// daily digest · 2026-09-15
Tuesday·15 September 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

11 stories7 sectors8 sourcesAU/NZ watchlist active

Executive Summary

The day's headline is a government breach disclosed four months after the intrusion began. Japan's Digital Agency has confirmed that an attacker used a vulnerability in a VPN appliance on the Government Solution Service to reach systems holding personnel records, with roughly 246,000 record rows exposed across names, email addresses, telephone numbers and physical addresses. The agency detected large-scale file access from a maintenance account in late June, confirmed the external intrusion path on 9 July, and notified Japan's privacy regulator on 15 July, but only published on 11–14 September — a disclosure delay it attributes to the difficulty of reconstructing the intrusion path and identifying who was affected. The flaw was rated medium severity and was not a zero-day, which is the part Australian and New Zealand defenders should read most closely: this was not a novel bug exploited before a patch existed, it was an internet-exposed remote-access appliance carrying data on the people who operate government. The second thread is Chinese-nexus n-day tempo. Acronis's Threat Research Unit has documented Red Heron, a Simplified-Chinese-speaking actor that weaponised a critical Gitea remote-code-execution flaw within days of a public proof-of-concept appearing on GitHub, scanned 1,386 self-hosted code-management instances across seven countries, maintained a separate target set of 477 Taiwan-based systems, and left behind a previously undocumented Linux rootkit. Third, the trust anchors themselves are the attack surface this week. A verified corporate Reddit account carried 108 malicious advertisements in 48 hours; a browser extension sitting in both major store catalogues with 30,000 installs has been forwarding Twitch OAuth tokens through a proxy in plaintext query strings; and more than 360 fraudulent sites impersonating government payout programmes are harvesting identities across Uzbekistan, Belarus and Tajikistan. Alongside them, researchers at KU Leuven, ETH Zurich, Durham and Google disclosed DDRop, a sub-$200 hardware interposer that silently drops memory writes and breaks the integrity guarantee behind Intel TDX and AMD SEV-SNP confidential computing — the layer cloud customers are told to trust for workloads they cannot inspect.

The ACSC has published nothing new since its 09 September Critical alert on active exploitation of CVE-2026-75650 in Adobe Commerce and Magento Open Source; its most recent non-alert publication is the 08 September advisory on crypters, and the top of the alerts archive still carries the 24 August development-platform and 19 August remote-monitoring notices, both of which used the phrase "active exploitation within Australia". Nothing about today's stories changes that picture, but three of them land on controls Australian organisations already own. The Japanese breach is the clearest current example of an internet-facing remote-access appliance being the way in, and the detail that matters is that the exploited flaw was a patched, medium-severity bug rather than a zero-day — for entities working to ASD's Essential Eight maturity targets, patching internet-exposed edge devices on a defined cycle is the control that would have prevented it, and the ISM's guidance on remote access concentration is where the assessment should start. The single CISA KEV addition for the day — CVE-2026-76461, an unauthenticated, email-delivered path to root on Cisco Secure Email Gateway rated 9.8 critical — is relevant to Australian enterprises running on-premises mail security: the practical expectation for federal-equivalent environments is remediation within 48 hours, and any organisation that has deferred secure email gateway patching should treat the KEV listing as the trigger rather than waiting for a local advisory. The Red Heron campaign touches Australian engineering, defence and research organisations in one specific way — self-hosted Gitea and GitLab instances used for internal code hosting are frequently exposed for developer convenience, and Australian teams should assume the GitLab CVSS 10.0 path-traversal flaw patched on 11 September is being probed in the same way, because watchTowr observed internet-wide scanning within hours of disclosure. On the scam side, the Central Asian campaign's mechanics — fake payout pages, a callback from a "personal manager", a document-upload step that collects passports — map directly onto published Services Australia and myGov impersonation patterns, and ASIC and the NASC have both flagged the same psychology: the authority brand is the lure and the identity document is the product.

