| New Threats Detection Added | • SocGholish • OnionDrop • GrizzlyLoader • Etherhiding • Lumma Stealer • TonRAT |
| New Threat Protection | 94 |
| Newly Detected Threats | 15 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
TonRAT | |||||||||||||||||||||
|
TonRAT is a Remote Access Trojan (RAT) based in Node.js, which can maintain remote access to compromised targets. This malware is often delivered through phishing campaigns containing a malicious ZIP archive that has LNK files that executes PowerShell scripts to deploy the malware. Once installed, it will allow the attackers to execute commands, maintain persistence, and download additional payloads like infostealers or credential theft tools.
|
||||||||||||||||||||||
|
Threat Protected:
|
03 | |||||||||||||||||||||
|
Rule Set Type:
|
|
|||||||||||||||||||||
|
Class Type:
|
Command-and-Control | |||||||||||||||||||||
|
Kill Chain:
|
|
|||||||||||||||||||||
Known Exploited Vulnerabilities (Week 1 - September 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-1st-week-of-september-2026/696.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
8.8
|
Unauthenticated RCE - Google Chromium V8 contains a type confusion vulnerability that can allow an unauthenticated remote attacker to execute code within the context of the browsers sandbox when visiting a specially crafted HTML page. This vulnerability may affect additional web browsers that utilise Chromium.
|
Check vendor advisories for affected products and versions.
|
|||
|
8.8
|
Authentication Bypass - BerriAI LiteLLM contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to establish an authenticated MCP session without a valid LiteLLM key.
|
<= 1.83.14
|
1.84.0
|
||
|
6.5
|
Request Smuggling - Kludex Starlette contains a HTTP Request Smuggling vulnerability that can allow an unauthenticated remote attacker to reconstruct the request path used by the webserver in HTTP requests by using a modified HOST header. Exploitation of this vulnerability can allow an attacker to bypass security controls and can be used in further attacks against the server.
|
Check vendor advisories for affected products and versions.
|
|||
|
10
|
Unauthenticated RCE - Kestra OSS contains an command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands on the system through the creation and execution of arbitrary workflows.
|
<= 1.0.44
1.1.0 - 1.3.20 |
1.0.45
1.3.21 |
||
|
9.8
|
Authentication Bypass - JFrog Artifactory contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to obtain administrative privileges on the system.
|
Check vendor advisory for affected versions.
|
|||
|
9.8
|
Unauthenticated SQL Injection - Sangoma Switchbox contains an SQL Injection vulnerability that can allow an unauthenticated remote attacker to execute arbitrary SQL queries that can result in the retrieval of information stored within the database and lead to code execution on the system.
|
8.2.2.1 - 8.4.0.1
|
8.4.0.2
|
||
|
10
|
Unauthenticated SSRF - SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that can allow an unauthenticated remote attacker to send requests on behalf of the system, enabling access to sensitive functionality and can result in an attacker gaining further access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
7.8
|
Authenticated Command Injection - SonicWall SMA1000 Appliances contain a command injection vulnerability that can allow an authenticated remote attacker with administrative privileges to execute arbitrary operating system commands on the device.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.4
|
Authenticated RCE - PaperCut NG/MF contains an unsafe reflection vulnerability that can allow an authenticated attacker to execute arbitrary Java bytecode on the system in the context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
|
Check vendor advisory for affected versions.
|
|||
|
9.8
|
Authentication Bypass - PaperCut NG/MF contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to access and modify administrative functions without authentication. This vulnerability can be chained with CVE-2026-82078 for code execution on the system.
|
Check vendor advisory for affected versions.
|
|||
ICS Advisories
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
Rockwell Automation RSLinx Classic (Multiple CVEs)
|
7.5 - 8.6
|
Denial of Service – Rockwell Automation RSLinx Classic products contain multiple Denial of Service vulnerabilities that can allow an attacker to crash the service, requiring the service to be restarted for recovery.
|
<= V4.50
|
V4.60
|
|
|
Rockwell Automation Redundancy Module Configuration Tool
|
7.3
|
Privilege Escalation – Rockwell Automation Redundancy Module Configuration Tool contains privilege escalation vulnerabilities that can allow an authenticated local attacker to escalate to Administrator or SYSTEM level privileges on the system.
|
10.01.00
|
||
|
7.5
|
Denial of Service - Rockwell Automation Logic Platform contains a Denial-of-Service vulnerability that can allow an attacker to crash the system, requiring a power cycle to recover.
