Last Week in Threats Banner

Last Week in Threats: Week 40

Bottom Line

What changed this week: Ransomware victim disclosures jumped 47%, from 146 to 215 between September 28 and October 4, 2026, led by a 580% surge from thegentlemen (ransomware.live, pulled 2026-10-05). CISA added six actively exploited vulnerabilities to its KEV catalog, hitting Apple, Cisco SD-WAN, Fortinet email security, Zammad, and Citrix NetScaler products.

Who is most exposed: Manufacturing absorbed the most victim disclosures (45), followed by healthcare (35), technology (20), and professional services (20). The new KEV entries expose network edge, SD-WAN, email security, and customer support platforms, while 545 attacker addresses probed AI and LLM endpoints over four weeks (AI Honeypot Observatory, pulled 2026-10-05).

Recommended action: Patch the six new KEV entries: three (Apple, Cisco, FortiMail) were already past CISA's due date on October 5, and the other three fall due by October 7. Hunt edge appliances, SD-WAN controllers, and email gateways for unusual processes and outbound connections, and watch AI endpoints for Model Context Protocol (MCP) scanning.

Week in Review

The week of September 28 to October 4, 2026 brought a sharp escalation in ransomware victim disclosures and a significant shift in group activity. Ransomware.live recorded 215 new victim posts, a 47% increase over the prior week's 146 (pulled 2026-10-05). The thegentlemen group posted 34 victims, up from five the previous week, a 580% surge that made it the most active group by a wide margin. Storm posted 15 victims (up 150% from six), while five groups entered the top 10 for the first time: safepay, lamashtu, krybit, emperador, and threeam. Another five groups that held top 10 positions the prior week dropped out entirely.

CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog during the week, with due dates ranging from October 2 to October 7 (CISA KEV, pulled 2026-10-05). The additions targeted Apple products, Cisco Catalyst SD-WAN Manager, Fortinet FortiMail, Zammad helpdesk software, and Citrix NetScaler appliances. AI and LLM infrastructure faced heavy reconnaissance, with 545 distinct attacker addresses observed in the 28-day window ending October 5, including 171 new addresses that week (AI Honeypot Observatory, pulled 2026-10-05). The most common attack pattern targeted Model Context Protocol (MCP) endpoints, followed by mass scanning and credential harvesting.

Ransomware Activity

The thegentlemen group posted 34 victims during the week, up 580% from the prior week's five and the highest weekly total for any group (ransomware.live, pulled 2026-10-05). Storm posted 15 victims, up 150% from six, while Qilin posted 14, down slightly from 17. New to the top 10 were safepay with 11 victims, lamashtu with 10, krybit with nine, and emperador and threeam with seven each. Dropping out of the top 10 were metaencryptor, SilentRansomGroup, Wallstreet, everest, and Booba Project.

The United States remained the most-targeted geography with 74 victim disclosures, followed by 20 victims whose country could not be determined from the leak-site data. Germany recorded 12 victims, Great Britain 10, and Brazil eight (ransomware.live, pulled 2026-10-05).

Most Active Groups by Victim Postings

thegentlemen 34 Storm 15 qilin 14 safepay 11 incransom 10 lamashtu 10 akira 9 krybit 9

Victim Postings by Week

242 W33 242 W34 207 W35 166 W36 162 W37 185 W38 146 W39 215 W40

Sector and Technology

Manufacturing organizations absorbed 45 ransomware victim disclosures during the week, making it the most-targeted sector (ransomware.live, pulled 2026-10-05). Healthcare followed with 35 victims, then technology and professional services, each with 20. Retail and hospitality recorded 13 victims, while education, agriculture and food, energy and utilities, and transportation recorded seven each. Financial services recorded six victims, and government five. The feed classified 42 victims as unclassified, reflecting gaps in publicly available industry categorization.

The week's CISA KEV additions targeted five distinct technology classes (CISA KEV, pulled 2026-10-05):

Most-Targeted Industries

Manufacturing 45 Healthcare 35 Technology 20 Professional Services 20 Retail Hospitality 13 Education 8 Agriculture Food 7 Energy Utilities 7

Malicious IP Activity

AbuseIPDB's 100% confidence list put 12 addresses at the top of the week's report counts, most of them hosting infrastructure in the Netherlands, Hong Kong, and Vietnam. Sampled reports against them were email and credential brute-force, port scanning, SSH brute-force, and web-application attacks. Each address is listed below with the network that owns it.

Attacker Infrastructure

Of the 12 most-reported addresses, nine sat on hosting or VPS networks (one of them a Tor exit) and three on consumer ISPs, per AbuseIPDB usage type, with network ownership from AlienVault OTX. The hosting share points to rented attacker infrastructure, while the home-network addresses are more likely compromised endpoints than malicious providers. None of the addresses matched known malware command-and-control or payload hosting in abuse.ch ThreatFox and URLhaus.

Hosting Providers

  • AS206509 Kcom Group Limited: 86.54.31.38
  • AS135377 Ucloud Information Technology (Hk) Limited: 152.32.254.222
  • AS131353 Nhanhoa Software Company: 103.28.37.125
  • AS6908 Six Degrees Technology Group Limited: 77.239.124.62
  • AS38365 Beijing Baidu Netcom: 106.12.84.220
  • ASN not resolved, ISP Microsoft Limited: 57.153.8.89
  • AS36030 Equinix Inc.: 74.200.22.12
  • ASN not resolved, ISP GOLD VPS LIMITED: 103.72.57.129

Residential Networks

  • AS7713 Pt Telekomunikasi Indonesia: 36.64.131.68
  • AS23889 African Network Information Center: 197.227.8.186
  • AS36947 African Network Information Center: 41.110.90.25

Tor Exit Nodes

  • AS1101 Surfnet Bv: 192.42.116.58

Vulnerability Additions

CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog between September 29 and October 4, with remediation due dates ranging from October 2 to October 7 (CISA KEV, pulled 2026-10-05):

  • CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write (added September 29, due October 2, one AlienVault OTX pulse)
  • CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (added September 30, due October 3, six OTX pulses)
  • CVE-2026-104286: Fortinet FortiMail Path Traversal (added October 1, due October 4, 11 OTX pulses)
  • CVE-2026-102489: Zammad Session Fixation (added October 2, due October 5, one OTX pulse)
  • CVE-2026-102490: Zammad Improper Privilege Management (added October 2, due October 5, one OTX pulse)
  • CVE-2026-88779: Citrix NetScaler Memory Buffer Restriction (added October 4, due October 7, four OTX pulses)

All six vulnerabilities carried "Unknown" ransomware-use status at the time CISA added them, indicating known exploitation in the wild but no confirmed ransomware-group adoption in CISA's tracking data. The Fortinet FortiMail path traversal vulnerability (CVE-2026-104286) drew the highest community attention, appearing in 11 AlienVault OTX threat intelligence pulses (AlienVault OTX, pulled 2026-10-05).

Malware Infrastructure

Abuse.ch ThreatFox reported 7,637 malware-related indicators of compromise in the three-day window ending October 5, 2026, including 592 fresh command-and-control addresses (abuse.ch ThreatFox, pulled 2026-10-05). The Mirai botnet family accounted for 2,865 indicators, AsyncRAT for 1,951, and an unattributed loader classified as "Unknown Loader" for 1,001. The ClearFake campaign contributed 487 indicators, while unattributed malware accounted for 157. AMOS stealer contributed 112 indicators, Vidar 96, and IClickFix 81.

AI Infrastructure Attacks

The week brought 171 new attacker addresses into the 28-day observation window, while 374 addresses persisted from prior weeks. The most common MITRE ATT&CK technique observed was T1046 (Network Service Discovery), attributed to all 545 addresses in the window. T1190 (Exploit Public-Facing Application) appeared in activity from 199 addresses, while T1552.001 (Unsecured Credentials in Files) appeared in 114 address profiles (AI Honeypot Observatory MITRE mapping, pulled 2026-10-05).

