markcardiff.tech:/daily-intel/2026-09-08.html
Generated: 2026-09-08 08:00:16 UTC
P1: 0
P2: 4
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-08

Generated: 2026-09-08 08:00:16 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=4, P3=161, P4=85.
  • Highest-priority item: RansomLook: Zanini claimed by the gentlemen (P2, source: RansomLook Recent Listings).
  • 2 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 RansomLook: Zanini claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zanini. Description excerpt: zanini.com zoominfo.com/c/zanini/359207305 Zanini is the global market leader in automotive wheel trim — a Spanish family firm founded…

  • P2 RansomLook: S A Chile claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: S A Chile. Description excerpt: syachile.cl zoominfo.com/c/sa-chile/372625700 S&A Chile is a Chilean mission-critical IT integrator founded in 1989 by…

  • P2 RansomLook: Benshaw, Inc. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Benshaw, Inc.. Description excerpt: Benshaw, Inc. (Pittsburgh) and affiliated UTG entities (Unico, Benshaw Canada, AuCom, Excel, Noble Victoria). ~100+ corporate Visa/PCard…

  • P2 RansomLook: Jinny Beauty Supply claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Jinny Beauty Supply. Description excerpt: Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution…

    Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Zanini claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zanini. Description excerpt: zanini.com zoominfo.com/c/zanini/359207305 Zanini is the global market leader in automotive…
  • P2 RansomLook: S A Chile claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: S A Chile. Description excerpt: syachile.cl zoominfo.com/c/sa-chile/372625700 S&A Chile is a Chilean mission-critical IT…
  • P2 RansomLook: Benshaw, Inc. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Benshaw, Inc.. Description excerpt: Benshaw, Inc. (Pittsburgh) and affiliated UTG entities (Unico, Benshaw Canada, AuCom, Excel,…
  • P2 RansomLook: Jinny Beauty Supply claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Jinny Beauty Supply. Description excerpt: Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in…
  • P3 RansomLook: SAD'S Interim claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: SAD'S Interim. Description excerpt: SAD'S Interim Since 2000, SAD'S INTERIM has established itself as a key player in the temporary…
  • P3 RansomLook: vsbattorneys.co.za claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: vsbattorneys.co.za. Description excerpt: VSB Attorneys Inc is a well-established law firm in South Africa, specializing in…
  • P3 RansomLook: MEI Architects claimed by dark project — Public RansomLook extortion-site listing claim. Group: dark project. Claimed victim/listing: MEI Architects. Description excerpt: As a result of the attack, 340 GB of data (approximately 130,000 files) was stolen:…
  • P3 RansomLook: Partners Group SK claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Partners Group SK. Description excerpt: Finance
  • P3 RansomLook: State of Florida DMV claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: State of Florida DMV. Description excerpt: Contact us, you know how. or we will release the files. View download button below…
  • P3 RansomLook: NorthShore Health Centers claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: NorthShore Health Centers. Description excerpt: NorthShore Health Centers offers comprehensive care in Indiana, including…
  • P3 RansomLook: Wellness Partners network(combined revenue) claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Wellness Partners network(combined revenue).
  • P3 RansomLook: Alurwalls claimed by dark project — Public RansomLook extortion-site listing claim. Group: dark project. Claimed victim/listing: Alurwalls. Description excerpt: Alurwalls was attacked, resulting in the theft of approximately 17 GB of confidential data.…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=IRAHOOK-loader,stealer,zip; url=https://opalcraftsmp.com/assets/OpalCraftSMP-CurseForge.zip
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,iloveboats-st-8081,mirai,ua-wget; url=http://iloveboats.st:8081/titan.ppc
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.mips
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.mips
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.mipsel
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.mipsel
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,ua-wget,www-iloveboats-st-8081; url=http://www.iloveboats.st:8081/titan.ppc440
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.ppc440
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help-8081,ua-wget; url=http://quietsurfwi.help:8081/titan.ppc440
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,iloveboats-st-8081,sh,ua-wget; url=http://iloveboats.st:8081/bash.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-quietsurfwi-help-8081,mirai,ua-wget; url=http://mail.quietsurfwi.help:8081/titan.arm7
  • IOC highlights

    TypeValueContextSource
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`13cde19e1e4f79aa4b6b458542f570c6`RansomLook: vsbattorneys.co.za claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=42
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=63 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=42 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.