Ninja Signal Mic Drops — Edition 000000006
NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)
Threat intel from inside the graph. Published when the signal-to-noise demands it.
Edition 000000006.
Last edition I did something you're not supposed to do in this business: I told you one of my own feeds was dead. The ransomware mirror had frozen — last claimed victim stuck at 2025-06-16 — and I benched a whole forecast rather than grade it against a year-old photograph and call it radar.
Then I said Edition 006 would wire it back to live and timestamp it in front of you.
So here's the timestamp. Most recent claimed victim on the board as I write this: 2026-07-27T12:59 UTC. Today. The dish is spinning again — 19,013 total claims tracked, 274 of them in the last seven days.
And the dead feed's first big catch back online is not subtle: at 12:58 UTC, while I was writing this, ShinyHunters posted Ernst & Young — a Big Four firm — to the board, alongside RingCentral and Brinks Home in the same afternoon. The instrument I un-benched immediately caught an accounting giant. You cannot script a better argument for keeping the radar honest and on.
NIKO (my editor): You reopened by fixing the thing you broke last time — and it bagged a Big Four firm on day one.
Me: I reopened by proving the fix, Niko. The graph provided the exclamation point itself.
RECEIPTS — THE DEAD FEED, AND 005'S THREE CALLS
First, the resurrection — and the vindication it drags with it.
004's benched forecast was: "Qilin holds #1 on the live ransomware board." I couldn't grade it in 005 because the board wasn't live. It's live now. And here's the live board, last 14 days:
> qilin — 65 claimed victims. Still #1. 004 was right; I just couldn't prove it until the feed breathed again.
> thegentlemen — 55 · dragonforce — 33 · Global Secret Group — 31 · nova — 20 · CRPxO — 20 · Section9 — 18 · incransom — 17.
The forecast wasn't wrong. The instrument was unplugged. There's a difference, and printing it is the entire product.
Now 005's three calls — graded honestly, hits and misses.
1) "A named espionage op — Kimsuky / SideCopy / Cloud Atlas — gets a fresh tie within 10 days."
IN FLIGHT, not clean. The velocity engine didn't fire a new named report on those exact three in-window. What it did do: Kimsuky climbed to #6 of all tracked actors by graph degree (389 edges) — the same crew, structurally louder. Corroboration, not a clean hit. I'm not rounding it up.
2) "A collaboration-tool abuse technique shows up in a named campaign or KEV inside two weeks."
MISS on the letter. No fresh Teams/Webex/Slack-named campaign landed in the two-week window. The thesis — trusted comms surfaces are the new spearphish — resurfaced days later as Operation RoundPress and its half-click webmail zero-days (z=8.8), but that's webmail, not the named tools, and outside the window. Missed the call; the pattern held. Both true.
3) "An invisible dependency — an image/PDF/media library like Magick.NET — gets tied to a real compromise."
HIT. The engine logged "Exploitation in the Wild of wp2shell" (z=8.2) — a dependency tied to live exploitation — while Magick.NET kept spiking into 07-23 (Q16-x86, OpenMP-arm64) and pip/open-webui lit up at z=17.4 and npm/@budibase/server at z=12.5. The library nobody threat-models is exactly the one getting popped.
NIKO: One clean hit, one in-flight, one clean miss.
Me: That's what a radar looks like when you don't airbrush it, Niko.
THE SIGNAL — THE WORMS WENT CORPORATE, AND THEY FEED THE BOARD
The ransomware mirror didn't just come back — it came back into a room that got louder while it was asleep. And the throughline this edition isn't a brand. It's automation. The velocity engine's hottest fresh signals aren't phishing lures — they're self-propagating, credential-harvesting machines eating exposed infrastructure at scale:
> PCPJack — "Cloud Worm Evicts TeamPCP and Steals Credentials at Scale" (z=8.1). A worm that fights other worms for the box, then strips its credentials. Cloud-native, competitive, automated. This is malware with a go-to-market.
> "Exploitation in the Wild" — Cisco Catalyst SD-WAN (z=8.2), Oracle PeopleSoft against the education sector (z=7.3), wp2shell (z=8.2). Not advisories. Not "could be exploited." Exploited, now, on the edge and the ERP.
> Operation RoundPress — more half-click webmail zero-days (z=8.8). You don't even have to click all the way anymore.
> A raw Mirai-class payload staging off 83.168.95.235/bins/arm7 (z=9.8) — the botnet supply line never closed; it just went ARM.
What it means: the extortion board posted 274 victims in seven days, and the fuel line behind it is now automated exploitation of exposed edge and enterprise services — SD-WAN, PeopleSoft, webmail, cloud IAM. The KEV list isn't a backlog. It's an ammunition feed: worms and exploit kits at the front of the funnel, the ransomware brands at the back, and the same exploited CVEs joining them in the middle. You are not being targeted. You are being harvested.
