markcardiff.tech:/daily-intel/2026-08-23.html
Generated: 2026-08-23 08:00:34 UTC
P1: 0
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-23

Generated: 2026-08-23 08:00:34 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=0, P3=78, P4=172.
  • No P1/P2 items were identified in this run.
  • 2 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • None.
  • Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P3 RansomLook: ReliaQuest, LLC claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: ReliaQuest, LLC. Description excerpt: This time the post is about you, not us. Let Mandiant report and advise on us…
  • P3 RansomLook: el-group claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: el-group.
  • P3 RansomLook: Vietnam Electricity(EVNHANOI) claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Vietnam Electricity(EVNHANOI). Description excerpt: Vietnam Electricity (EVN), legally known as Tập đoàn Điện lực Việt Nam, is…
  • P3 RansomLook: NovoCure Limited claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NovoCure Limited. Description excerpt: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along…
  • P3 RansomLook: BOK Financial claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: BOK Financial. Description excerpt: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with…
  • P3 RansomLook: Integrated Health Systems NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Integrated Health Systems NEW. Description excerpt: Business Services - $9.3 Million
  • P3 RansomLook: RXPE Group NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: RXPE Group NEW. Description excerpt: Electronics - $319 Million
  • P3 RansomLook: Tower Insurance NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Tower Insurance NEW. Description excerpt: Insurance - $283.7 Million
  • P3 RansomLook: Flecha Bus NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Flecha Bus NEW. Description excerpt: Transportation, Freight & Logistics Services - $366.3 Million
  • P3 RansomLook: OTEIS Conseil & Ingénierie NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: OTEIS Conseil & Ingénierie NEW. Description excerpt: Architecture, Engineering & Design - $69.8 Million
  • P3 RansomLook: Longhorn Investments NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Longhorn Investments NEW. Description excerpt: Finance - $15.5 Million
  • P3 RansomLook: Kessler Creative NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Kessler Creative NEW. Description excerpt: Advertising Networks - $17.1 Million
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Application%20Files/Drastok_1_0_0_223/Drastok.dll.deploy
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Drastok.application
  • P3 Hackers infect Android car head units with proxy botnet malware — A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.224.70.52:48398/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://216.196.170.32:4154/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://112.237.148.180:50714/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.224.70.52:48398/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://112.237.148.180:50714/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://83.219.1.198:34396/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://219.156.34.146:35324/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://219.156.34.146:35324/bin.sh
  • IOC highlights

    TypeValueContextSource
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`e994f54274410052c992e9eef9bbd031`RansomLook: icnavais.com claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=16 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=26 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.