 

 

T1567.002

 

Exfiltration Over Web Service: Exfiltration to Cloud Storage

Latest Developments Observed

The threat actor is suspected of targeting government organizations across Latin America, including entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group has deployed a newly developed modular C++ backdoor, SparroWocky, using DLL sideloading and reflective in-memory execution to enable command execution, screenshot capture, and file exfiltration. The activity appears to be espionage-driven, with the likely objective of monitoring regional governments and collecting strategically valuable information aligned with China’s economic and strategic interests in the region.

ETLM Insights

FamousSparrow, a China-aligned cyber-espionage group, continues to demonstrate an evolving operational model through geographic targeting shifts and modernization of its malware capabilities. Its recent activities reflect an increasing emphasis on stealth, extensibility, and flexible post-compromise operations to support intelligence collection.

The threat actor’s recent activity highlights:

  • Targeting expansion   toward    Latin  American government organizations, representing a significant shift in the group’s recent geographic focus.
  • Malware modernization through SparroWocky, providing command execution, data exfiltration, screenshot capture, TCP proxying, and system reconnaissance.
  • Advanced defense evasion through DLL sideloading, reflective in-memory execution, stack spoofing, and API hooking to conceal malicious activity.
  • Increased operational flexibility through BOF support, enabling additional in-memory capabilities to be loaded through the primary backdoor.

Looking ahead, FamousSparrow is likely to further refine its modular malware and defense-evasion capabilities while continuing to adapt its targeting toward strategically valuable organizations. The integration of BOF execution and offensive-security components into SparroWocky may provide greater flexibility for post-compromise operations. Continued development of stealth-oriented execution and adaptable tooling is likely to support sustained intelligence-collection activities across changing targets.

IOCs:

Kindly refer to the IOCs section to exercise control of your security systems. (Source: Surface Web)

YARA Rules

rule FamousSparrow_SaltTyphoon_IOC_Detection

{

meta:

description = “Detects supplied FamousSparrow/Salt Typhoon-related IP, domain, and Win32 EXE indicators”

author = “CYFIRMA” date = “2026-09-29”

category = “Threat Intelligence IOC Detection”

strings:

// IP addresses

$ip1 = “36.106.166.96” ascii wide

$ip2 = “139.59.236.31” ascii wide

$ip3 = “137.135.178.23” ascii wide

$ip4 = “36.106.166.97” ascii wide

$ip5 = “114.119.158.36” ascii wide

// Domains

$domain1 = “5jkl8ae8ph.ucarecd.net” ascii wide nocase

$domain2 = “5jiyuz.frost-echo.in.net” ascii wide nocase

$domain3 = “altra-paris.fr” ascii wide nocase

$domain4 = “altra-chaussure.fr” ascii wide nocase

// File type

$filetype = “win32 exe” ascii wide nocase

condition:

1 of ($ip*) or

1 of ($domain*) or

$filetype

}

Recommendations

 Strategic Recommendations

  • Establish a robust plan to identify assets by leveraging a risk-based approach along with the Defense-in-Depth (DiD) method as part of the organization’s security strategy to minimize the risk exposure of vulnerabilities to an acceptable level for an organization.
  • Incorporate Digital Risk Protection (DRP) as part of the overall security posture to proactively defend against impersonation and phishing attacks.

Management Recommendations

  • Regularly reinforce awareness of unauthorized attempts with end-users across the environment and emphasize the human weakness in mandatory information security training sessions.
  • Minimize network exposure for all control system devices and/or systems, and unless there is a business requirement, make sure they are not exposed to the Internet.

Tactical Recommendations

  • Create risk-based vulnerability management with deep knowledge about each asset. Assign a triaged risk score based on the type of vulnerability and criticality of the asset to help ensure that the most severe and dangerous vulnerabilities are dealt with first.
  • Enable Network traffic/security monitoring, security incident detection, notification, and alerting by leveraging SIEM
  • Add the YARA rules for threat detection and monitoring, which will help to detect anomalies in log events, identify and monitor suspicious activities.
  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs and strengthening defence based on the tactical intelligence provided.

