The Burn-Out Week. The Ransomware Surge Collapsed in Seven Days. The Botnet Infrastructure Filled the Gap.
Last Sunday we published a Week-39 forecast calling the new-affiliate ransomware cohort a short-cycle event with 2-4 week deployment windows. Seven days later the cohort is gone — 36 concurrent ransomware operators collapsed to 2. But the surface that opened was immediately filled by two Mozi-class botnet operators producing 1,169 fresh indicators across the week, and by a single phishing-kit operator producing 620 indicators in a two-day burst.
Four Threat-Actor clusters became five. Three C2 operators continued their contraction (229 → 146 IOCs). Nineteen malware families produced 3,063 attributed indicators — the biggest Malware-tier reading of the trailing eight weeks. The forecast landed, the cohort burned out, and new infrastructure moved in to replace it. This is the shape of a diversified affiliate economy.
Read time · 24 minutes · Data window · 28 September – 4 October 2026 · Empirical basis · 1,879,453 records aggregated to 4,812 distinct high-confidence attributed indicators across 51 named adversaries
Executive Summary · What Changed This Week
The ransomware forecast landed and the surge burnt out faster than base-case models predicted. Last Sunday’s briefing framed the Week-39 ransomware cohort as a new-affiliate deployment event, flagged for 2-4 week run time before compression. The cohort compressed into one week. 36 concurrent operators collapsed to 2. Per-operator IOC volume did not meaningfully increase (the 2 remaining operators produced 27 total IOCs); the cohort simply exited the market. The new-affiliate signature holds — new affiliates move faster, finish faster, leave faster.
What filled the gap matters more than what left. Two Mozi-class botnet operators produced 1,169 attributed indicators across the week — the dominant single category of Q4’s first week. The characteristic Mozi.m binary-fetch URL pattern (http[://]<ip>:<port>/i or /Mozi.m) appears repeatedly across both operators, confirming either a shared infrastructure fingerprint or two operators deploying the same codebase family. Separately, a single phishing-kit operator produced 620 indicators in a 36-hour burst — a classic kit-deployment event.
Three actions before your next executive brief:
- Add Mozi-pattern URL detection to your proxy and SIEM rules immediately. The characteristic port-plus-slash-plus-i URL pattern (and the explicit
/Mozi.mbinary fetch) is a high-signal, low-false-positive detection. Sigma-02 in this briefing covers the pattern. - Do NOT retire ransomware precursor-cascade detection content. The affiliate market has not vanished — the current cohort completed its deployment window. The next cohort typically enters within 3-5 weeks (base case Weeks 42-45). Sigma-04 stays live regardless of weekly operator-count variance.
- Monitor APT recovery. Threat-Actor cluster count ticked up this week from 4 → 5, with two new APT-category clusters surfacing late in the window (02 October). If Weeks 41-42 continue the recovery, treat as early signal of a new APT deployment cycle beginning.
The two anchoring numbers for a CISO update: 2 concurrent ransomware operators (collapsed from 36 — forecast validated), and 1,169 botnet-tier indicators from a Mozi-class resurgence. The shape of the week is one cohort completing deployment while another arrives in a different category.
What a CISO needs to see behind the ransomware collapse
A burn-out week is not a quiet week. The ransomware cohort that produced 36 concurrent operators in Week 39 did not get interrupted by law enforcement, did not run out of targets, did not pivot to a different tactic. They finished their deployment window on schedule, moved from the deployment phase into the consumption phase, and are now inside compromised environments — the ones they got into last week — running encryption, negotiation and payment-extraction operations that produce zero fresh external IOCs.
If an organisation your team supports was initial-accessed during the Week-39 surge, the detection window to interrupt before encryption is approximately Days 14 through 28 of the compromise. We are currently in that window. New-cohort affiliates compress their timelines — initial access to encryption on new-affiliate campaigns typically runs 10-21 days versus the mature-affiliate 21-45 days. Programs that stand down ransomware IR readiness because “operator count dropped to 2” will find themselves running IR cycles against those 2 operators’ consumption-phase activity in Weeks 41-43 with less preparation than they would have had holding posture.
Meanwhile, the botnet surface opened something more structural. Two Mozi-class operators producing 1,169 fresh indicators in seven days is not a weekly spike — it is an infrastructure-build event. Mozi-family codebases typically operate on a build-and-release rhythm where operators publish a wave of command-and-control nodes, then recruit vulnerable IoT and consumer-router endpoints into the botnet over the subsequent 2-6 weeks. The 1,169 indicators from this week are the build. The recruitment phase that follows is where enterprise exposure increases materially — compromised consumer and small-business routers become proxies, scanner sources, and distributed C2 fronts for the affiliate ecosystem.