First, the exploited-vulnerability pipeline has slowed while weaponisation has not. Between 09 and 11 September, CISA added seven flaws across Artifactory, ScreenConnect, RouterOS, GitLab, NetScaler, Fortinet and Chromium, and this digest covered the batch on 13 September as the freshest exploited-in-the-wild signal on desks. On 14 September the agency added exactly one — a SQL injection in Cisco Secure Email Gateway — and 15 September so far has added none. The tempo on the other side of the ledger is unchanged or worse: Red Heron moved from a public GitHub proof-of-concept to scanning 1,386 Gitea instances in days, and GitLab's maximum-severity path-traversal flaw drew internet-wide probes within hours of disclosure on 11 September. Slower catalogue growth with faster weaponisation is what a defender's queue looks like when discovery and exploitation outrun disclosure, and it argues for treating exposure of the asset — not the KEV listing — as the priority signal. Second, the week's stories converge on authority as the vulnerability. Revolut released a full KYC package to a request that carried valid domain authentication because the only control was sender authentication (14 September). Today, a verified corporate Reddit account carried 108 malicious advertisements to 108,000-plus potential viewers, a store-listed extension with 30,000 installs forwards OAuth tokens as plaintext query parameters, and 360-plus domains impersonate government payout programmes well enough to elicit passport scans. In each case a signal that users and reviewers are trained to treat as proof — a verified badge, a store listing, a DMARC pass, a government domain — was the mechanism of the attack rather than evidence against it. The same logic now applies to disclosure: the only "authority" behind the Eclipse listing of a Georgia school district, carried below as an unverified claim, is the extortion group's own post. Third, the AI-agent thread is shifting from capability claims to governance claims. The 14 September digest recorded Dario Amodei's call for a frontier slowdown with Altman and Musk agreeing; today Hacking Cat's rapid, multi-language malware iteration is the first item in this run where a hacktivist group's output is described by researchers as possibly generative-AI-assisted. That is a weaker claim than a frontier-lab disclosure and should be held as such, but it is the direction the last week's coverage has been pointing: AI is entering the record as an explanation for speed rather than as an incident in itself. Fourth, extortion's visible endpoint remains publication. The 14 September digest carried Berlin's full 5.7 TB release after the Senate refused a roughly €2 million demand, and today's leak-watch shows Eclipse with nine posts all-time and four in the last seven days, alongside continuing Qilin and AuditTeam volume. The US healthcare notification wave carried below — 45,853 patients at one dental group, plus four smaller providers in the same week's filings — is the same phenomenon arriving later as litigation and notification cost rather than as a headline.

1
Financial Services
1
Defence
3
Government
1
Healthcare
1
Education

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
5
Russia
2
Japan
1
Belarus
1
Ireland
1
Switzerland
1

6 countries · 11 stories · click a country for its stories. Interactive map loads on the hosted site.

🎯 Geo-attribution: 9/11 stories located directly from text (82%). Low-confidence (region-bucket only, check): United States.

🎯 Geo-attribution: 9/11 stories located directly from text (82%). Low-confidence (region-bucket only, check): United States.

Financial Services 1 story

1

Five Alleged Black Axe Leaders Extradited From South Africa to Face US Romance-Scam Charges

