Last Week in Threats: Week 33
Bottom Line
What changed this week: Clop and Qilin ransomware groups doubled their leak-site postings this week while CISA added three actively-exploited vulnerabilities to the KEV catalog (a Cisco firewall denial-of-service flaw, a Windows privilege-escalation zero-day linked to the Lazarus group, and a Metabase SQL injection enabling full database access).
Who is most exposed: Healthcare and education organizations running Cisco Secure Firewall products, Windows endpoints, or Metabase analytics dashboards face the highest risk.
Recommended action: Patch the three KEV vulnerabilities by their due dates and hunt for lateral movement originating from edge devices or analytics platforms that may have been compromised before patches shipped.
The Week in Review
The week of August 10 to 16, 2026 saw Clop and Qilin ransomware operations more than double their leak-site activity. Clop posted 46 victims (up 100% from the prior week's 23), Qilin posted 37 (up 208% from 12), and The Gentlemen maintained steady pressure with 31 postings. Healthcare organizations bore the brunt of the targeting, with 2,612 victims tracked across the year through mid-August, followed by education at 1,353 victims. United States organizations accounted for 82 of the week's 242 leak-site postings.
On the vulnerability front, CISA added three exploited flaws to the KEV catalog on August 11. All three are under active attack: a Cisco firewall heap-inspection flaw enabling denial of service (CVE-2026-20349), a Windows WinSock use-after-free permitting privilege escalation that AlienVault OTX ties to Lazarus and a rootkit dubbed FudModule (CVE-2026-68820), and a Metabase SQL injection granting unauthenticated admin access (CVE-2026-72898). The attacker-infrastructure picture split evenly between hosting providers and compromised residential connections, with 45.148.10.157 drawing the most abuse reports (215,162 from 900 distinct submitters).
Ransomware Leak-Site Activity
Clop and Qilin ramped up extortion operations this week, with Clop posting 46 victims and Qilin posting 37 (both more than doubling their prior-week totals). The Gentlemen remained active with 31 postings, while Direwolf (15 victims) continues a multi-month run that began in May 2025. United States organizations accounted for 82 of the 242 total postings, followed by Italy (15), the United Kingdom (12), and Germany (11). (ransomware.live, pulled 2026-08-23)
- Victim postings this week: 242 (complete Monday-Sunday coverage, ransomware.live, pulled 2026-08-23)
- Week-over-week: Clop up 100% (23 → 46), Qilin up 208% (12 → 37), The Gentlemen up 24% (25 → 31)
- Most active groups: Clop (46), Qilin (37), The Gentlemen (31), Direwolf (15), Storm (10)
- Top victim countries: United States (82), Italy (15), United Kingdom (12), Germany (11), India (10)
- New group this week: none
Sector & Technology Watch
Healthcare and education organizations are the most-targeted industries, with 2,612 healthcare victims and 1,353 education victims tracked year-to-date through mid-August. This week's three new KEV vulnerabilities put edge firewall appliances (Cisco), Windows environments, and business analytics platforms (Metabase) in the crosshairs. (ransomware.live, pulled 2026-08-23; CISA KEV, added 2026-08-11)
- Most-targeted industries: Healthcare (2,612 victims), Education (1,353), plus high activity in Manufacturing and Technology (ransomware.live, pulled 2026-08-23)
- Technology in the crosshairs: Edge/firewall appliances (Cisco Secure Firewall ASA/FTD), Windows endpoints (privilege escalation zero-day), business analytics platforms (Metabase)
- If you run Cisco ASA/FTD, Windows, or Metabase: confirm the three KEV items are patched by their due dates and hunt for outbound connections from edge devices and analytics platforms to unusual destinations
Most-Reported Malicious IPs
One hundred IPs reached 100% confidence on AbuseIPDB's blacklist as of August 23. The top-reported address (45.148.10.157, operated by TECHOFF SRV LIMITED in a datacenter) drew 215,162 abuse reports from 900 distinct submitters. Residential connections accounted for seven of the fifteen most-reported IPs, reflecting compromised home routers and consumer broadband endpoints rather than malicious ISPs. (AbuseIPDB usage-type as of 2026-08-23; scanner context from GreyNoise Community as of 2026-08-23)
- 100%-confidence entries listed: 100
- Most-reported this week: 45.148.10.157 (215,162 reports / 900 reporters, hosting), 79.124.49.70 (7,309 / 243, residential), 113.193.234.210 (5,052 / 1,033, residential), 45.4.179.4 (4,457 / 972, residential), 180.168.24.186 (2,120 / 690, residential) (AbuseIPDB usage-type as of 2026-08-23)
- Top source countries: United States (21), Netherlands (6), China (5), Germany (5), South Korea (4)
Context matters: Two addresses in the top 15 are benign research scanners (199.45.155.55 operated by Censys, 5.252.83.8 operated by Infrawatch), flagged by GreyNoise Community as of 2026-08-23. The residential addresses are compromised consumer endpoints, not malicious ISPs.
Attacker Infrastructure & Networks
This week's malicious IPs split evenly between hosting providers and compromised residential connections: 7 hosting, 7 residential, 1 business. None of the top 15 addresses appeared in ThreatFox C2 or URLhaus malware-host feeds, indicating pure brute-force/scanning activity with no detected malware-infrastructure overlap. Network-ownership data was partially collected due to API timeouts, yielding ASN attribution for 2 of the 15 top IPs. (Network owner and hosting type: AbuseIPDB usage-type as of 2026-08-23; ASN: AlienVault OTX as of 2026-08-23; malware-infra correlation: ThreatFox (abuse.ch) and URLhaus (abuse.ch), pulled 2026-08-23)
- Hosting vs. home: 7 of 15 enriched IPs traced to consumer/residential connections (compromised endpoints), 7 to hosting/datacenter providers, 1 to business/commercial (AbuseIPDB usage-type as of 2026-08-23)
- Also known malware infrastructure: none this week (0 of 15 IPs flagged in ThreatFox C2 or URLhaus payload-host feeds; ThreatFox (abuse.ch) / URLhaus (abuse.ch), pulled 2026-08-23)
The residential IPs reflect compromised home routers and consumer broadband endpoints rather than malicious providers. The hosting-side IPs are operated by datacenter providers and warrant scrutiny as potential bulletproof or abuse-tolerant infrastructure.
Exploited-Vulnerability Watch
CISA added three actively-exploited vulnerabilities to the KEV catalog on August 11. All three have confirmed in-the-wild exploitation tracked by AlienVault OTX community pulses. Each CVE links to its NVD detail page; the full catalog is the CISA KEV catalog. (CISA KEV, added 2026-08-11; weaponized-CVE signal from AlienVault OTX, pulled 2026-08-23)
- CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) – heap inspection flaw enabling unauthenticated remote denial of service; remediation due August 14, 2026 (CISA KEV, added 2026-08-11). In-the-wild exploitation confirmed by AlienVault OTX (2 pulses, "Cisco Firewall Zero Day Under Active Attack"; AlienVault OTX, pulled 2026-08-23).
- CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock) – use-after-free in AFD.sys permitting local privilege escalation; remediation due August 25, 2026 (CISA KEV, added 2026-08-11). AlienVault OTX ties this to Lazarus group exploitation and a rootkit dubbed FudModule (8 pulses, "Lazarus Exploits Windows Zero-Day (FudModule Rootkit)"; AlienVault OTX, pulled 2026-08-23).
- CVE-2026-72898 (Metabase) – unauthenticated SQL injection enabling full administrator access and data theft; remediation due August 14, 2026 (CISA KEV, added 2026-08-11). In-the-wild exploitation confirmed by AlienVault OTX (1 pulse, "Metabase Unauth SQLi Zero-Day (Admin Access)"; AlienVault OTX, pulled 2026-08-23).