|
<= V33
V34.011 – V34.014
V35.011 – V35.013
V36.011 – V36.012
|
V37.011
V34.015
V35.014
V36.013
|
||
|
7.8
|
Privilege Escalation - Rockwell Automation FactoryTalk Activation Manager contains a privilege escalation vulnerability within the installer that can allow an attacker with local access to obtain SYSTEM-level command prompt through hijacking a visible console window.
|
<= V5.02
|
V5.03
|
||
|
7.5
|
Multiple Rockwell Automation Products contain a denial-of-service vulnerability that can allow an attacker to crash the controllers which can result in a major non-recoverable fault (MNRF), requiring a factory reset to recover.
This vulnerability is a denial-of-service vulnerability within TinyXML, which by sending a crafted XML can create an infinite loop.
|
Check vendor advisory for affected products and versions.
|
|||
|
Rockwell Automation Historian ME
|
4.5 – 8
|
Rockwell Automation Historian ME contains vulnerabilities that can allow an authenticated local attacker execute code on the system. Additionally, an authenticated attacker within the same network can crash the device by sending a specially crafted web request.
|
Series C: 7.101
Series B: 5.202
|
7.102
5.203
|
|
|
8.3
|
Authentication Bypass – Multiple Schneider Electric products contain an authentication bypass vulnerability that can allow a network adjacent attacker to gain access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
Tycon Systems TPDIN-Monitor-WEB2
|
4.3 – 9.8
|
Tycon Systems TPDIN-Monitor-WEB2 contains a vulnerability that can allow an attacker to gain access to an unconfigured device via the installation page.
Additionally, an authenticated attacker can obtain cleartext credentials via configuration pages, which may allow an attacker to compromise additional systems on the local network.
|
< 2.4.5
|
2.4.5
|
|
|
4.6
|
Privilege Escalation – OPCFoundation OPC UA LocalDiscoveryServer (LDS) contains a vulnerability that can allow an attacker to take control of a high-privileged command window during the installation process. In order to exploit this vulnerability, an attack must have physical access via a keyboard and display during installation.
|
< 1.04.420
|
1.04.420
|
||
|
9.4
|
IXON VPN Client contains a CRLF injection vulnerability that can allow an unauthenticated remote attacker to gain privileged access to the system running the VPN client.
|
<= 1.4.6
|
1.4.7
|
||
|
7.3
|
Unauthenticated RCE – Rockwell Automation ControlFLASH contains a vulnerability that can allow an attacker to execute code on the system with privileges of the currently logged in user. This vulnerability is possible due to the installer granting the installation directory write permissions to “Everyone”.
|
< V15.07
|
V15.08
|
||
|
Rockwell Automation ArmorStart LT
|
7.3 – 7.5
|
Rockwell Automation ArmorStart LT contains multiple Cross-Site Scripting vulnerabilities that can allow an attacker to inject malicious JavaScript on the system. Additionally, a Denial-of-Service vulnerability exists which can allow an attacker to crash the webserver via a specially crafted HTTP PUT request.
|
<= V2.001
|
V2.002
|
|
|
7.5
|
Denial of Service – Rockwell Automation 1756-ENBT Module contains a denial of service vulnerability that can allow an attacker to crash the device, requiring the device to be restarted to recover.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.7
|
Insecure Default Permissions - Inductive Automation Ignition contains a vulnerability that can allow an authenticated attacker of any role to create projects on the system.
|
<= 8.1.53
|
8.1.54
|
||
|
9.8
|
Pyramid Solutions NetStaX EtherNet/IP Stack contains a buffer overflow vulnerability that can allow an unauthenticated remote attacker to execute code on the system.
|
< 5.6.1
|
5.6.1
|
||
|
Tycon Systems TPDIN-Monitor-Web3
|
6.5 – 8.8
|
Tycon Systems TPDIN-Monitor-WEB3 contains multiple vulnerabilities that can allow an attacker to intercept sensitive credentials, perform state changing operations via a Cross-Site Request Forgery vulnerability, and gain access to the system without authentication.
|
<= 2.2.9
|
2.4.2
|
|
Updated Malware Signature (Week 1 - September 2026)
|
Threat
|
Description | |
|
OnionDrop
|
OnionDrop is a sophisticated multi-stage malware loader discovered in early 2026 that is known to deploy info-stealing payloads. The infection usually happens when the victims open a malicious ZIP archive that can trigger a malicious DLL sideloading chain.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that The Gentlemen was the most active ransomware group, impacting 25 countries, which accounted for 10.08% of the total ransomware hits. This made The Gentlemen the leading ransomware actor during the reporting period. Qilin recorded the second-highest activity, affecting 21 countries and contributing 8.47% of the total ransomware activity. Orova followed with 19 countries impacted, representing 7.66%, while Inc Ransom and Krybit each affected 16 countries, accounting for 6.45% individually. A significant level of activity was observed from Zawoo, which impacted 15 countries, contributing 6.05% of total ransomware hits. Coinbase Cartel affected 14 countries, representing 5.65%, while Akira impacted 11 countries, accounting for 4.44%. Moderate ransomware activity was observed from Direwolf, which affected 9 countries, contributing 3.63%. Lockbit5 and Brain Cipher each impacted 8 countries, representing 3.23% individually. Dysphor1a affected 7 countries, accounting for 2.82%. Several ransomware groups showed lower but notable activity. ShinyHunters and Wallstreet each impacted 5 countries, contributing 2.02% individually. Iah647, Play, and Vexy each affected 4 countries, representing 1.61% individually. Groups including Falcon, Aurora, Nightspire, DragonForce, Everest, LeakedData, and Pear each impacted 3 countries, accounting for 1.21% individually. PayoutsKing, Doommageddon, Panzer, Insomnia, Global Secret Group, Ransomhouse, Audit Team, and Space Bears each affected 2 countries, contributing 0.81% individually. The remaining ransomware groups, including M3rx, Emperador, Lynx, 3AM, Interlock, Bravox, Fulcrumsec, Majinahanashi, Black X, Deadlock, Rhysida, Kairos, Eclipse, Anubis, TridentLocker, and smaller Space Bears/Vexy variants, each impacted 1 country, representing 0.40% individually. Overall, ransomware activity last week was primarily driven by The Gentlemen, Qilin, Orova, Inc Ransom, Krybit, and Zawoo, which together accounted for a significant portion of global ransomware activity. The distribution indicates a highly active ransomware ecosystem, with both established operators and emerging groups continuing to expand their operational reach across multiple regions. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 101 victims, accounting for 40.73% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing more than two-fifths of all reported ransomware incidents.
Germany recorded the second-highest number of victims, with 15 cases, contributing 6.05% of the total. Canada followed with 9 victims, representing 3.63%, while India also recorded 9 victims, accounting for 3.63% of overall ransomware activity.
Other countries with notable ransomware impact included Taiwan and Mexico, each reporting 7 victims, representing 2.82% individually. Thailand, United Kingdom, and Netherlands each recorded 6 victims, contributing 2.42% individually.
Countries including Spain, Brazil, Indonesia, and Hong Kong each reported 5 victims, accounting for 2.02% individually. France, Italy, Argentina, Malaysia, and Türkiye each recorded 4 victims, contributing 1.61% individually.
Moderate ransomware activity was observed in Myanmar, with 3 victims, representing 1.21% of total activity. Philippines, Switzerland, Australia, China, New Zealand, Sweden, Saudi Arabia, Japan, and Colombia each recorded 2 victims, accounting for 0.81% individually.
The remaining countries recorded 1 victim each, representing 0.40% individually. These included Czechia, Austria, Puerto Rico, Malta, Portugal, North Macedonia, Chile, Qatar, United Arab Emirates, Bhutan, Peru, South Korea, Hungary, South Africa, Panama, Singapore, Guatemala, Ecuador, Russian Federation, and Poland.
Overall, the data shows that ransomware activity was heavily concentrated in the United States, which accounted for a significant share of global victims. However, the presence of impacted organisations across North America, Europe, Asia-Pacific, the Middle East, Africa, and South America demonstrates the continued global reach of ransomware operations and the persistent targeting of organizations across diverse regions.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 42 victims, accounting for 16.94% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Healthcare recorded the second-highest number of victims, with 27 cases, representing 10.89% of the total. Business Services followed with 25 victims, contributing 10.08%, while Retail accounted for 23 victims, representing 9.27% of overall ransomware activity.
Other sectors with significant ransomware impact included Finance, with 15 victims, accounting for 6.05%, and Transportation, with 14 victims, contributing 5.65%. IT recorded 12 victims, representing 4.84% of total activity.
