| New Threats Detection Added | • Shai-Hulud |
| New Threat Protection | 69 |
| Newly Detected Threats | 6 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
Shai-Hulud | ||||||||||||||||||
|
Shai-Hulud is a self-propagating supply chain worm that focuses on Node.js (NPM) ecosystems, GitHub repositories, developer workstations and CI/CD pipelines. It exploits pipeline dependencies to poison the supply chain by publishing malicious packages, compromising, and abusing trusted NPM packages allowing the execution of malicious code during package installation.
The latest variant of Shai-Hulud uses a pre-install script that executes prior to the package installation. Once infected, it has the capabilities to steal credentials, access tokens, source code and can automatically propagate throughout other packages the compromised account has access to, which can result in the infection and publishing of additional malicious installation packages and source code from private repositories.
|
|||||||||||||||||||
|
Threat Protected:
|
02 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Command-and-Control | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Known Exploited Vulnerabilities (Week 2 - August 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-2nd-week-of-august-2026/681.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
9.6
|
Unauthenticated Command Injection - Progress LoadMaster contains a command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands on the system.
|
(LoadMaster GA) <= 7.2.63.1
(LoadMaster LTSF) <= 7.2.54.17 (Connection Manager) <= 7.2.63.1 |
7.2.63.2
7.2.54.18 7.2.63.2 |
||
|
9.8
|
Unauthenticated RCE - JetBrains TeamCity contains a deserialisation vulnerability within the agent polling protocol that can allow an unauthenticated remote attacker to execute code on the system.
|
<= 2025.11.5
2026.1 - 2026.1.2 |
2025.11.7
2026.1.3 |
||
|
7.5
|
Missing Encryption of Sensitive Data - Apache Tomcat contains a missing encryption of sensitive data vulnerability that can allow an unauthenticated remote attacker to bypass the EncryptInterceptor functionality to achieve code execution on the system when chained with CVE-2025-24813. This vulnerability was introduced as a fix for CVE-2026-29146.
|
11.0.20
10.1.53 9.0.116 |
11.0.21
10.1.54 9.0.117 |
||
|
9.8
|
Unauthenticated RCE - Langflow contains a vulnerability that can allow an unauthenticated remote attacker to execute code on the system. This vulnerability affects default Langflow installations.
|
1.0.0 - 1.10.0
|
1.10.1
|
Updated Malware Signature (Week 2 - August 2026)
|
Threat
|
Description | |
|
Malicious Win32/Netsupport Rat
|
Win32/NetSupport RAT is a remote access trojan that impersonates NetSupport Manager IT administration Software to gain unauthorised control of their target, mainly Windows devices. The attackers commonly used fake software, browser updates and phishing emails to be able to reach and infect their targets.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Qilin was the most active ransomware group, impacting 32 countries, which accounted for 12.96% of the total ransomware hits. This made Qilin the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, affecting 28 countries and contributing 11.34% of the total ransomware activity. L Group followed closely with 26 countries impacted, representing 10.53%, while Orova affected 25 countries, accounting for 10.12% of overall ransomware hits. A significant level of activity was also observed from Dark Project, which impacted 19 countries, contributing 7.69% of total ransomware activity. Krybit affected 12 countries, representing 4.86%, while Inc Ransom impacted 11 countries, accounting for 4.45%. Lockbit5 recorded activity across 10 countries, contributing 4.05%. Moderate ransomware activity was observed from SafePay and Storm, each impacting 9 countries, accounting for 3.64% individually. Play affected 8 countries, representing 3.24%, while RansomHouse and DragonForce each impacted 7 countries, contributing 2.83% individually. Several ransomware groups showed lower but notable activity. Gunra, Coinbase Cartel, Akira, and Barracuda each affected 4 countries, representing 1.62% individually. Anubis and Global Secret Group impacted 3 countries, accounting for 1.21% each. The remaining ransomware groups recorded limited activity. Gammax, Aurora, Panzer, Space Bears, Chaos, Lynx, Clop each impacted 2 countries, contributing 0.81% individually. Groups including Payload, Everest, Triple X, 3AM, Orion, Insomnia, Bravox, and Cry0 each affected 1 country, representing 0.40% individually. |
Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 120 victims, accounting for 48.58% of the total ransomware activity. This indicates that nearly half of all reported ransomware victims were located in the United States, making it the primary target region during this period.
France and Germany recorded the second-highest number of victims, each with 10 cases, representing 4.05% individually. Brazil and Canada followed with 9 victims each, contributing 3.64% individually. The United Kingdom recorded 6 victims, accounting for 2.43% of the total ransomware activity.
Other countries with notable ransomware impact included Australia, India, and Italy, each reporting 5 victims, representing 2.02% individually. Singapore, South Africa, China, and Taiwan each recorded 4 victims, contributing 1.62% each.
Moderate activity was observed in Spain, Romania, and Japan, each with 3 victims, accounting for 1.21% individually. Several countries including Argentina, Malaysia, Thailand, Saudi Arabia, Belgium, Poland, Indonesia, Norway, Korea, Austria, Venezuela, Hungary, and Sweden each reported 2 victims, representing 0.81% individually.
The remaining countries recorded 1 victim each, accounting for 0.40% individually. These included Philippines, Netherlands, Viet Nam, Russia, Israel, Mexico, Ireland, Egypt, Switzerland, Türkiye, South Korea, Luxembourg, Vietnam, Guatemala, Cyprus, Czechia, and Peru.
Overall, the data shows that ransomware activity was heavily concentrated in the United States, which accounted for nearly half of all reported victims. However, the distribution across North America, Europe, Asia-Pacific, the Middle East, Africa, and South America highlight the continued global reach of ransomware operations and the persistent targeting of organisations across multiple regions.
Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 46 victims, accounting for 18.62% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 33 cases, representing 13.36% of the total. Retail followed with 30 victims, contributing 12.15%, while Construction accounted for 24 victims, representing 9.72% of overall ransomware activity.
The Healthcare sector also experienced significant ransomware impact, with 22 victims, accounting for 8.91% of the total. Finance recorded 14 victims, contributing 5.67%, while IT reported 13 victims, representing 5.26% of ransomware activity.
Moderate activity was observed in Federal, Architecture, and Education, each recording 9 victims and accounting for 3.64% individually. Hospitality recorded 7 victims, contributing 2.83%, while Organisations and Law Firms each reported 5 victims, representing 2.02% individually.
Lower levels of ransomware activity were observed in Energy and Media & Internet, each with 4 victims, accounting for 1.62% individually. Real Estate and Telecommunications each recorded 3 victims, contributing 1.21% each.
The least affected sectors included Insurance, Transportation, and Agriculture, each with 2 victims, representing 0.81% individually. Electronics recorded the lowest activity, with 1 victim, accounting for 0.40% of the total ransomware activity.
Overall, the data shows that ransomware activity was primarily concentrated in Manufacturing, Business Services, Retail, Construction, and Healthcare sectors. These industries accounted for the majority of reported victims, highlighting continued attacker focus on sectors with critical operations, valuable data assets, and a high potential for operational disruption.
