Last Week in Threats: Week 40
Bottom Line
What changed this week: Ransomware victim disclosures jumped 47%, from 146 to 215 between September 28 and October 4, 2026, led by a 580% surge from thegentlemen (ransomware.live, pulled 2026-10-05). CISA added six actively exploited vulnerabilities to its KEV catalog, hitting Apple, Cisco SD-WAN, Fortinet email security, Zammad, and Citrix NetScaler products.
Who is most exposed: Manufacturing absorbed the most victim disclosures (45), followed by healthcare (35), technology (20), and professional services (20). The new KEV entries expose network edge, SD-WAN, email security, and customer support platforms, while 545 attacker addresses probed AI and LLM endpoints over four weeks (AI Honeypot Observatory, pulled 2026-10-05).
Recommended action: Patch the six new KEV entries: three (Apple, Cisco, FortiMail) were already past CISA's due date on October 5, and the other three fall due by October 7. Hunt edge appliances, SD-WAN controllers, and email gateways for unusual processes and outbound connections, and watch AI endpoints for Model Context Protocol (MCP) scanning.
Week in Review
The week of September 28 to October 4, 2026 brought a sharp escalation in ransomware victim disclosures and a significant shift in group activity. Ransomware.live recorded 215 new victim posts, a 47% increase over the prior week's 146 (pulled 2026-10-05). The thegentlemen group posted 34 victims, up from five the previous week, a 580% surge that made it the most active group by a wide margin. Storm posted 15 victims (up 150% from six), while five groups entered the top 10 for the first time: safepay, lamashtu, krybit, emperador, and threeam. Another five groups that held top 10 positions the prior week dropped out entirely.
CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog during the week, with due dates ranging from October 2 to October 7 (CISA KEV, pulled 2026-10-05). The additions targeted Apple products, Cisco Catalyst SD-WAN Manager, Fortinet FortiMail, Zammad helpdesk software, and Citrix NetScaler appliances. AI and LLM infrastructure faced heavy reconnaissance, with 545 distinct attacker addresses observed in the 28-day window ending October 5, including 171 new addresses that week (AI Honeypot Observatory, pulled 2026-10-05). The most common attack pattern targeted Model Context Protocol (MCP) endpoints, followed by mass scanning and credential harvesting.
Ransomware Activity
The thegentlemen group posted 34 victims during the week, up 580% from the prior week's five and the highest weekly total for any group (ransomware.live, pulled 2026-10-05). Storm posted 15 victims, up 150% from six, while Qilin posted 14, down slightly from 17. New to the top 10 were safepay with 11 victims, lamashtu with 10, krybit with nine, and emperador and threeam with seven each. Dropping out of the top 10 were metaencryptor, SilentRansomGroup, Wallstreet, everest, and Booba Project.
The United States remained the most-targeted geography with 74 victim disclosures, followed by 20 victims whose country could not be determined from the leak-site data. Germany recorded 12 victims, Great Britain 10, and Brazil eight (ransomware.live, pulled 2026-10-05).
Most Active Groups by Victim Postings
Victim Postings by Week
Sector and Technology
Manufacturing organizations absorbed 45 ransomware victim disclosures during the week, making it the most-targeted sector (ransomware.live, pulled 2026-10-05). Healthcare followed with 35 victims, then technology and professional services, each with 20. Retail and hospitality recorded 13 victims, while education, agriculture and food, energy and utilities, and transportation recorded seven each. Financial services recorded six victims, and government five. The feed classified 42 victims as unclassified, reflecting gaps in publicly available industry categorization.
The week's CISA KEV additions targeted five distinct technology classes (CISA KEV, pulled 2026-10-05):
- Apple products (CVE-2026-86950)
- Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
- Fortinet FortiMail (CVE-2026-104286)
- Zammad helpdesk software (CVE-2026-102489, CVE-2026-102490)
- Citrix NetScaler appliances (CVE-2026-88779)
Most-Targeted Industries
Malicious IP Activity
AbuseIPDB's 100% confidence list put 12 addresses at the top of the week's report counts, most of them hosting infrastructure in the Netherlands, Hong Kong, and Vietnam. Sampled reports against them were email and credential brute-force, port scanning, SSH brute-force, and web-application attacks. Each address is listed below with the network that owns it.
