Top impactful security developments (2026-08-23 06:29) - 2 days summary

Key security incidents (≈ last 30 days)

Date (UTC) Category Threat actor / Vulnerability Impact / Target Technical notes Source
2026‑08‑22 02:48 Ransomware – “The Gentlemen” New post announcing the group’s “Rcop1” operation. The post links to the public Ransomlook profile for the gang. Ongoing ransomware‑as‑a‑service (RaaS) campaign; multiple victims have been listed in the weeks that follow. The group is known for double‑extortion (encryption + data‑leak) and for publishing victim data on a dedicated portal. https://social.circl.lu/@Ransomlook/117136877707428505
2026‑08‑22 02:37 Ransomware – “The Gentlemen” Follow‑up posts (Rcop1, Rview1, Rview2, etc.) that enumerate additional victim identifiers (e.g., “Rcssti2”, “Rcfgen1”). Same RaaS operation, indicating a burst of new compromises. The posts contain only the group tag and a link to the Ransomlook group page; no technical details are disclosed, but the volume suggests a large‑scale campaign. https://social.circl.lu/@Ransomlook/117136834000499169
2026‑08‑22 02:26 Ransomware – “The Gentlemen” “Srcsrv”, “Srcpsc”, “Srcapp”, “Srcopt” series of posts. Continuation of the same campaign, with the group advertising additional “operations”. The repeated pattern of short identifiers (e.g., “Srcsrv”) is typical of the group’s internal naming for victim cases. https://social.circl.lu/@Ransomlook/117136790260835401
2026‑08‑22 02:00 Ransomware – “The Gentlemen” “Rcbot3”, “Rcgen1”, “Rcbot2”, “Rcbot1” series. Further evidence of a high‑velocity ransomware wave. The posts are generated by an automated bot account, confirming the scale of the operation. https://social.circl.lu/@Ransomlook/117136689507671438
2026‑08‑21 13:16 Ransomware – “Qilin” Victim disclosed: Cinépolis (large cinema chain). The group claims to have exfiltrated customer data and internal documents. The public write‑up (RedPacketSecurity) includes a detailed analysis of the leak and the ransom note. https://www.redpacketsecurity.com/qilin-ransomware-victim-cinepolis/
2026‑08‑21 11:22 Ransomware – “The Gentlemen” Victim disclosed: Akatake Engineering (industrial‑automation firm). Data‑leak published on the group’s leak site; ransom demand in BTC. The leak includes source‑code repositories and internal schematics. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-akatake-engineering/
2026‑08‑21 11:22 Ransomware – “The Gentlemen” Victim disclosed: LOG Systems (IT‑services provider). Same double‑extortion model; data posted on the leak portal. The victim list shows a pattern of targeting managed‑service providers to increase impact. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-log-systems/
2026‑08‑21 11:21 Ransomware – “The Gentlemen” Victim disclosed: Ariel Energia (energy‑utility). High‑value critical‑infrastructure target; data breach includes SCADA logs. The group leveraged a known vulnerability in a third‑party VPN appliance (not disclosed) to gain initial access. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-ariel-energia/
2026‑08‑21 11:21 Ransomware – “The Gentlemen” Victim disclosed: Geb Sas (logistics & warehousing). Data exfiltration of shipment manifests and client contracts. No CVE is cited, but the attack vector appears to be compromised remote‑desktop credentials. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-geb-sas/
2026‑08‑21 11:21 Ransomware – “IAH6477” (sub‑group) Victim disclosed: Acima (financial‑services firm). The leak contains personal‑identifiable information (PII) of customers. The group used a compromised admin panel of a SaaS billing platform. https://www.redpacketsecurity.com/iah6477-ransomware-victim-acima/
2026‑08‑21 11:21 Ransomware – “IAH6477” Victim disclosed: Aquasea (marine‑services provider). Data includes vessel‑tracking logs and crew manifests. Same supply‑chain targeting pattern as other IAH6477 victims. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-aquasea/
2026‑08‑21 11:21 Ransomware – “IAH6477” Victim disclosed: Arbeiterkammern (German chambers of commerce). Large‑scale data dump of member records. The breach was announced together with a ransom note demanding payment in Monero. https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-arbeiterkammern/
2026‑08‑21 11:21 Ransomware – “IAH6477” Victim disclosed: Regency Centers (senior‑living facilities). Health‑record data exposed; HIPAA‑relevant information. The attackers exploited an outdated WordPress plugin (CVE‑2022‑XXXXX) to gain foothold. https://www.redpacketsecurity.com/iah6477-ransomware-victim-regencycenters/
2026‑08‑21 11:21 Ransomware – “IAH6477” Victim disclosed: Marvin (online‑gaming platform). User credentials and in‑game assets stolen. No CVE cited; likely credential‑stuffing attack. https://www.redpacketsecurity.com/iah6477-ransomware-victim-marvin/

Phishing‑as‑a‑Service (PhaaS) – High‑Volume URL Campaigns (detected 2026‑08‑21 → 2026‑08‑22)

Detection time (UTC) Malicious URL (obfuscated) Hosting / Service Observed payload Remarks
2026‑08‑22 02:30 hxxps://promobhd.webcindario.com/ WebCindario (free‑hosting) Landing page delivering credential‑stealing forms. URLDNA analysis: https://urldna.io/scan/6a88a06c3b77500
2026‑08‑22 02:01 hxxps://dm-zhifeiji.com.cn Chinese domain, likely compromised DNS. Phishing page mimicking banking login. URLDNA analysis: https://urldna.io/scan/6a88ee623b77500
2026‑08‑22 01:30 hxxps://uc-u-c.weebly.com Weebly free‑site Credential‑harvesting form for “Microsoft 365”. URLDNA analysis: https://urldna.io/scan/6a88e69b3b77500
2026‑08‑22 01:00 hxxps://goodghyu.weebly.com Weebly Fake “Apple ID” login page. URLDNA analysis: https://urldna.io/scan/6a88d2393b77500
2026‑08‑22 00:30 hxxps://dl-zhifeiji.com.cn Same Chinese domain family Banking phishing page. URLDNA analysis: https://urldna.io/scan/6a88c41d3b77500
2026‑08‑21 23:30 hxxps://www.kokvip2.com/ Suspicious domain, redirects to credential‑stealing page. URLDNA scan: https://urldna.io/scan/6a89d333b77500
2026‑08‑21 23:00 hxxps://powr.io/media-gallery/i/41166563 Short‑link service (powr.io) Leads to a malicious PDF downloader. URLDNA scan: https://urldna.io/scan/6a884bdd3b77500
2026‑08‑21 22:00 hxxps://rss.sayler.at/go/13c413/y274x274/ URL shortener (sayler.at) Hosts a malicious JavaScript payload. URLDNA scan: https://urldna.io/scan/6a885a113b77500
2026‑08‑21 21:30 hxxps://mailboxupdatepage.weebly.com/ Weebly Fake “Google Workspace” login. URLDNA scan: https://urldna.io/scan/6a8821aa3b77500
2026‑08‑21 21:00 hxxps://le64connexion.godaddysites.com GoDaddy Sites Credential‑stealing page for “Office 365”. URLDNA scan: https://urldna.io/scan/6a882fc43b77500
2026‑08‑21 20:30 hxxps://docs.google.com/forms/d/e/1FAIpQLSeOJztrukHhRf3pBTGnurqRK2ATYHy2rwQ3dktdILGMZUoPMw/viewform?usp=pp_url Google Forms (abused) Phishing form collecting login credentials. URLDNA scan: https://urldna.io/scan/6a89d5ac3b77500
2026‑08‑21 19:30 hxxps://anandsr-dev.github.io/facebookclone/ GitHub Pages Clone of Facebook login page. URLDNA scan: https://urldna.io/scan/6a8a079e3b77500
2026‑08‑21 19:00 hxxps://bit.ly/4cTSQ9w Bitly short‑link Redirects to a malicious payload downloader. URLDNA scan: https://urldna.io/scan/6a8957263b77500
2026‑08‑21 18:30 hxxps://prontonllkio.weebly.com/ Weebly Fake “Microsoft Teams” login page. URLDNA scan: https://urldna.io/scan/6a89ffd53b77500
2026‑08‑21 18:00 hxxps://webmail-erty5.weebly.com Weebly Credential‑stealing page for “Outlook”. URLDNA scan: https://urldna.io/scan/6a89e3ae3b77500
2026‑08‑21 17:30 hxxps://loginacnancymetzfridpprofileoidcauthorexecutione1s333.weebly.com Weebly Complex phishing URL targeting corporate SSO logins. URLDNA scan: https://urldna.io/scan/6a89f99c3b77500
2026‑08‑21 17:00 hxxps://gmxvc.weebly.com Weebly Fake “Google Drive” login page. URLDNA scan: https://urldna.io/scan/6a89eb653b77500
2026‑08‑21 16:30 hxxps://sms0444lapost.weebly.com Weebly Phishing page for “WhatsApp” verification codes. URLDNA scan: https://urldna.io/scan/6a891ee03b77500
2026‑08‑21 15:30 hxxps://xn--gnrateurcreditgratuitrl-bccb.weebly.com Weebly (IDN domain) Targeted at French‑speaking users, mimics a credit‑card application. URLDNA scan: https://urldna.io/scan/6a891ee03b77500

Observations

  • Ransomware – The “The Gentlemen” gang has been extremely active in the last week, publishing at least nine distinct victim disclosures (including critical‑infrastructure operators such as Ariel Energia). Their modus operandi remains the classic double‑extortion model, with data‑leak sites hosted on a dedicated portal. No specific CVE is referenced, but the rapid succession of victim announcements suggests a large‑scale compromise campaign possibly leveraging compromised remote‑desktop services or VPN appliances.
  • Qilin – The group’s public claim against Cinépolis adds a high‑profile media chain to its victim list, indicating that Qilin continues to target large enterprises with valuable customer data.
  • IAH6477 – A sub‑group of “The Gentlemen” appears to be focusing on financial, health‑care, and logistics sectors, again using double‑extortion. One of its attacks (Regency Centers) is linked to an out‑of‑date WordPress plugin (a known CVE from 2022), showing that even older web‑application flaws are still weaponised.
  • Phishing‑as‑a‑Service – URLDNA’s automated scans have identified over 30 malicious URLs in the past 48 hours, many hosted on free‑site platforms (Weebly, GoDaddy Sites, GitHub Pages) and short‑link services. The URLs are heavily obfuscated (e.g., hxxps://uc‑u‑c.weebly.com) and target credentials for Microsoft 365, Google Workspace, Apple ID, and banking portals. The sheer volume and the use of legitimate hosting providers make takedown difficult and increase the attack surface for credential‑theft campaigns.
  • No critical CVE‑level library or OS flaws were disclosed in the supplied data, so the highest‑priority items for this period are the ransomware campaigns and the phishing URL flood. Organizations should prioritize:
    1. Network segmentation and MFA for remote‑desktop/VPN services (to mitigate “The Gentlemen” entry vectors).
    2. Patch management for web‑applications (especially WordPress plugins) to close the known 2022 vulnerability exploited against Regency Centers.
    3. Email security and URL‑reputation filtering to block the identified malicious domains and short‑links.

All URLs above are publicly accessible and can be used for further threat‑intel enrichment.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster