markcardiff.tech:/daily-intel/2026-08-24.html
Generated: 2026-08-24 08:00:14 UTC
P1: 1
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-24

Generated: 2026-08-24 08:00:14 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=0, P3=18, P4=231.
  • Highest-priority item: RansomLook: CyrusOne, LLC. claimed by shinyhunters (P1, source: RansomLook Recent Listings).
  • 3 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 RansomLook: CyrusOne, LLC. claimed by shinyhunters — RansomLook Recent Listings; score 83; technologies: SharePoint.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: CyrusOne, LLC.. Description excerpt: Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours…

    Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P1 RansomLook: CyrusOne, LLC. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: CyrusOne, LLC.. Description excerpt: Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a…
  • P3 RansomLook: resi.com claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: resi.com. Description excerpt: Resi is a UK-based online architectural and home renovation platform founded in 2017 by Alexandra…
  • P3 RansomLook: Private(Chat...) claimed by black x — Public RansomLook extortion-site listing claim. Group: black x. Claimed victim/listing: Private(Chat...).
  • P3 RansomLook: Westwing Group SE NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Westwing Group SE NEW. Description excerpt: Furniture - $465.5 Million
  • P3 RansomLook: Hospitality Health ER (Longview) claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: Hospitality Health ER (Longview). Description excerpt: A healthcare organization
  • P3 RansomLook: S.E.M.P. s.r.l. claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: S.E.M.P. s.r.l.. Description excerpt: Business Services
  • P3 RansomLook: adt.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: adt.com. Description excerpt: ADT is a security company that offers security systems, cameras, alarms ad home automation…
  • P3 RansomLook: Studio BOLDRIN PAOLO claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Studio BOLDRIN PAOLO. Description excerpt: Real Estate
  • P3 RansomLook: Euroflora srl claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Euroflora srl. Description excerpt: Business Services
  • P3 RansomLook: Tecnici Associati STP claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Tecnici Associati STP. Description excerpt: Architecture, Engineering & Design
  • P3 RansomLook: Aurore Development S.p.A. claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Aurore Development S.p.A.. Description excerpt: Business Services
  • P3 RansomLook: Clear Align claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Clear Align. Description excerpt: Manufacturing
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 DOUBLECUP's PNG Payload, (Mon, Aug 24th) — New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t use real steganography:
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,Mozi; url=http://80.83.230.144:53523/Mozi.m
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_44ef7cc8421220d0.exe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot; url=http://150.241.65.250:67/dp.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,CoinMiner,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_865d4f3e8fa37c05.exe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,powershell; url=https://cdn.jsdelivr.net/gh/payphone-blip/gd65h7gfd9834/34jtg8sp7
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot; url=http://77.239.124.108/atomic/main_arm7
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://196.189.3.1:51410/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://123.14.32.199:49971/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.49.6.248:33966/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://113.228.140.10:33110/bin.sh
  • IOC highlights

    TypeValueContextSource
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`94e954f9fa4095799dede0c689e6d6b51ddddaff16d44b75cf49ba265dc3a79a`RansomLook: resi.com claimed by krybitRansomLook Recent Listings
    hash`7548bc0cc36f548dd1ea08ab886b3c22`RansomLook: adt.com claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=19 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=31 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.