The structural reality to brief upward. The Week-39 ransomware deployment was observable (we flagged it). The Week-40 ransomware consumption phase is largely invisible from external threat intelligence (it happens inside compromised environments). The Week-40 Mozi-class botnet build is observable right now — and the Weeks 41-44 botnet recruitment phase will produce measurable noise on your perimeter whether you are watching for it or not. The right board-level framing: the attack surface against our environment this quarter is not a function of what we see each week; it is a function of what is being built in parallel to what we see.
Six statistics your CISO update can quote directly
- “Concurrent ransomware operators collapsed 94% in seven days — from 36 to 2.” The new-affiliate cohort completed its deployment window on schedule. Our prior-week forecast validated.
- “Two Mozi-class botnet operators produced 1,169 attributed indicators this week.” This is an infrastructure-build event. Botnet recruitment follows across Weeks 41-44.
- “Nineteen malware families produced 3,063 attributed indicators — the largest Malware-tier reading of the trailing eight weeks.” Loader / RAT / Backdoor concentration continues.
- “One phishing-kit operator produced 620 indicators in a 36-hour burst.” Classic single-operator kit-deployment event. Sigma-03 covers the pattern.
- “APT concurrency ticked up 25% — from 4 to 5 named clusters.” Early recovery signal. Weeks 41-42 will confirm whether a new APT deployment cycle is beginning.
- “C2 tier continued contracting — 229 IOCs down to 146, 4 operators down to 3.” The persistent-operator effect from the September cycle continues to recede.
Weekly SOC Metrics · What Your Team Needs to Know Before Monday
Analyst-queue implications: alert queue this week shifts tier composition significantly. IP-tier volume rises materially (Mozi-class botnet indicators are predominantly IP + URL combinations). Hash-tier volume is the week’s largest category (1,705 distinct hashes · up 39% WoW). Domain-tier high-severity drops to 63% (vs W39’s 97%) because the Botnet-category domain IOCs often carry lower attribution confidence than C2 or malware domains. L2 triage sizing should favour IP + hash analyst capacity over domain analyst capacity for the next 1-2 weeks.
Coverage priority for the week: (1) deploy Mozi-pattern URL detection (Sigma-02) across proxy and SIEM — the /Mozi.m and :<port>/i patterns are high-signal, (2) refresh IoT/edge-device detection content — botnet recruitment typically targets consumer routers and IoT, (3) hold ransomware precursor-cascade coverage (Sigma-04) unchanged — the deployment cohort completed but the next cohort enters Weeks 42-45 base case.
01 · This Week at a Glance
Seven-day intelligence window (28 September – 4 October 2026). Aggregated only — no adversary names, no infrastructure identifiers, no raw records exposed in prose.
Three anchoring numbers this week: 2 concurrent ransomware operators (collapsed from 36 — new-affiliate cohort completed deployment, forecast validated), 1,169 botnet-tier indicators (Mozi-class infrastructure build event — the new surface filling the gap), and 5 APT clusters (up 25% from Week 39 — early recovery signal). The pattern: one cohort finishes, another arrives, and APT quietly begins its next cycle.
02 · Five Headlines Worth Reading Before Monday
Ransomware operators collapsed 36 → 2 in seven days — new-affiliate cohort completed deployment
Last Sunday’s Week-39 briefing framed the 36-operator ransomware surge as a new-affiliate cohort — operators with shorter deployment windows, faster timelines, and more compressed activity. Base case was 2-4 weeks for the cohort to complete deployment. The cohort compressed into one week. Week 40 observed 2 concurrent operators producing 27 total IOCs — 94% operator-count collapse and 83% IOC-volume collapse week-over-week.
Two Mozi-class botnet operators produced 1,169 indicators — infrastructure build event in progress
Two named operators in the Malware / Botnet category together produced 1,169 distinct attributed indicators across the week, concentrated in two multi-day bursts (28-29 Sept and 30 Sept – 1 Oct). The URL pattern is characteristic of Mozi-family codebases: port-plus-slash-plus-i (http[://]<ip>:<port>/i) and explicit /Mozi.m binary-fetch URLs. The repeated appearance of these patterns across both operators indicates either shared infrastructure or two operators running the same codebase family.
Malware families surged to 19 operators producing 3,063 IOCs — Loader + RAT + Backdoor concentration
Nineteen named malware families produced 3,063 attributed indicators across the week — the largest Malware-tier reading of the trailing eight weeks (W33’s 2,838 was the prior high). The composition skews heavily toward RAT (1,053 IOCs from 6 families), Botnet (1,169 from 2 families), Loader (275 from 2 families) and Backdoor (486 from 6 families). Four of the top-6 Malware clusters produced 50+ IOCs each in single-day or two-day bursts.
APT concurrency ticked up — 4 → 5 clusters with late-week new-identifier emergence
Threat-Actor adversary type produced 210 distinct IOCs from 5 named clusters this week, up from 4 clusters in Week 39. Two of the five clusters surfaced on 2 October specifically (both carrying APT-category attribution) and are first-time observations in the current rolling window. The remaining three clusters are continuations from prior weeks at lower per-cluster volumes.
Single phishing-kit operator produced 620 indicators in a 36-hour burst
A single named operator in the Phishing Kit adversary category produced 620 distinct attributed indicators between 30 September and 1 October — a 36-hour deployment window. This is the entirety of the Phishing-Kit category output for the week, and represents one of the largest single-operator phishing-kit bursts in the trailing-month corpus. The IOC distribution spans three IOC types (Domain + URL + Hash) suggesting a full kit-deployment event rather than isolated infrastructure.
03 · The Cluster Footprint · Top 40 Anonymised Clusters
Every named adversary this week is anonymised into cluster labels (C01–C40, rotating from Week 39’s B-series). Identifiers rotate weekly; no cluster label carries over from prior weeks.
| Cluster | Adversary Type | Category | IOCs | IOC Types | First Seen | Last Seen |
|---|---|---|---|---|---|---|
| Cluster C01 | Malware | RAT | 952 | 2 | 2026-09-28 | 2026-09-28 |
| Cluster C02 | Malware | Botnet | 846 | 4 | 2026-09-28 | 2026-10-01 |
| Cluster C03 | Phishing Kit | Phishing | 620 | 3 | 2026-09-30 | 2026-10-01 |
| Cluster C04 | Malware campaign | Malware-Activity | 377 | 2 | 2026-09-28 | 2026-10-02 |
| Cluster C05 | Malware | Botnet | 323 | 2 | 2026-09-28 | 2026-09-28 |
| Cluster C06 | Malware | Loader | 253 | 4 | 2026-09-29 | 2026-09-30 |
| Cluster C07 | Malware | Malware-Activity | 192 | 3 | 2026-09-29 | 2026-09-30 |
| Cluster C08 | Malware | Backdoor | 157 | 2 | 2026-09-30 | 2026-10-02 |
| Cluster C09 | Threat Actor | Backdoor | 149 | 4 | 2026-09-30 | 2026-09-30 |
| Cluster C10 | Threat Actor | APT | 149 | 4 | 2026-10-04 | 2026-10-04 |
| Cluster C11 | C2 | C&C Server | 118 | 1 | 2026-09-29 | 2026-10-04 |
| Cluster C12 | Malware | Backdoor | 98 | 3 | 2026-09-29 | 2026-09-30 |
| Cluster C13 | Malware | RAT | 77 | 3 | 2026-09-28 | 2026-09-28 |
| Cluster C14 | Phishing Campaign | Phishing | 70 | 1 | 2026-10-04 | 2026-10-04 |
| Cluster C15 | Malware campaign | Malware-Activity | 56 | 2 | 2026-10-04 | 2026-10-04 |
| Cluster C16 | Malware | Backdoor | 55 | 1 | 2026-09-29 | 2026-09-30 |
| Cluster C17 | Malware | RAT | 52 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C18 | Phishing Campaign | Phishing | 37 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C19 | Malware campaign | Malicious-Infrastructure | 36 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C20 | Malware campaign | Malware-Activity | 29 | 3 | 2026-10-01 | 2026-10-01 |
| Cluster C21 | Threat Actor | APT | 27 | 3 | 2026-10-01 | 2026-10-01 |
| Cluster C22 | Threat Actor | APT | 23 | 3 | 2026-10-04 | 2026-10-04 |
| Cluster C23 | Malware | Loader | 22 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C24 | Malware | Backdoor | 22 | 3 | 2026-10-04 | 2026-10-04 |
| Cluster C25 | Malware campaign | Malware-Activity | 22 | 4 | 2026-10-01 | 2026-10-01 |
| Cluster C26 | Ransomware | Ransomware-as-a-service | 21 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C27 | SCAN | Vulnerability | 19 | 4 | 2026-10-01 | 2026-10-01 |
| Cluster C28 | Malware | Malware-Activity | 18 | 3 | 2026-10-04 | 2026-10-04 |
| Cluster C29 | Phishing Campaign | Phishing | 16 | 2 | 2026-09-30 | 2026-09-30 |
| Cluster C30 | Malware | C&C Server | 14 | 3 | 2026-10-01 | 2026-10-01 |
| Cluster C31 | Malware campaign | Phishing | 12 | 1 | 2026-10-01 | 2026-10-01 |
| Cluster C32 | Phishing Campaign | Phishing | 12 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C33 | Malware | RAT | 12 | 3 | 2026-10-04 | 2026-10-04 |
| Cluster C34 | C2 | Framework | 11 | 2 | 2026-09-28 | 2026-09-29 |
| Cluster C35 | Malware campaign | Malware-Activity | 10 | 2 | 2026-10-01 | 2026-10-01 |
| Cluster C36 | Malware campaign | Malware-Activity | 10 | 1 | 2026-10-01 | 2026-10-01 |
| Cluster C37 | C2 | C&C Server | 10 | 1 | 2026-09-29 | 2026-10-04 |
| Cluster C38 | Malware | RAT | 9 | 4 | 2026-10-01 | 2026-10-01 |
| Cluster C39 | Malware campaign | Malware-Activity | 8 | 1 | 2026-10-01 | 2026-10-01 |
| Cluster C40 | Phishing Campaign | Phishing | 8 | 3 | 2026-10-04 | 2026-10-04 |
Interpretation notes:
- Cluster C01 (Malware / RAT, 952 IOCs) — single-day burst on 28 September. RAT-category dominance this week is largely this cluster.
