| New Threats Detection Added | • PackClient RAT • TryNode RAT • ReverseLoader |
| New Threat Protection | 11 |
| Newly Detected Threats | 86 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
PackClient RAT | ||||||||||||||||||||||||
|
PackClient RAT is a modular Remote Access Trojan (RAT) and command-and-control (C2) framework mainly used by Chinese-speaking threat actor TA4922. PackClient RAT is openly sold on Chinese-language Telegram marketplaces. This malware provides attackers with multi-stage architecture capable of data theft, user surveillance, and deployment of additional plugins. PackClient RAT is primarily distributed via targeted tax-themed phishing email campaigns.
|
|||||||||||||||||||||||||
|
Threat Protected:
|
02 | ||||||||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||||||||
|
Class Type:
|
Trojan-activity | ||||||||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||||||||
Known Exploited Vulnerabilities (Week 1 - October 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-1st-week-of-october-2026/700.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
8.7
|
Citrix NetScaler ADC and Citrix NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote threat actor to trigger a denial of service if SAML SP or SAML IdP are configured.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.4
|
Zammad contains an improper privilege management vulnerability that can allow the local Zammad user to escalate privileges to root level permissions.
|
=>1.5.0
|
7.1.0
|
||
|
9.4
|
Zammad contains a session fixation (hijack) vulnerability that can lead to remote code execution as the zammad user.
|
=>6.3.0
=>7.0.0
|
6.5.4
7.1.3
|
||
|
9.8
|
Fortinet FortiMail contains a path traversal vulnerability that can allow an unauthenticated remote attacker to create arbitrary files on the system via a specially crafted HTTP request.
|
8.0.0 – 8.0.1
7.6.0 – 7.6.6
7.4.0 – 7.4.8
7.2.0 – 7.2.9
|
8.0.2
7.6.7
7.4.9
|
||
|
9.8
|
Cisco Catalyst SD-WAN Manager contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker gain privileged access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Multiple Apple products contain an out of bounds write vulnerability that can allow an unauthenticated remote attacker execute code on the device upon processing a specially crafted file.
|
< 26.7.1
< 15.8.1
|
26.7.1
15.8.1
|
||
ICS Advisories (Week 1 - October 2026)
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
Meari
|
IoT Cloud Platform OpenAPI Service
CVE-2026-101104 (CVSS: 7.7)
CVE-2026-96613 (CVSS: 6.5)
|
Contains vulnerabilities that can allow an attacker to modify configuration and access sensitive information from devices they don’t own.
|
N/A
|
N/A
|
|
|
Johnson Controls
|
EasyIO Neo Series EC and CW Controllers
CVE-2026-64893 (CVSS: 5.4)
|
Contains a vulnerability that can allow an attacker within the same network to intercept and read sensitive information in plain text.
|
EC: V3.3b62 – V3.3b62
CW: V3.3b24 – V3.3b25
|
V3.3b64
V3.3b26 |
|
|
EasyIO Neo Series EC and CW Controllers
|
Contains a vulnerability that can allow an unauthenticated attacker to obtain sensitive information that can be used in further attacks against the system.
|
EC: V3.3b62 – V3.3b63
CW: V3.3b24 – V3.3b25
|
V3.3b64
V3.3b26
|
||
|
ABB
|
Protection and Control IED Manager PCM600
CVE-2026-15952 (CVSS: 6.4)
CVE-2026-15953 (CVSS: 5.0)
|
Contains a vulnerability that can allow an authenticated attacker to escalate to SYSTEM level privileges on the system.
|
<= 2.14
|
N/A
|
|
|
Monta
|
monta.app
CVE-2026-95102 (CVSS: 9.4)
CVE-2026-97363 (CVSS: 7.5)
CVE-2026-97212 (CVSS: 7.3)
CVE-2026-93474 (CVSS: 6.5)
|
Contains an authentication bypass vulnerability that can allow an unauthenticated attacker to gain access to the system. Additionally, the lack of rate limiting can allow an attacker to bruteforce valid WebSocket session identifiers.