Malware & C2 This Week
ThreatFox cataloged 2,257 high-confidence indicators and 794 active command-and-control endpoints in the three-day period leading up to the weekly pull. JavaScript-based fake-update campaigns (js.clearfake, js.iclickfix) and Python-based info-stealers (py.venus_stealer) dominated the malware landscape, alongside continued Vidar and Sliver activity. (ThreatFox (abuse.ch), pulled 2026-08-23)
- Top malware families: js.clearfake (386 IOCs), js.iclickfix (234), unknown_loader (166), py.venus_stealer (138), win.vidar (98), win.sliver (98) (ThreatFox (abuse.ch), pulled 2026-08-23)
- Fresh C2 indicators: 794 high-confidence C2 IOCs (ThreatFox (abuse.ch), pulled 2026-08-23)
This Week's Hunting Takeaway
CVE-2026-68820 is a local privilege-escalation zero-day in the Windows WinSock driver (AFD.sys) under active exploitation by the Lazarus group, with AlienVault OTX tying it to a rootkit dubbed FudModule. The attack chain typically begins with an initial compromise, followed by unsigned kernel-mode driver loads to escalate privileges, credential harvesting, and lateral movement. Hunt for unsigned driver loads in rapid succession with credential access and outbound network connections.
Hunt: Unsigned Kernel Driver Loads Followed by Credential Access
Behavior Targeted: Unsigned or untrusted kernel-mode driver loads followed by LSASS memory access or credential dumping, indicating privilege escalation paired with credential harvesting
MITRE ATT&CK: T1068 (Exploitation for Privilege Escalation), T1003 (OS Credential Dumping)
Telemetry: Sysmon (Event ID 6: driver load), Windows Defender (driver-load events), EDR process/memory-access logs
False Positive Likelihood: LOW (unsigned driver loads are rare in managed environments; the sequence is high-fidelity)
Splunk SPL Query
index=windows sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational EventCode=6
| eval driver_signature=if(isnull(Signature) OR Signature="", "unsigned", "signed")
| where driver_signature="unsigned"
| transaction host maxspan=5m
| search sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational EventCode=10
TargetImage="*lsass.exe"
| table _time, host, ImageLoaded, Hashes, SourceImage, TargetImage
| sort 0 _time
Microsoft KQL Query (Defender/Sentinel)
// Unsigned driver loads followed by LSASS access within 5 minutes
let UnsignedDrivers = DeviceEvents
| where ActionType == "DriverLoad"
| where InitiatingProcessVersionInfoProductName == "" or isempty(InitiatingProcessVersionInfoProductName)
| project Timestamp, DeviceName, DriverPath=AdditionalFields.ImageLoaded, DriverHash=SHA256;
let LsassAccess = DeviceProcessEvents
| where ProcessCommandLine has "lsass" or FileName =~ "lsass.exe"
| project Timestamp, DeviceName, TargetProcess=FileName;
UnsignedDrivers
| join kind=inner (LsassAccess) on DeviceName
| where (Timestamp1 - Timestamp) between (0min .. 5min)
| project Timestamp, DeviceName, DriverPath, DriverHash, TargetProcess
| order by Timestamp desc
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Check Your Environment
Take this week's high-confidence malicious IPs and newly exploited CVEs and look for them in your own telemetry. These sweeps are a starting point: the IP list is drawn straight from the appendix, and the benign research scanners noted above are deliberately excluded.