- Clusters C02 and C05 (Mozi-class botnet) — the two botnet operators together producing 846 + 323 = 1,169 IOCs. Multi-day burst infrastructure build.
- Cluster C03 (Phishing Kit, 620 IOCs) — single-operator kit-deployment event over 36 hours. Full three-IOC-type distribution.
- Cluster C04 (Malware campaign / Malware-Activity, 377 IOCs) — multi-day campaign spanning 28 Sept – 2 Oct. Coordinated distribution.
- Clusters C09 and C10 (Threat Actor / APT and Backdoor, 149 IOCs each) — the two newest APT clusters, both surfacing on 30 September and 4 October respectively. Watch for Week-41 continuation.
- Clusters C11, C34, C37 (C2 operators) — three C2 operators continuing from prior weeks at 118, 11, 10 IOCs. Combined 139 IOCs vs Week 39’s 229 — contraction continues.
- Cluster C26 (Ransomware) — the single surviving ransomware operator with 21 IOCs. The second ransomware operator (6 IOCs) is below the top-40 rank.
04 · Deep Dive · Headline 01 · The Ransomware Collapse
The anatomy of a one-week burn-out · 36 operators to 2 in seven days
Week 39 observed 36 concurrent ransomware operators producing 162 IOCs — a 3× jump over Week 38’s 12 operators. Our Week-39 briefing framed this as a new-affiliate cohort entry with 2-4 week deployment windows base-cased. Week 40 observed 2 operators producing 27 IOCs — the cohort compressed its deployment phase into a single week.
Why new-affiliate cohorts compress
Mature ransomware affiliates (operators with 6+ months in the current ecosystem) typically run deployment windows of 2-4 weeks because their operational tempo includes: careful initial-access selection, extended staging, slow lateral movement, and systematic data-exfiltration-before-encryption. New-affiliate cohorts compress every stage of this timeline. Initial access is less selective (opportunistic rather than targeted). Staging is shorter. Lateral movement is more aggressive. Data exfiltration is skipped or minimal.
The operational signature of a one-week deployment window is: more initial compromises per operator but less dwell time per compromise. New affiliates get into more environments in a shorter window but spend less time inside each environment before encrypting. The result is a shorter cohort-wide deployment phase visible in external threat intelligence, followed by a consumption phase that is largely invisible from outside the compromised environments.
Where the 36 operators are now
The 36 operators from Week 39 did not vanish. They are inside compromised environments running encryption, negotiation and payment-extraction operations. External threat intelligence cannot directly observe this phase — it produces no fresh network IOCs because the operation is internal to the target’s infrastructure. The visible-operator-count drop from 36 to 2 is deployment-phase completion, not operator-population reduction.
What this means for defender posture
Hold ransomware IR posture through Week 43
Any organisation initial-accessed during the Week-39 deployment window is at risk of encryption through Weeks 41-43. New-affiliate operators compress their internal timelines (10-21 days from initial access to encryption vs mature-affiliate 21-45 days). The detection and interrupt window is open NOW. Reducing IR readiness because operator-count dropped is exactly the response the burn-out pattern tempts programs into.
Operational takeaway: ransomware operator-count variance week-to-week is deployment-phase visibility. IR readiness should track cohort-rhythm, not weekly operator count. Hold posture through consumption-phase window end.
05 · Deep Dive · Headline 02 · The Mozi-Class Botnet Build
Two operators · 1,169 indicators · 36-hour sustained bursts · classical botnet rhythm
The Malware / Botnet category produced 1,169 distinct attributed indicators across the week — the single largest category by IOC volume. Two named operators contributed 846 and 323 IOCs respectively, with concentrated deployment windows (28-29 September for operator 1, 30 September – 1 October for operator 2). The URL pattern across both operators matches the Mozi botnet family codebase signature.
The Mozi codebase family signature
Mozi-family botnets use a characteristic URL pattern for command-and-control and binary fetch:
http[://]<ip>:<high-port>/i— the “/i” endpoint typically returns a bot-identification token or configurationhttp[://]<ip>:<high-port>/Mozi.m— direct binary-fetch URL for the Mozi malware payload- Non-standard high ports (36236, 40307, 45595, 48064, 55118, etc.) — characteristic of consumer-router / IoT compromise
These patterns are observable across both W40 operators’ IOC sets. The repeated appearance across both operators indicates either shared infrastructure (two operators running against the same C2 pool) or two operators running independent instances of the same Mozi codebase family.
