| New Threats Detection Added | • Lumma Stealer • SocGholish |
| New Threat Protection | 122 |
| Newly Detected Threats | 8 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
Lumma Stealer | ||||||||||||||||||
|
Lumma Stealer is a malicious software known for stealing information. This is designed to collect and gather sensitive data from infected machines. This primarily collects browser credentials, session cookies, cryptocurrency wallets, and MFA tokens. This stolen information is being exfiltrated to a command-and-control (C2) infrastructure that allows the attacker to conduct account takeovers, commit fraud, and to further compromise the network. Lumma Stealer is being distributed through phishing emails, malicious downloads, fake installers, and even compromised websites.
Lumma Stealer was able to recover after a major law enforcement disruption in 2025 and remains one of the most active infostealers by rebuilding its infrastructure and deploying stealthier delivery methods.
|
|||||||||||||||||||
|
Threat Protected:
|
26 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Domain-c2 | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Known Exploited Vulnerabilities (Week 5- August 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-5th-week-of-august-2026/693.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
9.8
|
Authentication Bypass - ownCloud contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to access files on the system.
|
10.6.0 - 10.13.0
|
10.13.1
|
||
|
7.8
|
Privilege Escalation - Linux Kernel contains a vulnerability within the IPv6 networking subsystem that can allow an attacker to escalate to root level privileges.
|
Check vendor advisory for affected products and versions.
|
|||
|
5.3
|
Path Traversal - JFrog Artifactory contains a path traversal vulnerability that can allow an authenticated attacker to write data outside the intended Docker cache path.
|
<= 7.146.34
|
7.146.35
|
||
|
8.1
|
Unauthenticated RCE - Ajax.NET Professional (AjaxPro) contains a deserialisation vulnerability that can allow an unauthenticated remote attacker to execute code via arbitrary .NET classes.
|
End-of-Life
|
N/A |
||
|
5.1
|
Privilege Escalation - Red Hat libuser contains a race condition vulnerability that can allow an authenticated local attacker to escalate their privileges through modification of the '/etc/passwd' file.
|
Check vendor advisory for affected products and versions.
|
|||
|
7.8
|
Privilege Escalation - Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that can allow an attacker with local access to escalate their privileges root via symlinks.
|
Check vendor advisory for affected products and versions.
|
|||
|
7.8
|
Privilege Escalation - Linux Kernel contains an out-of-bounds write vulnerability that can allow an attacker with local access to elevate their privileges to root.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Unauthenticated RCE - Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that can allow an attacker execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Authenticated RCE - Microsoft SQL Server contains a stack overflow vulnerability that can allow an authenticated attacker to execute code on the system in the context of the SQL Server Database Engine service account.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Unauthenticated RCE - Gitea contains a code execution vulnerability that can allow an unauthenticated remote attacker to execute arbitrary operating system commands on the system via Git hooks.
|
1.17.0 - 1.27.0
|
1.27.1
|
||
|
10
|
Authentication Bypass - Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
ICS Advisories
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
8.7
|
Insufficiently Protected Credentials - Rently Smart Home contains a vulnerability that can allow an attacker to receive pins including the Master Pin, which can result in the overriding of standard user permissions. CISA ICS Advisory: ICSA-26-237-01
|
<= 20.1.0
|
Check vendor advisory for affected products and versions.
|
||
|
8.7
|
Command Injection - ZoneMinder contains a command injection vulnerability that can allow an authenticated remote attacker to execute operating system commands on the system. CISA ICS Advisory: ICSA-26-237-02
|
1.37.48 < 1.38.3
|
1.38.3
|
||
|
10
|
Unauthenticated Remote Code Execution - Siemens SIMATIC IoT2050 Advanced contains a vulnerability that can allow an unauthenticated remote attacker to execute arbitrary code with maximum privileges via the Node-RED HTTP interface, which can result in complete system compromise. CISA ICS Advisory: ICSA-26-237-03
|
< V4.3.4.1 (with Node-RED installed)
|
V4.3.4.1
|
||
|
8.8
|
Missing Authorisation - PayRange API contains a vulnerability that can allow an unauthenticated remote attacker to enumerate, modify, or delete device configurations, which can result in unauthorised control of connected devices.
