| New Threats Detection Added | • Phantomcore |
| New Threat Protection | 110 |
| Newly Detected Threats | 7 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
Phantomcore | |||||||||||||||||||||
|
PhantomCore is a Windows-based backdoor malware and remote access trojan (RAT) linked to the Head Mare threat group targeting organisations in Russia. Phantomcore malware is often delivered using trojanised and unsigned software installers or exploiting vulnerable public facing applications. Once the malware is successfully installed, it steals information from the infected host and can remotely execute malicious commands.
Phantomcore also able to perform credential dumping LSASS memory to obtain user credentials. This can also establish its persistence by malicious code in registry-based COM CLSID ensuring that will remain in its connection even after rebooting the system. Phantomcore also utilises legitimate Microsoft OneDrive account to move the stolen data by dropping a second backdoor, PhantomGraph.
|
||||||||||||||||||||||
|
Threat Protected:
|
20 | |||||||||||||||||||||
|
Rule Set Type:
|
|
|||||||||||||||||||||
|
Class Type:
|
Domain-c2 | |||||||||||||||||||||
|
Kill Chain:
|
|
|||||||||||||||||||||
Known Exploited Vulnerabilities (Week 3 - August 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-3rd-week-of-august-2026/685.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
8.6
|
Unauthenticated DoS - Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that can allow an unauthenticated remote attacker to create a denial-of-service condition when sending a specially crafted HTTP request, successful exploitation can cause the device to reload unexpectedly.
|
Check vendor advisory for affected products and versions.
|
|||
|
7
|
Privilege Escalation - Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that can allow an authenticated local attacker to escalate to SYSTEM level privileges.
|
Check vendor advisory for affected products and versions.
|
|||
|
10
|
Unauthenticated SQL Injection - Metabase contains an SQL Injection vulnerability that can allow an unauthenticated remote attacker to inject arbitrary SQL into the application, resulting in the exposure of sensitive information and can allow an attacker to gain access to the system.
|
Check vendor advisory for affected versions.
|
|||
Updated Malware Signature (Week 3 - August 2026)
|
Threat
|
Description | |
|
XWorm V3
|
XWorm V3 is a .Net-based Remote Access Trojan (RAT) targeting mainly Windows systems. This malware commonly known for credential theft, records screens, captures keystrokes and accesses webcams and microphones for surveillance. This also communicates using encrypted C2 communications for malware deployment.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Clop was the most active ransomware group, impacting 43 countries, which accounted for 17.55% of the total ransomware hits. This made Clop the leading ransomware actor during the reporting period. Crpx0 recorded the second-highest activity, affecting 41 countries and contributing 16.73% of the total ransomware activity. Qilin and The Gentlemen followed, each impacting 33 countries and representing 13.47% individually. A notable level of activity was observed from LeakedData, which affected 14 countries, accounting for 5.71% of total ransomware hits. Inc Ransom impacted 8 countries, contributing 3.27%, while Krybit and Akira each affected 6 countries, representing 2.45% individually. Moderate ransomware activity was observed from RansomHouse, Payload, Direwolf, and Coinbase Cartel, each impacting 4 countries, accounting for 1.63% individually. Panzer, Play, Storm, Ethics, and Global Secret Group each affected 3 countries, contributing 1.22% individually. Several ransomware groups showed lower activity, impacting 2 countries each. These included Unsafe, Space Bears, Wallstreet, Settra, Genesis, DragonForce, Interlock, Ailock, Rhysida, and Bluewhale, each accounting for 0.82% of the total activity. The remaining ransomware groups, including Sovcali, Bravox, Aurora, Anubis, PayoutsKing, Deadlock, Kairos, Nightspire, M3rx, and SafePay, each impacted 1 country, representing 0.41% individually. Overall, ransomware activity last week was primarily driven by Clop, Crpx0, Qilin, and The Gentlemen, which together accounted for a significant share of global ransomware activity. The presence of multiple high-volume ransomware groups alongside smaller emerging operators highlights the continued expansion and diversification of the ransomware threat landscape. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 119 victims, accounting for 48.57% of the total ransomware activity. This indicates that nearly half of all reported ransomware victims were located in the United States, making it the primary target region during this period.
The United Kingdom recorded the second-highest number of victims, with 14 cases, representing 5.71% of the total. Türkiye followed with 11 victims, contributing 4.49%, while Italy reported 9 victims, accounting for 3.67% of overall ransomware activity.
Other countries with notable ransomware impact included Canada, with 8 victims, representing 3.27%, and India, with 7 victims, contributing 2.86%. Germany and Australia each recorded 6 victims, accounting for 2.45% individually.
