| New Threats Detection Added | • Lumma Stealer • ClickFix • Go Titan • SocGholish |
| New Threat Protection | 187 |
| Newly Detected Threats | 29 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
SocGholish | ||||||||||||||||||
|
SocGholish, also known as "FakeUpdates", is a malicious JavaScript-based malware that is commonly distributed via infected or compromised legitimate websites, showing fake browser or software updates that trick the victim into downloading and executing the malicious file. Once infected, the attacker can collect information from the victim's device and communicate with command-and-control (C2) servers to download additional malware payloads.
|
|||||||||||||||||||
|
Threat Protected:
|
12 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Trojan-activity | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Active Threats to Siemens S7 Series PLCs
CISA and various other organisation such as FBI, DOE, and EPA have released an advisory last week detailing active cyber threats against Siemens S7 PLCs. These PLCs are used in various organisations that make up Manufacturing, Water and Wastewater, Food and Agriculture, and Energy. The PLCs are used to monitor and action tasks depending on program parameters. For the Energy sector, they are used to regulate the power distribution, start or stop generators, Turn off and on cooling system. They are even used to setting up the flow of water for hydroelectric power plants.
Threat Actors have been using AI-generated exploitation scripts disguised as legitimate tools such as snap7.dll and python-snap7. Snap7 is a legitimate open-source tool designed and used for communicating with Siemens S7 PLCs. The availability of AI and LLM dramatically reduces the technical expertise required to develop working exploits. The malicious tools and scripts that are designed to mimic the S7 libraries have the ability to read/write PLC memory, configuration data, and modify ladder logic programs all through the S7 protocol.
The Threat Actors target exposed PLC controls that can be accessed via the public internet and look for PLC that are running outdated software or are poorly secured. PLC control critical processes so a compromised PLC can lead to a shutdown of a process, safety incidents, damage to equipment or facilities and even cascading impacts across the whole system.
Red Piranha has created and implemented 9 new IDPS rules to detect and monitor S7 communication related to these activities.
A Summary of Threat Actor techniques are mapped to MITRE Att&CK Matrix and the MITRE ICS Matrix
Kill Chain:
|
Tactic
|
Technique ID
|
Technique Name
|
|
Reconnaissance
|
T1596.06
|
Search Open Technical Databases: Scan Databases
|
|
Resource Development
|
T1587.004
T1588.007
|
Develop Capabilities: Exploits
Obtain Capabilities: Artificial Intelligence
|
|
Persistence
|
T1694
|
Insecure Credentials
|
|
Execution
|
T0834
T0821
|
Native API
Modify Controller Tasking
|
|
Evasion
|
T0849
|
Masquerading
|
|
Collection
|
T0893
|
Data from Local System
|
Reference: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
Known Exploited Vulnerabilities (Week 4- August 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-4th-week-of-august-2026/686.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
8.9
|
Zimbra Collaboration Suite (ZCS) contains a unauthenticated remote command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP due to improper sanitation of untrusted input during the SNMP notification processing.
|
<10.1.20
|
10.1.20
|
||
|
9.0
|
TrueConf Server contains a code injection vulnerability that could allow an unauthorised remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
TrueConf Server contains a missing authentication for an undocumented function which could allow a remote unauthorised attacker with network access via port 4307/TCP to execute an arbitrary script.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.3
|
Microsoft Internet Key Exchange (IKE) Service Extensions (IKE VPN) contains a double free vulnerability that could enable remote code execution via reverse shells.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Broadcom VMware vCenter contains a path traversal vulnerability in the Syslog server which could allow a threat actor with network access to vCenter to execute arbitrary code.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.1
|
Microsoft SharePoint contains a weak JWT authentication vulnerability which allows an unauthorised attacker to bypass SharePoint authentication over a network.
|
<16.0.19725.20434
|
16.0.19725.20434
|
||
|
9.8
|
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
|
<14.8.9, <15.7.9, <26.6.1
|
14.8.9, 15.7.9, 26.6.1
|
||
|
8.8
|
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari via malicious websites or malicious advertisements (Malvertising).
|
<2.52.0
|
2.52.0
|
||
|
6.9
|
Johnson Controls Simplex Incident Manager/Autocall Fire Administrator a threat actor may be able to retrieve sensitive data about system information as its stored in cleartext in memory.
|
<=V2.01
|
>V2.01
|
||
|
7.8
|
Simcenter Femap and Simcenter Nastran are affected by stack overflow vulnerability that could lead to code execution by a threat actor sending a specially crafted string as an argument.
