| New Threats Detection Added | • OWAReaper |
| New Threat Protection | 68 |
| Newly Detected Threats | 8 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
OWAReaper | ||||||||||||||||||
|
OWAReaper is a malicious Javascript-based backdoor targeting Microsoft Outlook Web Access (OWA) by exploiting a cross-site scripting vulnerability, allowing the malware to be executed by simply opening a phishing/malicious email. Once it is successfully deployed, it has the capabilities to steal credentials, access the entire mailbox data, the ability to maintain persistence within the webmail environment, and communicate to attacker C2 host. OWAReaper uses stealth and server-side persistence techniques that allow the attacker to maintain its access even after a user performs a password to reset or reimage the device.
|
|||||||||||||||||||
|
Threat Protected:
|
05 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Trojan-Activity | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Known Exploited Vulnerabilities (Week 1 - August 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-1st-week-of-august-2026/680.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
5.3
|
Hard-coded Credentials - Cisco Secure Firewall Management Center (FMC) contains a vulnerability that allows an unauthenticated remote attacker to gain access to a low-privileged account through the use of a hard-coded password.
|
Check vendor advisory for affected products and versions.
|
|||
|
5.3
|
Information Disclosure - Fortinet FortiOS contains an information disclosure vulnerability within FortiOS SSL-VPN that can allow an unauthenticated remote attacker to obtain information that could be used in further attacks against the device.
|
6.4.0 - 7.4.6
7.6.0 - 7.6.1 |
7.4.7
7.6.2 |
||
|
10
|
Unauthenticated Command Injection - Arista VeloCloud Orchestrator On-Prem contains a command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands on the system.
|
5.2.0 - < 5.2.3.14
6.1.0 - < 6.1.3.4 6.4 - < 6.4.2.4 7.0 - < 7.0.0.1 |
5.2.3.14
6.1.3.4 6.4.2.4 7.0.0.1 |
||
|
7.4
|
Authentication Bypass – N-able N-central contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system.
|
<= 2026.1
|
2026.3.1
|
||
|
8.1
|
Authentication Bypass – N-able N-central contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system. This vulnerability is due to an incomplete patch for CVE-2026-18556.
|
< 2026.3
|
2026.3.1.7
|
||
Updated Malware Signature (Week 1 - August 2026)
|
Threat
|
Description | |
|
Gholoader
|
Gholoader is a malware loader associated with TA569 (SocGholish). This is being distributed via compromised websites that masquerade as a legitimate browser update that prompts the users to download the malicious payloads.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that The Gentlemen was the most active ransomware group, impacting 43 countries, which accounted for 16.60% of the total ransomware hits. This made The Gentlemen the leading ransomware actor during the reporting period. Qilin recorded the second-highest activity, affecting 28 countries and contributing 10.81% of the total ransomware activity. Global Secret Group followed with 24 countries impacted, representing 9.27%, while Everest affected 21 countries, accounting for 8.11%. A significant level of activity was also observed from ExfilSquad, which impacted 18 countries, contributing 6.95% of total ransomware hits. Booba Team affected 13 countries, representing 5.02%, while NightSpire impacted 12 countries, accounting for 4.63%. SafePay and Inc Ransom each affected 11 countries, contributing 4.25% individually. Deadlock impacted 9 countries, representing 3.47%, while Genesis affected 8 countries, accounting for 3.09%. Moderate activity was observed from DragonForce, which impacted 6 countries and contributed 2.32%. CMD Organization affected 5 countries, representing 1.93%, while ShinyHunters, Aurora, and Unsafe each impacted 4 countries, accounting for 1.54% individually. Several ransomware groups showed lower activity, impacting 3 countries each, including Chaos, M3rx, and Insomnia, contributing 1.16% individually. Groups such as Arcus Media, Kairos, Nova, Securotrop, Anubis, Coinbase Cartel, Termite, Akira, and Gammax affected 2 countries, accounting for 0.77% each. The remaining ransomware groups, including Bravox, Blackwater, Money Message, Doommageddon, Space Bears, Black X, Leaknet, Pear, Morpheus, Interlock, and Clop, each impacted 1 country, representing 0.39% individually. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 130 victims, accounting for 50.19% of the total ransomware activity. This indicates that more than half of the reported ransomware victims were located in the United States, making it the primary target region during this period.
Germany recorded the second-highest number of victims, with 19 cases, representing 7.34% of the total. The United Kingdom followed with 12 victims, contributing 4.63%, while India recorded 10 victims, accounting for 3.86% of overall ransomware activity.
Other countries with notable ransomware impact included Canada, with 8 victims, representing 3.09%, and Brazil, with 6 victims, contributing 2.32%. Australia recorded 4 victims, while Spain, France, and Switzerland each reported 4 victims, accounting for 1.54% individually.
Moderate ransomware activity was observed in Italy, Mexico, Sweden, Thailand, Singapore, Belgium, and the United Arab Emirates, each recording 3 victims, representing 1.16% individually.
Countries including Argentina, Russian Federation, Malaysia, Turkey, Chile, Peru, Netherlands, Israel, and Poland each reported 2 victims, contributing 0.77% individually.
The remaining countries recorded 1 victim each, accounting for 0.39% individually. These included Morocco, Croatia, Romania, Nigeria, China, Iraq, Cyprus, Türkiye, Portugal, Colombia, Turkiye, Norway, Ecuador, Taiwan, Guatemala, Indonesia, Saudi Arabia, Tanzania, and Denmark.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 55 victims, accounting for 21.24% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 48 cases, representing 18.53% of the total. Together, Manufacturing and Business Services accounted for a significant portion of overall ransomware activity, highlighting continued attacker focus on sectors handling critical operations and valuable business data.
Retail followed with 23 victims, contributing 8.88% of total ransomware activity. IT recorded 19 victims, accounting for 7.34%, while Healthcare reported 18 victims, representing 6.95%. Finance also experienced notable impact, with 16 victims, contributing 6.18% of the total.
Moderate ransomware activity was observed in Construction, which recorded 15 victims, accounting for 5.79%. Transportation and Federal each reported 11 victims, contributing 4.25% individually. Education recorded 9 victims, representing 3.47% of total activity.
Other affected sectors included Energy with 7 victims, accounting for 2.70%, and Hospitality with 6 victims, representing 2.32%. Real Estate recorded 5 victims, contributing 1.93%.
Lower levels of ransomware activity were observed in Organisations, with 4 victims, accounting for 1.54%. Law Firms reported 3 victims, contributing 1.16%, while Electronics, Architecture, and Agriculture each recorded 2 victims, representing 0.77% individually.
The least affected sectors were Media & Internet, Minerals & Mining, and Consumer Services, each recording 1 victim, accounting for 0.39% individually.

Ransomware Group in Focus
Money Message
Threat Actor Description
Money Message surfaced in mid-March 2023 (estimated first activity around 19 March 2023), was first reported publicly by a victim on 28 March 2023, and was documented by Zscaler ThreatLabz the following day. Tracker records place first discovery on 29 March 2023. It has operated continuously since, with no known law-enforcement takedown, arrests, or indictments as of this reporting window, and no established rebrand lineage in either direction. [1][5]
Operating and extortion model: assessed as a small closed team rather than an open affiliate programme - there is no public evidence of affiliate recruitment. The group runs classic double extortion (data theft plus encryption) with million-dollar demands; the largest documented demand is USD 4,000,000 against MSI.[1][5]
The group’s defining incident remains its 2023 breach of Micro-Star International (MSI), where it claimed 1.5 TB of stolen data and demanded USD 4 million. After MSI refused, Money Message leaked firmware source code including image-signing private keys for 57 MSI products and Intel Boot Guard OEM private keys for 116 products. Because Boot Guard keys are fused into hardware, that exposure is effectively unpatchable and remains a long-tail supply-chain risk across affected Tiger Lake, Adler Lake and Raptor Lake platforms. The episode demonstrates the group’s willingness to weaponise deep intellectual-property theft rather than rely solely on encryption pressure. [8]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
This actor has an unusually strong evidence base: a full Sophos X-Ops incident-response engagement plus multiple independent reverse-engineering analyses. The great majority of rows below are therefore CONFIRMED from forensic or sample evidence rather than cohort inference. [2][3][4]
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Initial Access
|
T1078
|
Valid Accounts
|
Intrusion via the victim VPN protected by SINGLE-FACTOR authentication only - the sole forensically confirmed entry vector. [2]
|
|
Defence Evasion
|
T1562.001
|
Impair Defences
|
Group Policy Object deployed to disable Windows Defender real-time protection estate wide. [2]
|
|
Credential Access
|
T1003.002
|
OS Credential Dumping: SAM
|
Impacket secretsdump.py used to extract the SAM hive. [2]
|
|
Lateral Movement
|
T1021.001
|
Remote Desktop Protocol
|
PsExec used to run a batch script enabling RDP, followed by RDP lateral movement. [2]
|
|
Lateral Movement
|
T1021.002
|
SMB/Admin Shares
|
WNetAddConnection2W called with admin credentials read from the embedded config to reach administrative shares. [3]
|
|
Execution
|
T1059.003
|
Windows Command Shell
|
cmd.exe used for recovery inhibition and service control. [3][4]
|
|
Execution
|
T1059.004
|
Unix Shell
|
ESXi variant uses a shell-script wrapper with sed, ps, awk and kill. [3]
|
|
Discovery
|
T1083/T1082
|
File & System Discovery
|
Directory enumeration excluding core Windows paths; esxcli storage filesystem list on ESXi. [3][4]
|
|
Collection
|
TA0009
|
Data from Network Shares
|
Finance, Payroll, SalesReport and HR folders accessed on the file server via a compromised account. [2]
|
|
Exfiltration
|
T1567.002
|
Exfiltration to Cloud Storage
|
MEGAsync used to move stolen data off network. [2]
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
ChaCha20 with ECDH (P-384) key exchange; NO extension appended and files not renamed; note money_message.log at root of C:. [3][4]
|
|
Impact
|
T1490
|
Inhibit System Recovery
|
cmd.exe /c vssadmin.exe delete shadows /all /quiet. [3][4]
|
|
Impact
|
T1489
|
Service Stop
|
Stops vss, sql, svc$, memtas, mepocs, sophos, veeam, backup, vmms; kills ~30 processes incl. database and Office binaries. [3]
|
|
Impact
|
T1561
|
Disk Wipe
|
Linux/ESXi variant force-terminates VMs and destroys virtual hard disks. [2][3]
|
|
Comm. & Control
|
-
|
No encryptor C2
|
The encryptor uses no network C2 channel; it relies on embedded credentials. Do not deploy fabricated C2 indicators. [3][4]
|
ESXi/Linux Variant Behaviour
The hypervisor variant is operationally distinct and warrants separate detection engineering. It enumerates datastores, force-terminates running virtual machines, and applies partial encryption - files under 128 MB are encrypted in full, while larger files are encrypted in calculated steps. This renders virtual machines unrecoverable while dramatically reducing encryption time. Newer samples add Base64 obfuscation and anti-forensic behaviour and specifically target .vmx configuration files. [3][6]
Attack Lifecycle
Reconstructed primarily from a documented incident-response engagement, so nearly every stage below is confirmed rather than inferred. Note the hands-on-keyboard character of the intrusion - there is no automated loader or worm component. [2][3]
1. INITIAL ACCESS - Single-Factor VPN / Valid Credentials
The operator authenticates to the victim VPN using valid credentials where only single-factor authentication is enforced. In the most recent documented case (a Canadian legal firm, listed just before this window), compromised credentials were used to enter the network approximately one month before exfiltration and encryption - indicating a substantial dwell period. [2][7]
Observable artefacts: VPN authentication from unfamiliar geographies or ASNs; successful logins on accounts lacking MFA; credentials appearing in infostealer dumps; impossible-travel sign-ins.
2. DEFENCE EVASION - GPO Disables Defender
A Group Policy Object is deployed to disable Windows Defender real-time protection across the estate. This is a high-value, high-fidelity detection point: legitimate administrators rarely disable real-time protection domain-wide without a corresponding change record. [2]
Observable artefacts: GPO creation or modification altering Defender/real-time protection settings; tamper-protection alerts; sudden estate-wide drop in endpoint telemetry.
3. CREDENTIAL ACCESS & LATERAL MOVEMENT - Impacket, PsExec, RDP
The SAM hive is dumped using Impacket secretsdump.py. PsExec then executes a batch script that enables RDP on target hosts, and the operator moves laterally over RDP. The encryptor separately reaches administrative shares using credentials embedded in its own configuration. [2][3]
Observable artefacts: secretsdump/Impacket behaviour and remote SAM access; PsExec service creation; registry changes enabling RDP (fDenyTSConnections); new inbound RDP between servers that do not normally peer.
4. COLLECTION & EXFILTRATION - Finance/HR Shares to MEGAsync
The operator browses to and collects from Finance, Payroll, SalesReport and HR directories on the file server, then exfiltrates via MEGAsync to cloud storage before deploying the encryptor. [2]
Observable artefacts: MEGAsync installation or execution on servers; large outbound transfers to mega.nz infrastructure; anomalous access to Finance/HR/Payroll shares by a single account.
5. IMPACT - Encryption Across Windows and ESXi
Shadow copies are deleted, backup and database services are stopped, and the Windows encryptor runs - leaving filenames unchanged and dropping money_message.log at the root of C:. In parallel or subsequently, the ESXi variant force-terminates virtual machines and encrypts datastores. Victims that refuse to pay are listed on the Tor blog and their data published. [2][3][4]
Observable artefacts: vssadmin delete shadows /all /quiet; mutex 12345-12345-12235-12354; money_message.log at drive root; mass file modification WITHOUT rename; ESXi VMs terminating en masse; victim appearing on the Money Message blog.
Mitigation - Crystal Eye 5.5 Controls
Controls are prioritised against this group’s confirmed kill chain. The single highest-value action is eliminating single-factor remote access - the only forensically confirmed initial-access vector for this actor.
CE Identity Hardening + MFA (highest priority)
Enforce phishing-resistant MFA on every VPN and remote-access entry point. Any remaining single-factor VPN account should be treated as a critical finding and remediated immediately. Monitor infostealer-log marketplaces for managed-client domains and force credential rotation on any hit - both in-window victims and the immediately preceding victim showed prior credential-exposure indicators.
CE Antivirus + MDR (tamper protection and GPO watch)
Enable endpoint tamper protection so that Defender real-time protection cannot be disabled by policy, and alert on any GPO creation or modification that alters antivirus or real-time-protection settings. Investigate immediately in the absence of a matching change ticket - this is the group’s signature evasion step.
CE Advanced Firewall + IDPS (contain lateral movement)
Restrict RDP to a hardened, MFA-gated jump host and block server-to-server RDP at the network layer. Use CE IDPS rules to alert on PsExec service creation, Impacket/secretsdump behaviour (remote SAM access), and registry changes that enable RDP. Alert on net.exe or taskkill.exe activity against backup and database services outside approved maintenance windows.
CE DLP + SWG Egress Monitoring (block the exfiltration path)
Block or tightly control MEGAsync and equivalent consumer cloud-sync clients on servers and inspect large outbound transfers to consumer cloud storage. Apply DLP monitoring to Finance, HR and Payroll shares - the group’s documented collection targets - and alert on bulk access by a single account.
CE Hypervisor Hardening (ESXi)
Disable SSH on ESXi hosts when not actively required, restrict management-plane access to a dedicated administrative network, keep hypervisors patched, and alert on mass VM shutdown events or writes to .vmdk / .vmx files originating from unexpected shells. The ESXi variant destroys virtual disks, so hypervisor compromise is a total-loss scenario without offline backups.
CE Backup Integrity + CESOC Escalation
Maintain immutable, offline, tested backups - the encryptor deletes volume shadow copies and the ESXi variant destroys virtual disks, so online snapshots alone are insufficient. Escalate to CESOC on any of: a client or supply-chain third party appearing on the Money Message blog, detection of any indicator in this report, or a sustained rise above the group’s baseline tempo of roughly one victim per month.
Indicators of Compromise (IOCs)
Source & confidence: Money Message has well-attributed, sample-derived indicators from multiple independent reverse-engineering analyses. All values below are defanged. Do not substitute indicators from unrelated families that share ChaCha20. [3][4]
Windows Encryptor Hashes
|
Type
|
Value
|
|
|
SHA-256
|
8be41efd6e6ace53b8c59344be2ba91fe41003987a8e38484b20760d7c400a42
|
|
|
SHA-256
|
dc563953f845fb88c6375b3e9311ebed49ce4bcd613f7044989304c8de384dac
|
|
|
MD5
|
400fa5d02c1ac704cd290d959b725e67
|
|
|
SHA-256
|
bbdac308d2b15a4724de7919bf8e9ffa713dea60ae3a482417c44c60012a654b
|
|
|
MD5
|
163e651162f292028ca9a8d7f1ed7340
|
|
Linux/ESXi Encryptor Hashes
|
Type
|
Value
|
|
SHA-256
|
4f8bd37851b772ee91ba54b8fd48304a6520d49ea4a81d751570ea67ef0a9904
|
|
MD5
|
abe3c3cc45dec9c01762ba3e534564ed
|
|
SHA-1
|
3b4ecff980285461642cc4aef60d4a1b9708453e
|
Host-Based Artefacts
|
Type
|
Indicator/Value
|
|
Mutex
|
12345-12345-12235-12354
|
|
Ransom note
|
money_message.log (dropped at root of C:)
|
|
File extension
|
NONE appended - files are not renamed
|
|
Recovery inhibition
|
cmd.exe /c vssadmin.exe delete shadows /all /quiet
|
|
Encryption
|
ChaCha20 + ECDH (curve P-384) with hard-coded public key
|
|
Service stop list
|
vss, sql, svc$, memtas, mepocs, sophos, veeam, backup, vmms
|
|
Detection name
|
Troj/Ransom-GWD (Sophos)
|
Network & Contact Indicators
|
Type
|
Indicator/Value
|
|
Tor DLS (blog)
|
blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd[.]onion
|
|
Negotiation onion
|
xuutya4qc5zxpz2pgl3zpfnzr6memzf7g62k4koc7fktn4ekzcebssid[.]onion (example)
|
|
Encryptor C2
|
NONE - the encryptor uses no network C2 channel
|
|
Crypto wallet
|
None consistently attributable in open sources
|
|
Tox IDs
|
Tox: 50DADDED26D859469371938B793456D8210A5AE02DD3C42979F5E52411BCB648F1CA68A5EDE5
|
References
[1] Ransomware.live - Money Message Group Profile - https://www.ransomware.live/group/money%20message.
[2] Sophos X-Ops - Step-by-step through the Money Message ransomware - https://www.sophos.com/en-us/blog/step-by-step-through-the-money-message-ransomware.
[3] Cyble - Demystifying Money Message Ransomware - https://cyble.com/blog/demystifying-money-message-ransomware/.
[4] SecurityScorecard - A Detailed Analysis of the Money Message Ransomware (whitepaper) - https://securityscorecard.com/wp-content/uploads/2024/01/Whitepaper-A-Detailed-Analysis-of-the-Money-Message-Ransomware.pdf
[5] BleepingComputer - New Money Message ransomware demands million dollar ransoms - https://www.bleepingcomputer.com/news/security/new-money-message-ransomware-demands-million-dollar-ransoms/.
[6] Broadcom/Symantec - Money Message Ransomware activities continue - https://www.broadcom.com/support/security-center/protection-bulletin/money-message-ransomware-activities-continue.
[7] BeyondMachines - X-Copper Legal Firm Reports Data Breach Following Ransomware Attack - https://beyondmachines.net/event_details/x-copper-legal-firm-reports-data-breach-following-ransomware-attack-h-a-9-9-t.
[8] Dark Reading - Leak of Intel Boot Guard Keys Could Have Security Repercussions for Years - https://www.darkreading.com/cyberattacks-data-breaches/leak-of-intel-boot-guard-keys-could-have-security-repercussions-for-years.