| New Threats Detection Added | • Lumma Stealer • SocGholish |
| New Threat Protection | 70 |
| Newly Detected Threats | 6 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
Lumma Stealer | ||||||||||||||||||
|
Lumma Stealer is an information-stealing malware operated as a malware-as-a-service since 2022. After being taken down last 2025. approximately 2,300 malicious domains were seized, suspended, and blocked. By early 2026, Lumma's infrastructure has been rebuilt and spreading again globally through newly acquired domains, fresh hosting, and updated network of distribution channels. Their main delivery method is a trick known as ClickFix, a social engineering technique where their attackers trick you in executing the malware on your computer using phishing emails, fake CAPTCHA and malicious links.
|
|||||||||||||||||||
|
Threat Protected:
|
06 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Domain-c2 | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Known Exploited Vulnerabilities (Week 3 - July 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-3rd-week-of-july-2026/677.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
9.8
|
Unauthenticated RCE - Microsoft SharePoint (on-premises) contains a deserialisation vulnerability that can allow an unauthenticated remote attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.1
|
Unauthenticated RCE - Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contains an OS command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands via a specifically crafted HTTP request.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.1
|
Unauthenticated RCE - Fortinet FortiSandbox contains an OS command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands with root privileges via a HTTP request.
|
4.4.0 - 4.4.8
|
4.4.9
|
||
|
9.8
|
Authentication Bypass - Oracle E-Business Suite contains a vulnerability within the File Transmission component that can allow an unauthenticated remote attacker to gain access to Oracle Payments.
|
12.2.23 - 12.2.15
|
|
||
|
7.5
|
Overly Restrictive Account Lockout Mechanism - KNX Association KNX Protocol Connection Authorisation contains an overly restrictive account lockout mechanism that could allow an attacker to prevent legitimate users from accessing the device.
|
Check vendor advisory for affected products and versions.
|
|||
|
7.8
|
Privilege Escalation - Microsoft Active Directory Federation Services contains a privilege escalation vulnerability that can allow an attacker to elevate to Administrator level privileges.
|
Check vendor advisory for affected products and versions.
|
|||
|
5.3
|
Privilege Escalation - Microsoft SharePoint (on-premises) contains a vulnerability that can allow an unauthenticated remote attacker to elevate their privileges.
|
Check vendor advisory for affected products and versions.
|
|||
|
10.0
|
Unauthenticated Server-Side Request Forgery - SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that can allow an unauthenticated remote attacker to send arbitrary requests on behalf of the appliance.
|
Check vendor advisory for affected products and versions.
|
|||
|
7.2
|
Authenticated Command Injection - SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that can allow an unauthenticated remote attacker to send arbitrary requests on behalf of the appliance.
|
Check vendor advisory for affected products and versions.
|
|||
|
4.3
|
Cross-site Request Forgery - SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that can allow an unauthenticated remote attacker to send arbitrary requests on behalf of the appliance.
|
12.4
|
N/A (End-of-Life)
|
||
Updated Malware Signature (Week 3 - July 2026)
|
Threat
|
Description | |
|
Malicious Certificate Issuer Observed in TLS Certificate
|
Malicious Certificate Issuer Observed in TLS Certificate is a C2 connection or phishing attempt where it uses fake certificates to hide phishing sites or to control infected machines.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that DragonForce was the most active ransomware group, impacting 30 countries, which accounted for 19.11% of the total ransomware hits. This made DragonForce the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, attacking 22 countries and contributing 14.01% of the total ransomware activity. Qilin followed with 20 countries impacted, representing 12.74% of overall ransomware hits. A moderate level of activity was observed from Akira and Arcus Media, each impacting 6 countries and accounting for 3.82% individually. M3rx, Inc Ransom, and Play each affected 5 countries, contributing 3.18% of the total activity. Several ransomware groups showed similar levels of activity, impacting 4 countries each. These included Cmd Organisation, Titan, Anubis, Chaos, Ailock, Interlock, and Krybit, each representing 2.55% of total ransomware activity. Groups with lower but notable activity included D1r, Space Bears, Pear, and Settra, each impacting 3 countries, accounting for 1.91% individually. NightSpire, Coinbase Cartel, Black X, and Ransomhouse each affected 2 countries, contributing 1.27% individually. The remaining ransomware groups, including Gunra, Syndicate, SafePay, PayoutsKing, ShinyHunters, Leaknet, and Securotrop, each impacted 1 country, accounting for 0.64% individually. |
D1R Ransomware
During the reporting window of 04 July 2026 to 13 July 2026, a newly-emerged data-extortion actor tracked as D1R first appeared on public ransomware trackers, listing three victims on 12–13 July 2026.
D1R is not a conventional encryptor-based ransomware family. It operates a novel, parasitic “recycling” data-leak extortion model: rather than breaching victims itself, it harvests data already exposed in other groups’ leaks and re-publishes it, taunting the named companies.