Ransomware Group in Focus
L Group
Threat Actor Description
L Group first appeared on public trackers on 07 August 2026, classified as “New Group | Active.” It operates a Tor data-leak site branded “L Blog” (server banner Apache 2.4.52), reachable at the time of collection. Tracker naming varies - “L Group”, “LGROUP”, “LGroup” - all referring to the same entity. [1][2][3]
Operating model: data-leak extortion. The group publishes named organisations on a Tor blog with no published ransom demands, no data-volume claims, and no negotiation portal identified. No affiliate or RaaS recruitment has been observed. No administrator persona, alias, or cryptocurrency wallet is documented. [1][3]
Sophistication: assessed LOW and unproven. The indicators are consistent with an aggregator rather than an operator: a single-day mass posting of 26 entries, an average gap of roughly 375 days between estimated attack dates and disclosure, no technical footprint of any kind, and - decisively - a victim roster substantially copied from a defunct predecessor. [1][4][5]
Relationship to “J Group” - Evidence Base
The link between L Group and the earlier J Group brand is established across four independent sources. Note also the shared single-letter naming convention (J → L), consistent with either a deliberate rebrand or a copycat scraping the earlier group’s leak site. [1][4][5][6]
|
Source
|
Finding
|
|
ransomware.live group page for “J”
|
jean-petit.lu, atp.chaco.gob.ar, l-a.com.vn, automobile-mueller.info, laticrete.com.cn and mygoalseek.com all recorded as discovered 02 May 2025 under group “J”. [4]
|
|
CTI Academy public post (2025)
|
Published J Group “first wave” list - GoalSeek, LATICRETE China, Automobile Mueller, L&A Vietnam, ATP Chaco, Jean Petit, Rose Kennedy Greenway, AUSFEC and UVA. All nine reappear in L Group’s August 2026 list. [5]
|
|
BlackFog “New Ransomware Gangs in 2025”
|
J Group victim roster additionally includes Ratna Sagar, BR Digital, Bouygues Energies & Services, Immobilia, Dayco Host, NoKota Packers, Venezuelan Paints, Ferretornillos and PSEC - all of which reappear under L Group. [6]
|
|
BlackFog State of Ransomware, June 2025
|
Independently corroborates J Group as a real 2025 actor: NoKota Packers listed with an alleged 50 GB claim. [7]
|
|
ransomware.live duplicate flags
|
Several L Group entries (including rosekennedygreenway.org, laticrete.com.cn and jean-petit.lu) are automatically flagged “Duplicate Entry” - now explained by the prior J Group listings. [1]
|
Metadata note: L Group’s estimated attack dates for the recycled victims are consistently offset roughly one month later than J Group’s equivalents (for example jean-petit.lu: J recorded 02 March 2025, L records 02 April 2025). This shift is consistent with metadata being regenerated rather than derived from genuine incident evidence. [1][4]
than rely solely on encryption pressure. [8]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Resource Dev.
|
T1593
|
Search Open/Closed Sources
|
Republication of an earlier group’s leak-site roster - the only behaviour actually evidenced. [1][4][5]
|
|
Initial Access
|
T1078
|
Valid Accounts
|
Possible use of infostealer-sourced credentials; inferred solely from a cohort statistic (~42% of L Group victims with a domain show infostealer exposure). Not confirmed for any intrusion. [1]
|
|
Exfiltration
|
T1567
|
Exfiltration Over Web Service
|
Data theft inferred from the existence of a leak site; no exfiltration observed or documented. [1]
|
|
Impact
|
T1657
|
Financial Theft/Data Extortion
|
Public naming of organisations on the “L Blog” Tor site. The only directly observable impact. [1][2]
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
NOT observed - no encryptor, extension, or ransom note attributable to L Group. [3][7]
|
Attack Lifecycle
Only the final stage of a conventional ransomware lifecycle is observable for L Group. The preceding stages are unevidenced, and for the recycled majority of victims they are more properly attributed to J Group’s 2025 activity than to this actor. [1][4]
1. SOURCE ACQUISITION - Harvesting a Predecessor’s Roster
The only behaviour actually demonstrated is acquisition of an earlier group’s victim list. Eighteen of the 26 entries correspond directly to J Group postings from 02 May 2025, with regenerated attack-date metadata. [1][4][5][6]
Observable artefacts: Reappearance of a previously-leaked organisation under a new brand; “duplicate entry” flags on tracker records; estimated attack dates inconsistent with the claiming group’s own operational window.
2. INITIAL ACCESS THROUGH EXFILTRATION - Unevidenced
No stage between initial access and exfiltration is documented for L Group. Where fresh compromise did occur (plausibly limited to the eight novel entries), the vector is unknown; a credential-driven route is possible given cohort infostealer overlap, but this is inference from a statistic rather than observation. [1]
Observable artefacts: For the eight novel victims only: credentials appearing in infostealer dumps; anomalous remote-access authentication; unexplained bulk data egress in the Dec 2025 – Jun 2026 period.
