Home › Blog

NinjaSignal Mic Drop 000000007: We named the botnet

NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)

Threat intel from inside the graph. Published when the signal-to-noise demands it.

The frame

Yesterday our Box 1 edge took 41,794 requests from 6,407 source IPs. Somewhere in that haystack, two addresses were quietly asking six of our domains for the same file: . Secrets. API keys. The kind of request every web server on earth sees every day, and almost every SOC ignores.

This edition is about what happened next, because for the first time the platform didn't just flag it. It named it.

  • Sense. A local detection sensor runs next to the web log on the box itself. It reads the real client IP (not the CDN edge), fingerprints behaviour, and ships only findings. Raw logs never leave the host.

  • Fingerprint. Every hostile source gets a behavioural DNA: archetype, hostility score, kill-chain phase, exactly what it probed. 72 hostile sources out of 6,407 in the day.

  • Attribute. The DNA is correlated against our Signal threat-intel graph, and the platform names the botnet, campaign or actor, with a confidence score and the evidence chain behind it.

  • Respond. A high-confidence attribution raises its own incident, keyed on the attacker, and Claude triages it with the DNA and the attribution in view. Recommend-only. A human decides.

Here's what it found. 94.154.43.164 is a Mirai payload server. Our Signal graph (fed by abuse.ch URLhaus and ThreatFox) has it serving Mirai / Wraith builds for every IoT CPU: , , , , , , plus the dropper scripts and . Its /24 carries 2,344 known-bad indicators, 1,274 of them Mirai. And it was probing us for secrets.

Two independent lines of evidence, combined by noisy-OR: 1 − (1 − 0.85)(1 − 0.40) = 0.91. HIGH. Its sibling, 94.154.43.84, was attributed independently to the same family at the same confidence.

Niko: So who's behind it? Scott: Nobody we can prove. Mirai is a family, not a person. No actor in our graph owns it, so the platform asserts no actor. It names what the evidence supports and stops there.

Three details matter more than the headline:

  • It matched the payload URL, not just the IP. Most reputation lookups check a bare IP. Botnet infrastructure usually lives in threat intel as C2 listeners or as the host of a payload URL. Matching only exact IPs, this attacker scores zero.

  • Coordination is evidence. Four Azure-hosted IPs shared one behavioural DNA and all hunted the same WordPress web-shell backdoor. One operation, rotating addresses. Coordination lifted that campaign attribution from 0.45 to 0.63.

  • The behaviour stayed under every rule threshold. The Mirai node was quiet: two requests, low hostility. No rule fired. The attribution raised the incident on its own.

Receipts: grading Edition 006

We publish forecasts with a window, then grade them. All three windows from 006 have closed.

  • #1 HIT. The ransomware board stays live and a rising crew posts another double-digit week. The board is live (last claim 24 Sep, 20,974 tracked). The week after the call: The Gentlemen 43, CRPxO 31, Qilin 29, INC Ransom 12, NightSpire 12.

  • #2 MISS. Cisco SD-WAN / PeopleSoft / Roundcube gets a fresh KEV edge within 10 days. The newest matching KEV entry in our graph is 15 June. Right front, wrong clock.

  • #3 UNVERIFIED. A PCPJack-style cloud worm gets a named variant within two weeks. A second PCPJack campaign did surface (a hidden SMTP relay across 230 AWS/GCP/Azure servers), but it isn't a named variant and our record isn't dated. We don't award ourselves hits we can't date.

Scorecard: 1 hit · 1 miss · 1 unverified. Receipts or it didn't happen.

The Ninja Labz CHATTER Deep Report

CHATTER is our converged threat-chatter hub in Ninja Labz. Eleven feeds (leak sites, dark-web mirrors, CISA KEV, NVD, ThreatFox, OTX, Telegram CTI trackers, Mastodon, advisories, 0-day news and our own Atlas correlations) are embedded on the box, linked to their nearest CTI entity and scored for novelty. Then one extended-thinking pass writes the deep report. This one was generated 2026-09-24 23:05 UTC over the latest 100 items by claude-sonnet-4-6, and it's reproduced here in full.

How to read it: this is a machine-written synthesis of public feeds. Named CVEs, malware families and victim counts are as reported by those feeds; verify against the primary advisory before acting. The predictions are falsifiable on purpose, and we'll grade them.