Splunk SPL – sweep this week's malicious IPs
index=* (src_ip IN ("119.96.158.238","113.193.234.210","57.155.67.48","209.205.206.247","213.209.159.16","51.38.71.55","79.124.49.70","181.214.83.147","45.148.10.157","180.168.24.186","220.86.129.106","45.4.179.4","185.177.72.56") OR dest_ip IN ("119.96.158.238","113.193.234.210","57.155.67.48","209.205.206.247","213.209.159.16","51.38.71.55","79.124.49.70","181.214.83.147","45.148.10.157","180.168.24.186","220.86.129.106","45.4.179.4","185.177.72.56"))
| stats count min(_time) as first_seen max(_time) as last_seen values(sourcetype) as sourcetypes by src_ip, dest_ip
| convert ctime(first_seen) ctime(last_seen)
Microsoft KQL – sweep this week's malicious IPs
let weekIPs = dynamic(["119.96.158.238","113.193.234.210","57.155.67.48","209.205.206.247","213.209.159.16","51.38.71.55","79.124.49.70","181.214.83.147","45.148.10.157","180.168.24.186","220.86.129.106","45.4.179.4","185.177.72.56"]);
CommonSecurityLog
| where TimeGenerated > ago(7d)
| where SourceIP in (weekIPs) or DestinationIP in (weekIPs)
| summarize Hits=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by SourceIP, DestinationIP, DeviceVendor
Vulnerability check: confirm none of this week's KEV additions (CVE-2026-20349, CVE-2026-68820, CVE-2026-72898) apply to your internet-facing inventory. Start from each CVE's NVD page for affected versions, then reconcile against your asset and patch records.
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Appendix: The Week in Data
Top Ransomware Groups (ransomware.live, pulled 2026-08-23)
| Group | Victim Count |
|---|---|
| Clop | 46 |
| Qilin | 37 |
| The Gentlemen | 31 |
| Direwolf | 15 |
| Storm | 10 |
| Incransom | 7 |
Most-Reported Malicious IPs (AbuseIPDB 100% confidence + usage-type, and GreyNoise Community, as of 2026-08-23)
| IP Address | Country | Origin Type | ISP / Network | Total Reports | Reporters | Last Reported | GreyNoise |
|---|---|---|---|---|---|---|---|
| 45.148.10.157 | NL | hosting | TECHOFF SRV LIMITED | 215,162 | 900 | 2026-08-23 | malicious |
| 79.124.49.70 | BG | residential | Tamatiya EOOD | 7,309 | 243 | 2026-08-23 | unknown |
| 113.193.234.210 | IN | residential | Tikona Infinet Ltd. | 5,052 | 1,033 | 2026-08-23 | malicious |
| 45.4.179.4 | BR | residential | YUHOO NET | 4,457 | 972 | 2026-08-23 | malicious |
| 180.168.24.186 | CN | residential | Financial Life Insurance Company | 2,120 | 690 | 2026-08-23 | malicious |
Benign Research Scanners, excluded from sweeps (GreyNoise Community, as of 2026-08-23)
| IP Address | Scanner |
|---|---|
| 199.45.155.55 | Censys |
| 5.252.83.8 | Infrawatch |
New CISA KEV Additions (CISA KEV, added 2026-08-11)
| CVE | Vendor / Product | Date Added |
|---|---|---|
| CVE-2026-20349 | Cisco Secure Firewall ASA/FTD | 2026-08-11 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | 2026-08-11 |
| CVE-2026-72898 | Metabase | 2026-08-11 |
Methodology & Sources
This report is built entirely from open-source threat intelligence: public ransomware leak-site activity (ransomware.live, pulled 2026-08-23), community IP-reputation data (AbuseIPDB, as of 2026-08-23; GreyNoise Community, as of 2026-08-23), network ownership and hosting-type classification (AlienVault OTX for ASN, AbuseIPDB for usage-type, Pulsedive for route/device fingerprints), malware-infrastructure correlation (ThreatFox (abuse.ch) and URLhaus (abuse.ch), pulled 2026-08-23), and the government catalog of actively exploited vulnerabilities (CISA KEV, added 2026-08-11). Figures are aggregated across these public sources, cross-referenced, and captured as a point-in-time snapshot. They are aggregate public statistics, not original Focused Hunts detections, and each traces back to its source and to the raw snapshot retained for this edition.
Confirmed listings are kept separate from actor claims, and partial counts are reported as a floor. Week-over-week trends are drawn once successive snapshots support them. Feeds unavailable this week: none.