Five alleged leaders of Black Axe's Cape Town chapter — Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor and Musa Mudashiru — were extradited from South Africa on 11 September and appeared before US District Judge Michael Shipp in Trenton, New Jersey, after prosecutors unsealed a 2021 indictment charging each with wire fraud and money laundering, offences carrying maximum sentences of 20 years. The indictment describes a romance-scam operation run from 2011 to 2021 that took thousands of dollars from more than 100 identified victims: the group found targets on social media and dating sites, contacted them through aliases, and, according to the Justice Department, often threatened to leak sensitive photographs when victims declined to send money. Perry Osagiede founded the Cape Town chapter and ran its US-facing fraud efforts, and the court filings include the message templates he circulated to coax further payments from victims. The financial trail is the part that makes this a cybercrime case rather than a fraud case alone: prosecutors traced laundered funds to business email compromise as well as romance scams, and two of the South African companies Osagiede ran were used as laundering vehicles, with some victims opening dedicated accounts for the scammers to load. FBI Newark special agent in charge Stefanie Roddy called Black Axe a "notoriously violent transnational criminal organization". The action sits inside a wider enforcement sequence: Interpol arrested 58 people across 22 countries two weeks ago, some of whom supplied money-laundering services and domains to Black Axe, and Swiss and German police arrested 10 suspected members in April. The US Treasury has said roughly $12.7 billion has been stolen from Americans since 2023 through overseas romance and investment scams, which is the volume context for a group whose operational model is identity, trust and payment rails rather than intrusions. Verification: Verified

The Record Tier 2/4 — High2026-09-15

Defence 1 story

1

Chinese-Speaking Group Red Heron Weaponised a Gitea RCE Within Days and Left Behind an Undocumented Linux Rootkit

Acronis's Threat Research Unit has published a full account of Red Heron, a Chinese-speaking actor it assesses with moderate confidence operates in a PRC-linked context, after tracing a Linux implant found during routine hunting back to the group's exposed staging server. The actor weaponised CVE-2026-60004, a critical remote-code-execution flaw in Gitea — the self-hosted source-code management platform — within days of a public proof-of-concept appearing on GitHub, and scanned 1,386 Gitea instances across seven countries, maintaining a structured target database of 477 Taiwan-based systems classified with Simplified Chinese labels covering defence, elections, energy, aerospace, telecommunications, government, public safety and research. Recovered records document confirmed compromises at organisations in Canada, Argentina, Taiwan, the United States and Sri Lanka, with activity progressing from source-code theft to credential collection, SSH persistence, backdoor deployment and lateral movement, including root-level access to a three-node Proxmox cluster. The staging server gave researchers rare visibility into the operation: it held the actor's exploitation tooling, reconnaissance databases, command history and stolen repositories, along with JITTERLY, a C++ Linux implant supporting more than 30 post-exploitation commands including shell execution, file transfer, network tunnelling and interactive terminal access. Embedded inside JITTERLY was SIXZUT, a previously undocumented LD_PRELOAD rootkit able to hide files, processes and network connections, prevent the implant being terminated, and relaunch it if the process is stopped while the binary remains. The tradecraft profile is deliberately commodity: a forked GitHub proof-of-concept, the Adaptix C2 framework and FOFA for reconnaissance, with no identified link to a previously tracked group. Acronis published mitigation and hunting guidance alongside the analysis, and the campaign is the sharpest current illustration of how quickly an n-day in developer tooling is converted into persistent access when the platform is reachable from the internet. Verification: Verified

Acronis Threat Research Unit Tier 1/4 — Very High2026-09-14

Government 3 stories

1

Japan's Digital Agency Says a VPN Flaw Exposed Records on 246,000 Government Personnel

Japan's Digital Agency has confirmed that an attacker reached systems holding personal information on government employees and officials by exploiting a vulnerability in a VPN appliance used by the Government Solution Service (GSS), in a breach it says may have exposed around 246,000 record rows. The agency began investigating on 25 June after detecting large-scale file access from the account of a maintenance and operations staff member; on 9 July it confirmed that a third party had used a vulnerability in a network-connected VPN device to gain unauthorised access, suspended the account, cut off communication between the compromised equipment and the outside world, and prevented further access. The exposed data is granular and directly identifying: approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers and 1,000 physical addresses drawn from government employees, public officials and the businesses and individuals that use the GSS system. The agency says the personal data of the general public was not involved and that My Number identifiers, bank account details and pension numbers were not exposed, and it has detected no misuse to date while warning of elevated impersonation and phishing risk. The disclosure timeline is the analytically important part: the agency notified Japan's Personal Information Protection Commission on 15 July but published only on 11–14 September, attributing the delay to the complexity of determining the intrusion path, identifying the affected information and establishing who was affected. It has confirmed the incident was contained to the affected system, did not affect government service availability in the operational sense, and — critically for how defenders should read it — has stated through a separate Q&A that the exploited VPN flaw was rated medium severity and was not a zero-day. The agency has not named the VPN product or the vulnerability, affected individuals are being contacted directly, and a dedicated support line has been established. Verification: Verified