Headline

AI-augmented attack tooling converges with active network-edge exploitation and broad ransomware campaigns in a high-tempo September 2026 threat landscape

Overview

Three converging dynamics define this cycle's threat picture: the weaponization of AI for autonomous command-and-control and mass exploitation at scale, sustained active exploitation of critical vulnerabilities in perimeter security products, and a vigorous ransomware ecosystem claiming victims across sectors and geographies simultaneously. CISA's KEV additions for Check Point, F5 BIG-IP, Zyxel, and Arista VeloCloud—with Check Point CVE-2026-85102 independently confirmed as actively exploited in pre-authentication RCE attacks—signal that security gateway and VPN infrastructure has become the preferred initial-access target. Concurrently, novel malware families including CLOSEDQUORUM, CARBONATO, AvisLoader, PavinLoader, and RemControl demonstrate rapid capability maturation, with AI integration recurring as a cross-cutting theme across criminal tooling, exploit pipelines, and attack orchestration. The ransomware ecosystem shows no deceleration, with at least twelve distinct groups posting victims ranging from logistics and aviation to agriculture, healthcare-adjacent services, and financial firms, while CISA explicitly warns that ransomware operators are now folding KEV-class vulnerabilities into their initial-access playbooks.

By feed type

Vulnerabilities & exploitation. CISA's KEV additions are dominated by network-edge and security product flaws: a stack-based buffer overflow in Zyxel GS1900 switches exploitable via the CGI program, two separate Check Point vulnerabilities covering improper certificate validation in Security Gateway VPN endpoints and path traversal in Security Management and Log Server products, a heap-based buffer overflow in F5 BIG-IP APM triggered when OAuth and access policy are co-configured, and an improper input validation flaw in Arista VeloCloud Orchestrator allowing access to privileged internal functionality. Check Point CVE-2026-85102 stands out as the most operationally urgent item, confirmed as pre-authentication RCE by both the vendor and independent advisory feeds, with VeloCloud separately corroborated by an OTX pulse. The clustering of security gateway and VPN product vulnerabilities in a single KEV batch reflects adversary preference for compromising the perimeter layer itself to establish footholds with minimal detection exposure. NVD entries in this batch are legacy CVEs from the year 2000 and constitute feed noise with no current operational relevance.

IOCs & malware infrastructure. The IOC streams reveal concurrent operation of several distinct malware families against freshly provisioned infrastructure. Remcos maintains at least two duckdns-hosted C2 domains suggesting active phishing or dropper operations, while ClearFake distributes payloads through an Iran-themed WordPress domain consistent with its fake browser update lure pattern. A PHP webshell served via a Cloudflare Workers subdomain represents a notable abuse of legitimate CDN infrastructure to obscure C2 traffic. Two Remus botnet C2 endpoints and a pair of active Cobalt Strike team servers complete a busy, multi-actor infrastructure snapshot. OTX pulses add substantial depth: CLOSEDQUORUM is documented as the first implant using up to four AI models in an ensemble vote to determine next-step tasking rather than relying on a traditional attacker-controlled server, AvisLoader employs the Tox encrypted P2P network for takedown-resistant C2, PavinLoader is distributed across ClickFix and fake download campaigns simultaneously, and CARBONATO exploits unauthenticated Docker daemon exposure on port 2375 while incorporating an AI agent for operational decisions. The bulletproof hosting provider AS202412 registered to OMEGATECH LTD in the Seychelles is documented supporting four distinct malicious distribution chains across a five-month continuous operational window.

Ransomware. The ransomware ecosystem is exceptionally active this cycle, with claims attributable to at least twelve distinct groups across both clearnet and dark-web feeds. Qilin is among the most prolific, listing an agricultural cooperative, a software pipeline company, a technology firm, and multiple Latin American businesses within the observation window. Zawoo is conspicuously concentrated on French organizations, having published data from four separate victims spanning PVC manufacturing, technical engineering, real estate services, and accounting advisory, collectively amounting to hundreds of gigabytes of exfiltrated data. Transportation and logistics constitute a priority target sector, with Asyad Group in Oman, OnTrac in the US, and Air Tanzania each claimed by separate groups. CISA's advisory that ransomware gangs are actively exploiting a critical TeamCity vulnerability ties the KEV and ransomware streams together directly, confirming that initial-access brokers are translating freshly disclosed critical flaws into ransomware deployment opportunities within compressed timelines.

