| New Threats Detection Added | • GateSentinel • TryNodeRAT |
| New Threat Protection | 11 |
| Newly Detected Threats | 166 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
GateSentinel | ||||||||||||||||||||||||
|
GateSentinel is an open source, lightweight, modern C2 (command-and-control) framework on Github commonly used for security research and penetration testing. It utilises a Go-based server and a C-based client (the beacon). GateSentinel supports HTTP and HTTPS, stealthy c2 traffic masquerading as legitimate web content, and configurable endpoints designed to evade detection.
|
|||||||||||||||||||||||||
|
Threat Protected:
|
07 | ||||||||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||||||||
|
Class Type:
|
Trojan-activity | ||||||||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||||||||
Known Exploited Vulnerabilities (Week 4 - September 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-4th-week-of-september-2026/699.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
9.5
|
Unauthenticated RCE - Citrix NetScaler ADC and NetScaler Gateway contains a buffer overflow vulnerability that can allow an attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.5
|
Unauthenticated RCE - Citrix NetScaler ADC and NetScaler Gateway contains a command execution vulnerability that can allow an unauthenticated remote attacker to execute arbitrary commands on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
6.9
|
Authentication Bypass - Mikrotik RouterOS contains vulnerability that can allow an unauthenticated remote attacker to open a session channel and send exec request. This vulnerability can be chained with CVE-2026-86060 to elevate to root level privileges.
|
6.0 - 6.49.20
7.0 - 7.23.3 7.24 - 7.24.1 |
6.49.21
7.23.4 7.24.2 |
||
|
8.8
|
Authenticated RCE - Microsoft SharePoint (On-prem) contains a vulnerability that can allow an authenticated remote attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.1
|
Unauthenticated RCE - WordPress Core contains a vulnerability within the page-template resolution that can allow an unauthenticated remote attacker to include '.php' files which get executed in the context of the webserver, leading to code execution on the system.
|
Check vendor advisory for affected versions.
|
|||
|
10
|
Unauthenticated RCE - WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a vulnerability that can allow an unauthenticated remote attacker to bypass authentication and execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.1
|
Authentication Bypass - Adobe Commerce and Magento contains a privilege escalation vulnerability that can allow an unauthenticated remote attacker to gain access to the system.
|
Check vendor advisory for affected versions.
|
|||
|
10
|
Unauthenticated RCE - Arista VeloCloud Orchestrator (VCO) on-prem contains a vulnerability that can allow an unauthenticated remote attacker to access privileged internal functionality which can lead to code execution on the system.
|
5.2.0 - 5.2.3.15
6.1.0 - 6.1.3.7 6.4.0 - 6.4.2.7 7.0.0 - 7.0.0.2 |
5.2.3.16
6.1.3.8 6.4.2.8 7.0.0.3 |
||
|
9.8
|
Unauthenticated RCE - F5 BIG-IP APM contains a buffer overflow vulnerability that can allow an unauthenticated remote attacker to execute code on the system.
|
Check vendor advisory for affected versions.
|
|||
|
9.8
|
Unauthenticated RCE - Multiple Check Point products contain a path traversal vulnerability that can allow an unauthenticated remote attacker to upload and execute arbitrary code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Unauthenticated RCE - Check Point Security Gateway and Spark Firewall contain a vulnerability that can allow an unauthenticated remote attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Unauthenticated RCE - Zyxel GS1900 series switches contain a buffer overflow vulnerability that can allow an unauthenticated attacker within the same network to execute operation system commands via a specially crafted HTTP request.
|
Check vendor advisory for affected products and versions.
|
|||
ICS Advisories (Week 4 - September 2026)
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
lwIP
|
Contains a vulnerability that can allow an unauthenticated attacker to execute code on the device.
|
2.0.1 – 2.2.1
|
|||
|
Lightweight IP
CVE-2026-91018 (CVSS: 8.8)
|
Contains a double free vulnerability within the API that can allow an attacker to execute code on the system.
|
2.0.1 – 2.2.1
|
|||
|
Siemens
|
Contains a vulnerability within the OIS web module that can allow an authenticated attacker to upload arbitrary files on the system which can lead to an attacker gaining root level access to the host system.
|
Check vendor advisory for affected products and versions.