Leak-site observation (13 Jul 2026): D1R’s Tor site brands itself “D1R - Cybersecurity audits since 2025” and presents a “Data Leaks” gallery with the three victim cards, each running an ~10-day extortion countdown (deadline on or around 23–24 July 2026). Notably, the ARM card is tagged “.exe / Leak” and offers a downloadable executable rather than ARM proprietary data - reinforcing the assessment that D1R’s “leaks” are low-substance and recycled.
The claims are unverified. D1R should be treated as a low-to-moderate, monitoring-only watch-list item.
Threat Actor Description
Origin and Profile
D1R has no known history before 12 July 2026, and Ransom-DB. Its leak site carries the self-styled tagline “Cybersecurity audits since 2025”. No vendor has linked it to a parent family. Its thesis is parasitic: instead of gaining its own initial access, it mines data dumps published by other extortion groups and cross-references a curated “TARGETLIST.txt” to pivot to follow-on targets.
Operating model: data-leak/extortion only, built on recycling third-party leaks. There is no evidence D1R performs encryption. It seeks notoriety and reputational pressure through public data dumps, taunts, and countdown timers. Sophistication is currently assessed as low and unproven. [1][2]
Upstream source (context): D1R’s data appears sourced from the Synopsys breach claimed by Arkana Security - discovered 6 June 2025 (attack 4 June 2025), 41,000+ corporate records alleged, later disclosed by Synopsys to regulators in an April 2026 filing. Arkana runs a leak-centric “Ransom → Sale → Leak” model and has been linked to the Qilin RaaS ecosystem. Arkana’s indicators are Arkana’s, not D1R’s, and must not be attributed to D1R.
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Initial Access
|
T1078
|
Valid Accounts (recycled)
|
CLAIMED - no direct access; D1R claims to reuse credentials/artefacts from other groups’ leaked databases. Unconfirmed.
|
|
Defence Evasion
|
T1111
|
Multi-Factor Authentication Interception
|
CLAIMED (unverified) - asserts an SSL certificate + “Athena Download Manager” bypasses ARM.com 2FA. Boastful; uncorroborated.
|
|
Resource Dev.
|
T1608
|
Stage Capabilities/Tool Distribution
|
Distributes AthenaDM-windows-installer_1.9.10.exe via Gofile as leak-site “.exe” content (suspected payload).
|
|
Impact
|
T1657
|
Financial Theft/Data Extortion
|
CONFIRMED behaviour - public data-leak extortion with countdown timers via the Tor DLS.
|
Attack Lifecycle
The following reconstructs D1R’s operating cycle from its leak-site narrative and observed site content. It is data-leak/extortion only - there is no encryption stage, and most steps are self-reported rather than independently verified.
SOURCE ACQUISITION - Harvesting Other Groups’ Leaks
D1R downloads datasets leaked by other extortion actors (principally the Arkana–Synopsys dump) and mines a curated “TARGETLIST.txt” for follow-on opportunities.
Observable artefacts: Recirculation of previously-leaked corporate datasets; references to prior breaches/other groups’ dumps; appearance of your data in a new actor’s post shortly after an upstream leak.
TARGET SELECTION - Cross-Referencing Leaked Data
Leaked corporate data is cross-referenced to pivot from the source victim (Synopsys) to related organisations (ARM, Bosch) sharing supply-chain, credential, or certificate relationships.
Observable artefacts: Follow-on targeting of an upstream victim’s partners/customers; reuse of the upstream victim’s name as the “access” justification.
SECONDARY ACCESS & TOOLING - Recycled Artefacts + Distributed .exe
D1R claims to reach follow-on targets using recycled credentials/certificates from the source leak - e.g., the unverified ARM 2FA-bypass narrative - and distributes a Windows executable (AthenaDM-windows-installer_1.9.10.exe, 12.8 MB, via Gofile) as the ARM “.exe/Leak” payload. This stage is unconfirmed and the executable is treated as suspected malware.
Observable artefacts: Downloads of AthenaDM-windows-installer_1.9.10.exe; outbound connections to gofile.io/d/telQJ5; logins using credentials present in an upstream leak; certificate-gated flows that sidestep step-up 2FA.
IMPACT - Publication & Extortion (no encryption)
D1R posts each victim on its Tor DLS with a taunting narrative, a ~10-day countdown timer, and an offer to release the recycled data or tool. No encryption, ransom figure, or negotiation portal is observed.
Observable artefacts: Victim organisation appearing on the D1R leak site with a countdown; outbound Tor connectivity; media reports of an alleged leak the organisation cannot confirm.
Mitigation - Crystal Eye 5.5 Controls
Crystal Eye Endpoint Controls (block the distributed .exe)
Block execution and download of AthenaDM-windows-installer_1.9.10.exe and block the Gofile distribution URL (gofile.io/d/telQJ5) at the web gateway. Treat the file as suspected malware, alert on its presence, and submit any recovered sample to a controlled sandbox before further action.