Dark web. Dark-web leak mirrors corroborate clearnet ransomware claims and add granularity on the scale of data exposed. Zawoo's four French victims collectively represent hundreds of gigabytes of published data, with Agiliance alone exceeding 210 GB—a volume indicating deep, sustained access rather than opportunistic exfiltration. Krybit's concurrent listings of a premium Australian grocer and a national African airline illustrate the geographic breadth that even less-prominent groups are achieving. DragonForce's publication of Arizona Vascular Medical Equipment data continues a documented pattern of healthcare-adjacent targeting. INC Ransom's claim against Grupo Caberj adds a Latin American telecommunications organization to the visible victim pool. The diversity of sectors and geographies across dark-web postings confirms that no single vertical or region is receiving meaningful protection from current ransomware pressure.

News & advisories. News and advisory feeds are anchored by confirmed exploitation events and novel campaign reporting rather than theoretical risk. Check Point's confirmation that CVE-2026-85102 is being actively exploited as a pre-authentication RCE is the most operationally urgent disclosure. A separate financially motivated campaign is using three open-source AI agent frameworks for vulnerability research, exploitation, and attack orchestration against online retailers at scale, reportedly compromising over 100 sites and harvesting more than 600,000 payment cards—a volume that would previously have required a substantially larger human operator team. Both the Roundcube Webmail code injection flaw and WordPress CVE-2026-87902 have transitioned from disclosure to active exploitation within the observation window, compressing the effective patch window to days. The ClickFix attack surface has expanded to the 'third-party.com' placeholder domain embedded in developer documentation, a novel seed vector. Android threat activity is rising simultaneously across two independent campaigns: Corp MDM Spyware targeting logistics-sector employees to intercept SMS and redirect calls, and the RemControl MaaS platform targeting banking customers in Europe and Canada through malvertising impersonating a popular streaming application.

Actor chatter (Telegram). Telegram traffic is sparse in operational signal but meaningful at the margins. LLCPPC is hardening its infrastructure by adding bot-based broadcast channels as a contingency against platform-level bans, a standard operational security posture for groups anticipating disruption. Cyberknow's tracking references an October-dated Israel-Palestine cyber activity report, signaling continued hacktivist coordination in that conflict theater. FalconFeedsio's advertisement of anti-bot detection services with Telegram API integration and backup hosting reflects a continuing market for evasion tooling sold through semi-public channels, indicating demand from actors seeking more resilient campaign infrastructure.

Practitioner social. Mastodon traffic from the infosec community is largely ambient, with conference announcements, geopolitical commentary, and personal posts dominating the feed. The most substantive analytical thread involves a practitioner recounting how an AI-powered SOC investigation tool failed to generate meaningful investigative leads from a standard Suricata alert, offering a grounding counterpoint to the AI-capability claims surfacing in other feed types. The RemControl malware advisory is organically circulating in social channels, indicating growing practitioner awareness of the new Android banking MaaS threat, which may translate into faster detection rule and indicator sharing in the near term.

Fast-burn: 0-day and active exploitation (days)

1. Exploitation of Check Point CVE-2026-85102 pre-authentication RCE in Security Gateway VPN will spread at mass scale as initial access brokers and ransomware affiliates weaponize the flaw before enterprise patch deployment can keep pace.

  • Confidence: high · Horizon: 24-72 hours

  • Why: CVE-2026-85102 is simultaneously present in CISA KEV, confirmed as actively exploited by the vendor, independently corroborated by news advisories describing pre-auth RCE, and co-listed alongside a related Check Point path traversal flaw suggesting coordinated disclosure of a broader attack surface. Pre-authentication vulnerabilities in widely deployed VPN gateways have a documented history of near-immediate mass exploitation. CISA's concurrent warning that ransomware gangs are now exploiting KEV-listed flaws rapidly further elevates urgency.

  • Signals: CVE-2026-85102 added to CISA KEV · Check Point vendor advisory confirms active exploitation · rss advisory describes pre-auth RCE in production environments · CISA warning on ransomware operators adopting KEV flaws

2. WordPress CVE-2026-87902 exploitation will escalate from observed file-write activity to systematic web shell deployment and payload staging across a large population of unpatched sites.

  • Confidence: medium · Horizon: 3-7 days

  • Why: Advisory feeds explicitly note the transition from scanning and probing to active file writes and shell code execution, meaning weaponization is already underway. WordPress's enormous install base and the typical rapid diffusion of working exploits through criminal marketplaces compress the window between initial exploitation and mass-scale campaign activity.

  • Signals: rss advisory: CVE-2026-87902 exploitation confirmed with shell code execution observed · shift documented from probing to active payload delivery · large unpatched WordPress install base providing target-rich environment

3. Roundcube Webmail code injection exploitation will be leveraged in targeted credential harvesting and email collection campaigns, with government and diplomatic mail servers at elevated risk given Roundcube's known deployment profile in those sectors.