|
N/A
|
N/A
|
|
|
Armatura LLC
|
Armatura One
CVE-2023-46604 (CVSS: 9.8)
CVE-2026-94591 (CVSS: 8.4)
CVE-2026-94592 (CVSS: 8.4)
CVE-2026-94593 (CVSS: 7.8)
CVE-2026-94594 (CVSS: 4.0)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to gain access to the system and execute code on the host device.
|
< 4.7.2
< 4.6.1
|
4.7.2
4.6.1
|
|
|
MikroTik
|
RouterOS
CVE-2026-84411 (CVSS: 9.8)
|
Contains an integer underflow vulnerability that can allow an unauthenticated remote attacker to execute code with elevated privileges by sending a specially crafted HTTP request.
|
< 7.24
|
7.24
|
|
|
Viidure
|
Dashcam Android Application
CVE-2026-94204 (CVSS: 7.5)
CVE-2026-96587 (CVSS: 10.0)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to access and modify sensitive user data stored on the system.
|
<= 3.3.1.260403
|
N/A
|
|
|
Anjvision
|
YSSD-RTMP-H5
Multiple CVEs (9x) (CVSS: 5.3 – 9.8)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker gain access to the system, access sensitive information and execute operating system commands on the device.
CISA ICS Advisory: icsa-26-272-05 |
<= 3.3.2.4
|
N/A
|
|
|
Baicells
|
Nova 430H
CVE-2026-96274 (CVSS: 7.4)
|
Contains a denial-of-service vulnerability that can allow an unauthenticated remote attacker within radio range of the device to cause the device to shut down.
|
<= 3.0.12
|
||
|
VIVOTEK
|
Camera Firmware
CVE-2026-22755 (CVSS: 10.0)
|
Contains a command injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands with root level privileges on the device.
|
Check vendor advisory for affected products and versions.
|
||
|
Toptech
|
TMS7 and TopHAT
Multiple CVEs (10x) (CVSS: 3.5 – 10.0)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to gain access to the system without authentication. Additionally, contains vulnerabilities that can allow an unauthenticated attacker to upload arbitrary PHP files and retrieve information stored in the database via multiple SQL Injection vulnerabilities.
CISA ICS Advisory: icsa-26-272-02 |
<= 7.6.3
|
7.8
|
|
|
Lantronix
|
G520 Series Cellular Gateway
CVE-2026-84409 (CVSS: 7.5)
CVE-2026-91191 (CVSS: 7.5)
|
Contains vulnerabilities that can allow an attacker to replace the software used by the device which may result in arbitrary code execution with root level privileges.
CISA ICS Advisory: icsa-26-272-01 |
< 2.6.0.4R6
|
2.6.0.7R6
|
|
Updated Malware Signature (Week 1 - October 2026)
|
Threat
|
Description | |
|
ReverseLoader
|
ReverseLoader is a malware loader used to deliver and execute additional malicious payloads on compromised systems. ReverseLoader primary function is to evade detection and while establishing persistance and downloading secondary malware such as Remote Access Trojan (RATs), information stealers, and other malware families. This malware is being distributed through highly deceptive phishing email and embedding malicious attachment scripts inside the phishing email.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that The Gentlemen was the most active ransomware group, impacting 34 victims, which accounted for 14.59% of the total ransomware hits. This made The Gentlemen the leading ransomware actor during the reporting period. Metaencryptor recorded the second-highest activity, affecting 16 victims and contributing 6.87% of the total ransomware activity. Storm followed with 15 victims, representing 6.44%, while Qilin and SafePay each impacted 12 victims, accounting for 5.15% individually. A significant level of activity was observed from Inc Ransom and Lamashtu, each affecting 10 victims, contributing 4.29% individually. N0n, Emperador, Akira, and Brain Cipher each recorded 8 victims, representing 3.43% individually. Moderate ransomware activity was observed from M3rx and 3AM, each impacting 7 victims, accounting for 3.00% individually. Global Cybernetic Collective and Booba Team each recorded 6 victims, contributing 2.58% individually. Play and Krybit each affected 5 victims, representing 2.15% individually. Several ransomware groups showed lower but notable activity. Rhysida and Genesis each impacted 4 victims, accounting for 1.72% individually. Interlock, Panzer, Kairos, Chaos, Lockbit5, and Ransomhouse each recorded 3 victims, representing 1.29% individually. Groups including Endzone, Pear, Shiba, Doommageddon, Wallstreet, Gammax, Vexy, Aurora, Audit Team, and ShinyHunters each affected 2 victims, accounting for 0.86% individually. The remaining ransomware groups, including Blacklocks, Spirals, Termite, Arcus Media, Ulose, Payload, Cry0, Eclipse, Redact, and Morpheus, each recorded 1 victim, representing 0.43% individually. |
Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 107 victims, accounting for 45.92% of the total ransomware activity. This indicates that nearly half of all reported ransomware victims were located in the United States, making it the primary target region during this period.