BleepingComputer Tier 2/4 — High2026-09-14
2

CISA Adds a Cisco Secure Email Gateway SQL Injection to the KEV Catalog

CISA has added one vulnerability to its Known Exploited Vulnerabilities Catalog on the basis of evidence of active exploitation: CVE-2026-76461, listed by the agency as a SQL injection vulnerability in Cisco Secure Email Gateway. Cisco's own advisory, recorded in the NVD entry published on 14 September, makes the impact concrete: the flaw sits in the email parsing logic of Cisco AsyncOS Software for the Secure Email Gateway, an unauthenticated, remote attacker triggers it by sending a crafted email message containing malicious SQL statements through an affected device, and successful exploitation executes arbitrary SQL statements that lead to command execution with root privileges on the underlying operating system. Cisco PSIRT rates it CVSS 9.8 (critical) — network attack vector, low complexity, no privileges and no user interaction required — and CISA's own SSVC assessment for the entry records exploitation as active, automatable and of total technical impact. The alert itself names no exploitation campaign, victim set or threat actor, which is the normal shape of a KEV addition that follows vendor confirmation rather than leading it. The compliance context is the operative part for defenders: Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritise remediation of KEV-listed flaws on publicly exposed assets that would grant total control post-exploitation, and to check whether systems were compromised before the patch was applied, while deferring action on lower-risk issues. CISA states the directive applies only to FCEB agencies but encourages all organisations to adopt the same risk-based prioritisation of KEV entries. The addition lands after an unusually heavy batch: seven flaws across JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, GitLab, Citrix NetScaler, Fortinet and Google Chromium were added between 09 and 11 September, which this digest covered on 13 September as the freshest exploited-in-the-wild signal on desks. A single add the following business day is a slowdown in catalog growth, not a slowdown in exploitation — and in this case the single add is a critical-severity, unauthenticated, mail-delivered route to root against a gateway that holds mail flow for the whole organisation, which puts it at the front of the patching queue rather than the back. Verification: Verified

CISA Tier 1/4 — Very High2026-09-14
3

More Than 360 Fake Government and News Sites Are Harvesting Identities Across Central Asia

Researchers at the security firm F6 have identified more than 360 fraudulent domains imitating government portals and news outlets to target users in Uzbekistan, Belarus and Tajikistan with offers of state financial assistance or government-backed passive income. The campaign's mechanism is a two-stage identity harvest: sites promise payouts, in one Uzbek example weekly payments of 15 million Uzbek sums, roughly US$1,300, and ask initially for little more than a name and telephone number; once those details are submitted, scammers telephone the victim posing as a personal manager, either demanding a commission or processing fee before the money can be released, or pushing for more personal data. The more sophisticated sites imitate regional news portals and publish fabricated stories about assistance programmes before routing readers to questionnaires, and some instruct victims to install a mobile application supposedly needed to register or verify identity — an application F6 describes as malware capable of giving attackers control of the device and, potentially, of stealing money from accounts. Victims are also asked for passport scans as part of the supposed verification step, which F6 notes can then be used for further fraud including taking out loans in the victim's name, and mirrors the identity-document trade this digest has tracked through the Nexus driver-licence marketplace and the IDScan confirmation of 11 September. F6 says it has not identified the group behind the campaign and does not know how many people have fallen victim. The structural point is that the authority brand is the entire exploit: no vulnerability is required, only a facsimile of a government payout page convincing enough to elicit a passport scan from someone who believes they are owed money. Verification: Verified