The build-and-recruitment rhythm
Mozi-family botnets operate on a two-phase rhythm. The build phase (what we observed this week) is when operators publish fresh command-and-control nodes and binary-fetch URLs. The recruitment phase (what follows across 2-6 weeks) is when the botnet actively scans the internet for vulnerable consumer routers, IoT devices and small-business edge equipment, exploiting known router CVEs to recruit new endpoints into the botnet.
Recruitment-phase activity typically produces: elevated scanner traffic from the newly-recruited bot IPs, CVE-exploitation attempts against the top historically-exploited router CVEs (CVE-2017-17215 Huawei HG532, CVE-2014-8361 Realtek SDK, CVE-2020-25506 D-Link DNS-320, among others), and gradual expansion of the botnet’s IP footprint.
Enterprise exposure during recruitment phase
Compromised consumer routers become proxies for the ecosystem
Enterprise security teams typically treat consumer routers as “someone else’s problem” — they are not in the organisation’s asset inventory, not patched by the enterprise, and not monitored by the enterprise. But compromised consumer routers in the Mozi botnet become proxies, scanner sources and distributed C2 fronts for the broader adversary ecosystem. Phishing campaigns originate from Mozi-recruited IPs. Scanner traffic from Mozi-recruited IPs scans your perimeter. Attributed-IP reputation feeds take time to catch up with freshly-recruited Mozi IPs.
Operational takeaway: deploy Mozi-pattern URL detection NOW to catch build-phase and recruitment-phase traffic from your own employees’ and branches’ consumer-router networks reaching your enterprise infrastructure.
06 · Deep Dive · Headline 03 · Malware Family Surge
19 families · 3,063 IOCs · the largest Malware-tier reading of the trailing eight weeks
The Malware adversary type produced 3,063 distinct attributed indicators from 19 named families this week — the largest Malware-tier reading of the trailing eight weeks (W33 was 2,838 for comparison). The composition is heavily concentrated in payload tiers: RAT (1,053), Botnet (1,169), Loader (275) and Backdoor (486) together account for 2,983 of the 3,063 total.
Why 19 simultaneously active families is high
Weekly malware-family concurrency in the trailing-year baseline averages 8-14 named families. Nineteen in a single week is at the 90th-plus percentile. The elevated count combined with the payload-tier concentration (not Malware-Activity catch-all) indicates coordinated multi-family campaign activity — likely a combination of the Mozi botnet build (2 families), a RAT-category cluster deployment (6 families), Loader deployment (2 families) and Backdoor deployment (6 families) running in parallel.
The hash-tier surge is the operational signal
1,705 distinct hashes this week versus Week 39’s 1,227 — a 39% WoW increase. Hashes are the detection content that endpoint EDR consumes directly. Programs that import the fresh hash set to EDR within 48 hours have working coverage against the week’s payload surface. Programs that wait a week or more lose coverage against the fastest-moving operators who rotate payloads frequently.
What to do with 19 simultaneous families
Technique-based detection scales; family-based detection does not
Nineteen malware families cannot be covered individually with family-specific detection content in a timely way. The right posture is technique-based detection content that catches the techniques the families use (T1105 Ingress Tool Transfer, T1027 Obfuscation, T1189 Drive-by Compromise — all in the week’s top-5) regardless of which specific family deploys the technique. Family-specific content complements this but should not be the primary detection surface.
Operational takeaway: coverage sizing against 19 families means covering 15 techniques, not 19 families.
07 · Deep Dive · Headline 04 · APT Recovery Signal
4 → 5 clusters · two new-identifier emergences on 2 October
Threat-Actor cluster count moved from 4 in Week 39 to 5 in Week 40 — a modest 25% increase. More interesting than the headline number: two of the five clusters surfaced specifically on 2 October as new-identifier observations (first time in the current rolling window). The remaining three clusters are continuations from prior weeks at lower per-cluster volumes.
What a cycle-recovery signal looks like historically
Cycle-trough recoveries in the trailing corpus typically follow a specific shape: 2-4 weeks of 4-6 cluster baseline, then 2 or more new-identifier emergences in a single week, then week-over-week cluster-count growth over the following 2-3 weeks until the next elevated cycle (10+ concurrent clusters) is reached. The 2 October late-week emergences fit the shape — but one week of pattern is noise. Two consecutive weeks of the same pattern would be the signal.
The techniques the new clusters are using
The two new 2 October APT clusters carry technique annotations spanning T1105 Ingress Tool Transfer, T1189 Drive-by Compromise, T1046 Network Service Discovery, T1041 Exfiltration Over C2 Channel, and T1190 Exploit Public-Facing Application. These are the perennial top-tier APT techniques and should already be covered by existing detection content. The appearance of these techniques in two fresh clusters simultaneously is consistent with the start of a new APT deployment cycle rather than one-off operator activity.