- 36.64.131.68 (ID): AS7713 Pt Telekomunikasi Indonesia, ISP PT TELKOM INDONESIA, residential, 16,791 reports
- 86.54.31.38 (NL): AS206509 Kcom Group Limited, ISP Black HOST Ltd., hosting, 7,198 reports
- 197.227.8.186 (MU): AS23889 African Network Information Center, ISP MauritiusTelecom, residential, 5,629 reports
- 152.32.254.222 (HK): AS135377 Ucloud Information Technology (Hk) Limited, hosting, 5,393 reports
- 103.28.37.125 (VN): AS131353 Nhanhoa Software Company, hosting, 1,738 reports
- 77.239.124.62 (NL): AS6908 Six Degrees Technology Group Limited, ISP ROCKET & MARINICA LTD, hosting, 938 reports
- 41.110.90.25 (DZ): AS36947 African Network Information Center, ISP Telecom Algeria, residential, 892 reports
- 192.42.116.58 (NL): AS1101 Surfnet Bv, ISP TOR EXIT AND MORE, Tor exit, 624 reports
- 106.12.84.220 (CN): AS38365 Beijing Baidu Netcom, hosting, 465 reports
- 57.153.8.89 (NL): ASN not resolved, ISP Microsoft Limited, hosting, 210 reports
- 74.200.22.12 (CA): AS36030 Equinix Inc., hosting, 82 reports
- 103.72.57.129 (VN): ASN not resolved, ISP GOLD VPS LIMITED, hosting, 76 reports
Attacker Infrastructure
Of the 12 most-reported addresses, nine sat on hosting or VPS networks (one of them a Tor exit) and three on consumer ISPs, per AbuseIPDB usage type, with network ownership from AlienVault OTX. The hosting share points to rented attacker infrastructure, while the home-network addresses are more likely compromised endpoints than malicious providers. None of the addresses matched known malware command-and-control or payload hosting in abuse.ch ThreatFox and URLhaus.
Hosting Providers
- AS206509 Kcom Group Limited: 86.54.31.38
- AS135377 Ucloud Information Technology (Hk) Limited: 152.32.254.222
- AS131353 Nhanhoa Software Company: 103.28.37.125
- AS6908 Six Degrees Technology Group Limited: 77.239.124.62
- AS38365 Beijing Baidu Netcom: 106.12.84.220
- ASN not resolved, ISP Microsoft Limited: 57.153.8.89
- AS36030 Equinix Inc.: 74.200.22.12
- ASN not resolved, ISP GOLD VPS LIMITED: 103.72.57.129
Residential Networks
- AS7713 Pt Telekomunikasi Indonesia: 36.64.131.68
- AS23889 African Network Information Center: 197.227.8.186
- AS36947 African Network Information Center: 41.110.90.25
Tor Exit Nodes
- AS1101 Surfnet Bv: 192.42.116.58
Vulnerability Additions
CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog between September 29 and October 4, with remediation due dates ranging from October 2 to October 7 (CISA KEV, pulled 2026-10-05):
- CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write (added September 29, due October 2, one AlienVault OTX pulse)
- CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (added September 30, due October 3, six OTX pulses)
- CVE-2026-104286: Fortinet FortiMail Path Traversal (added October 1, due October 4, 11 OTX pulses)
- CVE-2026-102489: Zammad Session Fixation (added October 2, due October 5, one OTX pulse)
- CVE-2026-102490: Zammad Improper Privilege Management (added October 2, due October 5, one OTX pulse)
- CVE-2026-88779: Citrix NetScaler Memory Buffer Restriction (added October 4, due October 7, four OTX pulses)
All six vulnerabilities carried "Unknown" ransomware-use status at the time CISA added them, indicating known exploitation in the wild but no confirmed ransomware-group adoption in CISA's tracking data. The Fortinet FortiMail path traversal vulnerability (CVE-2026-104286) drew the highest community attention, appearing in 11 AlienVault OTX threat intelligence pulses (AlienVault OTX, pulled 2026-10-05).