Germany recorded the second-highest number of victims, with 12 cases, representing 5.15% of the total. Brazil and France each reported 8 victims, contributing 3.43% individually. India recorded 7 victims, accounting for 3.00% of overall ransomware activity.
Other countries with notable ransomware impact included Japan, with 6 victims, representing 2.58%. South Africa, Canada, Spain, and the United Kingdom each recorded 5 victims, contributing 2.15% individually.
Moderate ransomware activity was observed in Switzerland, China, and Italy, each reporting 4 victims, accounting for 1.72% individually. South Korea, Mexico, Thailand, Belgium, Australia, Sweden, and Taiwan each recorded 3 victims, representing 1.29% individually.
Several countries reported lower but notable activity, including Indonesia, Philippines, and Argentina, each with 2 victims, accounting for 0.86% individually.
The remaining countries recorded 1 victim each, representing 0.43% individually. These included Oman, Venezuela, Uzbekistan, Mali, Bangladesh, Czech Republic, Lithuania, Colombia, Ireland, Uruguay, Singapore, New Zealand, Georgia, Bulgaria, Nicaragua, Vietnam, Romania, Israel, Portugal, Turkey, United Arab Emirates, Puerto Rico, Czechia, Peru.
Industry-wide Ransomware Victim
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 49 victims, accounting for 21.03% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Healthcare recorded the second-highest number of victims, with 36 cases, representing 15.45% of the total. Business Services followed with 27 victims, contributing 11.59%, while IT and Retail each recorded 19 victims, accounting for 8.15% individually.
Other sectors with significant ransomware impact included Construction, with 13 victims, representing 5.58%, and Transportation, with 12 victims, accounting for 5.15%. Education recorded 10 victims, contributing 4.29%.
Moderate ransomware activity was observed in Finance, with 9 victims, representing 3.86%. Energy recorded 7 victims, contributing 3.00%, while Law Firms, Federal, and Hospitality each reported 5 victims, accounting for 2.15% individually.
Lower levels of ransomware activity were observed in Architecture, Telecommunications, and Real Estate, each recording 3 victims, representing 1.29% individually. Consumer Services, Media & Internet, and Organisations each reported 2 victims, accounting for 0.86% individually.
The least affected sectors were Insurance and Agriculture, each recording 1 victim, representing 0.43% of the total ransomware activity.
Overall, the data shows that ransomware activity was primarily concentrated in Manufacturing, Healthcare, Business Services, IT, and Retail sectors. These industries accounted for the majority of reported victims, highlighting continued attacker focus on sectors with critical operations, valuable data assets, and a high potential for operational disruption and financial impact.