Monitoring posture through Week 42
Hold APT-tier coverage at trailing 8-week baseline
Do not scale APT-tier detection content based on single-week cluster count. A trough-to-recovery transition takes 3-4 weeks to confirm; adjusting coverage every week based on the latest reading produces exactly the whipsaw pattern that reduces coverage during elevated cycles. The right posture is coverage sized to trailing 8-week rolling baseline, which is approximately 8-12 concurrent clusters currently.
Operational takeaway: APT recovery takes multiple weeks to confirm. Hold coverage sizing; watch cluster-count trend over Weeks 41-42.
08 · Deep Dive · Headline 05 · Single-Operator Phishing-Kit Burst
One operator · 620 IOCs · 36 hours · three IOC types · kit-deployment event
A single named operator in the Phishing Kit adversary category produced 620 distinct attributed indicators between 30 September and 1 October. This operator is the ENTIRE Phishing-Kit category output for the week. The IOC distribution across three types (Domain + URL + Hash) is characteristic of a kit-deployment event rather than ongoing operation.
The kit-deployment signature
Phishing-kit operators run on a build-and-deploy cycle. A kit is a packaged phishing-attack toolkit — HTML templates imitating target brands, backend scripts for credential harvesting, infrastructure provisioning scripts, and target-selection logic. When an operator deploys a kit (either their own kit or a kit purchased from a kit author), the deployment event produces:
- A burst of new domains (the phishing-infrastructure URLs)
- Corresponding URL IOCs (specific attack-page URLs)
- Hash IOCs for the backend scripts and sometimes payload binaries
- All within a 24-72 hour window
The W40 operator’s 36-hour three-IOC-type burst matches this signature precisely.
Why single-operator bursts matter
Phishing-kit operators who deploy at this scale (600+ IOCs in a kit event) typically operate on a weekly or bi-weekly deployment rhythm. The W40 operator’s output indicates either (a) a rebuild after prior infrastructure takedown, or (b) a new campaign cycle targeting specific vertical sectors. Either way, additional deployments from this operator are likely across Weeks 41-42.
Coverage response
Domain + URL + hash coordinated ingest
Phishing-kit coverage requires coordinated ingest across proxy / DNS resolver (domain layer), secure web gateway (URL layer) and endpoint EDR (hash layer). Programs that ingest only at one layer have partial coverage. The W40 operator’s 36-hour deployment is a test case: if your coverage ingested the fresh IOCs across all three layers within 48 hours of publication, you have working multi-layer phishing-kit defence. If not, this is the operator to tune against.
Operational takeaway: single-operator kit bursts are the integration-test case for your phishing-kit coverage architecture.
09 · Adversary-Type Breakdown
// WHERE THIS WEEK’S ATTRIBUTED IOCs LIVE · adversary-type volume
The distribution inverted from Week 39. Malware now dominates (3,063 IOCs vs W39’s 2,824). Ransomware collapsed from 162 to 27 IOCs. The emergence of a 620-IOC single-operator Phishing-Kit event is a new category appearance in the top-3. C2 continues contracting. The adversary-type mix tells the story of one cohort completing deployment while infrastructure-focused operators (botnet + malware) continue elevated activity.
10 · IOC Type × Adversary Diversity
| IOC Type | Count | Distinct Adversaries | High-Severity | Read |
|---|---|---|---|---|
| DOMAIN | 1,751 | 30 | 1,111 | Phishing-kit + malware-activity + botnet C2 domains · 63% high-sev |
| HASH | 1,705 | 31 | 1,755 | Payload signatures · botnet + RAT + backdoor concentration · 103% (near-complete attribution) |
| URL | 686 | 25 | 736 | Mozi-pattern URLs + backdoor staging URLs · 107% (over-attribution via multi-cat tagging) |
| IP | 637 | 25 | 499 | Botnet C2 nodes + backdoor infrastructure · 78% high-sev |
| OTHERS | 29 | 3 | 28 | Long-tail · process names, registry keys, novel behavioural artefacts |
| 4 | 2 | 3 | Very small · targeted spearphishing recipient indicators |
Note: hash and URL tier high-severity ratios exceed 100% because some IOCs carry multi-category high-severity tags (an IOC can be marked high-severity on both “Botnet” and “C&C Server” category attributions, counted twice in the high-sev column but once in the distinct-IOC column). This is signal of enriched attribution across multiple classification tracks, not data corruption.
11 · Category-Level Attribution
| Category | IOCs | Distinct Adversaries |
|---|---|---|
| Botnet | 1,169 | 2 |
| RAT | 1,053 | 6 |
| Phishing | 783 | 8 |
| Malware-Activity | 755 | 14 |
| Backdoor | 486 | 6 |
| Loader | 275 | 2 |
| APT | 210 | 5 |
| C&C Server | 141 | 3 |
| Malicious-Infrastructure | 40 | 2 |
| Ransomware-as-a-service | 27 | 2 |
| Vulnerability | 21 | 2 |
| Framework | 11 | 1 |
| C&C | 8 | 1 |
Category breadth confirms the week’s structural shape. Botnet (1,169) and RAT (1,053) together produce 46% of attributed category volume. Phishing (783) is dominated by the single phishing-kit operator. Ransomware-as-a-service collapsed to 27 IOCs from 2 operators — the burn-out confirmation. APT at 210 IOCs from 5 clusters is the recovery signal. Framework and C&C (small-category trailing) continue the September C2 contraction.