CISA ICS Advisory: ICSA-26-237-04 |
Check vendor advisory for affected products and versions.
|
|||
|
7.7 / 7.1 / 5.3
|
Multiple Vulnerabilities - Bendix EC80 Brake ECU contains multiple vulnerabilities that can allow a remote attacker to execute arbitrary code, inject arbitrary CAN bus traffic, and disable automatic traction control, which can result in loss of ABS, steering assist, speedometer, and shifting. CISA ICS Advisory: ICSA-26-237-05
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Multiple Vulnerabilities - Ebyte NE2-D11 contains multiple vulnerabilities that can allow an unauthenticated remote attacker to gain administrative access, disclose sensitive information, modify device configuration, and hijack authenticated sessions, which can result in full device compromise. Additional vulnerabilities are documented in the linked advisory.
CISA ICS Advisory: ICSA-26-237-06 |
Firmware FW-9167-0-11
|
N/A
|
||
|
9.1/7.5
|
Multiple Vulnerabilities - Furuno FA-50 Class B AIS Transponder contains multiple vulnerabilities that can allow an attacker with network access to alter device settings without valid credentials, which can result in unauthorised modification of device settings. CISA ICS Advisory: ICSA-26-237-07
|
All versions
|
End-of-Life
|
||
|
7.1
|
Improper Enforcement of Message Integrity - Mitsubishi Electric CC-Link IE TSN contains a vulnerability that can allow an attacker with network access to tamper with control I/O values, which can result in denial-of-service or incorrect operation. CISA ICS Advisory: ICSA-25-128-03
|
Multiple CC-Link IE TSN products (all versions)
|
Check vendor advisory for affected products and versions.
|
||
|
5.9
|
Denial of Service - Mitsubishi Electric CNC Series contains a vulnerability that can allow a remote attacker to cause a denial-of-service condition on the CNC controller.
CISA ICS Advisory: ICSA-26-078-05 |
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Multiple Vulnerabilities - Xiiaozet LK100W contains multiple vulnerabilities that can allow an unauthenticated remote attacker to execute operating system commands and bypass authentication, which can result in full control over the device. CISA ICS Advisory: ICSA-26-239-01
|
< 2.1.240
|
2.1.240
|
||
|
6.8
|
Weak Password Hashing - Rockwell Automation OTTO Fleet Manager contains a vulnerability that can allow an attacker to perform offline brute-force attacks against stored password hashes, which can result in unauthorised account access.
CISA ICS Advisory: ICSA-26-239-03 |
<= V2.36.2
|
Check vendor advisory for affected products and versions.
|
||
|
9.8
|
Multiple Vulnerabilities - Applied Systems Engineering ASE2000 V2 contains multiple vulnerabilities that can allow an attacker to intercept and modify protected communications and perform arbitrary file read and write operations, which can result in compromise of sensitive data and system integrity. CISA ICS Advisory: ICSA-26-239-04
|
2.25 to 2.37
|
2.38
|
||
|
9.8
|
Multiple Vulnerabilities - Ebyte NA111-M contains multiple vulnerabilities that can allow an unauthenticated remote attacker to gain administrative access, disclose sensitive information, and compromise device integrity, which can result in full device compromise. Additional vulnerabilities are documented in the linked advisory. CISA ICS Advisory: ICSA-26-239-05
|
Firmware 9013-2-17
|
Check vendor advisory for affected products and versions.
|
||
|
8.7
|
Multiple Vulnerabilities - All-Line Equipment Company Fuel-Boss contains multiple vulnerabilities that can allow a remote attacker to execute arbitrary commands or code via argument injection and buffer overflow, which can result in unauthorised system access. CISA ICS Advisory: ICSA-26-239-02
|
V1 Standard/Portal/Master/Slave/Backflush
|
Check vendor advisory for affected products and versions.
