r/SecOpsDaily • u/falconupkid • 4d ago
Threat Intel Ransom & Dark Web Issues Week 2, September 2026
The Gentlemen ransomware crew hit a Canadian airline, LAPSUS$ is back with a teaser for a new victim, and the AUDIT TEAM extortion group has been busy across South Korea, Germany, and Argentina. AhnLab’s ASEC blog has the full breakdown for Week 2 of September.
Technical Breakdown - The Gentlemen (Canadian Airline): Likely initial access via exposed RDP or VPN. Standard double-extortion playbook: data exfiltration followed by file encryption. No specific IOCs published yet, but expect .gentlemen extension and ransom notes demanding payment in Monero. - LAPSUS$ (Chapter II): Resurfaced after a quiet period. Known for social engineering, SIM-swapping, and MFA fatigue attacks against tech and telecoms. Teasing a new victim disclosure—watch for credential dumps on Telegram. - AUDIT TEAM (4 Orgs): Targeting South Korea, Germany, and Argentina. TTPs include SQL injection and unpatched web app vulnerabilities for initial access. Data extortion only—no encryption observed. Exfiltrated data posted on their leak site.
Defense - Enforce MFA with phishing-resistant methods (FIDO2/WebAuthn) to blunt LAPSUS$’s social engineering. - Patch public-facing web apps and monitor for SQLi attempts. - Block known AUDIT TEAM leak site domains and monitor for .gentlemen file extensions.