AI-Endpoint Attacker Categories

Mcp Scanner 199 Scanner Mass 121 Credential Harvester 105 Relay Customer 62 Scanner Enum 37 Identity Prober 16 Relay Verifier 3 Relay Cataloger 2

Hunting Takeaway

The week's 580% surge in thegentlemen ransomware activity and the concentration of new CISA KEV entries in network edge and SD-WAN infrastructure point to a hunt for anomalous behavior in perimeter appliances and centralized management platforms. Hunt for unusual parent-child process relationships or unexpected outbound network connections from FortiMail, Cisco Catalyst SD-WAN Manager, Citrix NetScaler, and Zammad processes. Look for service account creation or privilege escalation in these platforms outside of documented change windows. The behavioral hunt complements, but does not replace, patching the six new KEV entries, three of which were already past CISA's due date on October 5.

Splunk SPL Query

index=main sourcetype IN (linux_secure, cisco:sdwan:syslog, fortinet:fortimail:event)
| eval service_class=case(
    sourcetype=="fortinet:fortimail:event", "fortimail",
    sourcetype=="cisco:sdwan:syslog", "sdwan",
    sourcetype=="linux_secure" AND (process_name="zammad" OR parent_process_name="zammad"), "zammad",
    1=1, "other"
)
| where service_class!="other"
| search (action="process_create" OR action="network_connection" OR action="account_created")
| stats count by service_class, action, user, dest_ip, dest_port, process_name, parent_process_name
| where count < 5

Microsoft KQL Query

let EdgeServices = dynamic(["fortimail", "vmanage", "sdwan", "zammad", "netscaler"]);
union SecurityEvent, Syslog, CommonSecurityLog
| where TimeGenerated > ago(7d)
| extend ServiceClass = case(
    ProcessName has_any (EdgeServices), ProcessName,
    ParentProcessName has_any (EdgeServices), ParentProcessName,
    ""
)
| where ServiceClass != ""
| where EventID in (4688, 5156, 4720) or Activity in ("process_create", "network_connection", "account_created")
| summarize Count=count() by ServiceClass, EventID, Activity, Account, DestinationIP, DestinationPort, ProcessName, ParentProcessName
| where Count < 5

Note: These queries were generated with AI assistance and are a starting point for threat hunting and detection rule considerations.

Environment Sweep

Check your environment for connections to or from the week's most-reported malicious IP addresses. No results does not mean no threat; it means these specific addresses did not appear in your logs during the search window.

Splunk SPL Query

index=main dest_ip IN ("86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129")
    OR src_ip IN ("86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129")
| stats count by src_ip, dest_ip, dest_port, action

Microsoft KQL Query

let MaliciousIPs = dynamic(["86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129"]);
union SecurityEvent, CommonSecurityLog, Syslog
| where DestinationIP in (MaliciousIPs) or SourceIP in (MaliciousIPs)
| summarize Count=count() by SourceIP, DestinationIP, DestinationPort, Activity

Verify your patch status for the six CISA KEV entries added this week. The queries below search for the affected products; presence indicates potential exposure, not confirmed vulnerability.

Splunk SPL Query

index=main sourcetype IN (vulnerability_scan, asset_inventory)
| search (product="Apple*" AND cve="CVE-2026-86950")
    OR (product="Cisco Catalyst SD-WAN*" AND cve="CVE-2026-76504")
    OR (product="Fortinet FortiMail*" AND cve="CVE-2026-104286")
    OR (product="Zammad*" AND (cve="CVE-2026-102489" OR cve="CVE-2026-102490"))
    OR (product="Citrix NetScaler*" AND cve="CVE-2026-88779")
| stats count by product, cve, version, patch_status

Microsoft KQL Query

DeviceTvmSoftwareVulnerabilities
| where CveId in ("CVE-2026-86950", "CVE-2026-76504", "CVE-2026-104286", "CVE-2026-102489", "CVE-2026-102490", "CVE-2026-88779")
| summarize Count=count() by CveId, SoftwareName, SoftwareVersion, RecommendedSecurityUpdate

Note: These queries were generated with AI assistance and are a starting point for threat hunting and detection rule considerations.