Moderate ransomware activity was observed across several sectors. Hospitality, Education, and Federal each reported 10 victims, accounting for 4.03% individually. Construction, Architecture, and Law Firms each recorded 9 victims, representing 3.63% individually.
Agriculture recorded 8 victims, contributing 3.23%, while Organizations reported 6 victims, accounting for 2.42%. Energy recorded 5 victims, representing 2.02% of the total activity.
Lower levels of ransomware activity were observed in Real Estate, with 4 victims, accounting for 1.61%. Electronics and Telecommunications each recorded 3 victims, contributing 1.21% individually. Insurance reported 2 victims, representing 0.81%.
The least affected sectors were Media & Internet and Consumer Services, each recording 1 victim, accounting for 0.40% individually.
Overall, the data shows that ransomware activity was primarily concentrated in the Manufacturing, Healthcare, Business Services, and Retail sectors. These industries accounted for a major portion of reported victims, highlighting continued attacker focus on sectors with valuable information, critical operations, and a higher likelihood of disruption from ransomware incidents.

Ransomware Group in Focus
AuditTeam Ransomware
Origin and Profile
AuditTeam (styled “Audit Team” on its leak site) is a small double-extortion ransomware operation first observed in early April 2026. ransomware.live added the group on 08 April 2026, the same day its debut victims - Kawasaki Motors Philippines Corporation and South Korean game developer Joycity - were posted. Trackers describe it as a small group that initially concentrated on East and Southeast Asian technology and manufacturing targets, though its victim base has since shifted heavily toward Russia. No law-enforcement action, affiliate programme, or administrator alias has been identified. [1][3][5][6]
The group’s distinguishing feature is its “security audit” persona. Its leak site is branded “/// DATA EXPOSURE TERMINAL ///” and victim posts are styled “AUDIT ENTITY”, each assigned a 16-character hexadecimal “AUDIT ID” and a “DISCOVERY DATE”. The ransom note - a file named [rand].README.txt (randomised prefix) - is addressed to “Executive Management and Legal Compliance Teams”, opens with “[ AUDIT LOG: SEVERE INFRASTRUCTURE COMPROMISE VERIFIED ]”, and frames the ransom as an “Audit & Consulting fee”, offering “OPTION A (REMEDIATION)” - payment, data purge, and a vulnerability report - against “OPTION B (PUBLIC TRANSPARENCY)”, under which the archive is released and clients, partners, and regulators are notified directly. [2][4]
Six months of leak-site history shows roughly 21 posts covering about fourteen distinct entities. Crucially, at least five posts are marked “[ COOPERATION REACHED ]” with the boilerplate “// ALL ACQUIRED DATA HAS BEEN PURGED FROM OUR SERVERS // ENTERPRISE SECURITY REMEDIATION VERIFIED - CASE CLOSED” - covering unnamed entities in China, Thailand, Hong Kong, and Russia. This is rare direct evidence that victims have paid: the group converts more of its small caseload than its volume suggests. [2]
Operating Model and Infrastructure
AuditTeam runs two Tor v3 services: the primary “/// DATA EXPOSURE TERMINAL ///” leak site (87–88% uptime over 30 days) and a separate file server titled “[ SYSTEM ERROR ]” used to host exfiltrated data (down at the time of writing; ~90% uptime over 30 days). Inspection of the scraped site source confirms a static, custom terminal-styled build with /about and /contact pages, a paginated victim grid, and status badges that encode the extortion workflow: REMEDIATION_WINDOW → EVIDENCE_DISCLOSED → PUBLIC_TRANSPARENCY → RESOLVED. No chat, wallet addresses, Session/Tox IDs, email addresses, or mirror domains are embedded anywhere in the scraped source - contact is handled exclusively on-site against the victim’s Audit ID. [2]
The posting lifecycle is unusually disciplined. New victims first appear under a pseudonymised name (e.g. “De***up”, “ma***up”, “PI***al”) with a live countdown of roughly 7–8 days; if the deadline passes without payment, the post is reissued under the organisation’s full name with a corporate profile and evidence description (e.g. “De***up” → Demidov Steel Group, “ma***up” → mansurovogroup, “PI***al” → PIT.local). Audit IDs remain constant across the rename, allowing the two phases to be linked - the same mechanism visible in June (“I-***YS” → I-SYS) and May (“Mo***et” → Mopas, “Tr***ic” → Trésor Public). Paid victims are scrubbed to “COOPERATION REACHED” placeholders rather than deleted, preserving the group’s public record of successful collections. [2]
