The first half of September was defined less by ransomware disruption than by an unusually heavy vulnerability window and a fresh malware set. The Gentlemen retook the ransomware lead, mid-market victims expanded, and critical enterprise flaws—including exploited Microsoft Windows and Chromium V8 zero-days—raised patching pressure as actors paired identity-driven access with newer cross-platform and remote-control tooling.

Report Links

Download Threat Brief For September 1-15 2026

Ransomware Actors

Ransomware Percentage Notes
The Gentlemen 13.99% Returned to first place
Qilin 8.91% Eased from 17.71%
Krybit 7.12% Returned to the top five
SAFEPAY 5.09% Rebounded from #46
Akira 4.58% Returned to the top five

The Gentlemen moved back into first as Qilin declined from 17.71% to 8.91%. Krybit and Akira returned to the top five, while SAFEPAY’s jump from #46 is better read as a rebound for a group that regularly circulates in the top 15. Overall, the movement looks like the usual rotation in ransomware activity rather than a structural shift.

Victim Sector

Sector Percentage
Manufacturing 15.78%
Technology 15.01%
Retail 13.99%
Financial Services 10.69%
Construction 10.18%

Victim Location

Location Percentage
USA 41.22%
India 5.34%
Canada 4.83%
Brazil 2.54%
Spain 3.05%

The United States remained the leading victim location, while India and Brazil underscore the broader geographic spread of observed activity.

Victim Organization Size

Organization size Percentage
Small Business (500 or less) 71.50%
Mid-Market (501-5000) 23.58%
Large Enterprise (5000+) 4.92%

Mid-market organizations expanded to nearly one quarter of observed victims, making them an increasingly important focus for defensive planning.

Trending Adversaries

  • BREEZE COMET
  • Cordial Spider
  • Gambling Goblin
  • Mirage Kitten
  • Springs / Spring Ring
  • UAC-0099

BREEZE COMET and Gambling Goblin reflect financially motivated operations, from manipulating Brazilian payment systems to hijacking government sites for gambling traffic. Cordial Spider and Springs lean on vishing and trusted SSO or collaboration workflows, while Mirage Kitten expands cross-platform espionage with NodeRabbit and PollCat. UAC-0099 has experimented with prompt injection to hinder AI-assisted analysis. The mix is evenly split between newer and established actors, but identity abuse and novel tooling are the strongest common threads.

Trending & Actively Exploited Vulnerabilities

The vulnerability window was unusually crowded, with CISA adding more than 20 flaws during the period. The selected exposures focus on enterprise systems across Citrix, Cisco, Adobe Commerce, Microsoft, JFrog, ConnectWise, Google Chromium, and GitLab.

CVE Vendor Product
CVE-2026-19490 Citrix NetScaler
CVE-2026-20079 Cisco Secure Firewall Management Center and Security Cloud Control
CVE-2026-75650 Adobe Commerce and Magento
CVE-2026-81963 Microsoft Windows
CVE-2026-82329 JFrog Artifactory
CVE-2026-84869 ConnectWise ScreenConnect
CVE-2026-85046 Google Chromium V8
CVE-2026-85706 GitLab Community Edition and Enterprise Edition
CVE-2026-85880 Microsoft Windows
CVE-2026-87491 Google Chromium V8

Prioritize internet-facing management systems first, then accelerate browser and endpoint patching where exploitation can reach users quickly.

Trending Malware

Malware Details
BambooToken Multi-platform espionage malware that uses MQTT and DLL sideloading to quietly control and profile Windows and Linux hosts.
PollCat Cross-platform RAT paired with NodeRabbit, using obfuscated JavaScript and HTTP C2 to execute commands, move files, and maintain stealthy persistence.
Cyclops Blink A modular botnet and backdoor upgraded for modern Linux appliances and used by Sandworm-linked actors for deep network visibility.
REVSTEALER Feature-rich infostealer combining anti-analysis, wallet and credential theft, gaming-account targeting, and Polygon-based fallback C2.
NodeRabbit Cross-platform JavaScript RAT delivered via trojanized coding challenges, giving attackers persistent remote control and file/system access.
VectraRAT Malware-as-a-service remote access trojan offering turnkey control, data theft, and flexible modules to subscribing threat actors.

Top News

  • A ClickFix campaign compromised 31 organizations and abused the Polygon blockchain.
  • Old, unpatched flaws gave attackers access to a Philippines nuclear agency.
  • US authorities charged a Russian national with infecting 80,000 freelancers with malware.
  • Two exploited zero-days and 113 critical vulnerabilities appeared among 972 September CVEs.
  • Japan’s digital agency said a VPN flaw exposed 246,000 personnel records.
  • Hackers abused Claude to extract secrets from 1.8 million Android apps.
  • China-based AI companies targeted US models with industrial-scale knowledge distillation.
  • A threat actor generated one million personalized fraud emails in three days.

Contributors

Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky
Executive Summaries & Adversary Bios by Geoff Rehmet, Cybersecurity Expert
Produced & Distributed By Byer Co Cybersecurity Marketing Division (aka Phish Tank Digital)