Appendix: Raw Tables

Top Ransomware Groups

ransomware.live, pulled 2026-10-05

GroupVictim CountChange from Prior Week
thegentlemen34+29 (+580.0%)
Storm15+9 (+150.0%)
qilin14-3 (-17.6%)
safepay11new to the top ranks
incransom10+2 (+25.0%)
lamashtu10new to the top ranks
akira90 (0.0%)
krybit9new to the top ranks
emperador7new to the top ranks
threeam7new to the top ranks

Most-Reported Malicious IPs

AbuseIPDB 100% confidence, pulled 2026-10-05; ASN from AlienVault OTX; scan verdict from GreyNoise Community

IP AddressCountryOrigin TypeASN / ISPTotal ReportsReportersLast ReportedGreyNoise
103.72.57.129VNhosting–76682026-10-05not seen
86.54.31.38NLhostingAS206509 Kcom Group Limited71985162026-10-05not seen
41.110.90.25DZresidentialAS36947 African Network Information Center8924902026-10-05not seen
103.28.37.125VNhostingAS131353 Nhanhoa Software Company17385382026-10-05not seen
57.153.8.89NLhosting–2101332026-10-05not seen
192.42.116.58NLhostingAS1101 Surfnet Bv6242372026-10-05not seen
152.32.254.222HKhostingAS135377 Ucloud Information Technology (Hk) Limited539311922026-10-05not seen
77.239.124.62NLhostingAS6908 Six Degrees Technology Group Limited9383832026-10-05not seen
106.12.84.220CNhostingAS38365 Beijing Baidu Netcom Science And Technology Co. Ltd.4652842026-10-05not seen
197.227.8.186MUresidentialAS23889 African Network Information Center562910512026-10-05not seen
74.200.22.12CAhostingAS36030 Equinix Inc.82562026-10-05not seen
36.64.131.68IDresidentialAS7713 Pt Telekomunikasi Indonesia1679114532026-10-05not seen

Attacker Networks

network ownership from AlienVault OTX, report volume from AbuseIPDB, pulled 2026-10-05

ASNProvider / ISPOrigin ClassIP CountTotal Reports
AS7713Pt Telekomunikasi Indonesiaresidential116791
AS206509Kcom Group Limitedhosting17198
AS23889African Network Information Centerresidential15629
AS135377Ucloud Information Technology (Hk) Limitedhosting15393
AS131353Nhanhoa Software Companyhosting11738
AS6908Six Degrees Technology Group Limitedhosting1938
AS36947African Network Information Centerresidential1892
AS1101Surfnet Bvhosting1624
AS38365Beijing Baidu Netcom Science And Technology Co. Ltd.hosting1465
AS36030Equinix Inc.hosting182

New KEV Additions

CISA Known Exploited Vulnerabilities catalog, pulled 2026-10-05; in-the-wild pulse counts from AlienVault OTX

CVEVendor / ProductVulnerability TypeDate AddedDue Date
CVE-2026-86950Apple Multiple ProductsApple Multiple Products Out-of-Bounds Write Vulnerability (1 OTX pulses)2026-09-292026-10-02
CVE-2026-76504Cisco Catalyst SD-WAN ManagerCisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (6 OTX pulses)2026-09-302026-10-03
CVE-2026-104286Fortinet FortiMailFortinet FortiMail Path Traversal Vulnerability (11 OTX pulses)2026-10-012026-10-04
CVE-2026-102489Zammad GmbH ZammadZammad GmbH Zammad Session Fixation Vulnerability (1 OTX pulses)2026-10-022026-10-05
CVE-2026-102490Zammad GmbH ZammadZammad GmbH Zammad Improper Privilege Management Vulnerability (1 OTX pulses)2026-10-022026-10-05
CVE-2026-88779Citrix NetScalerCitrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (4 OTX pulses)2026-10-042026-10-07