  • Confidence: medium · Horizon: 3-10 days

  • Why: Active exploitation is confirmed by Canadian CCCS, and Roundcube has a documented history of being prioritized by state-sponsored actors for email access against public-sector targets. The May patch date means a large population of servers remains exposed after a four-month lag, and concurrent news and advisory corroboration increases confidence in current active exploitation.

  • Signals: cyber-news and rss both confirm active exploitation · Canadian CCCS advisory issued · Roundcube's historical APT targeting profile for email collection

4. The AI-powered e-commerce skimming campaign that has already infected over 100 retail sites and stolen 600,000 credit cards will continue to expand its victim pool as automated AI-driven enumeration continuously surfaces new vulnerable targets.

  • Confidence: medium · Horizon: 1-2 weeks

  • Why: The campaign is described as ongoing and using AI frameworks for both vulnerability discovery and attack orchestration, creating a self-amplifying loop where successful compromises inform additional targeting. Campaigns of this architecture do not have natural stopping points absent takedown action against the underlying infrastructure or AI agent endpoints.

  • Signals: rss advisory: 600K cards stolen, 100+ sites compromised and ongoing · cyber-news: three AI harnesses used for research, exploitation, and orchestration · OTX pulses documenting AI-driven exploitation infrastructure at scale

5. ClickFix attacks will proliferate using additional placeholder, example, and developer-documentation domains beyond 'third-party.com' as adversaries exploit the inherent trust users extend to domains they recognize from technical contexts.

  • Confidence: medium · Horizon: 3-14 days

  • Why: The third-party.com case demonstrates a deliberate adversary strategy of identifying domains with ambient technical legitimacy rather than registering lookalikes, and the PavinLoader OTX pulse independently confirms ClickFix as a live, multi-campaign distribution mechanism. Public disclosure of the technique reliably accelerates imitation.

  • Signals: rss advisory: third-party.com ClickFix attacks active · OTX PavinLoader pulse: ClickFix used across multiple distribution campaigns · ClickFix technique now documented as mature and widely adopted

Slow-burn: emerging shifts (weeks to months)

1. CLOSEDQUORUM-style autonomous AI C2 architecture will inspire derivative implant development across criminal and state-sponsored actor communities, marking the beginning of a durable shift toward AI-native malware that uses model ensembles for real-time operational decision-making rather than static attacker-issued commands.

  • Confidence: medium · Horizon: 2-5 months

  • Why: CLOSEDQUORUM is documented as the first implant using multi-model AI voting for C2 decisions, a genuine architectural novelty. The simultaneous emergence of CARBONATO incorporating an AI agent and the AI-orchestrated e-commerce campaign confirms this is not an isolated experiment but the leading edge of a broader capability diffusion. Novel techniques that reduce operator workload or improve evasion reliably spread through criminal markets after public documentation.

  • Signals: OTX CLOSEDQUORUM: first documented autonomous AI-driven C2 implant · OTX CARBONATO: Docker botnet integrating AI agent for operational decisions · cyber-news and rss: AI agent frameworks used for end-to-end attack orchestration

2. RemControl Android banking MaaS will expand geographic targeting beyond its initial Europe and Canada footprint and broaden its overlay library to cover additional financial and cryptocurrency applications as subscriber growth incentivizes capability investment.

  • Confidence: medium · Horizon: 6-12 weeks

  • Why: RemControl has been operational since May 2026 and has already achieved full MaaS maturity with malvertising-based distribution, suggesting an established operator with reinvestment capacity. Android banking trojans operating as MaaS platforms have a documented pattern of aggressive overlay expansion to grow subscriber revenue, and AI-generated overlay capability noted in the OTX pulse enables rapid customization across new banking application targets.

  • Signals: OTX RemControl pulse: MaaS operational since May 2026 · rss advisory: malvertising via fake TVTap targeting European and Canadian banking users · social: practitioner awareness growing suggesting expanding victim reports · AI-generated overlay capability enabling fast adaptation to new targets

3. AvisLoader's Tox P2P-based C2 technique will be adopted by additional malware developers as a resilient alternative to domain-based infrastructure, particularly as law enforcement operations against conventional C2 hosting continue to mature.

  • Confidence: medium · Horizon: 6-10 weeks

  • Why: Tox-based C2 is inherently resistant to domain seizures and IP-based blocking because it relies on a decentralized peer-to-peer network, and the OTX pulse explicitly frames AvisLoader as designed to survive takedown attempts. Techniques that demonstrably outlast law enforcement actions attract rapid adoption once published, following the same diffusion pattern seen with earlier C2 innovations such as domain generation algorithms and blockchain-based beaconing.

  • Signals: OTX AvisLoader pulse: Tox P2P network for C2 explicitly framed as takedown-resistant · established pattern of novel resilient C2 channels diffusing through criminal markets after public documentation

4. Bulletproof hosting provider AS202412 (OMEGATECH LTD, Seychelles) will attract additional criminal clientele and expand the number of malicious campaigns it anchors, absent targeted ASN-level disruption, given its demonstrated five-month operational resilience.

  • Confidence: medium · Horizon: 4-8 weeks

  • Why: Five continuous months of operation supporting four distinct malicious infrastructure chains without disruption establishes AS202412 as a proven reliable option in the criminal hosting market. Providers that demonstrate longevity become preferred infrastructure for higher-tier actors willing to pay a premium for stability, creating a positive feedback loop of increased utilization and revenue that sustains continued operation.

  • Signals: OTX Disposable Domains pulse: AS202412 documented supporting four chains over five months · demonstrated longevity making the provider attractive to additional threat actors

5. Chinese threat actor UTA0565 will deploy reserve zero-day capabilities or acquire replacement exploits following public disclosure of their Chrome and Windows 0-day tooling, sustaining targeted compromise operations against high-value endpoints.

  • Confidence: low · Horizon: 4-10 weeks

  • Why: UTA0565 is documented exploiting simultaneous Chrome and Windows zero-days in September 2026, indicating an actor with significant vulnerability research capacity or access to a zero-day broker pipeline. State-sponsored actors of this sophistication tier routinely rotate tooling after public attribution and typically hold reserve capabilities specifically for this contingency. Browser and OS zero-day targeting suggests a focused interest in endpoint compromise against high-value intelligence targets.

  • Signals: OTX UTA0565 pulse: concurrent Chrome and Windows 0-day exploitation in September 2026 · Chinese APT actor with demonstrated zero-day acquisition and stockpiling capacity · public disclosure historically triggers tool rotation and reserve capability deployment

6. Zawoo ransomware will intensify targeting of French-speaking European organizations, potentially expanding into Belgium, Switzerland, and Luxembourg, as the group builds sector-specific access expertise and French-language extortion workflows on the foundation of its current French campaign.

  • Confidence: low · Horizon: 4-8 weeks

  • Why: Four separate French victim organizations posted in a single observation window across manufacturing, engineering, real estate, and accounting represents deliberate geographic and sector focus rather than opportunistic targeting. Ransomware groups that develop language-specific access and negotiation capability tend to deepen rather than abandon that specialization, and the natural geographic expansion of French-language targeting encompasses multiple adjacent countries.

  • Signals: ransomlook: four distinct French company leaks attributed to zawoo in single observation window · sector diversity across victims suggesting broad access capability within French SME landscape · geographic clustering as indicator of deliberate rather than opportunistic targeting strategy

Defender quickwin (KQL)

The lesson of the Mirai catch, as a Sentinel hunt: match edge sources against threat intel including the host of payload URLs and ip:port indicators, not just bare IPs. Swap in your own web-log table.

7-day forecast (graded in 008)

  • 1. 94.154.43.0/24, the Mirai payload neighbourhood, hits our edge again within 7 days (measured by the sensor).

  • 2. The Gentlemen or Qilin is in the top three by 7-day ransomware claims on 2 October.

  • 3. CHATTER's top fast-burn call: Check Point CVE-2026-85102 is linked to a named ransomware or initial-access campaign in our feeds within 7 days.

By the numbers

  • 41,794 edge requests in a day · 6,407 source IPs · 72 hostile · 30 attributed

  • 0.54 s for a local sensor to fingerprint the whole day

  • 0.91 Mirai attribution on two IPs · 2,344 IOCs in their /24

  • 6 independent evidence types · 0 actors asserted without evidence

  • 100 chatter items across 11 feeds in the deep report · roughly 6–10¢ to generate it

Why this exists

Reputation lookups tell you an IP is bad. They rarely tell you what it is, who else it's with, or how sure anyone should be. Adversary DNA plus attribution does all three, from your own logs, without shipping them anywhere. And because every claim carries its evidence and every forecast gets graded, you can check our work.

Radar, not a museum.

— Scottg

#ThreatIntel #CyberSecurity #SOC #DetectionEngineering #Mirai #Botnet #Ransomware #AI #Attribution #NinjaSignal

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing