markcardiff.tech:/daily-intel/2026-08-01.html
Generated: 2026-08-01 08:00:52 UTC
P1: 0
P2: 6
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-01

Generated: 2026-08-01 08:00:52 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=6, P3=57, P4=187.
  • Highest-priority item: RansomLook: Lamont Pridmore claimed by dragonforce (P2, source: RansomLook Recent Listings).
  • 2 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 RansomLook: Lamont Pridmore claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Lamont Pridmore. Description excerpt: Lamont Pridmore is a leading independent chartered accountancy practice based in Carlisle, Cumbria, and Lancashire, offering a…

  • P2 RansomLook: RUS Industrial claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: RUS Industrial. Description excerpt: RUS Industrial specializes in heavy industrial construction services, catering to sectors such as chemical refineries,…

  • P2 RansomLook: www.mbmlawsc.com claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: www.mbmlawsc.com. Description excerpt: MBM Law (Moore Bradley Myers) is a South Carolina-based law firm founded in 1971. For over half a century, the firm has…

  • P2 RansomLook: Stewart Belland & Associates Inc. claimed by cmd organization — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: cmd organization. Claimed victim/listing: Stewart Belland & Associates Inc.. Description excerpt: Stewart Belland & Associates Inc. (SBA) is a Civil Enforcement Agency licensed by the Province of Alberta.…

  • P2 RansomLook: Paula Fish claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Paula Fish. Description excerpt: paulafish.pl zoominfo.com/c/paula-fish/448451882 Paula Fish is a market leader in fish processing in Central Europe, headquartered…

  • P2 RansomLook: CFS claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: CFS. Description excerpt: cfsinc.com zoominfo.com/c/cfs-inc/12944410 CFS Inc. is a Massachusetts-based marketing support services company with over 30 years of…

    Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Lamont Pridmore claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Lamont Pridmore. Description excerpt: Lamont Pridmore is a leading independent chartered accountancy practice based in…
  • P2 RansomLook: RUS Industrial claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: RUS Industrial. Description excerpt: RUS Industrial specializes in heavy industrial construction services, catering to sectors…
  • P2 RansomLook: www.mbmlawsc.com claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: www.mbmlawsc.com. Description excerpt: MBM Law (Moore Bradley Myers) is a South Carolina-based law firm founded in 1971. For…
  • P2 RansomLook: Stewart Belland & Associates Inc. claimed by cmd organization — Public RansomLook extortion-site listing claim. Group: cmd organization. Claimed victim/listing: Stewart Belland & Associates Inc.. Description excerpt: Stewart Belland & Associates Inc. (SBA) is a Civil Enforcement…
  • P2 RansomLook: Paula Fish claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Paula Fish. Description excerpt: paulafish.pl zoominfo.com/c/paula-fish/448451882 Paula Fish is a market leader in fish…
  • P2 RansomLook: CFS claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: CFS. Description excerpt: cfsinc.com zoominfo.com/c/cfs-inc/12944410 CFS Inc. is a Massachusetts-based marketing support…
  • P3 ESET tracks rise in malicious AI skills and adaptable malware — Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks,…
  • P3 RansomLook: Merritt Woodwork claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Merritt Woodwork. Description excerpt: Merritt provides strategic interior solutions for global estates and superyachts, from…
  • P3 RansomLook: Laempe Reich claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Laempe Reich. Description excerpt: Laempe Reich is North America’s leading foundry core machine supplier, providing sand core…
  • P3 RansomLook: Community Management Associates claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Community Management Associates. Description excerpt: Real Estate
  • P3 RansomLook: Gardiner Family Chiropractic claimed by interlock — Public RansomLook extortion-site listing claim. Group: interlock. Claimed victim/listing: Gardiner Family Chiropractic. Description excerpt: https://www.gardinerfamilychiropractic.com/ Gardiner Family Chiropractic has…
  • P3 RansomLook: ** claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: **. Description excerpt: A healthcare organization
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,bash,sh,ua-wget; url=http://51.75.118.165/loader.sh
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version — Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET…
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://42.224.123.145:51281/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://105.225.135.114:54011/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://108.170.136.155:39745/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://42.224.123.145:51281/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://160.30.142.2:59486/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://123.172.49.26:50679/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://221.15.14.66:42121/i
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,ua-wget; url=http://51.75.118.165/dl/BlahajNet.riscv32
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,ua-wget; url=http://162.249.125.141/mpsl
  • IOC highlights

    TypeValueContextSource
    ipv4`51.75.118.165`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=34
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=29 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=80 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.