Top Malware Families

abuse.ch ThreatFox, three-day window ending 2026-10-05

FamilyIOC Count
Mirai2865
AsyncRAT1951
Unknown Loader1001
ClearFake487
Unknown malware157
AMOS112
Vidar96
IClickFix81
php.shin_webshell75
Bashlite66

AI-Endpoint Attacker IOCs

AI Honeypot Observatory, 28-day feed window pulled 2026-10-05; INFRA-COLLISION rows excluded and Total Hits is the feed's rolling-window magnitude, not a per-week count

IP AddressActor CategoryConfidenceMITRE TTPsTotal Hits (feed window)First SeenLast Seen
118.194.252.175RELAY-CUSTOMERvery-highT1046, T11021247822026-09-072026-10-05
154.37.208.58SCANNER-MASSvery-highT10461077882026-09-072026-10-05
43.156.79.80RELAY-CUSTOMERvery-highT1046, T1102482992026-09-072026-10-05
104.168.115.214IDENTITY-PROBERvery-highT1046, T1592255142026-09-082026-10-05
187.14.116.152RELAY-CUSTOMERvery-highT1046, T1102175902026-10-022026-10-05
16.5.0.236SCANNER-MASSvery-highT1046154212026-09-072026-09-30
20.5.41.14RELAY-CUSTOMERvery-highT1046, T1102108322026-09-182026-10-04
23.95.226.221IDENTITY-PROBERvery-highT1046, T1592100892026-09-082026-10-05
101.42.172.53RELAY-CUSTOMERvery-highT1046, T110241122026-09-072026-10-05
47.84.122.196SCANNER-MASSvery-highT104635932026-09-282026-10-04
188.253.127.228SCANNER-ENUMvery-highT1046, T110233652026-09-262026-09-28
57.129.7.104RELAY-CUSTOMERvery-highT1046, T110226722026-09-072026-10-04
185.177.72.66CREDENTIAL-HARVESTERvery-highT1046, T1552.00124022026-09-302026-09-30
32.216.141.74SCANNER-ENUMvery-highT1046, T110222082026-09-262026-10-05
149.28.142.11IDENTITY-PROBERvery-highT1046, T159221762026-09-082026-10-04
23.249.17.187RELAY-CUSTOMERhighT1046, T110217742026-09-282026-09-30
217.138.216.148RELAY-CUSTOMERhighT1046, T110217562026-09-302026-10-01
178.83.203.98SCANNER-ENUMhighT1046, T110215462026-09-242026-10-03
138.84.78.239RELAY-CUSTOMERhighT1046, T110213972026-09-072026-10-05
193.32.204.199CREDENTIAL-HARVESTERhighT1046, T1552.00113902026-09-132026-10-05
108.186.84.69CREDENTIAL-HARVESTERhighT1046, T1552.00112892026-09-212026-10-05
136.0.10.220IDENTITY-PROBERhighT1046, T159212752026-09-072026-10-05
118.89.77.121SCANNER-ENUMhighT1046, T110212662026-09-182026-10-05
5.83.129.153CREDENTIAL-HARVESTERhighT1046, T1552.00112542026-09-112026-10-05
85.11.167.148IDENTITY-PROBERhighT1046, T159211862026-09-072026-10-04

Methodology and Sources

This report is built entirely from open-source threat intelligence: public ransomware leak-site activity, community IP-reputation data, network ownership and hosting-type classification of the reported addresses, and the government catalog of actively exploited vulnerabilities. Figures are aggregated across these public sources, cross-referenced, and captured as a point-in-time snapshot. They are aggregate public statistics, not original Focused Hunts detections, and each traces back to its source and to the raw snapshot retained for this edition.

Confirmed listings are kept separate from actor claims, and partial counts are reported as a floor. Week-over-week trends are drawn once successive snapshots support them.

← Back to Last Week in Threats