3. Major Geopolitical Developments in Cybersecurity

Russia hits data centres in Ukraine

Russian drone and missile strikes this week heavily targeted telecommunications facilities and data centers in Kyiv, cutting off reliable internet access for around 100,000 households across the Ukrainian capital and surrounding regions. At least four regional providers have reportedly suffered partial connectivity losses following the assault, which struck critical networking equipment, data center facilities, and a central internet traffic exchange. Individual providers detailed significant physical damage to their operations, with severe outages affecting communications lines and equipment across multiple regions.

Russia’s Defense Ministry claimed responsibility for hitting specific data centers allegedly tied to Ukrainian security agencies, though these military assertions remained unverified. The Ukrainian Foreign Ministry condemned the attacks on civilian networks, emphasizing that internet infrastructure is vital for maintaining everyday life and delivering life-saving air-raid warnings to the population. The devastating barrage, which also damaged residential areas, railway infrastructure, and a historic market, left two people dead and at least 43 injured, followed quickly by a massive strike the next day that impacted a maternity hospital, housing, and additional energy logistics.

ETLM Assessment:

In modern warfare, data centers and communications networks are just as vital as artillery factories, and Russia systematically targets this critical digital infrastructure to hobble Ukraine’s decisive advantage in integrated battlefield data collection and management systems. These telecommunications assaults form part of a broader, persistent pattern of Russian strikes targeting Ukrainian digital connectivity, following similar infrastructure hits earlier in the month involving major operator Kyivstar and a severe data center strike back in July. Complicating the regional digital landscape further, a suspicious fire broke out late Wednesday at a Starlink ground station in central Poland operated by Exatel, damaging critical power infrastructure like generators and switchboards. Coupled with suspicious incidents like the recent fire at a Polish Starlink ground station, these events highlight a broader and growing risk that critical data centers across Europe are increasingly vulnerable to an ongoing covert Russian sabotage campaign in Europe that CYFIRMA covered in this report.

North Korean hackers steal $387 million from a Singaporean exchange

A major cryptocurrency exchange experienced a significant security breach, resulting in the theft of approximately $387.5 million from its hot and warm wallet systems. During an emergency town hall meeting, the exchange’s leadership disclosed that preliminary evidence, including operational patterns and on-chain signatures, strongly indicated potential involvement by state-sponsored North Korean hackers.

The incident came to light after blockchain security firms detected sudden and substantial outflows from the platform. The exchange’s security team promptly activated emergency response protocols as unauthorized transfers began moving funds out of its wallet infrastructure. Initial findings suggest that the attackers compromised a critical backend system, manipulating transaction data to bypass authorization mechanisms and execute fraudulent withdrawals. However, private keys and offline cold storage wallets reportedly remained uncompromised and secure.

The stolen assets included multiple cryptocurrencies, such as Ethereum, XRP, USD Coin, and several other digital tokens across various blockchain networks. Attribution experts and blockchain analysts identified similarities between the incident and previous large-scale cryptocurrency thefts associated with North Korean-linked threat groups, including operations historically linked to the theft of billions of dollars from the global cryptocurrency ecosystem.

ETLM Assessment:

As noted in this CYFIRMA report, Pyongyang has spent years systematically refining an ever-expanding toolkit to generate hard currency for its nuclear and ballistic-missile programs, which run the gamut from classic diplomatic cover and ship-to-ship transfers to aggressive cyber theft and, more recently, the large-scale deployment of highly skilled IT workers operating under false identities abroad. But it is cybercrime that has rapidly become a cornerstone of North Korea’s state survival.