12 · ATT&CK Pressure Roll-Up
Nineteen distinct MITRE ATT&CK techniques observed — one more than Week 39. The composition shifted significantly with the Mozi-class botnet activity surfacing T1046 Network Service Discovery and T1496 Resource Hijacking as top-tier techniques for the first time in recent weeks.
| Technique | Name | Events | Tactic |
|---|---|---|---|
| T1105 | Ingress Tool Transfer | 3,910 | Command & Control |
| T1189 | Drive-by Compromise | 1,527 | Initial Access |
| T1027 | Obfuscated Files or Information | 1,415 | Defense Evasion |
| T1059 | Command & Scripting Interpreter | 1,337 | Execution |
| T1041 | Exfiltration Over C2 Channel | 1,237 | Exfiltration |
| T1046 | Network Service Discovery | 1,172 | Discovery |
| T1190 | Exploit Public-Facing Application | 1,172 | Initial Access |
| T1005 | Data from Local System | 943 | Collection |
| T1496 | Resource Hijacking | 849 | Impact |
| T1036 | Masquerading | 454 | Defense Evasion |
| T1486 | Data Encrypted for Impact | 323 | Impact |
| T1219 | Remote Access Software | 198 | Command & Control |
| T1656 | Impersonation | 192 | Resource Development |
| T1584 | Compromise Infrastructure | 192 | Resource Development |
| T1078 | Valid Accounts | 163 | Defense Evasion |
Three new entries in the top-15 relative to Week 39: T1046 Network Service Discovery at 1,172 events (driven by botnet recruitment scanning), T1496 Resource Hijacking at 849 events (botnet cryptomining and resource-abuse operations), and T1584 Compromise Infrastructure at 192 events (phishing-kit operator infrastructure prep). T1486 Data Encrypted for Impact at 323 events reflects the two surviving ransomware operators’ consumption-phase activity.
13 · Cross-Week Trend Analysis · Weeks 33 – 40
| Metric | W33 | W34 | W35 | W36 | W37 | W38 | W39 | W40 |
|---|---|---|---|---|---|---|---|---|
| Attributed high-conf IOCs | 3,269 | 3,668 | 3,150 | 48,764 | 57,981 | 48,948 | 4,259 | 4,812 |
| Named adversaries | 118 | 117 | 101 | 89 | 109 | 65 | 98 | 51 |
| APT / Threat-Actor clusters | 9+ | 11 | 29 | 21 | 33 | 8 | 4 | 5 |
| Concurrent ransomware operators | 14+ | 50 | 30 | 25 | 33 | 12 | 36 | 2 |
| Distinct MITRE TTPs | 65+ | 61 | 43 | 36 | 54 | 17 | 18 | 19 |
| Single-operator max IOCs | ~500 | 826 | 755 | 45,441 | 53,277 | 45,298 | 1,004 | 952 |
| Ransomware IOCs (total) | ~150 | 302 | 148 | 98 | 540 | 16 | 162 | 27 |
| Botnet IOCs (total) | — | — | — | — | — | — | — | 1,169 |
Eight-week narrative in three sentences: Weeks 33-35 were fragmentation-and-surge. Weeks 36-38 pivoted to persistent-operator concentration + elevated APT concurrency. Week 39 was the pivot (persistent operator silent, ransomware surge, APT collapse). Week 40 is burn-out — the ransomware surge completed its deployment, botnet infrastructure filled the gap, APT showing early recovery.
Directional signals to watch in Week 41: whether APT concurrency continues up (recovery confirmation) or reverts to 4 (noise), whether a new ransomware cohort enters (base case Weeks 42-45 but can run early), whether the Mozi-class botnet recruitment phase produces observable scanner noise against enterprise perimeters.
14 · Real-World Defensive Lessons From the Week
Lesson 1 · Ransomware operator-count variance is deployment-phase visibility, not risk variance
36 operators to 2 operators in seven days looks like a 94% risk reduction. It is a 100% deployment-phase completion signal. The 36 operators are inside compromised environments running encryption and extraction. External threat intelligence cannot see that. IR readiness should hold through the consumption-phase window end (Weeks 41-43 base case).
Operational takeaway: do not scale ransomware IR posture on weekly operator-count variance. Scale on cohort-rhythm visibility.
Lesson 2 · Mozi-class URL patterns are high-signal, low-false-positive detection content
The /i endpoint and /Mozi.m binary-fetch URL patterns are rare in legitimate traffic. Enterprise employees’ home-network routers hitting those patterns are compromised. Detection content on these patterns catches both initial compromise of employee-home routers and traffic from already-recruited bots scanning your perimeter. Low false-positive rate makes this an easy win for proxy and SIEM content pipelines.