|
||
Updated Malware Signature (Week 5 - August 2026)
|
Threat
|
Description | |
|
MakinoLoader
|
MakinoLoader is a malware loader used to establish initial access on the compromised devices. Once infected, it will download additional malicious payloads such as info-stealers or ransomware while maintaining communication with C2 server for additional malicious payload delivery and execution.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Qilin was the most active ransomware group, impacting 39 countries, which accounted for 22.67% of the total ransomware hits. This made Qilin the leading ransomware actor during the reporting period. Coinbase Cartel recorded the second-highest activity, affecting 16 countries and contributing 9.30% of the total ransomware activity. Krybit followed with 13 countries impacted, representing 7.56%, while Akira affected 12 countries, accounting for 6.98% of overall ransomware hits. A moderate level of activity was observed from Lockbit5, which impacted 7 countries, contributing 4.07% of total activity. The Crew, Dark Project, and Chaos each affected 6 countries, representing 3.49% individually. The Gentlemen impacted 5 countries, accounting for 2.91%. Several ransomware groups showed similar levels of activity. Emperador, ShinyHunters, Inc Ransom, Booba Team, and DragonForce each impacted 4 countries, contributing 2.33% individually. Pear and Rhysida each affected 3 countries, representing 1.74% individually, while Global Secret Group and Deadlock also contributed 1.74% with 3 countries impacted each. Groups with lower activity included Space Bears, L Group, Arcus Media, SafePay, Beast, Direwolf, Eclipse, Aurora, Ailock, and Black X, each affecting 2 countries, accounting for 1.16% individually. The remaining ransomware groups, including Nightspire, Termite, Genesis, Blackwater, Panzer, Majinahanashi, Abyss-Data, Money Message, Unsafe, and Anubis, each impacted 1 country, representing 0.58% individually. Overall, ransomware activity last week was heavily driven by Qilin, Coinbase Cartel, Krybit, and Akira, which together accounted for a significant portion of global ransomware activity. The continued activity from multiple ransomware operators demonstrates the evolving and fragmented nature of the threat landscape, with both major groups and smaller emerging actors actively targeting organisations worldwide. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 71 victims, accounting for 41.28% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing more than two-fifths of all reported ransomware incidents.
The United Kingdom recorded the second-highest number of victims, with 11 cases, contributing 6.40% of the total. Germany followed with 9 victims, accounting for 5.23%, while Italy recorded 8 victims, representing 4.65% of overall ransomware activity.
Other countries with notable ransomware impact included Brazil, with 7 victims, contributing 4.07%, and Argentina, Canada, and India, each reporting 4 victims, representing 2.33% individually. Indonesia and Mexico each recorded 3 victims, accounting for 1.74% individually.
Moderate ransomware activity was observed across several countries, including China, Philippines, Portugal, Czechia, Chile, United Arab Emirates, Myanmar, Romania, Malaysia, Netherlands, South Africa, and Australia, each recording 2 victims, representing 1.16% individually.
The remaining countries recorded 1 victim each, accounting for 0.58% individually. These included Nam, Israel, Zealand, France, Longhorn Investments, Jamaica, Qatar, Spain, Switzerland, Serbia, Russian Federation, Bolivia, South Korea, Egypt, Thailand, Gabon, Guatemala, Viet Nam, Gill Rock Drill Company Inc., Türkiye, Belgium, Singapore, Vietnam, and Finland.
Overall, the data shows that ransomware activity was heavily concentrated in the United States, which accounted for a significant share of global victims. However, the presence of victims across North America, Europe, Asia-Pacific, the Middle East, Africa, and South America highlights the continued global reach of ransomware operations and the ongoing targeting of organisations across diverse regions.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Business Services was the most affected sector, with 29 victims, accounting for 16.86% of total ransomware activity. This makes Business Services the primary target industry during this period.
Manufacturing recorded the second-highest number of victims, with 27 cases, representing 15.70% of the total. The Healthcare sector followed with 18 victims, contributing 10.47%, while Finance and IT each recorded 17 victims, accounting for 9.88% individually.
Retail reported 12 victims, representing 6.98% of overall ransomware activity. Agriculture and Construction each recorded 9 victims, contributing 5.23% individually. Transportation accounted for 8 victims, representing 4.65% of the total activity.
Moderate ransomware activity was observed in Federal, with 5 victims, accounting for 2.91%. Hospitality and Architecture each reported 4 victims, contributing 2.33% individually.
Lower levels of ransomware activity were observed in Energy and Education, each recording 3 victims, representing 1.74% individually. Real Estate and Law Firms each reported 2 victims, accounting for 1.16% individually.
The least affected sectors were Organisations, Consumer Services, and Insurance, each recording 1 victim, representing 0.58% of the total ransomware activity.
Overall, the data shows that ransomware activity was primarily concentrated in Business Services, Manufacturing, Healthcare, Finance, and IT sectors. These industries accounted for the majority of reported victims, highlighting continued attacker focus on sectors with critical operations, valuable information assets, and significant potential impact from service disruption.

