Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🧭 How Play is documented to operate · Valid Accounts · Valid Accounts: Domain Accounts · Valid Accounts: Local Accounts · External Remote Services MITRE ATT&CK techniques attributed to Play overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🏴 Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🔴 Play Bold Spring Nursery found dark web 📍 United States · Agriculture and Food Production · 4 Oct 2026 🏴 Play has listed 1,308 victims since November 2022. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #leaksitecyberthreatintelligence.netBold Spring Nursery — Ransomware Attack by PlayBased in United States. Agriculture and Food Production sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🧭 How Play is documented to operate · Valid Accounts · Valid Accounts: Domain Accounts · Valid Accounts: Local Accounts · External Remote Services MITRE ATT&CK techniques attributed to Play overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🏴 Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 3h🔴 Play Silicon Valley Glass on dark web list 📍 United States · Manufacturing · 4 Oct 2026 🏴 Play has listed 1,308 victims since November 2022. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #leaksitecyberthreatintelligence.netSilicon Valley Glass — Ransomware Attack by PlayBased in United States. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 5h🔴 OMUR HIRDAVAT LTD seen on Emperador's leak site 📍 Turkey · Manufacturing · 4 Oct 2026 🏴 Emperador has listed 15 victims since August 2026. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #leaksitecyberthreatintelligence.netOMUR HIRDAVAT LTD — Ransomware Attack by EmperadorBased in Turkey. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 Chadwick Switchboards listed by Qilin today 📍 Australia · Manufacturing · 4 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #qilin #manufacturingcyberthreatintelligence.netChadwick Switchboards — Ransomware Attack by QilinBased in Australia. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 Cotesma — listed by Qilin 📍 Chile · Manufacturing · 4 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #qilin #threatintelcyberthreatintelligence.netCotesma — Ransomware Attack by QilinBased in Chile. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 Emser, based in Spain, listed on Qilin's leak site. 📍 Spain · Manufacturing · 4 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #leaksitecyberthreatintelligence.netEmser — Ransomware Attack by QilinBased in Spain. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 MorseLife Health System, Inc. — listed by Booba project 📍 United States · Healthcare · 4 Oct 2026 🏴 Booba project has listed 16 victims since June 2026. #ransomware #boobaproject #threatintelcyberthreatintelligence.netMorseLife Health System, Inc. — Ransomware Attack by Booba projectBased in United States. Healthcare sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🏢 Nipigon District Memorial Hospital offers a range of healthcare services including diagnostic imaging, lab services, physiotherapy, and an assisted living program. The hospital aims to serve patients and residents in the Nipigon district, focusing on community health and well-being. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 Nipigon District Memorial Hospital listed by Storm 📍 Canada · Healthcare · 4 Oct 2026 🏴 Storm has listed 49 victims since August 2026. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #darkwebcyberthreatintelligence.netNipigon District Memorial Hospital — Ransomware Attack by StormBased in Canada. Healthcare sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 7h🔴 Unident Group now featured on Qilin’s leak site 📍 United States · Other · 4 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #leaksitecyberthreatintelligence.netUnident Group — Ransomware Attack by QilinBased in United States. Other sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🧭 How Thegentlemen is documented to operate · Valid Accounts · Valid Accounts: Domain Accounts · External Remote Services · Exploit Public-Facing Application MITRE ATT&CK techniques attributed to Thegentlemen overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more… 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏢 340GB Center State Engineering is a privately held civil engineering consultancy founded in 1997 and based in Monroe Township, New Jersey. It serves municipal and private clients with engineering, surveying, land planning, inspection, and construction management. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 Center State Engineering — listed by Thegentlemen 📍 United States · Manufacturing · 4 Oct 2026 🏴 Thegentlemen has listed 835 victims since February 2023. cyberthreatintelligence.net/ransomw… #ransomware #thegentlemen #threatintelcyberthreatintelligence.netCenter State Engineering — Ransomware Attack by ThegentlemenBased in United States. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's… 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏢 Dar Al-Tib is one of Egypt's and the Middle East's first and leading centers specializing in infertility treatment and a. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 Daralteb.com, healthcare provider in Egypt, listed on Krybit leak site 📍 Healthcare · 4 Oct 2026 🏴 Krybit has listed 134 victims since March 2026. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #darkwebcyberthreatintelligence.netdaralteb.com — Ransomware Attack by KrybitHealthcare sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's… 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏢 Groupe Euroditel is a French telecommunications and IT systems integrator founded in 1966, headquartered in Bagneux, Îl. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 euroditel.com — listed by Krybit 📍 France · Technology · 4 Oct 2026 🏴 Krybit has listed 134 victims since March 2026. cyberthreatintelligence.net/ransomw… #ransomware #krybit #threatintelcyberthreatintelligence.neteuroditel.com — Ransomware Attack by KrybitBased in France. Technology sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 M****C — listed by Payoutsking 📍 United States · 4 Oct 2026 🏴 Payoutsking has listed 110 victims since April 2025. cyberthreatintelligence.net/ransomw… #ransomware #payoutsking #threatintelcyberthreatintelligence.netM****C — Ransomware Attack by PayoutskingBased in United States. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 Mutsumi Group — listed by Qilin 📍 Japan · Manufacturing · 4 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #qilin #threatintelcyberthreatintelligence.netMutsumi Group — Ransomware Attack by QilinBased in Japan. Manufacturing sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather… 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 Softruck, a Technology sector player from Brazil, new to Direwolf's leak list. 📍 Brazil · Technology · 4 Oct 2026 🏴 Direwolf has listed 131 victims since April 2025. cyberthreatintelligence.net/ransomw… #ransomware #threatintel #darkwebcyberthreatintelligence.netSoftruck — Ransomware Attack by DirewolfBased in Brazil. Technology sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏴 Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's… 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🏢 Empaques y Servicios Superiores S.A.S. (SUPERPACK) is a Colombian medium-sized company founded on January 12, 1999, head. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 9h🔴 superpack.com.co — listed by Krybit 📍 Colombia · Retail & E-Commerce · 4 Oct 2026 🏴 Krybit has listed 134 victims since March 2026. cyberthreatintelligence.net/ransomw… #ransomware #krybit #threatintelcyberthreatintelligence.netsuperpack.com.co — Ransomware Attack by KrybitBased in Colombia. Retail & E-Commerce sector. Disclosed 4 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🧭 How Qilin is documented to operate · Valid Accounts · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service MITRE ATT&CK techniques attributed to Qilin overall — not a finding about how this organisation was reached. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🏴 Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🔴 Genesis Credit Management found on Qilin leak site 📍 United States · Financial Services · 3 Oct 2026 🏴 Qilin has listed 2,265 victims since October 2022. cyberthreatintelligence.net/ransomw… #ransomware #qilin #threatintelcyberthreatintelligence.netGenesis Credit Management — Ransomware Attack by QilinBased in United States. Financial Services sector. Disclosed 3 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🏴 NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital. 000
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🏢 Precon Marine, Inc. is a diversified marine contractor specializing in heavy marine construction and advanced subsea services. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🔴 Precon Marine Inc — listed by Netrunner 📍 Transportation · 3 Oct 2026 🏴 Netrunner has listed 6 victims since April 2026. cyberthreatintelligence.net/ransomw… #ransomware #netrunner #threatintelcyberthreatintelligence.netPrecon Marine Inc — Ransomware Attack by NetrunnerTransportation sector. Disclosed 3 Oct 2026. Incident profile, threat group background and sector analysis. 100
Cyber Threat Intelligence Daily @cyberintelligence.bsky.social · 03/10/2026🧭 How Rhysida is documented to operate · Abusing Elevation Control Mechanism: Bypass User Account Control · Phishing · Command and Scripting Interpreter · Shared Modules MITRE ATT&CK techniques attributed to Rhysida overall — not a finding about how this organisation was reached. 000