|
|||
|
SIPLUS and SIMATIC Products
CVE-2026-31431 (CVSS: 7.8)
|
Contains a vulnerability that can allow an authenticated local attacker to escalate privileges on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
Contains a vulnerability within the client application that can lead to code execution when a user opens an image with an embedded malicious script.
|
V6
V7 |
N/A
|
|||
|
Contains a authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to a user account through the password reset functionality.
|
Check vendor advisory for affected products and versions.
|
||||
|
Contains a path traversal vulnerability that can allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system.
|
Check vendor advisory for affected products and versions.
|
||||
|
Contains a denial-of-service vulnerability that can allow an unauthenticated remote attacker to force the device into protection mode, preventing remote access to the devices.
|
WTV676: < 3.9.4
WTV776: < 4.17 |
3.9.4
4.17 |
|||
|
Autonomy Logic
|
Contains a cross-site scripting vulnerability that can result in JavaScript execution when a user visits a specially crafted page.
|
3
|
N/A (End-of-life)
|
||
|
Botslab
|
G980H Dashcams
Multiple CVEs (14x) (CVSS: 4.6 – 8.8) |
Contains multiple vulnerabilities that can allow an attacker to bypass authentication, access sensitive information and modify device configuration.
|
Check advisory for affected products and versions.
|
||
|
Eufy
|
Omni C2, Omni X10 Pro
CVE-2026-93289 (CVSS: 7.5) CVE-2026-93290 (CVSS: 5.5) CVE-2026-93291 (CVSS: 9.3) |
Contains vulnerabilities that can allow an unauthenticated attacker to execute operating system commands on the device, gain access to the device through hardcoded credentials, and a lack of certificate validation can facilitate a man-in-the-middle attack which can lead to code execution on the device.
|
< 1.6.4
|
1.6.4
|
|
Updated Malware Signature (Week 4 - September 2026)
|
Threat
|
Description | |
|
TryNodeRAT
|
TryNodeRAT is a Node.js based remote access trojan (RAT) designed to target systems capable of running Node.js - Windows, macOS and Linux. This allows the attacker to gain full unauthorised access that communicates with command-and-control (C2) infrastructure to execute commands, gather system information, manage files and deploy additional malicious payloads. TryNodeRAT often uses obfuscation or bundles a portable Node.js executable file to avoid being detected by standard antivirus.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Clop was the most active ransomware group, impacting 23 victims, which accounted for 13.29% of the total ransomware hits. This made Clop the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, affecting 21 victims and contributing 12.14% of the total ransomware activity. Qilin followed with 17 victims, representing 9.83%, while Akira impacted 9 victims, accounting for 5.20%. A significant level of activity was observed from Inc Ransom, which affected 8 victims, contributing 4.62% of total ransomware activity. Wallstreet recorded 7 victims, representing 4.05%. DragonForce, Booba Team, and Everest each impacted 6 victims, accounting for 3.47% individually. Moderate ransomware activity was observed from Emperador and Storm, each affecting 5 victims, representing 2.89% individually. Krybit, Panzer, Lockbit5, and Zawoo each recorded 4 victims, contributing 2.31% individually. Several ransomware groups showed lower but notable activity. Arcus Media, Rhysida, LeakedData, Termite, and Pear each impacted 3 victims, accounting for 1.73% individually. Unsafe, Vexy, Audit Team, Orova, Nightspire, Play, Anubis, Global Secret Group, and Titan each recorded 2 victims, representing 1.16% individually. The remaining ransomware groups, including Cry0, Bravox, Money Message, Doommageddon, 3AM, Secp0, Kairos, Blacklocks, ShinyHunters, Space Bears, Brain Cipher, and others, each recorded 1 victim, accounting for 0.58% individually. Overall, ransomware activity last week was primarily driven by Clop, The Gentlemen, Qilin, Akira, Inc Ransom, and Wallstreet, which accounted for a significant share of the observed ransomware activity. The distribution highlights continued activity from both large-scale ransomware operators and smaller emerging groups, demonstrating the ongoing diversification of the ransomware threat landscape. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 66 victims, accounting for 38.15% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing more than one-third of all reported ransomware incidents.
Brazil recorded the second-highest number of victims, with 9 cases, contributing 5.20% of the total. Canada followed with 8 victims, representing 4.62%, while Italy, France, and the United Kingdom each recorded 7 victims, accounting for 4.05% individually.
Germany recorded 5 victims, contributing 2.89% of overall ransomware activity. Other countries with notable impact included Portugal, India, Thailand, Spain, Finland, South Africa, and Australia, each reporting 3 victims, representing 1.73% individually.
Moderate ransomware activity was observed in Türkiye, Japan, Argentina, Peru, Colombia, Austria, El Salvador, and Singapore, each recording 2 victims, accounting for 1.16% individually.
The remaining countries recorded 1 victim each, representing 0.58% individually. These included Viet Nam, Russian Federation, Switzerland, Hong Kong, Paraguay, Angola, Somalia, Israel, Netherlands, Mexico, Indonesia, Russia, Lebanon, Georgia, New Zealand, Oman, Czech Republic, South Korea, Ukraine, Tanzania, Taiwan, Saudi Arabia, Macao, Kenya, Morocco, Sweden, and Belgium.

Industry-wide Ransomware Victim
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 26 victims, accounting for 15.03% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 21 cases, representing 12.14% of the total. Retail followed with 19 victims, contributing 10.98%, while Healthcare accounted for 18 victims, representing 10.40% of overall ransomware activity.
Other sectors with significant ransomware impact included IT, with 15 victims, accounting for 8.67%, and Education, with 10 victims, contributing 5.78%. Finance recorded 8 victims, representing 4.62% of the total activity.
Moderate ransomware activity was observed in Law Firms and Transportation, each with 7 victims, accounting for 4.05% individually. Federal, Energy, and Insurance each recorded 6 victims, contributing 3.47% individually. Real Estate reported 5 victims, representing 2.89%.
Lower levels of ransomware activity were observed in Hospitality, with 4 victims, accounting for 2.31%. Agriculture recorded 3 victims, contributing 1.73%. Electronics, Minerals & Mining, Construction, Consumer Services, and Media & Internet each reported 2 victims, representing 1.16% individually.
The least affected sectors were Telecommunications and Architecture, each recording 1 victim, accounting for 0.58% of the total ransomware activity.

Zawoo Ransomware
Executive Summary
During the reporting window, public ransomware trackers recorded new Zawoo disclosure activity concentrated in France. RansomLook showed four published posts dated 24 September and three matching unpublished company-ID rows dated 19 September. No direct victim acknowledgement, regulator notice, or law-enforcement confirmation was identified for the named organisations in the reviewed sources. [1][7]
The strongest technical finding is the RansomLook static analysis of a Linux ELF64 Synology-focused sample. That sample uses a two-stage design: a silent stage encrypts file contents without renaming or dropping notes, and a later stage renames files and drops ransom notes. The binary itself contains no network or command-and-control capability, so data-theft claims require separate validation from egress telemetry or incident evidence. [2][3]
Group Overview
Public reporting places Zawoo or ZaWoo Team among newer ransomware or extortion operations first visible in August 2026. Zawoo Team among newly observed ransomware groups emerged in August and assessed that the group appears to use AI-assisted analysis or structured victim assessments on its data leak site. Certainity reported that the group had no leak site until 30 August, when it posted an initial batch of victims. [4][9]
Certainity's incident-response write-up describes one hands-on-keyboard intrusion involving valid VPN credentials without MFA, custom PowerShell scripts, PsExec, RDP, DSInternals, HRSword, local staging, and split 7z archives. Because this is a single engagement, it should not be treated as a complete Zawoo operating model. [4]
Technical Analysis
ZAWOOO Synology NAS Sample
RansomLook analysed sample 33d3afddaa5710cdcc4e93a7bae8be010c19747fb53d85fcd54ef32056a1eb0b as an ELF64 static-pie Synology NAS encryptor. The sample is built for x86-64 Synology DSM environments, uses Synology-specific exclusions, and defaults to scanning /volume* paths. [3]
The most important behaviour is the two-stage encryption model. Silent mode encrypts file contents in place without changing filenames or dropping notes. A later detonation mode identifies already encrypted files by footer magic, renames them, and drops How To Restore Your Files.txt. This makes backups taken during the silent phase risky because they may contain ciphertext under normal filenames. [2][3]
The analysed Linux binary contains no network capability. RansomLook specifically reported no command-and-control, no persistence, no lateral movement, no credential access, and no exfiltration capability inside that payload. The ransom note's data-leak threat therefore cannot be validated from this sample alone. [2][3]
Certainity Incident Evidence
Certainity's case evidence points to an enterprise intrusion path rather than a payload-only view. Observed activity included VPN access with valid already-privileged credentials, no MFA on the VPN, review and modification of SYSVOL netlogon scripts, Everything and tree output for discovery, DSInternals against a domain controller, PsExec and RDP activity, HRSword drivers, and local staging into split 7z archives. Exfiltration was assessed as highly likely in that case because a recovered deleted archive fragment matched a leak-site filename, but the authors stated that their own telemetry did not prove data left the network. [4]
PCrisk Sample Context
PCrisk documented ZAWOOO on 12 August after examining malware submitted to VirusTotal. That report described random filename replacement, a How To Restore Your Files.txt note, Session contact, and the address zawooorecover [at] onionmail[.]org. The sample context helps connect the ZAWOOO name, note filename, and contact channel, but it should not be used by itself to infer the intrusion path for September victims. [5]
MITRE ATTACK Mapping
|
Tactic
|
Technique | Evidence Basis |
|
Initial Access
|
T1078 Valid Accounts
|
Certainity observed VPN login with valid already-privileged credentials and no MFA in one engagement. [4]
|
|
Discovery
|
T1135 Network Share Discovery
|
SYSVOL netlogon scripts, Everything, and tree output were observed in the Certainity case. [4]
|
|
Credential Access
|
T1003.003 NTDS
|
Certainity observed DSInternals run against a domain controller. [4]
|
|
Lateral Movement
|
T1021.001 and T1021.002 Remote Services
|
RDP and PsExec activity were observed in the Certainity case. [4]
|
|
Defence Evasion
|
T1562.001 Impair Defences
|
HRSword drivers and tooling were observed in the Certainity case. [4]
|
|
Impact
|
T1486 Data Encrypted for Impact
|
Both Certainity and RansomLook describe encryption behaviour; RansomLook provides payload-level detail for the Linux sample. [3][4]
|
|
Exfiltration
|
T1567 Exfiltration Over Web Service
|
Certainity assessed likely exfiltration but could not prove it from firewall telemetry. The Linux sample has no network capability. [3][4]
|
Indicators of Compromise
The indicators below are suitable for scoped defensive hunting. They should not be treated as proof that a specific named organisation was compromised. Network values are defanged where appropriate. [2][3][4][5]
|
Type
|
Indicator | Use and limits |
|
SHA-256
|
33d3afddaa5710cdcc4e93a7bae8be010c19747fb53d85fcd54ef32056a1eb0b
|
RansomLook Synology/Linux sample. [3]
|
|
SHA-1
|
9d371d77700dca0950249b8e8a1da128dbbdc719
|
Same sample family context from RansomLook. [3]
|
|
MD5
|
d8957e860cb421e9c06e0fd05010cd4b
|
Same sample family context from RansomLook. [3]
|
|
SHA-256
|
dd21e22e2c4fffc5939dc6e42ee42ed497138d17245b59dcf4b0aca9739e337e
|
VirusTotal sample cited by Certainity; not recovered by that responder. [4]
|
|
Email
|
zawooorecover [at] onionmail[.]org
|
PCrisk and RansomLook sample contact. Variant-specific. [2][5]
|
|
Email
|
zawooorestore [at] onionmail[.]org
|
Certainity case contact. Variant-specific. [4]
|
|
Onion
|
fyenuhkq3pfhnbpidj5jm2fl2lryxip4byhg6eozynrnlomu4szf2nyd[.]onion
|
RansomLook Zawoo DLS. Do not browse from production networks. [1]
|
|
Path
|
/etc/slient-time/baseline.stamp
|
High-value marker for the Linux sample's silent stage. [3]
|
|
Path
|
/etc/f-index/baseline.stamp
|
Index baseline for the Linux sample's staged file inventory. [3]
|
|
Path
|