Ransomware Group in Focus
Emperador Ransomware
Origin and Profile
Emperador (styled “emperador” on its leak site) is a newly emerged ransomware-as-a-service (RaaS) operation first observed in early-to-mid August 2026. ransomware.live added the group to its tracker on 12 August 2026, and its first claimed victim - the City Government of Baguio in the Philippines - was posted with an estimated attack date of 10 August 2026. On or around 14 August 2026, the group published a recruitment announcement on the Dread cybercrime forum presenting itself as a RaaS and actively soliciting affiliates, pentesters, and initial access brokers (IABs), with the announcement independently flagged by dark-web monitoring researchers the same week. [1][2][11][12]
Operating Model and Infrastructure
Emperador operates a single Tor v3-based data-leak site branded “EMPERADOR - Leaks of Shame”, which RansomLook recorded at 100% uptime over the preceding 30 days. Inspection of the scraped site source confirms a static, custom-built site with Features, Join, and Contact pages alongside the victim blog - consistent with the RaaS self-presentation - and no embedded chat, file-store, or admin endpoints exposed to the public parser. Victim posts follow a consistent template: a victim profile, a red countdown timer, a scheduled publication date, claimed data volume, sector tags, and proof-of-possession screenshots. A “To Publish” mechanism stages releases 7–14 days after listing, and the site includes a price field - visible on a 22 August “Test” post displaying a USD 1,000,000 figure - indicating that direct data sales sit alongside classic name-and-shame extortion in the group’s model. [2]
Capability and Sophistication Assessment
Sophistication is assessed as a LOW to LOW-MODERATE, with the upper bound contingent on claims the group has not yet substantiated. The recruitment advertisement describes a custom Rust encryptor with Windows and Linux builds, a sub-1 MB payload, and per-victim affiliate tooling. [1][4][9][11].
Tactics, Techniques, and Procedures (TTPs)
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Resource Development
|
T1583.006
|
Acquire Infrastructure: Web Services
|
Tor v3 leak site and Dread recruitment presence directly observable HIGH confidence. [2][11][12]
|
|
Resource Development
|
T1588.002
|
Obtain Capabilities: Tool
|
Recruitment claims of a custom Rust encryptor with Windows/Linux builds and an affiliate build panel. [11][12]
|
|
Collection
|
T1074
|
Data Staged
|
Reporting aggregates stage-and-collect behaviour ahead of publication [4]
|
|
Exfiltration
|
T1567
|
Exfiltration Over Web Service
|
Multi-hundred-GB theft claims (300 GB EVNHANOI; 12 GB Hanwha). Actor assertion; channel undocumented. LOW confidence. [2][4][5]
|
|
Exfiltration
|
T1537
|
Transfer Data to Cloud Account
|
Reported in aggregated tradecraft tracking; no primary evidence. LOW confidence. [4]
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
Claimed verbatim in the Arcos post. LOW confidence. [4][5][11]
|
|
Impact
|
T1657
|
Financial Theft/Data Extortion
|
Leak-site publication threats, countdown timers, staged release, direct data sale, and messenger negotiation. [1][2]
|
|
Initial Access
|
T1078
|
Valid Accounts
|
Credential-driven access plausible. LOW confidence. [1][11]
|
Attack Lifecycle
Only the collection-through-extortion stages carry any evidence, and most of that rests on the actor’s own claims. Initial access through lateral movement is unevidenced and is recorded as a gap rather than reconstructed from assumption. [2][4]
Initial Access through Lateral Movement - Unevidenced
No information exists on how Emperador obtains access or operates inside a victim environment. The recruitment post’s explicit solicitation of initial access brokers indicates purchased access is an intended vector by design. Tracker enrichment shows significant prior infostealer exposure against at least two victim domains - 1,201 compromised employees, 1,809 compromised users and 50 third-party credentials at EVNHANOI, and 1 compromised employee, 11 compromised users and 3 third-party credentials at revealdata.com - which makes credential-driven access a plausible vector, but this is contextual exposure data rather than evidence of the intrusion path. [1][11]
Collection and Exfiltration - Large-Scale Data Theft (claimed)
Claimed hauls range from 18 MB (NetExam) to 300 GB (EVNHANOI), with the Hanwha post describing curated per-project archives containing PPAs, financial models, interconnection agreements, engineering designs, budgets, and PII. [2][5][6]
Impact - Publication, Sale, and (claimed) Encryption
The default impact pattern is leak-site publication under a countdown timer with staged proof-of-possession screenshots and a scheduled release date 7–14 days out, combined with direct negotiation over Session or Tox. [2][5][11]
Mitigation - Crystal Eye Controls
CE Advanced Firewall
The foundation the rest of the stack sits on. Dividing the estate into security zones bound to interfaces limits how far any single compromise can reach, and traffic rules determine what is allowed, rejected or blocked between them. The firewall is also where traffic is directed to the IDPS or Web Filter for inspection.