Malware Infrastructure
Abuse.ch ThreatFox reported 7,637 malware-related indicators of compromise in the three-day window ending October 5, 2026, including 592 fresh command-and-control addresses (abuse.ch ThreatFox, pulled 2026-10-05). The Mirai botnet family accounted for 2,865 indicators, AsyncRAT for 1,951, and an unattributed loader classified as "Unknown Loader" for 1,001. The ClearFake campaign contributed 487 indicators, while unattributed malware accounted for 157. AMOS stealer contributed 112 indicators, Vidar 96, and IClickFix 81.
AI Infrastructure Attacks
The week brought 171 new attacker addresses into the 28-day observation window, while 374 addresses persisted from prior weeks. The most common MITRE ATT&CK technique observed was T1046 (Network Service Discovery), attributed to all 545 addresses in the window. T1190 (Exploit Public-Facing Application) appeared in activity from 199 addresses, while T1552.001 (Unsecured Credentials in Files) appeared in 114 address profiles (AI Honeypot Observatory MITRE mapping, pulled 2026-10-05).
AI-Endpoint Attacker Categories
Hunting Takeaway
The week's 580% surge in thegentlemen ransomware activity and the concentration of new CISA KEV entries in network edge and SD-WAN infrastructure point to a hunt for anomalous behavior in perimeter appliances and centralized management platforms. Hunt for unusual parent-child process relationships or unexpected outbound network connections from FortiMail, Cisco Catalyst SD-WAN Manager, Citrix NetScaler, and Zammad processes. Look for service account creation or privilege escalation in these platforms outside of documented change windows. The behavioral hunt complements, but does not replace, patching the six new KEV entries, three of which were already past CISA's due date on October 5.
Splunk SPL Query
index=main sourcetype IN (linux_secure, cisco:sdwan:syslog, fortinet:fortimail:event)
| eval service_class=case(
sourcetype=="fortinet:fortimail:event", "fortimail",
sourcetype=="cisco:sdwan:syslog", "sdwan",
sourcetype=="linux_secure" AND (process_name="zammad" OR parent_process_name="zammad"), "zammad",
1=1, "other"
)
| where service_class!="other"
| search (action="process_create" OR action="network_connection" OR action="account_created")
| stats count by service_class, action, user, dest_ip, dest_port, process_name, parent_process_name
| where count < 5
Microsoft KQL Query
let EdgeServices = dynamic(["fortimail", "vmanage", "sdwan", "zammad", "netscaler"]);
union SecurityEvent, Syslog, CommonSecurityLog
| where TimeGenerated > ago(7d)
| extend ServiceClass = case(
ProcessName has_any (EdgeServices), ProcessName,
ParentProcessName has_any (EdgeServices), ParentProcessName,
""
)
| where ServiceClass != ""
| where EventID in (4688, 5156, 4720) or Activity in ("process_create", "network_connection", "account_created")
| summarize Count=count() by ServiceClass, EventID, Activity, Account, DestinationIP, DestinationPort, ProcessName, ParentProcessName
| where Count < 5
Note: These queries were generated with AI assistance and are a starting point for threat hunting and detection rule considerations.
Environment Sweep
Check your environment for connections to or from the week's most-reported malicious IP addresses. No results does not mean no threat; it means these specific addresses did not appear in your logs during the search window.