Moderate ransomware activity was observed in Taiwan, with 5 victims, representing 2.04%. Countries including China, Japan, Switzerland, Netherlands, and Brazil each reported 4 victims, contributing 1.63% individually.
Several countries recorded lower but notable activity, including Singapore, Thailand, Mexico, Finland, and Qatar? with 3 victims each, representing 1.22% individually. France, Philippines, Romania, Greece, Austria, and South Korea each recorded 2 victims, accounting for 0.82% individually.
The remaining countries recorded 1 victim each, accounting for 0.41% individually. These included Nigeria, Chile, Peru, Belgium, Agriculture, Israel, Argentina, Pakistan, Qatar, Saudi Arabia, Bahamas, Hungary, Poland, Jordan, Vietnam, Morocco, and Spain.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 44 victims, accounting for 17.96% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 39 cases, representing 15.92% of the total. Retail followed with 24 victims, contributing 9.80%, while IT accounted for 19 victims, representing 7.76% of overall ransomware activity.
The Law Firms sector also experienced significant impact, with 18 victims, accounting for 7.35%. Healthcare recorded 17 victims, contributing 6.94%, highlighting continued targeting of sectors handling sensitive information and critical services.
Moderate ransomware activity was observed in Construction and Finance, each reporting 13 victims, representing 5.31% individually. Organisations recorded 8 victims, accounting for 3.27%, while Hospitality and Architecture each reported 6 victims, contributing 2.45% individually.
Lower levels of ransomware activity were observed in Transportation and Energy, each with 5 victims, representing 2.04% individually. Education, Real Estate, Electronics, Federal, Insurance, and Agriculture each recorded 4 victims, accounting for 1.63% individually.
The least affected sectors included Media & Internet, with 2 victims, representing 0.82%, and Telecommunications and United Kingdom, each recording 1 victim, accounting for 0.41% individually.

Ransomware Group in Focus
BlueWhale Ransomware
Threat Actor Description
BlueWhale (also styled “Bluewhale”, “BLUEWHALE”) was first indexed by public trackers on 14 August 2026. It is classified as a new group with no established lineage to any known family - although with no sample available, no code, infrastructure, or ransom-note comparison has been possible. [1][2]
Operating model: a closed data-leak and extortion operation running a single Tor leak site on a name-and-shame basis, threatening publication unless the victim makes contact. There is no evidence of a ransomware-as-a-service affiliate programme, affiliate recruitment, auction mechanism, or tiered pressure tactics. [1][2]
Infrastructure and contact: one Tor onion address, currently down and averaging approximately 33% uptime over thirty days - a single unreliable mirror with no redundancy. Contact is a single ProtonMail address. No cryptocurrency wallet, Telegram, Tox, Session or jabber handle is attributable to the group, and no administrator persona has been identified beyond the mailbox local-part. [2]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
No forensic, incident-response, or sample-based evidence exists for this actor, so nothing can be marked confirmed. Only two techniques can be assessed at all, both inferred from leak-site posts. The remainder of the kill chain is genuinely unknown - recorded as such rather than populated with cohort assumptions. [1][2]
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Impact
|
T1657
|
Financial Theft/Data Extortion
|
Victims named on a Tor leak site with threatened publication unless contact is made. The only directly observable behaviour. [1][2]
|
|
Exfiltration
|
T1567
|
Exfiltration Over Web Service
|
Claimed data volumes of 1.2 GB and 1.5 GB imply small-scale data theft; method and channel undocumented. [1]
|
|
Initial Access
|
-
|
Unknown
|
No evidence of infostealer credentials, phishing, exposed RDP/VPN, or exploitation. Vector entirely undetermined.
|
|
Command & Control
|
-
|
Unknown
|
No C2 infrastructure attributable to this actor.
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
NOT evidenced - no encryptor exists. Aggregator wording implying encryption is templated and unverified. [3]
|
Attack Lifecycle
Only the final stages of a conventional lifecycle are observable. Everything from initial access through collection is unevidenced and is recorded here as a gap rather than reconstructed from assumption. [1][2]
1. INITIAL ACCESS THROUGH COLLECTION - Unevidenced
No information exists on how BlueWhale obtains access, what tooling it uses, or how it operates inside a victim environment. Given the profile of the two claimed victims - a recreational game server and an individual developer’s machine - opportunistic compromise of a poorly secured internet-facing host is plausible, but this is inference from target profile alone and is not evidence. [1]
2. EXFILTRATION - Small-Scale Data Theft
Claimed volumes are small - 1.2 GB and 1.5 GB - consistent with the theft of a limited dataset from a single host rather than an enterprise-scale collection operation. The exfiltration channel is undocumented. [1].