Negotiation structure is conventional double extortion: the ransom note directs executives to the Tor site with Tor Browser instructions, and threatens direct notification of “clients, partners, and regulatory oversight bodies” alongside publication - a triple-extortion element aimed at regulatory exposure. No public ransom figures, payment addresses, or per-incident negotiation chats have been observed. [2][4]
Sophistication is assessed LOW-MODERATE. Unlike most emerging groups covered in this series, AuditTeam has demonstrated the complete extortion loop: a working ransom note recovered by trackers, a YARA detection rule indexed against its tooling (AuditTeam.yar, indicating at least one analysed sample exists), a dedicated file-hosting service for stolen data, and - most significantly - at least five “COOPERATION REACHED” resolutions consistent with actual payments across six months. The disciplined two-stage naming workflow and persistent Audit-ID linkage indicate a deliberate, methodical operator rather than an opportunistic crew. [2][4]
Offsetting factors keep the assessment from rising further: total volume is very low (~14 entities in six months), long dormant gaps separate posting waves, the infrastructure is a simple static build, and no public reporting documents the group’s encryptor, intrusion tradecraft, or tooling beyond the generic technique set aggregated by commercial platforms (Section 5). Tracker enrichment also shows 66.7% of AuditTeam’s victims with an identified domain carried prior infostealer exposure - suggesting the group leans on commodity credential access rather than bespoke intrusion capability. The group should be treated as a low-volume but proven extortionist whose payment conversion rate makes even small victim counts financially meaningful. [1][4]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework: no public forensic or incident-response write-up exists for AuditTeam. The mapping below combines the recovered ransom note and directly observable leak-site behaviour (HIGH), a YARA rule indexed against the group’s tooling (MODERATE), and a technique set aggregated by commercial threat-intelligence profiling (LOW-MODERATE, marked). Confidence levels are stated per row. [2][4]
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Initial Access
|
T1078
|
Valid Accounts
|
Two-thirds of victims carried prior to infostealer exposure; credential-driven access is the most plausible vector. Contextual enrichment, not intrusion evidence. [1]
|
|
Persistence
|
T1547
|
Boot or Logon AutoStart Execution
|
Aggregated profiling; no primary evidence. [4]
|
|
Persistence
|
T1136
|
Create Account
|
Aggregated profiling; no primary evidence. [4]
|
|
Defence Evasion
|
T1562
|
Impair Defences
|
Aggregated profiling; consistent with ransomware norms. [4]
|
|
Discovery
|
T1046
|
Network Service Discovery
|
Aggregated profiling; consistent with pre-encryption staging. [4]
|
|
Execution
|
T1059
|
Command and Scripting Interpreter
|
Aggregated profiling. [4]
|
|
Lateral Movement
|
T1021/ T1021.001
|
Remote Services/ RDP
|
Aggregated profiling; RDP movement consistent with credential-led intrusions. [4]
|
|
Collection→Exfil
|
T1105
|
Ingress Tool Transfer
|
Aggregated profiling; tooling staged to victim estate. [4]
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
Ransom note asserts encryption (“absolute cryptographic proof… defences fully bypassed”); YARA rule AuditTeam.yar indexed against group tooling confirms a sample exists. [4]
|
|
Impact
|
T1490
|
Inhibit System Recovery
|
Aggregated profiling; shadow-copy/backup destruction typical of the kill chain. [4]
|
|
Impact
|
T1657
|
Financial Theft/ Data Extortion
|
Leak-site publication under countdown, staged pseudonym→reveal workflow, evidence hosting on a separate file service, and direct threats to notify regulators, clients, and partners. Directly observable. [2]
|
Attack Lifecycle
Unlike the purely extortion-evidenced groups in this series, AuditTeam leaves a partial forensic trail - a recovered ransom note and an indexed detection rule - that anchors the impact stage, while the intrusion phase remains documented only through aggregated profiling. Gaps are recorded as gaps. [2][4]
Initial Access through Lateral Movement - Plausible but Unevidenced
No confirmed intrusion narrative exists for any AuditTeam victim. The strong infostealer signal across its victim base (66.7% of victims with domains show prior infostealer exposure) and the aggregated presence of Valid Accounts (T1078) and RDP lateral movement (T1021.001) in its profile make a credential-led intrusion path - purchased or harvested credentials against exposed remote access - the working hypothesis. Nothing public confirms it for any specific incident. [1][4]
Observable artefacts: corporate credentials in infostealer logs; anomalous RDP/VPN authentication from unusual geographies; newly created local or domain accounts; logon-type anomalies against servers hosting financial or operational data.
Collection and Exfiltration - Data Theft with Dedicated Hosting
The ransom note claims acquisition of “extensive archives of corporate data, internal communications, and protected records”, and the group operates a separate Tor file service to host stolen material - an infrastructure investment most small groups skip. Evidence publications (“EVIDENCE_DISCLOSED” status) precede full releases, indicating staged proof-of-possession. Claimed data categories include financial records, order records, file-server content, and software-development assets across its victim base. Volumes are not consistently published and remain unverified. [2]
Observable artefacts: bulk archive creation and staging; large outbound transfers from file servers, finance systems, or document repositories; egress toward anonymity infrastructure or consumer file-sharing services; unexpected tooling transferred onto servers.
Impact - Encryption plus Structured Audit-Themed Extortion
The recovered note - [rand].README.txt - confirms an encryption stage and lays out the two-option extortion model verbatim: pay the “Audit & Consulting fee” for data purge and a vulnerability report (Remediation), or face public release plus direct notification of clients, partners, and regulators (Public Transparency). On-site, the model plays out through the four-state workflow (REMEDIATION_WINDOW → EVIDENCE_DISCLOSED → PUBLIC_TRANSPARENCY → RESOLVED), pseudonymised countdown posts of 7–8 days, full-name reveals on expiry, and purge confirmations for paying victims. [2][4]
Observable artefacts: mass file-rename/encryption events; README.txt files with randomised prefixes dropped across directories; Volume Shadow Copy deletion; the organisation appearing as an “AUDIT ENTITY” on the leak site; outbound Tor connectivity from server VLANs.
Mitigation - Crystal Eye Controls
CE Advanced Firewall
The foundation the rest of the stack sits on. Dividing the estate into security zones bound to interfaces limits how far any single compromise can reach, and traffic rules determine what is allowed, rejected or blocked between them.
CE Intrusion Protection & Detection
Inspects traffic against rulesets authored by Red Piranha’s security operations team and delivered through the service delivery network. Inline mode drops malicious traffic, but only where a corresponding Advanced Firewall traffic rule directs traffic to the IDPS; Detection and Protection mode alerts and logs, converting drop rules to reject.
CE IDPS Local Rules
Allows detection content to be written for campaign-specific indicators - defining protocol, source and destination objects, inspection direction and content match, with Alert, Reject, Drop or Pass actions.
CE Web Filter and Anti-phishing
Addresses delivery, the cheapest point at which to stop an attack. The Anti-phishing engines - Signature, Heuristic, Block SSL Mismatch and Block Cloaked URLs - block phishing and cloaked destinations, while blacklists, banned sites, MIME types and file extensions block malicious infrastructure and payload types.
CE Antivirus and Antimalware File Scanner
Signature and heuristic classification at the gateway, blocking known-malicious files before they reach endpoints, with the Gateway Scan Report providing the daily view of what was blocked and why. Two specific applications here: infostealer families that seed the credential supply, and the AuditTeam encryptor itself - a YARA rule exists and should be incorporated into gateway and endpoint scanning once acquired.
CE Forcefield
Automatically blocks traffic to and from hosts on reputation lists sourced from the service delivery network, cutting off known-bad infrastructure without manual rule writing. The update schedule should be moved to hourly during an active campaign, as criminal infrastructure is typically short-lived.
CE Protocol Filter
Blocks protocols across the network by traffic content, port and type, making it the appropriate control for closing anonymised and consumer file-sharing channels used to move stolen data - directly relevant to an actor that maintains dedicated evidence-hosting infrastructure for stolen archives.