CE IDPS Local Rules
Allows detection content to be written for campaign-specific indicators - defining protocol, source and destination objects, inspection direction and content match, with Alert, Reject, Drop or Pass actions.
CE Web Filter and Anti-phishing
Addresses delivery, the cheapest point at which to stop an attack. The Anti-phishing engines - Signature, Heuristic, Block SSL Mismatch and Block Cloaked URLs - block phishing and cloaked destinations, while blacklists, banned sites, MIME types and file extensions block malicious infrastructure and payload types.
CE Antivirus and Antimalware File Scanner
Signature and heuristic classification at the gateway, blocking known-malicious files before they reach endpoints, with the Gateway Scan Report providing the daily view of what was blocked and why. Relevant here on two axes: first, the infostealer families whose logs feed credential-driven intrusion; second, the advertised Emperador encryptor itself - a sub-1 MB Rust-compiled binary.
CE Forcefield
Automatically blocks traffic to and from hosts on reputation lists sourced from the service delivery network, cutting off known-bad infrastructure without manual rule writing.
Indicators of Compromise (IOCs)
IOC Availability - Verified Negative Findings
As of 31 August 2026, an expanded sweep across public malware and threat-intelligence platforms returns no Emperador sample, file hash, family entry, ransom note, encrypted-file extension, mutex, YARA or Sigma rule, command-and-control indicator, or cryptocurrency wallet. [1][2][4][9]
Confirmed Indicators - Infrastructure and Contact
The confirmed indicator set is limited to the group’s own infrastructure, contact channels, and page structure. All onion indicators are v3 addresses; access them only through a properly isolated Tor research environment, never operationally.
|
Type
|
Indicator (defanged)
|
|
Tor DLS v3 (onion)
|
emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad[.]onion
|
|
Dread recruitment post (onion)
|
dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/496b4ea429cf08
b3514b |
|
Session ID
|
054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608
|
|
Tox ID
|
852E34CBEBA2D40FD21BAC9F9E588B5194DBA9F31CACF9ECE316403120BE18765D22A8A453C4
|
References
All intelligence is directly sourced from the references below. Tracker and aggregator sources index the operator’s own unverified claims and are cited for situational awareness only; a leak-site listing does not constitute a confirmed breach.
[1] Ransomware.live
[2] RansomLook - Emperador group profile, post archive, leak-site monitoring, scraped site source, and wallet-tracking API (negative finding) - https://www.ransomlook.io/group/emperador
[3] Breachsense - EMPERADOR group profile and victim index - https://www.breachsense.com/ransomware-groups/emperador/
[4] Mallory.ai - emperador threat-actor profile (victimology, MITRE ATT&CK aggregation, observables) - https://mallory.ai/actors/019ff696-8b71-76be-ae3b-5a37071ca975
[5] DeXpose - Emperador incident alerts (NetExam; Prefeitura Municipal de Arcos; EVNHANOI) - https://www.dexpose.io/emperador-ransomware-strikes-vietnam-electricity-evnhanoi/
[6] HookPhish - Emperador incident alerts (FRUCASTRO SL; Capitol Mechanics; Hanwha Renewables; Uniguacu) - https://www.hookphish.com/blog/ransomware-group-emperador-hits-hanwha-renewables/
[7] Inquirer - “Digital advocates seek probe into alleged Baguio ransomware attack”, 15 Aug 2026 - https://newsinfo.inquirer.net/2284994/digital-advocates-seek-probe-into-alleged-baguio-ransomware-attack
[8] Digital Pinoys - statement on the Baguio BUILDPass incident - https://digitalpinoys.org/digital-pinoys-urges-investigation-into-baguio-ransomware-attack/
[9] Malpedia (Fraunhofer FKIE) and MalwareBazaar/abuse.ch - negative findings for Emperador family entries and samples - https://malpedia.caad.fkie.fraunhofer.de/ ; https://bazaar.abuse.ch/browse/
[10] Breachsense - July 2026 ransomware monthly report (ecosystem context) - https://www.breachsense.com/ransomware-reports/july-2026/
[11] Devel Group - “Nuevo Ransomware ‘Emperador’ anuncia operaciones y publica su primera víctima”, 14 Aug 2026 (Dread RaaS announcement; Rust encryptor claims; targeting rules; IOCs) - https://devel.group/blog/nuevo-ransomware-emperador-anuncia-operaciones-y-publica-su-primera-victima/
[12] DarkWebInformer - dark-web monitoring post corroborating the Emperador Dread announcement and leak site, Aug 2026 - https://x.com/DarkWebInformer/status/2087965818151661741