3. IMPACT - Publication and Extortion (no encryption evidenced)
Victims are listed on the Tor leak site with the threat of publication. Each post carries two attacker-supplied numeric fields whose meaning is unconfirmed - plausibly a demand figure and a countdown in days, but this should not be reported to clients as established. No encryption or impact on availability has been evidenced. [2]
Observable artefacts: Client organisation or an individual developer host appearing on the BlueWhale leak site; extortion contact from the ProtonMail address below; outbound Tor connectivity.
Mitigation - Crystal Eye Controls
Given an actor with no encryptor and no host-based indicators, the operative measures are exposure reduction, control of data movement, and disciplined verification of claims. The controls below are described by what they contribute against this class of threat.
CE Advanced Firewall
The foundation the rest of the stack sits on. Dividing the estate into security zones bound to interfaces limits how far any single compromise can reach, and traffic rules determine what is allowed, rejected or blocked between them.
CE Intrusion Protection & Detection
Inspects traffic against rulesets authored by Red Piranha’s security operations team and delivered through the service delivery network
CE IDPS Local Rules
Allows detection content to be written for campaign-specific indicators - defining protocol, source and destination objects, inspection direction and content match, with Alert, Reject, Drop or Pass actions.
CE Forcefield
Automatically blocks traffic to and from hosts on reputation lists sourced from the service delivery network, cutting off known-bad infrastructure without manual rule writing.
CE Protocol Filter
Blocks protocols across the network by traffic content, port and type, making it the appropriate control for closing anonymised and consumer file-sharing channels used to move stolen data. It is not installed by default and must be added from the Marketplace; where a block should apply only to selected traffic, use an Advanced Firewall traffic rule instead.
CE Data Loss Protection
The most directly relevant control against a data-leak actor. It operates in two ways: it detects structured personal data - credit card and social security number formats - above an administrator-defined count threshold on transfer over the WAN, with an Alert or Reject action; and it monitors movement of specific confidential files uploaded to the Sensitive File List, reporting timestamp, filename, source and destination address, country, HTTP referrer and file size.
CE Vulnerability Scanning
Identifies exposed and unpatched internet-facing systems and remote-access services before an attacker or access broker finds them, scheduled through the Task Scheduler and extendable to custom ports and container-host scanning.
CE Threat Hunt and Alert AI Analysis
Supports proactive review rather than waiting on alerts. The events logged per IDPS profile determine what is available to hunt through, and anomaly alerts are classified with administrator feedback used to refine the model - the mechanism by which alert noise is reduced without simply suppressing signatures.
CE SIEM
Consolidates events from the Advanced Firewall, IDPS, gateway antivirus, Data Loss Protection and endpoints into a single correlated view analysed by Red Piranha’s security operations team, allowing a coordinated intrusion to be identified from activity that appears inconsequential in isolation.
Indicators of Compromise (IOCs)
IOC availability: No encryptor binary, file hash, encrypted-file extension, ransom-note filename, mutex, YARA or Sigma rule, or command-and-control indicator is publicly attributable to BlueWhale across MalwareBazaar, VirusTotal, ANY.RUN, Triage, Malpedia, Hybrid Analysis or JoeSandbox, and none appears in any STIX or TAXII feed. no indicators from other families have been substituted.
Available Indicators
|
Type
|
Indicator (defanged)
|
|
Tor DLS (onion)
|
bluewh6bk2qt6wjib7qxdtplhgbwbi3p7cgofwnshfl5xo3xgwgstrid[.]onion
|
|
Contact email
|
samueladamsn344@proton[.]me
|
References
All intelligence is directly sourced from the references below. Tracker and aggregator sources index the operator’s own unverified claims and are cited for situational awareness only; a leak-site listing does not constitute a confirmed breach.
[1] Ransomware.live - BlueWhale victim records - https://ransomware.live/id/RmlmZXJGb3ggTWluZWNyYWZ0IFNlcnZlckBCbHVlV2hhbGU=.
[2] RansomLook - Bluewhale group profile - https://www.ransomlook.io/group/bluewhale.
[3] Hendryadrian - BlueWhale claim mirrors - https://www.hendryadrian.com/ransom-satellite-developer-server-aug-2026/. Automated mirror of the same claims; source of the unverified templated wording describing the actor as deploying encrypting ransomware.