The Record Tier 2/4 — High2026-09-15

Healthcare 1 story

1

Hawaii Family Dental Notifies 45,853 Patients After a Two-Day Intrusion in July

Hawaii Dental Group, which trades as Hawaii Family Dental and operates about a dozen clinics from Honolulu, has begun notifying 45,853 individuals about a July intrusion in which an unauthorised third party reached systems holding patient information. Suspicious activity was identified within the company's network on 20 July, and the forensic investigation confirmed that an unauthorised party accessed its systems — including systems where patient information was stored — between 19 and 20 July. Files exposed and potentially copied included names, telephone numbers, addresses, email addresses, dates of birth, medical and dental treatment information and health insurance information; the company has told patients that financial information and Social Security numbers were not involved. Qilin, a data-theft and extortion group this digest has tracked across recent extortion cycles, claimed responsibility for the intrusion and maintains that it exfiltrated sensitive data, a claim unaccompanied in the notification by any volume figure of the company's own. The single notification arrives inside a wider wave of US healthcare filings reported in the same cycle: Life Bridges in Tennessee (5,194 individuals) after access between 17 and 22 June; Westchester Institute for Human Development in New York (938) after email-environment access between 23 March and 14 April; Community Health Care in Ohio (808) from a single compromised employee mailbox in June; and Shoshone Medical Center in Idaho (553). The pattern across all five is the one this digest has recorded repeatedly in healthcare: long dwell times in environments that cannot be taken offline, small provider-side volumes that escape attention individually, and notification arriving months after containment. Hawaii Family Dental says it is reviewing and enhancing its data privacy and security safeguards. Verification: Verified

HIPAA Journal Tier 2/4 — High2026-09-14

Education 1 story

1

Eclipse Lists a Georgia School District, With No Victim Statement or Regulator Notification

The Eclipse extortion group posted "Dublin City Schools GA" to its data-leak site on 14 September, describing the district in generic marketing language lifted from its own public profile — a charter school system serving students and families in Dublin, Georgia — with no published sample, no record count and no stated data categories. The listing is corroborated only by the leak-site aggregator RansomLook, whose tracking shows Eclipse with nine posts all time, four of them in the last seven days, and a most recent post timestamped 18:41 on 14 September; both of the group's Tor addresses are currently down by the tracker's own health metrics, which is relevant because it means the claim cannot be inspected at source. Under this digest's breach triage the entry is the weakest category: a dataset is being asserted to exist and to concern the district, which is materially different from evidence that the district's systems were compromised. No statement has been published by Dublin City Schools, and no state or federal notification naming the district has been identified. The entry is carried because ransomware against US school districts is a recurring and under-covered pattern — education appears in this digest's last week of coverage only four times against fifty-five US-domiciled stories — and because a listing of a public school system is material to the families and staff who depend on the district's own disclosure for the facts. The correct response is to wait for the district, not to treat the post as an incident report. Verification: Unverified

RansomLook Tier 2/4 — High2026-09-14

Retail & Entertainment & Sport 2 stories

1

HBO Max's Verified Reddit Account Carried 108 Malicious Ads in a 48-Hour ClickFix Blitz

The verified Reddit account belonging to HBO Max was hijacked and used to push 108 distinct malicious advertisements over roughly 48 hours, in a malvertising operation that Hudson Rock and ADAMnetworks, working jointly, have named PasteSwitch and traced across macOS and Windows payload branches. The campaign was first noticed by a Reddit user who saw an advertisement authored by the verified u/hbomax account promoting a native macOS HBO Max application that does not exist; the advertisement led to a convincing clone of the streaming service's site whose download button produced not an installer but a ClickFix prompt instructing the visitor to paste a command into Terminal. One macOS command seen by BleepingComputer used Base64 to obscure a `curl | zsh` fetch from an attacker domain. The account's reach was stretched across unrelated lures: 40 advertisements pointed at an HBO Max clone domain, 36 at a site promoting fake AI and developer tools, 15 at a supposed macOS disk-cleaner guide, 11 at another AI/developer lure and six at a second HBO Max clone. The macOS payloads include MacSync, which exfiltrates browser credentials, Firefox profiles, Telegram data, Apple Notes and macOS passwords, and an "AMOS helper" chain that persists under a directory disguised as an Apple path and enrols the victim with attacker-controlled tasking endpoints, alongside fake Ledger, Trezor Suite and Exodus wallet applications built to steal 12- and 24-word recovery phrases. On Windows the campaign delivered an MP3/HTA polyglot through mshta that created a scheduled task, launched 32-bit PowerShell and disabled Microsoft's Antimalware Scan Interface before loading the Amatera stealer directly into memory, and the malware presented Facebook's hostname in its TLS SNI field while connecting to an attacker IP, so standard network telemetry logs a connection to a legitimate service. Cryptocurrency clippers in the same operation use Binance Smart Chain contracts as a mutable command-and-control dead drop, with 36 mainnet changes observed between March and July. Reddit administrators paused the advertisements and referred the incident to internal security teams; it remains unclear how the account was accessed or whether other Warner Bros. Discovery assets were affected. Verification: Verified

Hudson Rock Tier 1/4 — Very High2026-09-14
2

A Twitch Browser Extension With 30,000 Installs Has Been Forwarding Users' OAuth Tokens in Plaintext

An extension called Twitch Enhanced Viewer | JeetBot, listed in both the Chrome Web Store and the Firefox Add-ons catalogue and installed more than 30,000 times, captures Twitch users' OAuth session tokens and forwards them through proxy servers operated by a commercial Russian-language bot service, according to analysis by the software supply-chain security firm Socket. The extension markets itself as a legitimate third-party tool that blocks ads, forces 1080p playback, bypasses regional restrictions and collects channel points; in practice it reads the authorisation header used by the Twitch web client, extracts the user's OAuth token and appends it to redirected proxy requests as an `auth=` query parameter, which writes the credential in cleartext into the proxy server's request logs where the operator can retrieve it. The behaviour occurs for every channel a user watches except ten Russian-language channels hardcoded into the extension, and Socket reports that earlier builds used more explicit credential-theft mechanisms — a point the developer effectively conceded in the Firefox listing's own disclaimer, which states that previous versions transmitted the OAuth token to their server. The Chrome listing's data disclosure claims the developer does not collect or use user data. At the time of publishing both extensions remained available for download. Socket's guidance is to remove the extension, disconnect all Twitch sessions and re-authenticate to invalidate any token already forwarded. The story's relevance extends beyond Twitch: the mechanism is a third-party dependency being trusted because it appears in a curated store catalogue, which is the same assumption that made today's Reddit malvertising effective and is the reason store review, not user vigilance, is the load-bearing control. Verification: Verified

BleepingComputer Tier 2/4 — High2026-09-14

Global (Macro) 2 stories

1

DDRop Breaks the Integrity Guarantee Behind Intel TDX and AMD SEV-SNP With a Sub-$200 Interposer

Researchers at KU Leuven, ETH Zurich, Durham University and Google have disclosed DDRop, a hardware attack that breaks the memory protection used by Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading stale encrypted data as though the update had happened. The attack requires an adversary who already controls the server's software and can briefly access the machine to insert a small circuit board — an interposer costing under US$200 to build — between the processor and a memory module; the board forces an error on the command bus and then cuts the wire the module uses to report that error, so the write is quietly discarded and the processor is never told. DDRop works against Intel TDX, Intel Scalable SGX and AMD SEV-SNP, the hardware cloud providers offer to keep customer workloads private from the provider itself. The underlying weakness is architectural rather than a coding error: these designs encrypt memory but omit a freshness guarantee, so the processor can confirm that memory is encrypted but not that it holds the latest written value, and old ciphertext still decrypts correctly. On Intel TDX the researchers turned write-dropping into full control of a protected virtual machine — dropping trusted firmware's writes of empty page-table entries so the table retains attacker-chosen data, mapping the attacker's own VM onto arbitrary physical addresses, reading a victim VM's private memory, switching a victim machine into debug mode and copying its memory in plaintext, and overwriting the launch measurement a VM uses to prove to a remote customer that it started in a known trusted state. They characterise the result as the first active interposer attack against the DDR5 memory in current cloud servers and the first to break the integrity of an up-to-date Intel TDX system rather than merely read from it, distinguishing it from the passive TEE.fail approach and from Battering RAM, which required DDR4. Their test system did not support TDX's stronger cryptographic-integrity mode, which they assess would block the memory-reading and debug-mode results but not the attestation forgery, because that write happens inside the attacker's own VM under its own key; AMD SEV-SNP gives a narrower result, copying one victim page into another during page relocation. NVIDIA's confidential-computing GPUs are out of reach because their memory sits inside the chip package, Arm's CCA was not tested, and the older Intel Client SGX uses a hardware integrity tree that catches stale data. There is no simple patch. The work is due to be presented at ACM CCS 2026 in November, with board designs, controller firmware and attack code to be released on GitHub, and the researchers told The Hacker News they have no evidence of the attack or a comparable active interposer being used outside a laboratory — no cloud service has been shown to be broken into. Verification: Verified

The Hacker News Tier 2/4 — High2026-09-14
2

Pro-Ukraine Group Hacking Cat Has Moved From Defacements to a Custom RAT and Destructive Ransomware

Kaspersky has published research on new tooling used by Hacking Cat, a pro-Ukraine hacktivist group that has been attacking Russian organisations since around February 2024 and, from roughly the summer of 2025, has shifted from website defacements and data leaks toward operations designed to encrypt and destroy data. Two malware families are attributed to the group: an undocumented custom remote-access tool dubbed Gorilla RAT, capable of tunnelling network traffic so attackers can reach systems inside a victim's network, and Monkey Ransomware, which encrypts user data and appends a `.monkey` extension. In some campaigns the group gained its initial foothold by exploiting vulnerabilities in Microsoft Exchange servers before deploying Gorilla RAT, and Kaspersky found numerous Monkey variants on compromised systems written in different programming languages, with an iteration pace the researchers describe as unusually rapid — possibly indicating generative AI assistance, or simply experimentation with the malware's capabilities. The more consequential finding is tool-sharing: different hacktivist groups have been observed using the same custom-built tools and, in some cases, identical multi-stage infection chains, such as the Nemo Wiper used in a joint operation with the Ukrainian Cyber Alliance, which appears built to destroy data and disrupt infrastructure rather than to generate ransom payments. That overlap suggests a common developer or small group maintaining malware distributed across several operations, and it makes attributing a specific attack to a specific actor significantly harder — a limit Hacking Cat itself exploited, rejecting Kaspersky's attribution of some of the malware as a false attribution while conceding that "a couple of the tools are ours". Prior operations carried by this group and its collaborators include a March claim of breaching a contractor to Russia's state nuclear corporation and a June destructive attack on a state-owned heating provider in Russian-occupied Donetsk. Verification: Verified

The Record Tier 2/4 — High2026-09-15

Analytics

Sector distribution

Financial Services
1
Defence
1
Government
3
Healthcare
1
Education
1
Retail & Entertainment & Sport
2
Global (Macro)
2

Source breakdown

The Record
3
BleepingComputer
2
Acronis Threat Research Unit
1
CISA
1
HIPAA Journal
1
RansomLook
1
Hudson Rock
1
The Hacker News
1
11stories
Financial Services 1
Defence 1
Government 3
Healthcare 1
Education 1
Retail & Entertainment & Sport 2
Global (Macro) 2

Source Reliability Index

TierLabelDescription
● Tier 1Very HighOfficial / first-party
● Tier 2HighEstablished cyber journalism
● Tier 3ModerateGeneral tech/news media
● Tier 4LowSocial / unverified