/var/run/enc-nas.lock
|
Linux sample single-instance lock. [3]
|
|
Note
|
How To Restore Your Files.txt
|
Ransom note name across public reporting; capitalisation may vary. [2][5]
|
Detection Opportunities
- On Synology NAS systems, hunt for /etc/slient-time, /etc/f-index, /var/run/enc-nas.lock, and widespread How To Restore Your Files.txt creation. [2][3]
- Search NAS shares and backup sets for the ZAWOOO footer magic described by RansomLook before restoring any backup created after suspected silent encryption began. [2][3]
- Alert on unusual sustained read/write access to large NAS files, especially fixed-stride writes from a single process. [3]
- For Windows domain environments, monitor VPN logins without MFA, privileged-account use from unusual sources, PsExec service creation, RDP sessions, DSInternals activity, and SYSVOL netlogon script changes. [4]
- Search for HRSword artifacts such as sysdiag.sys, hrwfpdrv.sys, and usysdiag.exe when compatible with the environment and baseline. [4]
- Correlate any leak-site listing with outbound-transfer telemetry before concluding that exfiltration occurred. [3][4]
Mitigation Recommendations
- Enforce phishing-resistant MFA on VPN and remote-access paths, especially for privileged users. [4]
- Protect Synology DSM management interfaces from direct internet exposure and audit QuickConnect, SSH, and administrative login history. [3]
- Keep immutable or off-appliance backups and validate restore points for ZAWOOO footer markers before recovery. [2][3]
- Audit domain-controller access for DSInternals, NTDS extraction, suspicious registry exports, and privileged PowerShell history. [4]
- Monitor for unauthorised archiving tools and large local staging directories on servers. [4]
- Retain firewall, VPN, proxy, EDR, and file-server logs long enough to prove or disprove exfiltration. [4]
Red Piranha CE 6.0 Mitigation and Remediation Alignment
The following actions map the Zawoo detection opportunities to Red Piranha Crystal Eye 6.0 manual control areas.
- NAS and file-share encryption: Use Advanced Firewall zones and traffic rules to restrict SMB, NFS, and admin access to approved hosts; inspect selected flows with IDPS profiles or local rules.
- PsExec, RDP, and domain-controller activity: Create IDPS local rules or rulesets for SMB, RDP, and Active Directory patterns, then run them in Detection, Protection, or Inline mode where risk permits.
- Archive staging and suspected exfiltration: Use Threat Hunt Dashboard network activity, top users, top devices, top external IPs, and protocol or application activity to find upload spikes and top talkers.
- Malicious downloads and dual-use tooling: Use Gateway Antivirus and Gateway Scan reporting to inspect files in transit with signature and heuristic analysis and review blocked URL, source IP, reason, and content type.
Known Intelligence Gaps
- No direct victim confirmation for the September 19 to 25 claims.
- No primary spreadsheet or source-of-truth weekly dataset was supplied for independent statistical reconciliation.
- No authenticated exact-hash platform checks were completed in this workspace.
- No verified payment, wallet, negotiation, or settlement evidence was found.
- No confirmed initial-access vector exists for the September leak-site victims.
- No evidence proves that the Synology/Linux sample was used against the September French victims.
Source References
[1] RansomLook Zawoo group page. https://www.ransomlook.io/group/zawoo
[2] RansomLook ZAWOOO CTI report. https://www.ransomlook.io/group/zawoo/analysis/cti_report
[3] RansomLook ZAWOOO Linux full analysis. https://www.ransomlook.io/group/zawoo/analysis/linux
[4] Certainity Inside a Zawoo Team Intrusion. https://certainity.com/en/blog/zawoo-team-ransomware/
[5] PCrisk ZAWOOO ransomware removal guide. https://www.pcrisk.com/removal-guides/35728-zawooo-ransomware
[6] Derp ZaWoo ransomware profile. https://www.derp.ca/ransomware/zawoo/
[7] Rosetta Intel Threat Watch Sep 25 2026. https://intel.rosettalab.dev/threat/2026-09-25
[8] Yazoul AMB PVC ransomware claim by ZaWoo. https://www.yazoul.net/intel/claim/2026-09-24-amb-pvc-ransomware-claim-by-zawoo-aug-2026/
[9] Arete ransomware trends and data insights August 2026. https://areteir.com/resources/ransomware-trends-data-insights-august-2026