Splunk SPL Query
index=main dest_ip IN ("86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129")
OR src_ip IN ("86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129")
| stats count by src_ip, dest_ip, dest_port, action
Microsoft KQL Query
let MaliciousIPs = dynamic(["86.54.31.38", "197.227.8.186", "152.32.254.222", "103.28.37.125", "41.110.90.25", "57.153.8.89", "192.42.116.58", "77.239.124.62", "106.12.84.220", "103.72.57.129"]);
union SecurityEvent, CommonSecurityLog, Syslog
| where DestinationIP in (MaliciousIPs) or SourceIP in (MaliciousIPs)
| summarize Count=count() by SourceIP, DestinationIP, DestinationPort, Activity
Verify your patch status for the six CISA KEV entries added this week. The queries below search for the affected products; presence indicates potential exposure, not confirmed vulnerability.
Splunk SPL Query
index=main sourcetype IN (vulnerability_scan, asset_inventory)
| search (product="Apple*" AND cve="CVE-2026-86950")
OR (product="Cisco Catalyst SD-WAN*" AND cve="CVE-2026-76504")
OR (product="Fortinet FortiMail*" AND cve="CVE-2026-104286")
OR (product="Zammad*" AND (cve="CVE-2026-102489" OR cve="CVE-2026-102490"))
OR (product="Citrix NetScaler*" AND cve="CVE-2026-88779")
| stats count by product, cve, version, patch_status
Microsoft KQL Query
DeviceTvmSoftwareVulnerabilities
| where CveId in ("CVE-2026-86950", "CVE-2026-76504", "CVE-2026-104286", "CVE-2026-102489", "CVE-2026-102490", "CVE-2026-88779")
| summarize Count=count() by CveId, SoftwareName, SoftwareVersion, RecommendedSecurityUpdate
Note: These queries were generated with AI assistance and are a starting point for threat hunting and detection rule considerations.
Appendix: Raw Tables
Top Ransomware Groups
ransomware.live, pulled 2026-10-05
| Group | Victim Count | Change from Prior Week |
|---|---|---|
| thegentlemen | 34 | +29 (+580.0%) |
| Storm | 15 | +9 (+150.0%) |
| qilin | 14 | -3 (-17.6%) |
| safepay | 11 | new to the top ranks |
| incransom | 10 | +2 (+25.0%) |
| lamashtu | 10 | new to the top ranks |
| akira | 9 | 0 (0.0%) |
| krybit | 9 | new to the top ranks |
| emperador | 7 | new to the top ranks |
| threeam | 7 | new to the top ranks |
Most-Reported Malicious IPs
AbuseIPDB 100% confidence, pulled 2026-10-05; ASN from AlienVault OTX; scan verdict from GreyNoise Community
| IP Address | Country | Origin Type | ASN / ISP | Total Reports | Reporters | Last Reported | GreyNoise |
|---|---|---|---|---|---|---|---|
| 103.72.57.129 | VN | hosting | – | 76 | 68 | 2026-10-05 | not seen |
| 86.54.31.38 | NL | hosting | AS206509 Kcom Group Limited | 7198 | 516 | 2026-10-05 | not seen |
| 41.110.90.25 | DZ | residential | AS36947 African Network Information Center | 892 | 490 | 2026-10-05 | not seen |
| 103.28.37.125 | VN | hosting | AS131353 Nhanhoa Software Company | 1738 | 538 | 2026-10-05 | not seen |
| 57.153.8.89 | NL | hosting | – | 210 | 133 | 2026-10-05 | not seen |
| 192.42.116.58 | NL | hosting | AS1101 Surfnet Bv | 624 | 237 | 2026-10-05 | not seen |
| 152.32.254.222 | HK | hosting | AS135377 Ucloud Information Technology (Hk) Limited | 5393 | 1192 | 2026-10-05 | not seen |
| 77.239.124.62 | NL | hosting | AS6908 Six Degrees Technology Group Limited | 938 | 383 | 2026-10-05 | not seen |
| 106.12.84.220 | CN | hosting | AS38365 Beijing Baidu Netcom Science And Technology Co. Ltd. | 465 | 284 | 2026-10-05 | not seen |
| 197.227.8.186 | MU | residential | AS23889 African Network Information Center | 5629 | 1051 | 2026-10-05 | not seen |
| 74.200.22.12 | CA | hosting | AS36030 Equinix Inc. | 82 | 56 | 2026-10-05 | not seen |
| 36.64.131.68 | ID | residential | AS7713 Pt Telekomunikasi Indonesia | 16791 | 1453 | 2026-10-05 | not seen |
Attacker Networks
network ownership from AlienVault OTX, report volume from AbuseIPDB, pulled 2026-10-05
| ASN | Provider / ISP | Origin Class | IP Count | Total Reports |
|---|---|---|---|---|
| AS7713 | Pt Telekomunikasi Indonesia | residential | 1 | 16791 |
| AS206509 | Kcom Group Limited | hosting | 1 | 7198 |
| AS23889 | African Network Information Center | residential | 1 | 5629 |
| AS135377 | Ucloud Information Technology (Hk) Limited | hosting | 1 | 5393 |
| AS131353 | Nhanhoa Software Company | hosting | 1 | 1738 |
| AS6908 | Six Degrees Technology Group Limited | hosting | 1 | 938 |
| AS36947 | African Network Information Center | residential | 1 | 892 |
| AS1101 | Surfnet Bv | hosting | 1 | 624 |
| AS38365 | Beijing Baidu Netcom Science And Technology Co. Ltd. | hosting | 1 | 465 |
| AS36030 | Equinix Inc. | hosting | 1 | 82 |
New KEV Additions
CISA Known Exploited Vulnerabilities catalog, pulled 2026-10-05; in-the-wild pulse counts from AlienVault OTX
| CVE | Vendor / Product | Vulnerability Type | Date Added | Due Date |
|---|---|---|---|---|
| CVE-2026-86950 | Apple Multiple Products | Apple Multiple Products Out-of-Bounds Write Vulnerability (1 OTX pulses) | 2026-09-29 | 2026-10-02 |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (6 OTX pulses) | 2026-09-30 | 2026-10-03 |
| CVE-2026-104286 | Fortinet FortiMail | Fortinet FortiMail Path Traversal Vulnerability (11 OTX pulses) | 2026-10-01 | 2026-10-04 |
| CVE-2026-102489 | Zammad GmbH Zammad | Zammad GmbH Zammad Session Fixation Vulnerability (1 OTX pulses) | 2026-10-02 | 2026-10-05 |
| CVE-2026-102490 | Zammad GmbH Zammad | Zammad GmbH Zammad Improper Privilege Management Vulnerability (1 OTX pulses) | 2026-10-02 | 2026-10-05 |
| CVE-2026-88779 | Citrix NetScaler | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (4 OTX pulses) | 2026-10-04 | 2026-10-07 |
Top Malware Families
abuse.ch ThreatFox, three-day window ending 2026-10-05
| Family | IOC Count |
|---|---|
| Mirai | 2865 |
| AsyncRAT | 1951 |
| Unknown Loader | 1001 |
| ClearFake | 487 |
| Unknown malware | 157 |
| AMOS | 112 |
| Vidar | 96 |
| IClickFix | 81 |
| php.shin_webshell | 75 |
| Bashlite | 66 |
AI-Endpoint Attacker IOCs
AI Honeypot Observatory, 28-day feed window pulled 2026-10-05; INFRA-COLLISION rows excluded and Total Hits is the feed's rolling-window magnitude, not a per-week count
| IP Address | Actor Category | Confidence | MITRE TTPs | Total Hits (feed window) | First Seen | Last Seen |
|---|---|---|---|---|---|---|
| 118.194.252.175 | RELAY-CUSTOMER | very-high | T1046, T1102 | 124782 | 2026-09-07 | 2026-10-05 |
| 154.37.208.58 | SCANNER-MASS | very-high | T1046 | 107788 | 2026-09-07 | 2026-10-05 |
| 43.156.79.80 | RELAY-CUSTOMER | very-high | T1046, T1102 | 48299 | 2026-09-07 | 2026-10-05 |
| 104.168.115.214 | IDENTITY-PROBER | very-high | T1046, T1592 | 25514 | 2026-09-08 | 2026-10-05 |
| 187.14.116.152 | RELAY-CUSTOMER | very-high | T1046, T1102 | 17590 | 2026-10-02 | 2026-10-05 |
| 16.5.0.236 | SCANNER-MASS | very-high | T1046 | 15421 | 2026-09-07 | 2026-09-30 |
| 20.5.41.14 | RELAY-CUSTOMER | very-high | T1046, T1102 | 10832 | 2026-09-18 | 2026-10-04 |
| 23.95.226.221 | IDENTITY-PROBER | very-high | T1046, T1592 | 10089 | 2026-09-08 | 2026-10-05 |
| 101.42.172.53 | RELAY-CUSTOMER | very-high | T1046, T1102 | 4112 | 2026-09-07 | 2026-10-05 |
| 47.84.122.196 | SCANNER-MASS | very-high | T1046 | 3593 | 2026-09-28 | 2026-10-04 |
| 188.253.127.228 | SCANNER-ENUM | very-high | T1046, T1102 | 3365 | 2026-09-26 | 2026-09-28 |
| 57.129.7.104 | RELAY-CUSTOMER | very-high | T1046, T1102 | 2672 | 2026-09-07 | 2026-10-04 |
| 185.177.72.66 | CREDENTIAL-HARVESTER | very-high | T1046, T1552.001 | 2402 | 2026-09-30 | 2026-09-30 |
| 32.216.141.74 | SCANNER-ENUM | very-high | T1046, T1102 | 2208 | 2026-09-26 | 2026-10-05 |
| 149.28.142.11 | IDENTITY-PROBER | very-high | T1046, T1592 | 2176 | 2026-09-08 | 2026-10-04 |
| 23.249.17.187 | RELAY-CUSTOMER | high | T1046, T1102 | 1774 | 2026-09-28 | 2026-09-30 |
| 217.138.216.148 | RELAY-CUSTOMER | high | T1046, T1102 | 1756 | 2026-09-30 | 2026-10-01 |
| 178.83.203.98 | SCANNER-ENUM | high | T1046, T1102 | 1546 | 2026-09-24 | 2026-10-03 |
| 138.84.78.239 | RELAY-CUSTOMER | high | T1046, T1102 | 1397 | 2026-09-07 | 2026-10-05 |
| 193.32.204.199 | CREDENTIAL-HARVESTER | high | T1046, T1552.001 | 1390 | 2026-09-13 | 2026-10-05 |
| 108.186.84.69 | CREDENTIAL-HARVESTER | high | T1046, T1552.001 | 1289 | 2026-09-21 | 2026-10-05 |
| 136.0.10.220 | IDENTITY-PROBER | high | T1046, T1592 | 1275 | 2026-09-07 | 2026-10-05 |
| 118.89.77.121 | SCANNER-ENUM | high | T1046, T1102 | 1266 | 2026-09-18 | 2026-10-05 |
| 5.83.129.153 | CREDENTIAL-HARVESTER | high | T1046, T1552.001 | 1254 | 2026-09-11 | 2026-10-05 |
| 85.11.167.148 | IDENTITY-PROBER | high | T1046, T1592 | 1186 | 2026-09-07 | 2026-10-04 |
Methodology and Sources
This report is built entirely from open-source threat intelligence: public ransomware leak-site activity, community IP-reputation data, network ownership and hosting-type classification of the reported addresses, and the government catalog of actively exploited vulnerabilities. Figures are aggregated across these public sources, cross-referenced, and captured as a point-in-time snapshot. They are aggregate public statistics, not original Focused Hunts detections, and each traces back to its source and to the raw snapshot retained for this edition.
Confirmed listings are kept separate from actor claims, and partial counts are reported as a floor. Week-over-week trends are drawn once successive snapshots support them.