Crystal Eye Threat Intelligence
Add the D1R leak-site onion, the OnionMail address, the Tox ID, and the Telegram handle (below) to dark-web and DLS watchlists. Monitor for your organisation, subsidiaries, and key suppliers appearing in D1R posts or in upstream leaks (e.g., the Arkana-Synopsys dump) that D1R is likely to recycle.
Crystal Eye Identity Hardening + MFA
Enforce phishing-resistant MFA (e.g., FIDO2) and review any SSL/client-certificate-gated download portals that could sidestep step-up 2FA - directly countering D1R’s claimed ARM 2FA-bypass narrative.
Crystal Eye DLP + SWG Egress Monitoring
Enable DLP and SWG monitoring to detect exfiltration or re-download of sensitive repositories, block or inspect anonymised (Tor) egress, and block file-sharing hosts used for payload delivery.
Crystal Eye SIEM + CESOC Escalation
Correlate identity, DLP, SWG, and endpoint events, and ingest the D1R indicators.
INDICATORS OF COMPROMISE (IOCs)
IOC availability: As of 13 July 2026, no encryptor binary, verified file hash, ransom-note filename, encrypted-file extension, YARA rule, or C2 IP/domain is publicly attributable to D1R.
Leak Site/Contact Indicators
|
Type
|
Indicator/Value
|
|
Tor DLS (onion)
|
dirone3rl3vvq64ckcnrvhe2ogrhjrwu5u7hqzrlotu3rfvmqmmbsuqd[.]onion
(path/items)
|
|
Email
|
dir10nly@onionmail[.]org
|
|
Tox ID (QTOX)
|
063719AF013AD4EE89B497701BA5916898D70F45543C39E41154C4BCAC3A2F26F57913B31431
|
|
Telegram
|
@Qqqqqqops
|
|
Branding/tagline
|
“D1R – Cybersecurity audits since 2025”
|
|
DLS server banner
|
Apache 2.4.58 (Unix); OpenSSL 1.1.1w; PHP 8.2.12; mod_perl 2.0.12; Perl v5.34.1
|
Distributed Executable
|
Type
|
Indicator/Value
|
|
Filename
|
AthenaDM-windows-installer_1.9.10.exe
|
|
File size
|
12.8 MB
|
|
Delivery URL
|
hxxps://gofile[.]io/d/telQJ5
|
Source References
[1] RansomLook - D1R Group Profile - https://www.ransomlook.io/group/d1r. Primary tracker: D1R posts, victims, leak-site status/uptime, onion address, email and Tox contacts, and server banner.
[2] kairos.jordiserrano.me - D1R Group - https://kairos.jordiserrano.me/blog/arm. Corroborating tracker: victim list (Synopsys, ARM, Bosch), first/last discovery dates, and /items page reachability.
Primary observation - D1R leak site and Gofile file-host listing, captured 13 July 2026 (operator-controlled; live links deliberately not reproduced).
Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 60 victims, accounting for 38.22% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing more than one-third of all reported ransomware incidents.
Australia recorded the second-highest number of victims, with 9 cases, contributing 5.73% of the total. Germany and the United Kingdom each reported 6 victims, accounting for 3.82% individually. Canada and Japan followed with 5 victims each, representing 3.18% of the overall ransomware activity.
Other countries with notable ransomware impact included Italy, Spain, and France, each recording 4 victims, accounting for 2.55% individually. India, Argentina, Portugal, China, South Africa, Mexico, and Czech Republic each reported 3 victims, contributing 1.91% individually.
Moderate activity was observed in countries such as Colombia, Ecuador, Israel, Switzerland, Sweden, Hungary, and Czechia, each recording 2 victims, representing 1.27% of the total.
The remaining countries recorded 1 victim each, accounting for 0.64% individually. These included Ghana, Ireland, Saudi Arabia, Philippines, Bangladesh, United Arab Emirates, Bahrain, Thailand, New Zealand, Belgium, Yemen, Brazil, Finland, Singapore, Vietnam, and Malaysia.
Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 31 victims, accounting for 19.75% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 25 cases, representing 15.92% of the total. Construction followed with 17 victims, contributing 10.83%, while Retail accounted for 13 victims, representing 8.28% of overall ransomware activity.
Other industries with significant ransomware impact included Healthcare, with 9 victims, accounting for 5.73%, and Hospitality, with 8 victims, contributing 5.10%. Finance and Education each recorded 7 victims, representing 4.46% individually.
Moderate activity was observed in IT, with 6 victims, accounting for 3.82%, while Architecture recorded 5 victims, contributing 3.18%. Organisations and Law Firms each reported 4 victims, representing 2.55% individually.
Lower levels of ransomware activity were observed in Transportation, Energy, and Consumer Services, each recording 3 victims, accounting for 1.91% individually. Telecommunications, Media & Internet, Federal, and Agriculture each reported 2 victims, contributing 1.27% each.
The least affected sectors were Real Estate, Minerals & Mining, Electronics, and Insurance, each with 1 victim, representing 0.64% individually.