|
<2606
|
2606
|
Updated Malware Signature (Week 4 - August 2026)
|
Threat
|
Description | |
|
Vidar Stealer
|
Vidar Stealer is an information-stealing (infostealer) that primarily targets Windows System to steal sensitive information including cookies, browser credentials, cryptocurrency wallet information, banking details and other private information. This malware often spread through fake software, phishing campaigns and compromised websites.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Qilin was the most active ransomware group, impacting 45 countries, which accounted for 19.48% of the total ransomware hits. This made Qilin the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, affecting 28 countries and contributing 12.12% of the total ransomware activity. Direwolf followed closely with 27 countries impacted, representing 11.69% of overall ransomware hits. A significant level of activity was observed from Inc Ransom, which affected 12 countries, accounting for 5.19% of total activity. ShinyHunters impacted 10 countries, representing 4.33%, while Titan affected 8 countries, contributing 3.46%. Several ransomware groups showed moderate activity. Panzer, Xpl0itrs, Lockbit5, and Coinbase Cartel each impacted 7 countries, accounting for 3.03% individually. Play and Pear each affected 6 countries, representing 2.60% of total ransomware activity. Groups including Akira, Krybit, and Everest each impacted 5 countries, contributing 2.16% individually. Anubis, Aurora, Dragonforce, Majinahanashi, Iah647, and Rhysida each affected 3 countries, accounting for 1.30% individually. Lower levels of activity were observed from Securotrop, Blackwater, Eclipse, Emperador, Global Secret Group, Insomnia, and Deadlock, each impacting 2 countries, representing 0.87% individually. The remaining ransomware groups, including Space Bears, Barracuda, Bravox, RansomHouse, Leaknet, LeakedData, 3AM, Interlock, Gunra, Kairos, Payload, Sovcali, and others, each impacted 1 country, accounting for 0.43% individually. Overall, ransomware activity last week was primarily driven by Qilin, The Gentlemen, and Direwolf, which together accounted for a significant portion of global ransomware activity. The continued presence of multiple active ransomware groups, including established operators and emerging actors, highlights the increasingly diverse and competitive nature of the ransomware ecosystem. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 91 victims, accounting for 39.39% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing a significant portion of global ransomware incidents.
Italy recorded the second-highest number of victims, with 17 cases, contributing 7.36% of the total. Germany followed with 14 victims, representing 6.06%, while the United Kingdom recorded 12 victims, accounting for 5.19% of overall ransomware activity.
Other countries with notable ransomware impact included France, with 10 victims, representing 4.33%, and Brazil, Mexico, and Canada, each recording 6 victims, contributing 2.60% individually. United Arab Emirates reported 5 victims, accounting for 2.16% of the total activity.
Moderate ransomware activity was observed in Australia, Malaysia, Japan, and Taiwan, each with 4 victims, representing 1.73% individually. India, Philippines, Spain, and Sweden each recorded 3 victims, contributing 1.30% individually.
Several countries reported lower but notable activity, including Argentina, Singapore, Austria, Czechia, Switzerland, Peru, Thailand, and Indonesia, each with 2 victims, accounting for 0.87% individually.
The remaining countries recorded 1 victim each, representing 0.43% individually. These included Finland, Chile, Belgium, Albania, Trinidad and Tobago, South Korea, Israel, Honduras, Cyprus, Hong Kong, Croatia, Cameroon, Netherlands, South Africa, Romania, Samoa, Saudi Arabia, Portugal, Denmark, and Poland.
Overall, the data shows that ransomware activity was heavily concentrated in the United States, which accounted for nearly two-fifths of all reported victims. However, significant activity across Europe, Asia-Pacific, the Middle East, Africa, and the Americas demonstrates the continued global reach of ransomware operations and the persistent targeting of organisations across diverse regions.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 46 victims, accounting for 19.91% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 39 cases, representing 16.88% of the total. IT followed with 21 victims, contributing 9.09%, while Retail accounted for 20 victims, representing 8.66% of overall ransomware activity.
The Healthcare sector also experienced significant ransomware impact, with 18 victims, accounting for 7.79%. Finance recorded 17 victims, contributing 7.36%, highlighting continued targeting of sectors handling sensitive financial and operational data.
Moderate ransomware activity was observed in Construction, which reported 12 victims, representing 5.19% of the total. Hospitality recorded 11 victims, accounting for 4.76%, while Education reported 7 victims, contributing 3.03%.
Federal and Architecture each recorded 6 victims, representing 2.60% individually. Transportation and Energy each reported 5 victims, accounting for 2.16% individually. Law Firms recorded 4 victims, contributing 1.73%.