Ulose Ransomware
Executive Summary
Ulose leak-site claim was observed inside the requested reporting window. RansomLook recorded a post titled www.newyjh[.]com on 29 September 2026 and described it as a Korean hospital. The listing is evidence that the operator made a claim; it is not, by itself, confirmation that Ulose compromised the organisation, encrypted systems, or obtained the data it advertised. [1]
The domain newyjh.com is the official web domain of H Plus Yangji Hospital in Seoul, South Korea, so the operator's victim identity and sector description are consistent with a real organisation. That match validates the identity behind the domain, not the alleged intrusion. [5]
|
Key question
|
Assessment | Confidence |
|
In-window DLS activity
|
One operator claim was observed on 29 Sep 2026. [1][3]
|
HIGH for tracker observation
|
|
Victim identity
|
Victims’ information in DLS site matches the data leak. [5]
|
HIGH
|
|
Data exposure
|
A public research post described a ULOSE medical-sector spreadsheet sample but did not publicly name the institution or verify scope. [6]
|
MEDIUM
|
|
Encryption or ransomware payload
|
No public technical evidence was identified. [8][9]
|
UNVERIFIED
|
|
Public sandbox diagnosis
|
No exact Ulose or newyjh[.]com match was found in the reviewed ANY.RUN searches. [8]
|
UNVERIFIED
|
Scope and Evidence Handling
The reporting window controls the activity count in this report. Earlier claims are retained only as group background. Tracker dates represent when a collector observed a public post; they do not establish the intrusion, encryption, exfiltration, or publication time. Counts are source-specific and can change with crawler coverage, deduplication, and leak-site availability. [1][3][4]
- Operator-claimed means a Ulose-controlled page or a tracker of that page named the organisation; it is not victim confirmation. [1][3]
- Identity-validated means the claimed domain and sector match an official organisation source; it does not validate compromise. [5]
- Possible exposure means a public researcher reported seeing sample material, while the affected organisation and full data set remain unverified. [6]
- A platform no-match result is an intelligence gap, not proof that the family or domain is benign, inactive, or absent from private collections. [8][9]
In-Window Claim Assessment
|
Date
|
Claimed victim | Country/sector | Evidence status |
|
29 Sep 2026
|
H Plus Yangji Hospital/ newyjh[.]com [1][5]
|
South Korea/ Healthcare [1][5]
|
OPERATOR-CLAIMED. Identity is validated; compromise remains unconfirmed. A separate PLAINBIT observation raises the plausibility of exposed personal data but does not conclusively name this victim. [6]
|
Undercode News also reported that ThreatMon observed the newyjh.com listing on 29 September and noted that the public claim did not provide an initial-access method, encryption detail, data volume, ransom demand, or victim acknowledgement. This is secondary reporting and is used only to corroborate that the listing circulated publicly. [7]
Possible Data-Exposure Evidence
|
Evidence question
|
Finding | Assessment |
|
Does a real organisation match the listed domain?
|
Yes. H Plus Yangji Hospital uses newyjh.com. [5]
|
Identity corroborated.
|
|
Was sample material reportedly visible?
|
Yes. PLAINBIT described an unmasked Excel screenshot on a ULOSE page. [6]
|
Raises plausibility of real data exposure.
|
|
Is the public sample definitively tied to newyjh.com?
|
No. The PLAINBIT post masks the institution name. [6]
|
Not established.
|
|
Is encryption confirmed?
|
No public payload, victim statement, or technical report was identified. [7][8][9]
|
Unverified.
|
|
Is the full scope known?
|
No. PLAINBIT said medical-record inclusion and full scope remained unconfirmed. [6]
|
Unverified.
