INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploying Kaolin RAT via Spear-Phishing
| 2026-09-01 00:00 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A ransomware operation, attributed to the threat group GOLD SHERWOOD, was detected on September 1, 2026, originating from an external IP address in the Netherlands. The attackers used legitimate tools and compromised credentials to evade detection, deploying ransomware within 24 hours of initial access, with some incidents occurring as soon as a few hours after post-compromise activity began. The targeted sector includes various industries, with over 683 victim names added to the leak site by July 2026, including at least 169 victims in July alone. The attackers exploit vulnerabilities in firewalls and abuse VPN services credentials for initial access, often using tools such as FortiGate firewall management interfaces or compromised credentials against multiple VPN services. As of September 1, 2026, the current status is that the operation appears to be ongoing, with continued deployment of ransomware and posting of victim names on a dedicated leak site.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2024-55591 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
a8ba89••••••••••••••••••••••••••••••••••
a438ba••••••••••••••••••••••••••••••••••
be8c52••••••••••••••••••••••••••••••••••
c96baa••••••••••••••••••••••••••••••••••
0be8f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ddba5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
a348f5••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ccdde8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
no•••••.sys
xk•••••.sys
g1•••••.sys
re•••••.bat
hw•••••.exe
de•••••.exe
RE•••••.txt
bi•••••.exe
bc4a8d••••••••••••••••••••••••••
07e9f0••••••••••••••••••••••••••
738df7••••••••••••••••••••••••••
b23b65••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
HavocHavoc
CVE-2024-55591CVE-2024-55591
Target & Sectors
Global Scope
Incident Timeline
September 2025
Threat actors posted fewer than 20 victim names each month in September 2025, with the average increasing to over 75 by January 2026.
Click on any entity below to view its context and source!
victims
20 victim names
Fewer than 20 victim names were posted each month throughout the remainder of 2025, but the average rose to over 75 at the beginning of 2026 (see Figure 1).
victims
683 victim names
By the end of July 2026, a total of 683 victim names had been added to the leak site.
June 2026
Threat actors used PowerShell to enforce monitoring exclusions for Windows Defender, allowing them to deploy ransomware locally on single hosts or network shares.
Click on any entity below to view its context and source!
infrastructure
Windows
Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzed incidents.
In addition, multiple intrusions involved PowerShell to enforce monitoring exclusions for Windows Defender.
A threat actor in another compromise took a different approach, disabling Windows Defender by setting a Windows policy registry value:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t
Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption.
infrastructure
Linux
Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzed incidents.
July 2026
Threat actors used Rclone to exfiltrate data from compromised systems, often limiting its scope and leveraging legitimate credentials for lateral movement.
Click on any entity below to view its context and source!
infrastructure
Windows
For privilege escalation, attackers directly manipulate local and domain group memberships via native Windows administrative utilities (see Table 1).
This legitimate Windows system directory typically contains performance monitoring logs.
In one incident, the threat actor used a compromised administrator account to install a Cloudflared agent as a Windows service.
infrastructure
Fortigate
For example, in March, Group-IB
described
how affiliates conducted reconnaissance to identify internet-exposed FortiGate firewall management interfaces vulnerable to CVE-2024-55591.
2026/09/01
Threat actors used a Netlogon-hosted script to ensure consistent execution across multiple hosts, while also disabling AV and EDR solutions.
Click on any entity below to view its context and source!
infrastructure
Windows
…access services, promptly patching internet-facing firewalls and VPN appliances, restricting and monitoring administrative group changes, limiting RDP exposure, and alerting on suspicious registry, firewall, and Windows Defender exclusion changes.
Tactical Metrics
Metrics
infrastructure
Fortigate
Affected Product
Click for context!
For example, in March, Group-IB
described
how affiliates conducted reconnaissance to identify internet-exposed FortiGate firewall management interfaces vulnerable to CVE-2024-55591.
Metrics
infrastructure
Windows
Affected Product
For privilege escalation, attackers directly manipulate local and domain group memberships via native Windows administrative utilities (see Table 1).
Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzed incidents.
This legitimate Windows system directory typically contains performance monitoring logs.
In one incident, the threat actor used a compromised administrator account to install a Cloudflared agent as a Windows service.
In addition, multiple intrusions involved PowerShell to enforce monitoring exclusions for Windows Defender.
A threat actor in another compromise took a different approach, disabling Windows Defender by setting a Windows policy registry value:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t
Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption.
…access services, promptly patching internet-facing firewalls and VPN appliances, restricting and monitoring administrative group changes, limiting RDP exposure, and alerting on suspicious registry, firewall, and Windows Defender exclusion changes.
Metrics
infrastructure
Linux
Affected Product
Although there are Windows, Linux, and ESXi-compatible versions of the ransomware, CTU researchers only observed the Windows variant deployed in the analyzed incidents.
Metrics
victims
20
Victim Names
Fewer than 20 victim names were posted each month throughout the remainder of 2025, but the average rose to over 75 at the beginning of 2026 (see Figure 1).
Metrics
victims
683
Victim Names
By the end of July 2026, a total of 683 victim names had been added to the leak site.
Intelligence Sources
Sophos News
2026-09-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
31x
organisation
Identified Entity
IP
entity
7x
timeline
Temporal Reference
mid-2025
date
6x
tactic
Cyber Operation Type
Privilege Escalation
tactic
4x
tactic
MITRE ATT&CK Technique
T1021.001 - Remote Desktop Protocol
technique
3x
infrastructure
Affected Product
Fortigate
software
2x
victims
Victim Names
20
victim names
Contextual Telemetry
Context Block
14 METRICS
source region
Origin Country
Netherlands
country
industry
Targeted Sector
Defense
sector
general metric
Hours
24
hours
general metric
Separate Incidents
15
separate incidents
vulnerability
Exploited CVE
CVE-2024-55591
cve
malware
Offensive Tool
Mimikatz
tool
malware
Malware Payload
Havoc
tool
general metric
Gentlekiller Javelin
6
gentlekiller javelin
general metric
Gentlekiller Faceit
1
gentlekiller faceit
general metric
Killer X.Exe
2
killer x.exe
general metric
Remote Location
8
remote location
general metric
Minutes
25
minutes
general metric
Fdenytsconnections
0
fdenytsconnections
general metric
Variations
200
variations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.