Lower levels of ransomware activity were observed in Media & Internet and Telecommunications, each with 3 victims, representing 1.30% individually. Electronics, Agriculture, and Real Estate each recorded 2 victims, accounting for 0.87% individually.
The least affected sectors were Insurance and Minerals & Mining, each reporting 1 victim, representing 0.43% of the total ransomware activity.
Overall, the data shows that ransomware activity was primarily concentrated in Manufacturing, Business Services, IT, Retail, Healthcare, and Finance sectors. These industries accounted for the majority of reported victims, reflecting attacker preference for sectors with valuable information, critical operations, and a higher potential for financial and operational impact.

Ransomware Group in Focus
SovCali Ransomware
Threat Actor Description
Origin and Profile
Sovcali (also styled “SovCali”) was first observed around 6–9 August 2026, surfacing on the XSS cybercrime forum and through a newly activated Tor leak site. It is classified as a new group with no established lineage to any known family, and no law-enforcement action, affiliate programme, or administrator alias has been identified. A French security outlet located the actor on a Russian-language hacking forum, and one commercial profile attributes the group to Russia - weakly sourced and low confidence. [1][2][7]
Operating model: data-leak extortion with private negotiation. The group’s published manifesto claims it specialises in the identification and acquisition of valuable corporate data, wishes to deal only with the legitimate data owner through confidential negotiation, disclaims any intent to disrupt operations or pass data to third parties, and professes political neutrality with a purely commercial motive. One tracker analyst noted the group provides unusually detailed descriptions of the alleged data - file types, project scope, volumes and metadata - apparently to increase negotiating pressure. [7]
Infrastructure and contact: a single Tor leak site with approximately 81% uptime over thirty days, and a Session messenger identifier for contact. [2]
Sophistication: assessed LOW. Two victims in three weeks, no tooling of any kind in public repositories, no wallets, no affiliate structure, and a commercial profile that scores the group zero for sophistication despite labelling it a ransomware operation. [3]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
No forensic, incident-response, or sample-derived evidence exists for Sovcali.
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Impact
|
T1657
|
Financial Theft/Data Extortion
|
Victims named on the Tor leak site with staged release threats and demands for exclusive private negotiation. Directly observable. [1][2]
|
|
Exfiltration
|
T1567
|
Exfiltration Over Web Service
|
Multi-terabyte theft claimed (5.078 TB engineering archive; further 35 GB threatened). Actor assertion only; channel undocumented. [1]
|
|
Initial Access
|
T1078
|
Valid Accounts
|
Credential-driven access is plausible - tracker enrichment on the flagship victim domain showed prior to infostealer exposure - but is not confirmed for any intrusion. [1]
|
Attack Lifecycle
Only the exfiltration and extortion stages are evidenced, and even those rest largely on the actor’s own assertions. Everything from initial access through collection is unknown and is recorded as a gap rather than reconstructed from assumption. [1][4]
1. INITIAL ACCESS THROUGH COLLECTION - Unevidenced
No information exists on how Sovcali obtains access or operates inside a victim's environment. Tracker enrichment on the flagship victim domain recorded prior infostealer exposure - one compromised employee, 226 compromised users and 19 third-party credentials - which makes a credential-driven vector plausible, but this is contextual exposure data rather than evidence of the intrusion path. [1]
Observable artefacts: Credentials for the organisation or its suppliers appearing in infostealer dumps; anomalous remote-access authentication; access to engineering, PLM or CAD repositories by unexpected accounts.
2. COLLECTION AND EXFILTRATION - Large-Scale Engineering Data Theft (claimed)
The flagship claim describes a highly specific engineering archive - CATIA and STEP models, finite-element and noise-vibration analyses, multi-gigabyte computational fluid dynamics simulations, topology optimisation studies, enclosure results, bills of materials and internal progress reports - totalling 5.078 TB across a reported 56,000-plus files. The specificity is notable but remains an actor assertion with no independent confirmation. [1]
Observable artefacts: Sustained large-volume outbound transfer from engineering or PLM environments; bulk access to CAD/CAE repositories; egress from a design-services supplier rather than the brand-name organisation itself.
3. IMPACT - Publication and Private Negotiation (no encryption evidenced)
Victims are listed on the Tor site with a staged proof-of-possession release and a demand to negotiate exclusively with the organisation. The in-window “Alert” post follows this pattern precisely, threatening a further 35 GB within two days. No encryption, ransom figure, or decryption offer is present in any post. [1][2][6]
Observable artefacts: Client or supplier appearing on the Sovcali leak site; staged partial data releases as proof; contact via the Session identifier below; outbound Tor connectivity.
Mitigation - Crystal Eye Controls
CE Advanced Firewall
The foundation of the rest of the stack sits on. Dividing the estate into security zones bound to interfaces limits how far any single compromise can reach, and traffic rules determine what is allowed, rejected or blocked between them. Given this actor’s interest in engineering and design data, isolating PLM, CAD, and file-repository environments into their own zone is the highest-value segmentation decision. It is also where traffic is directed to the IDPS or Web Filter for inspection.
CE Intrusion Protection & Detection
Inspects traffic against rulesets authored by Red Piranha’s security operations team and delivered through the service delivery network. Inline mode drops malicious traffic, but only where a corresponding Advanced Firewall traffic rule directs traffic to the IDPS; Detection and Protection mode alerts and logs, converting drop rules to reject. Where a ruleset generates excessive noise, narrow it using meta key and value filtering rather than disabling rules outright.
CE IDPS Local Rules
Allows detection content to be written for campaign-specific indicators - defining protocol, source and destination objects, inspection direction and content match, with Alert, Reject, Drop or Pass actions. For Sovcali there are currently no network indicators to encode beyond the leak-site address; the capability is noted when indicators emerge.
CE Web Filter and Anti-phishing
Addresses delivery, the cheapest point at which to stop an attack. The Anti-phishing engines - Signature, Heuristic, Block SSL Mismatch and Block Cloaked URLs - block phishing and cloaked destinations, while blacklists, banned sites, MIME types and file extensions block malicious infrastructure and payload types.
CE Antivirus and Antimalware File Scanner
Signature and heuristic classification at the gateway, blocking known-malicious files before they reach endpoints, with the Gateway Scan Report providing the daily view of what was blocked and why. Note that releasing a blocked item also adds the originating site to the Web Filter exception list for that policy - a wider decision than it first appears.
CE Forcefield
Automatically blocks traffic to and from hosts on reputation lists sourced from the service delivery network, cutting off known-bad infrastructure without manual rule writing. The update schedule should be moved hourly during an active campaign, as criminal infrastructure is typically short-lived.
CE Protocol Filter
Blocks protocols across the network by traffic content, port and type, making it the appropriate control for closing anonymised and consumer file-sharing channels used to move stolen data - directly relevant to an actor whose entire model is bulk data movement. It is not installed by default and must be added to the Marketplace. Where a block should apply only to selected traffic, use an Advanced Firewall traffic rule instead.
Indicators of Compromise (IOCs)
IOC availability: Direct querying of MalwareBazaar, VirusTotal, ANY.RUN, Triage, Malpedia, Hybrid Analysis, JoeSandbox and AlienVault OTX returned no Sovcali sample, file hash, family entry, ransom note, encrypted-file extension, mutex, YARA or Sigma rule, or command-and-control indicator. Hash searches surfaced only unrelated families. This is a directly verified negative finding, and no indicators from other families have been substituted. [4]
Available Indicators
|
Type
|
Indicator (defanged)
|
Notes/confidence |
|
Tor DLS (onion)
|
z3mojpjnxt5tgqvu4wgosihl7pxvrcbyjcgquw2bwkyye5gwbhnf4kqd[.]onion
|
Sole leak site; ~81% uptime over 30 days. Do not access it operationally. MODERATE confidence. [1][2]
|
|
Session ID
|
058d6e873410870bb920e6aebda023f94514f6959c9823a4222265a1adeed69719
|
Operator negotiation contact recorded against the group. [2]
|
References
All intelligence is directly sourced from the references below. Tracker and aggregator sources index the operator’s own unverified claims and are cited for situational awareness only; a leak-site listing does not constitute a confirmed breach.
[1] Ransomware.live - Sovcali victim records - https://ransomware.live/id/THVjaWRtb3RvcnNAU292Y2FsaQ==.
[2] RansomLook - Sovcali group profile - https://www.ransomlook.io/group/sovcali.
[3] SOCRadar RansomwareRadar - Sovcali - https://socradar.io/free-tools/ransomware-intelligence/groups/sovcali.
[4] MalwareBazaar / abuse.ch and associated analysis platforms - https://bazaar.abuse.ch/browse/.
[5] Brinztech - Sovcali breach alert - https://www.brinztech.com/breach-alerts/brinztech-alert-emerging-sovcali-ransomware-syndicate-adds-technology-sector-victim-to-tor-leak-site-in-double-extortion-campaign/.
[6] RedPacket Security - SOVCALI victim posts - https://www.redpacketsecurity.com/sovcali-ransomware-victim-alert/.
[7] ZATAZ - analysis of the SovCali manifesto - https://www.zataz.com/encore-encore-encore-un-nouveau-groupe-ransomware-sovcali/.