|
Group Overview
The available public trackers disagree on Ulose's first-seen date. RansomLook and VULONE contain five posts dated 9 June 2026, while SOCRadar labels both first seen and last seen as September 2026. This report treats 9 June as the earliest available tracker record and records the discrepancy instead of silently selecting the later profile date. [1][3][4]
All six claims listed by RansomLook and VULONE involve South Korean organisations. VULONE groups the claimed victims mainly in financial services, healthcare, and manufacturing; SOCRadar also lists technology. These are tracker classifications based on victim identity, not evidence of targeting logic or access capability. [1][3][4]
The public listings use labels such as private, public, or sale, which is consistent with a data-extortion or data-sale presentation. The reviewed evidence does not establish whether Ulose also deploys an encryptor, operates through affiliates, or uses a consistent intrusion playbook. [1][3][6][7]
Technical Analysis
Public Malware Evidence
No public Ulose malware sample, cryptographic hash, binary filename, ransom note, extension, command line, configuration, network protocol, or reverse-engineering report was identified in the reviewed sources and authenticated platform searches. ANY.RUN returned no exact family-name or victim-domain match, and AlienVault OTX showed no files linked to the claimed domain. [8][9]
Accordingly, this report does not infer an encryption algorithm, execution method, persistence mechanism, lateral-movement tool, exfiltration utility, recovery-inhibition command, or initial-access vector. The evidence supports a leak-site operator making extortion or sale claims; it does not provide a public technical chain for a ransomware payload. [1][6][7][8][9]
MITRE ATTACK Evidence Boundary
MITRE ATT&CK technique IDs are assigned only when a source describes observable actor behaviour. Generic ransomware expectations are not Ulose evidence. The table therefore records material gaps rather than converting assumptions into actor-specific techniques. [10]
| Tactic Area | Technique status | Evidence decision |
|
Initial Access
|
NOT ESTABLISHED
|
No phishing, exploitation, remote-service, or credential-access evidence was identified. [7][8][9]
|
|
Execution/ Persistence
|
NOT ESTABLISHED
|
No sample, process chain, script, service, task, or autorun evidence was identified. [8][9]
|
|
Discovery/ Lateral Movement
|
NOT ESTABLISHED
|
No host, account, network, SMB, RDP, or remote-execution behaviour was identified. [8][9]
|
|
Collection/ Exfiltration
|
NOT ASSIGNED
|
The leak-site and reported spreadsheet make data exposure plausible, but do not reveal collection or transfer technique. [1][6]
|
|
Impact: T1486
|
NOT ASSIGNED
|
Data Encrypted for Impact is not assigned because no encryptor behaviour or victim confirmation was identified. [7][8][9][10]
|
|
Impact: T1490
|
NOT ASSIGNED
|
Inhibit System Recovery is not assigned because no recovery-tampering evidence was identified. [8][9][10]
|
Indicators and Contextual Observables
Only the tracked Ulose onion address is treated as actor infrastructure. The claimed victim domain is included for case correlation but is not malicious infrastructure. No public file hash, payload URL, ransom-note filename, extension, wallet, or confirmed command-and-control endpoint was available. [1][2][8][9]
| Type | Defanged value |
|
DLS onion
|
egm34gsyx65wb6jyqds4esvkskl34barx4robuebjhqpc4dfeavg7fyd[.]onion
|
|
Qtox ID
|
7FD474DA4CEE6D3B331AA5B0E04997FBE296435619920EAE2FCE4D176DB4F515B978E46FDA50
B6EA3F82D3957B07619753D5EF7E68C4C9E618756D9922B254D69353823DDF78C12135A564FE
|
Public Platform Validation
AlienVault OTX was checked on 3 October 2026 without submitting a sample. Searching Ulose returned three pulses whose titles or domains merely contained the character sequence ulose, including cellulose- and flocculose-related domains; they were excluded as substring false positives. The exact newyjh.com domain page showed zero pulses, zero files, three URLs, and 19 passive-DNS records, with no related tags. [9]
OTX resolved newyjh.com to 175.125.21.172 in South Korea on SK Broadband and displayed historical WHOIS and passive-DNS context. Those records describe the legitimate victim domain's infrastructure and do not diagnose ransomware, prove compromise, or make the address a malicious IOC. [9]
| Object | OTX Result | Assessment |
|
Ulose family search
|
Three substring false positives; no Ulose ransomware pulse identified. [9]
|
No family-level corroboration.
|
|
newyjh.com
|
0 pulses; 0 files; 3 URLs; 19 passive-DNS records; no related tags. [9]
|
Infrastructure context only.
|
Detection Opportunities
Because no Ulose-specific payload telemetry is public, the following detections are defensive controls for the observed risk pattern: a healthcare identity named on a leak site and possible exposure of structured personal data. They should not be represented as confirmed Ulose behaviours. [1][5][6][11]
- Alert on unusual access to patient-administration, CRM, billing, VIP, or identity datasets, especially large queries, export functions, and after-hours access by accounts that do not normally use them. [6][11]
- Correlate large archive creation, staged exports, cloud-sync activity, and sustained outbound transfer from database, application, or file servers. [6][11]
- Monitor new privileged accounts, MFA changes, unusual remote access, impossible travel, service-account interactive logons, and access from unmanaged devices. [11]
Mitigation and Remediation Recommendations
- Require phishing-resistant MFA for remote access, privileged administration, email, and cloud services; rotate credentials with evidence of misuse and invalidate active sessions. [11]
- Segment clinical systems, administrative systems, databases, backups, management networks, and internet-facing services; allow only documented flows between them. [11]
- Restrict bulk exports and removable-media or cloud uploads from systems containing patient and identity data; apply least privilege and dual approval to high-volume export functions. [6][11]
- Maintain offline or immutable backups, protect backup credentials separately, and test restoration of critical hospital services under realistic recovery conditions. [11]
- If a claim is received, preserve volatile memory, endpoint and server images, authentication records, database audit logs, proxy and firewall logs, and the exact operator communication before reimaging. [11]
- Validate alleged samples against authoritative records without redistributing exposed personal data; notify legal, privacy, executive, clinical, and incident-response stakeholders under the organization's breach process. [6][11]
Red Piranha CE 6.0 Alignment
The controls below align Crystal Eye with the actual Ulose evidence: possible theft or sale of healthcare personal data, an unknown initial-access path, and no diagnosed payload. The CE 6.0 manual portal is the governing entry point; the cited feature pages document the relevant firewall, IDPS, web-filter, threat-hunt, escalation, and incident-response functions.
- Reduce exposed attack paths - Use Advanced Firewall zones and permit-by-exception traffic rules for internet-facing, clinical, administrative, database, management, and backup networks. Attach IDPS or Web Filter actions where inspection is required.
- Detect suspicious access or exploit traffic - Apply IDPS policies to exposed and high-value segments, enable event logging, and use local rules when validated indicators or organization-specific patterns become available.
- Control anonymizers and unapproved web destinations - Use Web Filter profiles, banned sites and categories, file-extension or MIME controls, and SSL inspection where legally and operationally appropriate.
- Correlate a leak claim with telemetry - Use Threat Hunt top-user, top-device, external-IP, application, protocol, and upload-volume views to baseline and investigate spikes from healthcare-data systems.
- Escalate validated high-risk alerts - Use AI and Escalation Reports to review and escalate relevant IDPS and AV alerts to Red Piranha's Security Operations Team when the incident-response service is configured.
Red Piranha CE 6.0 Alignment
| Assessment | Confidence | Reason |
|
Ulose posted one in-window claim
|
HIGH
|
RansomLook and VULONE list newyjh.com on 29 September 2026. [1][3]
|
|
The claimed domain belongs to H Plus Yangji Hospital
|
HIGH
|
The hospital's official website uses newyjh.com. [5]
|
|
A ULOSE medical-sector listing contained plausible personal data
|
MEDIUM
|
PLAINBIT described an Excel screenshot and explicitly limited its conclusion. [6]
|
Known Intelligence Gaps
- No authoritative weekly spreadsheet, victim statement, regulator notice, or law-enforcement record was available to confirm the in-window claim. [1][5][7]
- No public malware sample, hash, note, extension, decryptor, encryption implementation, or behavior report was identified. [8][9]
- No confirmed initial-access, execution, persistence, credential-access, discovery, lateral-movement, exfiltration, or impact technique was identified. [8][9][10]
- The public PLAINBIT post masks the medical institution, preventing definitive matching of the reported spreadsheet sample to newyjh.com. [6]
- No verified data volume, ransom demand, deadline, negotiation, payment, wallet, settlement, or recovery outcome was identified. [2][7]
- The tracked leak site was down during review and the RansomLook page reported degraded collection health, limiting independent inspection of the current operator page. [1]
- Public tracker profiles disagree on whether Ulose was first seen in June or September 2026. [1][3][4]
- No relevant public ANY.RUN diagnosis or AlienVault OTX family pulse was identified; private collections were not accessible. [8][9]
Source References