4. Rise in Malware/Ransomware and Phishing

Qilin Ransomware Impacts an Electronics Manufacturing Company from Japan

  • Attack Type: Ransomware
  • Target Industry: Electronics Manufacturing
  • Target Geography: Japan
  • Ransomware: Qilin Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Japan was compromised by Qilin ransomware. The compromised company is a Japanese electronics manufacturer specialising in professional video and imaging technologies. The company develops and manufactures equipment used in broadcasting, medical imaging, security surveillance, video production, and industrial inspection. The ransomware attack reportedly resulted in the exposure of sensitive internal technical documents and engineering-related information, including broadcasting system design specifications, system architecture diagrams, equipment configuration details, technical drawings, operational documentation, system planning materials, and internal data tables. The leaked materials appear to contain detailed information about system infrastructure, component configurations, technical specifications, and project-related documentation, potentially exposing proprietary engineering knowledge and operational details. The total size of the compromised data is approximately 66 GB.

Source: Dark Web

Relevancy & Insights:

  • The Qilin Ransomware group operates a Ransomware-as-a-Service (RaaS) model, allowing affiliates to carry out attacks while Qilin provides infrastructure and malware
  • The Qilin Ransomware group primarily targets countries such as the United States of America, Germany, Canada, the United Kingdom, and France.
  • The Qilin Ransomware group primarily targets industries, including Professional Goods & Services, Manufacturing, Real Estate & Construction, Consumer Goods & Services, and Healthcare.
  • Based on the Qilin Ransomware victims list from 1stJan 2026 to 29th September 2026, the top 5 Target Countries are as follows:

  • The Top 10 Industries most affected by the Qilin Ransomware group victims list from 1st Jan 2026 to 29th September 2026 are as follows:

ETLM Assessment:

According to CYFIRMA’s assessment, Qilin ransomware poses a significant threat to organizations of all sizes. Its evolving tactics, including double extortion (data encryption and leak threats), cross-platform capabilities (Windows and Linux, including VMware ESXi), and a focus on speed and evasion, make it a particularly dangerous actor.

The Gentlemen Ransomware Impacts a Manufacturing Company from Thailand

  • Attack Type: Ransomware
  • Target Industry: Manufacturing
  • Target Geography: Thailand
  • Ransomware: The Gentlemen Ransomware
  • Objective: Data Theft, Data Encryption, Financial Gains
  • Business Impact: Financial Loss, Data Loss, Reputational Damage

Summary:

CYFIRMA observed on a ransomware data leak site (DLS) on the dark web that a company from Thailand was compromised by The Gentlemen Ransomware. The compromised company is a Thai-Japanese JV (founded 1990, HQ Samut Prakan/Bangkok) — the leading engineering-plastics distributor and fabricator in Thailand & Southeast Asia, importing materials from Japan and processing them locally: UHMW-PE, MC-Nylon, POM, PA6G, HDPE, PEEK, PVC-C, PVDF, PET, PTFE — sold as cut-to-size sheets/rods/tubes and CNC-machined custom parts for automotive, food & packaging, semiconductors, chemicals, oil & gas, robotics and water treatment across SEA. The compromised data includes confidential and sensitive information belonging to the organization.

Source: Dark Web

Relevancy & Insights:

  • The Gentlemen is a relatively highly sophisticated ransomware-as-a-service (RaaS) group that emerged in mid-2025.
  • The Gentlemen Ransomware group primarily targets countries such as the United States of America, France, Thailand, India, and
  • The Gentlemen Ransomware group primarily targets industries, including Manufacturing, Professional Goods & Services, Consumer Goods & Services, Information Technology, and Healthcare.
  • Based on the Gentlemen Ransomware victims list from 1stJan 2025 to 29th September 2026, the top 5 Target Countries are as follows:

  • The Top 10 Industries most affected by the Gentlemen Ransomware victims list from 1st Jan 2025 to 29th September 2026 are as follows:

ETLM Assessment:

According to CYFIRMA’s assessment, the Gentlemen Ransomware is a highly adaptive and globally active threat that leverages dual-extortion tactics, combining data theft with file encryption. The group employs advanced evasion and persistence techniques, supports cross-platform and scalable ransomware deployment, and conducts targeted attacks across multiple industries and geographic regions. This combination of capabilities makes it a significant risk to enterprise cybersecurity defenses, particularly for organizations with limited detection and incident-response maturity.

5. Vulnerabilities and Exploits

Vulnerability in CRI-O (Kubernetes)

  • Attack Type: Vulnerabilities & Exploits
  • Target Technology: Container Runtime / Kubernetes Infrastructure
  • Vulnerability: CVE-2026-92574
  • CVSS Base Score: 8 Source
  • Vulnerability Type: Execution with Unnecessary Privileges / Security Context Bypass
  • Summary: The vulnerability allows a remote attacker to compromise the target system

Relevancy & Insights: The vulnerability exists due to improper enforcement of the destination container’s security context during checkpoint restoration.

Impact: A remote user can gain elevated privileges on the system.

Affected Products:

  • https[:]//github[.]com/cri-o/cri-o/security/advisories/GHSA-pgj4-7h26-2r47

Recommendations:

  • Monitoring and Detection: Implement monitoring and detection mechanisms to identify unusual system behavior that might indicate an attempted exploitation of this vulnerability.

TOP 5 AFFECTED TECHNOLOGIES OF THE WEEK

This week, CYFIRMA researchers have observed significant impacts on various technologies due to a range of vulnerabilities. The following are the top 5 most affected technologies.

ETLM Assessment:

The vulnerability in CRI-O presents a significant security risk to organizations using affected versions in Kubernetes environments. The issue allows a user with permission to create a pod from a malicious checkpointed container image to bypass Kubernetes security context enforcement during container restoration. Successful exploitation could result in processes retaining credentials, Linux capabilities, and other security settings from the original checkpoint, potentially enabling execution with elevated privileges across the container security boundary. Organizations using affected CRI-O versions should prioritize applying the security updates provided by the respective vendors. Organizations should also review Kubernetes RBAC permissions, restrict checkpoint restoration functionality where unnecessary, and monitor suspicious pod creation and container restoration activities. Prompt remediation and continuous monitoring are recommended to reduce the risk of privilege escalation and unauthorized access to containerized workloads.

6. Latest Cyber-Attacks, Incidents, and Breaches

Krybit Ransomware attacked and published the data of a Construction company from India

  • Threat Actor: Krybit Ransomware
  • Attack Type: Ransomware
  • Objective: Data Leak, Financial Gains
  • Target Technology: Web Applications
  • Target Industry: Construction
  • Target Geography: India
  • Business Impact: Operational Disruption, Data Loss, Financial Loss, Potential Reputational Damage

Summary:

Recently, we observed that Krybit Ransomware attacked and published the data of a construction company from India on its dark web website. The compromised company is one of India’s largest civil construction and contracting companies, incorporated on November 2, 1979, headquartered in New Delhi, India, and listed on the National Stock Exchange (NSE). The company provides a comprehensive range of construction services, including civil and structural works, composite works, and finishing works for residential buildings, IT parks, metro stations and depots, commercial office spaces, automated car parking lots, power plants, retail centers, and hospitals, also executing Engineering, Procurement and Construction (EPC) projects and real estate development. It operates across multiple Indian states, including Karnataka, West Bengal, and Maharashtra through its subsidiaries. The compromised data appears to include identity and government records, such as national identification cards, tax or income-tax documents, passport-related information, photographs, signatures, dates of birth, residential addresses, handwritten forms, financial or salary-related records, account and transaction details, invoices, purchase or sales documents, and email correspondence containing personal and business information. The exposed material also includes scanned documents with QR codes, identification numbers, contact details, and other sensitive personally identifiable information (PII), creating risks of identity theft, financial fraud, phishing, impersonation, and further targeted attacks. The Total size of the compromised data is approximately 222.48 GB.

 

Source: Darkweb

Relevancy & Insights:

  • Krybit Ransomware is a financially motivated cybercriminal group that operates a dedicated data leak site (DLS) to extort victims by encrypting systems and threatening to publish stolen data unless a ransom is
  • The Krybit Ransomware group primarily targets industries, including Professional Goods & Services, Manufacturing, Government & Civic, Consumer Goods & Services, and Information Technology.

ETLM Assessment:

According to CYFIRMA’s assessment, Krybit represents a persistent, financially motivated Ransomware-as-a-Service (RaaS) and data extortion threat that leverages an opportunistic affiliate-driven operational model to maximize pressure on victims. Although the group functions via external threat actors incentivized by lucrative profit-sharing structures, its targeted deployment of custom malware suites across corporate environments highlights the critical importance of robust identity security, continuous network monitoring, timely vulnerability remediation, and rigorous data loss prevention measures to detect, contain, and mitigate potential ransomware extortion attacks.

7. Data Leaks

Unauthorized E-Commerce Customer Database Advertised on a Leak Site

  • Attack Type: Data Leak
  • Target Industry: E-Commerce and Retail
  • Target Geography: South Korea
  • Objective: Financial Gains
  • Business Impact: Exposure of Personally Identifiable Information (PII), Customer Data Disclosure, Identity Theft Risks, Phishing and Social Engineering Risks, Privacy Violations, Financial Loss, and Reputational Damage.

Summary

The CYFIRMA research team identified a post on a dark web forum advertising the sale of a large database allegedly originating from a South Korean e-commerce organization. According to the forum advertisement, the seller claims to possess more than 1 million unique customer records containing sensitive personally identifiable information (PII). The advertisement identifies the organization as an established online shopping platform involved in direct retail sales, third-party marketplace operations, and logistics services.

Based on the information shared in the forum post, the allegedly exposed database may contain the following information:

  1. Unique customer identification numbers (IDs)
  2. Customer email addresses
  3. Full names
  4. Phone numbers
  5. ZIP codes and postal information
  6. Residential and delivery addresses
  7. Structured customer database records
  8. Additional customer-related information

The authenticity of the allegedly exposed dataset remains unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums

Unauthorized Access to Philippine Government and Logistics Sector Systems Advertised on a Leak Site

  • Attack Type: Unauthorized Access / Data Compromise
  • Target Industry: Government and Logistics & Courier Services
  • Target Geography: Philippines
  • Objective: Financial Gains
  • Business Impact: Potential Exposure of Government Documents, User Credentials, Unauthorized Access to Critical Systems, Sensitive Information Disclosure, Operational Disruption, Regulatory Compliance Concerns, Financial Loss, and Reputational Damage.

Summary: The CYFIRMA research team identified a post on a dark web forum claiming unauthorized access to systems belonging to Philippine government and logistics-sector organizations. According to the forum advertisement, the seller claims to have obtained full access to multiple organizational environments, including a government institution responsible for national nutrition-related programs and a major logistics and courier service provider operating in the Philippines. The advertisement specifically highlights the availability of government documents and user credentials, suggesting potential exposure of sensitive organizational information and authentication-related data.

Based on the information shared in the forum post, the allegedly compromised information may include:

  • Government-related documents and administrative
  • User credentials and authentication
  • Sensitive organizational
  • Internal system access
  • Potentially exposed government and corporate
  • Additional information accessible through the allegedly compromised

The authenticity and extent of the alleged unauthorized access remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and has not been independently confirmed.

Source: Underground Forums

Relevancy & Insights:

Financially motivated cybercriminals are continuously looking for exposed and vulnerable systems and applications to exploit. A significant number of these malicious actors congregate within underground forums, where they discuss cybercrime and trade stolen digital assets. Operating discreetly, these opportunistic attackers target unpatched systems or vulnerabilities in applications to gain access and steal valuable data. Subsequently, the stolen data is advertised for sale within underground markets, where it can be acquired, repurposed, and utilized by other malicious actors in further illicit activities.

ETLM Assessment:

The threat actor is assessed as an active and capable cybercriminal entity primarily involved in data-leak and information-extortion activities, with multiple indications of unauthorized access to systems and the subsequent dissemination or sale of compromised data through underground forums. Their activities demonstrate the evolving sophistication of organized cybercriminal networks and highlight the increasing risk of sensitive information being exploited for financial gain, fraud, and follow-on attacks. Organizations should strengthen their cybersecurity posture through continuous monitoring, proactive threat intelligence, robust access controls, enhanced data protection, and timely defensive measures to safeguard sensitive information and critical infrastructure.

Recommendations:

Enhance the cybersecurity posture by:

  1. Updating all software products to their latest versions is essential to mitigate the risk of vulnerabilities being
  2. Ensure proper database configuration to mitigate the risk of database-related
  3. Establish robust password management policies, incorporating multi-factor authentication and role-based access to fortify credential security and prevent unauthorized access.

8. Other Observations

The CYFIRMA research team identified a post on a dark web forum advertising the alleged exposure of customer data belonging to an online financial trading and brokerage platform primarily focused on forex trading, while also offering access to commodities, indices, and cryptocurrency markets. According to the forum advertisement, the seller claims to possess a database containing sensitive customer information, including personal details and transaction-related records. The seller further alleges that the organization was involved in fraudulent activities and states that its website is currently shut down. However, these allegations have not been independently verified.

Based on the information shared in the forum post, the allegedly exposed dataset may contain the following information:

  • Customer email addresses
  • Full customer names
  • Transaction amounts
  • Country information
  • Customer transaction records
  • Transaction-related financial information
  • Customer identification details
  • Merchant customer identifiers
  • Transaction status and currency information

The authenticity and extent of the allegedly exposed dataset remain unverified at the time of reporting. This assessment is based solely on information published in the dark web forum advertisement and the accompanying screenshots and has not been independently confirmed.

Source: Underground Forums

RECOMMENDATIONS

 STRATEGIC RECOMMENDATIONS

  • Attack Surface Management should be adopted by organisations, ensuring that a continuous closed-loop process is created between attack surface monitoring and security testing.
  • Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation
  • Incorporate Digital Risk Protection (DRP) in the overall security posture that acts as a proactive defence against external threats targeting unsuspecting customers.
  • Implement a holistic security strategy that includes controls for attack surface reduction, effective patch management, and active network monitoring, through next-generation security solutions and a ready-to-go incident response
  • Create risk-based vulnerability management with deep knowledge about each asset. Assign a triaged risk score based on the type of vulnerability and criticality of the asset to help ensure that the most severe and dangerous vulnerabilities are dealt with first.

MANAGEMENT RECOMMENDATIONS

  • Take advantage of global Cyber Intelligence, providing valuable insights on threat actor activity, detection, and mitigation techniques.
  • Proactively monitor the effectiveness of risk-based information security strategy, the security controls applied, and the proper implementation of security technologies, followed by corrective actions, remediations, and lessons learned.
  • Consider implementing Network Traffic Analysis (NTA) and Network Detection and Response (NDR) security systems to compensate for the shortcomings of EDR and SIEM Solutions.
  • Ensure that detection processes are tested to ensure awareness of anomalous events. Timely communication of anomalies should be continuously evolved to keep up with refined ransomware threats.

TACTICAL RECOMMENDATIONS

  • Patch software/applications as soon as updates are Where feasible, automated remediation should be deployed since vulnerabilities are one of the top attack vectors.
  • Consider using security automation to speed up threat detection, improved incident response, increased visibility of security metrics, and rapid execution of security checklists.
  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs and strengthening defences based on the tactical intelligence provided.
  • Deploy detection technologies that are behavioral anomaly-based to detect ransomware attacks and help to take appropriate measures.
  • Implement a combination of security controls, such as reCAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP backlisting, Rate-limiting, and Account lockout to thwart automated brute-force attacks.
  • Ensure email and web content filtering uses real-time blocklists, reputation services, and other similar mechanisms to avoid accepting content from known and potentially malicious sources.

Situational Awareness – Cyber News

Please find the Geography-Wise and Industry-Wise breakup of cyber news for the last 5 days as part of the situational awareness pillar.

Geography-Wise Graph