Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-09-15

Daily Intelligence Briefing — Tuesday, September 15, 2026

4 critical10 high

On 2026-09-15, Threadlinqs published 12 new threat reports and updated 2, 4 rated critical and 10 high, spanning 132 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 126 new detection rules and 281 extracted indicators.

New threats
122 updated
Critical / high
144 critical · 10 high
ATT&CK techniques
132Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
281Count only · values are Red+
Detection rules
126New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged). Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation. Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices.

Highlights

  • TL-2026-2514 — Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
  • TL-2026-2515 — Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
  • TL-2026-2517 — Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
  • TL-2026-2519 — BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation
  • TL-2026-2520 — BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2

Theme of the day

Unattributed threats dominated the day with no dominant actor or sector, suggesting a broad, low-attribution attack surface.

  • cisa-kev
  • credential-theft
  • cross-platform-malware
  • linux-malware
  • windows-malware

Threats published

14 threat lines in the 2026-09-15 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

132 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

Nation-state attribution

  • Ukraine
  • MY
  • China
  • Iran
  • Russia

Threat categories

  • DATA_BREACH
  • RANSOMWARE
  • MALWARE
  • VULNERABILITY
  • PHISHING
  • SUPPLY_CHAIN
  • APT

Severity breakdown

  • critical4
  • high10
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

281 indicators of compromise · Red and above. Compare plans
  • network 69
  • file 59
  • infrastructure 40
  • entity 33
  • malware 30
  • tool 23
  • package 21
  • behavioral 6
126 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans