Threat Intelligence RoundUp: September

October 02, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants – The Hacker News

ShinyHunters has announced on their data leak site to have breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. The post claims “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job”. ShinyHunters claimed it targeted the FBI in response to a May 2026 public service announcement warning about the group’s targeting of Canvas, an online learning management system, and urging victims not to pay. The group disputed the FBI’s claims, calling them “substantial false allegations” and denying links to the Com cybercriminal collective, which it described as industry-driven “propaganda.” Read full article.

2. Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours – The Hacker News

Google Threat Intelligence Group (GTIG) reports that threat actors are increasingly targeting enterprise AI assets for espionage, extortion, and resource theft. Observed activity includes the theft of API credentials and proprietary AI data, including models, prompts, source code, and research, as well as the compromise of cloud environments to run unauthorized AI workloads. Financially motivated threat group, TeamPCP, has targeted software supply chains and AI coding assistants, while China-nexus actors have reportedly deployed local LLM infrastructure and conducted attacks against AI models to evade provider monitoring and extract proprietary capabilities. GTIG has also observed adversaries using agentic AI to accelerate malware and tooling development, underscoring the growing role of AI as both a target and an operational force multiplier for cyber threat actors. Read More.

Nimbus Manticore, the Iranian hacking group, has been connected to two (NodeRabbit and PollCat) previously undocumented malwares targeting Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Nimbus Manticore, also known as Iranian Dream Job, has been targeting job candidates with fake recruitment coding challenges designed to infect their computers. In one case, attackers distributed a project-management application called Taskflow and asked candidates to find bugs in the frontend within three hours. The challenge appeared legitimate, but malicious code was hidden in the supposedly “bug-free” server.js file. It loaded a trojanized Node.js package that secretly launched NodeRabbit, a backdoor capable of communicating with attacker-controlled servers. Once installed, NodeRabbit can collect system information, run commands, access and modify files, manage directories, and gather network details. It can also execute temporary scripts and delete them afterward to hide evidence of its activity. Read more here.

According to a joint cyber security advisory, North Korean threat actors (WarPlum) behind the Contagious Interview campaign have compromised at least “30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets”. A joint alert from cybersecurity and intelligence agencies in Japan, the U.S., Australia, and Germany warn of a campaign targeting web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3. The threat actors have stolen an estimated $10.71 million or more in cryptocurrency. According to the alert, the group “conducts cyber-attacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency.”. Following initial access, a variety of malware is deployed in an attempt to ensure access is gained. Read here.

5. Chinese Fire Ant hackers turn Cisco routers into spying platforms – Bleeping Computer

Researchers have uncovered a new tactic used by the threat actor known as Fire Ant, after identifying an active Generic Routing Encapsulation (GRE) tunnel interface on a Cisco IOS XR router that could not be accounted for by the device’s running configuration or commit history.

According to incident response firm Sygnia, Fire Ant activity “strongly overlaps” with the Chinese espionage group, UNC3886. Fire Ant has expanded its targeting beyond VMware hypervisors to include Cisco routers, TACACS authentication servers, and Linux management hosts. Further analysis of the compromised router revealed custom malware designed to maintain persistent access through a fake system service that activated the implant only during alternating hours, helping it evade detection.. Learn more.

6. US takes down NightmareStresser DDoS-for-hire platform – Bleeping Computer

On September 15, the FBI seized the domains of NightmareStresser, one of the longest-running DDoS-for-hire platforms. The service allowed users to rent access to compromised routers and IoT devices to launch large-scale distributed denial-of-service (DDoS) attacks. Before its domains were taken down, NightmareStresser claimed more than 566,000 registered users and the ability to generate attacks of up to 200 Gbps. According to the FBI, the platform was used to launch hundreds of thousands of actual or attempted DDoS attacks against targets worldwide since 2022. Read full article.

7. Spain’s data agency gets first report of AI-powered data breach – Bleeping Computer

The Spanish Data Protection Agency (AEPD) was notified of an alleged cyberattack involving an AI agent powered by a known large language model (LLM). The victim organization reported that the attack autonomously identified vulnerabilities, gained access to systems, modified personal data, and accessed financial documents. While the AEPD has not yet investigated or verified the incident, it said the report highlights how AI could increase the speed, scale, and adaptability of cyberattacks, reducing the time defenders have to respond. The agency recommends that organizations strengthen identity and credential security, improve rapid detection and containment capabilities, and update security and data protection strategies to account for AI-assisted and autonomous attacks. Read full article.

8. ShinyHunters hackers claim breach of Florida “DAVID” DMV database – Bleeping Computer

On September 08, ShinyHunters claimed on its data leak site to have breached DAVID, an online database platform used by the Florida Department of Motor Vehicles and exfiltrated more than 200,000 driver records. According to the threat actors, they gained access to DAVID by exploiting a password-reset vulnerability that enabled them to compromise multiple accounts. ShinyHunters further claimed that, after obtaining access, they enumerated records by ID and downloaded associated HTML pages and driver images. The group alleges that this activity resulted in the theft of more than 200,000 records, with the operation beginning on September 3. Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

See why DarkOwl is the Leader in Darknet Data

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.