NIKO: "Malware with a go-to-market." You're enjoying this.
Me: I'm respecting the adversary's product discipline. It's better than most SaaS I pay for.
EXPLOIT VELOCITY — THE KEV FIRE-HOSE
The graph is carrying 1,653 known-exploited relationships against 49,423 tracked vulnerabilities — the exploited slice widened again since 005 (1,629 / 48,271). This window's velocity engine put real names on the exploitation, not just CVE numbers: Cisco Catalyst SD-WAN, Oracle PeopleSoft, wp2shell, and the RoundPress webmail zero-days. Freshest known-exploited CVEs riding the edges include CVE-2026-9082, -8398, -7473, -6973. Patch the exploited slice first — it's ~3.3% of your CVE backlog and roughly 100% of what the worms are actually walking through.
DEFENDER QUICKWIN — catch the cloud worm at the credential grab
This edition's signal is automated credential theft at scale (PCPJack). The tell of a cloud worm is a script or shell — not the cloud agent — reaching the instance metadata endpoint to mint temporary IAM creds:
DeviceNetworkEvents
| where RemoteIP == "169.254.169.254" // cloud instance metadata (IMDS)
| where InitiatingProcessFileName !in~ ("cloud-init","amazon-ssm-agent","waagent",
"google_metadata_script_runner","cloud-agent","aws")
| where InitiatingProcessFileName in~ ("curl","wget","python","python3","perl",
"bash","sh","powershell.exe","pwsh","node","php","ruby")
| project Timestamp, DeviceName, AccountName,
InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP
Run it fleet-wide. Your cloud agent talks to 169.254.169.254 all day. When curl or a stray Python does, someone just taught your box to hand over its keys.
NIKO: Six editions, six working detections.
Me: Radar, not a museum. Say it with me now.
7-DAY FORECAST (graded in Edition 007 — against feeds I keep timestamping)
1. The ransomware board stays live and a currently-rising crew — thegentlemen, Global Secret Group, or nova — posts another double-digit week. Now that the mirror breathes, this is gradeable because I fixed it, and I'll grade it in front of you.
2. One of this week's "exploitation in the wild" edge targets — Cisco Catalyst SD-WAN / Oracle PeopleSoft / RoundPress webmail — picks up a fresh known-exploited edge or a second named campaign within 10 days. The edge is the funnel; funnels don't close.
3. A cloud-native worm or credential-stealer in the PCPJack mould (IMDS/metadata abuse, cred theft at scale) gets a named follow-on or a second variant inside two weeks. Malware found product-market fit in your cloud IAM. It's not giving that up.
Top actors by graph degree: TeamTNT, Rocke, Sofacy, GCMAN, UNC3886, Kimsuky, Storm-0501, APT 30, Equation, Scattered Spider, Strider, MuddyWater. TeamTNT and Rocke — two crews built for cloud cryptojacking and worming — sitting #1 and #2 the same week a cloud worm tops the velocity board is, once again, the graph drawing its own conclusion.
WHY THIS EXISTS
Edition 001: attribution is breaking. 002: AI tooling is the underbelly. 003: the supply chain is the battlefield. 004: ransomware brands are theatre. 005: the trusted-SaaS layer is the front door — and know which feed is alive before you trust it. This one: the fuel behind the extortion board is automation — worms and edge exploitation — and the feed I said was dead is breathing again, on the record.
Last edition I benched a forecast because the data had stopped moving, and I told you. This edition I un-benched it, proved Qilin was #1 all along, and graded my own calls one-hit-one-miss-one-in-flight without rounding anything up. That's the deal. Radar, not a museum — and a radar you can watch me re-plug a dish on, mid-broadcast.
If this helped, follow. If it didn't, follow anyway — Edition 007 I'm grading a live board against a live board, which is the whole reason I fixed it.
Edition 000000006 / 2026-07-27
Data pulled live from ninjasignal.ninja. All numbers reproducible. All receipts published — the resurrection, the hit, the miss, and the one still in flight.
— Scott
(Niko maintains the confession was the best part of 005 and is furious the fix might top it.)
Built on Rapid Threat Modeller | ninja.ing | @scottg
#ThreatIntelligence #CISO #SOC #DFIR #CTI #Cybersecurity #InfoSec #ThreatHunting #CISAKEV #Ransomware #Qilin #CloudSecurity #Worms #EdgeSecurity #CiscoSDWAN #PeopleSoft #DataIntegrity #BlueTeam #DetectionEngineering
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·