Indicators of Compromise (IOCs)
AuditTeam’s indicator set is richer than most small groups’: two Tor services, a recovered ransom-note filename pattern, an indexed YARA rule, and a set of 16-hex Audit IDs that function as durable victim-correlation keys. All onion indicators are v3 addresses; access only through an isolated Tor research environment.
|
Type
|
Indicator (defanged)
|
|
Tor DLS v3 (onion)
|
6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad[.]onion
|
|
Tor file server (onion)
|
cjg2avmzoly7k6mw7xobnyre354jxro4qegkoazhsmigdk2j3aziexyd[.]onion
|
|
Ransom note artefact
|
[rand].README.txt - randomised prefix, “AUDIT LOG: SEVERE INFRASTRUCTURE COMPROMISE VERIFIED” banner
|
|
YARA rule
|
AuditTeam.yar
|
|
Victim URL scheme
|
/entity/{16-hex} on the DLS
|
Audit IDs - Victim Correlation Keys
Every AuditTeam victim post carries a persistent 16-hex Audit ID that survives the pseudonym-to-reveal rename and appears in ransom-note contact instructions. These IDs are useful for correlating posts, tracker records, and any victim-facing communication. The observed set is listed below; IDs tied to resolved (paid) cases identify the group’s collection history.
|
Audit ID
|
Linked entity/status
|
|
DA68891EA2CD44B6
|
mansurovogroup (RU) - in-window reveal, discovery 2026-08-26
|
|
3382542458FC4332
|
PIT.local (CO) - in-window reveal, discovery 2026-08-27
|
|
22C42D81C3DA7328
|
Demidov Steel Group (RU) - revealed 26 Aug
|
|
C66B828414389C27
|
I-SYS (RU) - revealed 25 Jun
|
|
CC92E841B75A3DF6
|
Mopas Online Supermarket (TR) - revealed 23 May
|
|
D6A9F21B7E4C3A59
|
Trésor Public / DGCPT (SN) - revealed 18 May
|
|
168B1F8DD83F7DD9
|
ca***lm (RU) - never revealed
|
|
CCD233FEE92FFA2D / A98A624456DA525F / D3C1388C1B73BCA2 / B35411691DDC2265 / 111CEAA5AD9DA2F1
|
“Paid Victim” / COOPERATION REACHED cases (CN, TH, HK, RU ×2)
|
|
B7E1F9A2D4C86352 / C1C23C2621D1D387 / 6B55D91EA16DCB48 / 17E19C9B6B41D33F / A62A883688D9CFC1 / 974E9F6C44C975EA / D1DDFB2A56855328 / 8672CA95161255F7
|
Additional IDs harvested from the scraped site source (entity pages and archives); exact victim mapping not publicly resolvable
|
References
[1] Ransomware.live - AuditTeam group profile (incl. ransom-note and YARA-rule index entries, infostealer enrichment) and Aug/Sep 2026 victim datasets (weekly statistics in Sections 1–3 computed from the ransomware.live API, discovery timestamps 29 Aug–04 Sep 2026 UTC) - https://www.ransomware.live/group/AuditTeam
[2] RansomLook - Audit Team group profile, post archive, site-source capture, and uptime monitoring - https://www.ransomlook.io/group/audit%20team
[3] Breachsense - AuditTeam group profile and victim index - https://www.breachsense.com/ransomware-groups/auditteam/
[4] RansomLook ransom-note archive - AuditTeam [rand].README.txt full text; SOCRadar audit team group profile (aggregated TTPs) - https://www.ransomlook.io/notes/auditteam ; https://socradar.io/free-tools/ransomware-intelligence/groups/audit-team
[5] DeXpose - AuditTeam incident alerts (Joycity; Kawasaki Motors Philippines), Apr 2026 - https://www.dexpose.io/auditteam-ransomware-attack-on-joycity/
[6] SOCRadar - Kawasaki Motors Philippines Corporation victim record - https://socradar.io/free-tools/ransomware-intelligence/victims/kawasaki-motors-philippines-corporation-audit-team-cd6c01bb
[7] Undercode News - “AuditTeam Ransomware Targets Demidov Steel Group”, Aug 2026 - https://undercodenews.com/
[8] GalaxyWarden - “Audit Entity Listed by Audit Team Ransomware Group” (mansurovogroup listing, filing DA68891EA2CD44B6), 04 Sep 2026 - https://www.galaxywarden.com/blog/breach/audit-entity-auditteam-2026-09
[9] Malpedia (Fraunhofer FKIE) and MalwareBazaar/abuse.ch - negative finding for AuditTeam family entries and samples - https://malpedia.caad.fkie.fraunhofer.de/ ; https://bazaar.abuse.ch/browse/
[10] Black Kite - 2026 Ransomware Report (ecosystem context: 7,551 victims, fragmentation, new-entrant churn) - https://blackkite.com/reports/2026-ransomware-report