3. IMPACT - Publication on the “L Blog” Leak Site
Victims are named on the Tor leak site. No ransom figure, data volume, negotiation portal, or countdown timer has been published for any of the 26 entries - an unusually thin extortion apparatus that further supports the aggregator assessment. [1][2]
Observable artefacts: Client organisation appearing on the L Blog onion; outbound Tor connectivity; media or tracker reports of an alleged leak the organisation cannot corroborate.
Mitigation - Crystal Eye 5.5 Controls
Because L Group demonstrates republication rather than intrusion, the priority is verification before escalation - avoiding unnecessary incident response on stale claims - combined with baseline credential and egress hygiene against the possibility of genuine compromise in the novel subset.
Advanced Firewall
Build traffic rules to restrict lateral paths and remote-access exposure, where inspection of encrypted web traffic is required, set the content-filtering mode to Transparent with SSL decryption or Explicit with SSL decryption; use application rules to control DNAT exposure of internal services.
Web Filter (SWG)
Scans HTTP and HTTPS. Block parameters: Blacklists, Phrase Lists, MIME Types, File Extensions, Banned Sites, Gray Sites, Exception Sites. Multi-profile.
CE SIEM
Ingest the available indicators and treat any client listing as an unverified claim pending validation. Escalate to CESOC.
CE Backup Integrity
Retain immutable, offline, tested backups as standing practice.
Indicators of Compromise (IOCs)
IOC availability: As of 09 August 2026, no encryptor binary, file hash, ransom-note filename, encrypted-file extension, mutex, YARA or Sigma rule, or command-and-control indicator is publicly attributable to L Group across VirusTotal, MalwareBazaar, ANY.RUN, Malpedia, Triage or AlienVault OTX. Only two indicators exist. No indicators have been fabricated, and no artefacts from other “L”-prefixed families (Lynx, LockBit, LeakNet, Lilith) have been substituted. [1][3]
Available Indicators
|
Type
|
Indicator (defanged)
|
|
Tor DLS (onion)
|
4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd[.]onion (also /posts)
|
|
Email
|
js677832@onionmail[.]org
|
References
[1] Ransomware.live - L Group group and victim records - https://www.ransomware.live/. Primary source: New Group/Active classification, 26 victims discovered 07 Aug 2026, per-victim pages with estimated attack dates, duplicate-entry flags, sector and country breakdown, infostealer overlap statistic, and the standing “emerging group - treat with caution” advisory.
[2] Ransomfeed.it - ransomware victim feed - https://ransomfeed.it/. Independent corroboration of the 07 Aug 2026 posting burst with per-victim timestamps between 08:40 and 08:43 UTC.
[3] deepdarkCTI - ransomware gang list (fastfire/GitHub) - https://github.com/fastfire/deepdarkCTI/blob/main/ransomware_gang.md. Records “LGROUP · ONLINE” with the OnionMail operator contact; also shows the same contact convention used by unrelated groups, supporting the low-confidence rating.
[4] Ransomware.live - group profile for “J” - https://sandbox.ransomware.live/group/J. Establishes the May 2025 J Group listings for jean-petit.lu, atp.chaco.gob.ar, l-a.com.vn, automobile-mueller.info, laticrete.com.cn and mygoalseek.com - the basis of the recycling finding.
[5] CTI Academy - J Ransomware Group first-wave victim list - https://x.com/CTIAcademy/status/1918643255001964652. Contemporaneous 2025 publication of the J Group victim list, nine members of which reappear under L Group in August 2026.
[6] BlackFog - Ongoing: New Ransomware Gangs in 2025 - https://www.blackfog.com/ongoing-new-ransomware-gangs-in-2025/. Extended J Group victim roster including Ratna Sagar, BR Digital, Bouygues Energies & Services, Immobilia, Dayco Host, NoKota Packers, Venezuelan Paints, Ferretornillos and PSEC - all recurring under L Group.
[7] BlackFog - The State of Ransomware, June 2025 - https://www.blackfog.com/the-state-of-ransomware-june-2025/. Independent corroboration of J Group as a genuine 2025 actor, citing the NoKota Packers incident and an alleged 50 GB data claim.