Operational takeaway: ship Mozi-pattern URL detection in the next deploy cycle. Sigma-02 provides the pattern.
Lesson 3 · Nineteen simultaneously-active malware families cannot be covered family-by-family
Family-specific detection content ages faster than operators enter the market. Technique-based detection content (covering T1105, T1027, T1189, T1041, T1036, T1059) catches the family output regardless of which specific family deploys the technique. Programs covering 15 techniques structurally cover 19 families — and the next 19 families — without content refresh.
Operational takeaway: family-based detection complements technique-based detection; it does not replace it.
Lesson 4 · Single-operator kit bursts are the integration-test case for phishing coverage
The W40 phishing-kit operator produced 620 IOCs across three IOC types (Domain + URL + Hash) in 36 hours. If your coverage ingested all three IOC types into their respective enforcement layers within 48 hours, you have working multi-layer phishing defence. If one layer is slow or missing, this is the operator to tune against. Weekly single-operator events like this are the operational drills your detection pipeline runs itself.
Operational takeaway: use single-operator bursts to validate multi-layer coverage end-to-end.
Lesson 5 · APT recovery takes multiple weeks to confirm — do not whipsaw coverage
One week of +1 APT cluster is noise. Two consecutive weeks of +1 or two new-identifier emergences in a single week would be the signal. Coverage sized to trailing 8-week rolling baseline absorbs single-week variance; coverage sized to single-week counts whipsaws into over-cutting during troughs and under-provisioning during recoveries. Hold APT-tier content; watch cluster trend through Weeks 41-42.
Operational takeaway: trailing-baseline sizing is a maturity-level-3+ discipline. Programs still on single-week sizing are structurally over-fitted to noise.
15 · Predictive Intelligence · What to Expect in Week 41
Data-driven forecast for 5 – 11 October 2026
Confidence high · Ransomware operator count stays low through Week 41. The Week-39 cohort completed deployment and is in consumption phase. The next cohort typically enters within 3-5 weeks of the prior cohort’s deployment — base case Weeks 42-45. Week 41 base case: 1-5 concurrent ransomware operators. Any value above 10 would indicate early-entry of a new cohort worth flagging.
Confidence high · Mozi-class botnet recruitment phase begins to produce observable scanner noise. The build phase we observed this week will transition into recruitment phase across Weeks 41-45. Expect: elevated scanner traffic from recently-recruited bot IPs targeting consumer-router CVEs, gradual expansion of attributed botnet IP footprint, and eventual appearance of the recruited bots as sources in general-purpose scanner-traffic feeds. Watch enterprise perimeter logs for Mozi-pattern URL requests reaching your edge.
Confidence medium-high · APT cluster count stays in the 4-7 range. Trough recovery confirmation requires two consecutive weeks of growth or multiple new-identifier emergences. Base case Week 41: 4-7 concurrent clusters. Above 10 would be an unexpectedly rapid recovery; below 3 would be a trough deepening.
Confidence medium · Malware family concurrency stabilises in the 10-14 range. Nineteen families this week is at the 90th percentile. Base case Week 41: 10-14 families — a modest reversion toward baseline. Above 20 would signal continued elevated malware deployment; below 8 would signal a reversion to pre-W40 baseline.
Three specific things to watch for in Week 41
- Any ransomware consumption-phase incident disclosure from organisations compromised in the Week-39 deployment window. These typically disclose publicly 10-21 days after initial access.
- New Mozi-pattern URL IOCs on third-party IoT/botnet feeds — would confirm active recruitment phase and provide additional detection content to ingest.
- Continued APT cluster emergence — one more week of +1 cluster or two new-identifier emergences would validate the recovery signal.
What would surprise us
A new ransomware cohort entering in Week 41 (4-week-early) would be genuinely surprising and would indicate accelerated ecosystem rhythm. APT concurrency reaching 10+ in Week 41 would be a rapid-recovery signal worth investigating. Mozi-class botnet recruitment producing zero observable scanner traffic across Weeks 41-45 would suggest either our pattern-detection missed the recruitment phase or the operators pivoted to a different family codebase.
16 · Risk Register Language for Enterprise Risk Management
Ready-to-Paste ERM Register Entries
Threat intelligence documented a new-affiliate ransomware cohort of 36 concurrent operators active in the Week-39 (21-27 September 2026) deployment window. In the current Week-40 window, that cohort has collapsed to 2 visible operators — indicating deployment-phase completion and transition into consumption phase (encryption, negotiation, extraction operations inside previously-compromised environments). Any organisation initial-accessed during the Week-39 deployment window is at material risk of encryption completion across Weeks 41-43 (3-week consumption-phase window typical for new-affiliate cohorts). Risk owner: CISO / Head of IR joint. Treatment plan: maintain ransomware IR readiness at elevated posture through Week 43; verify shadow-copy audit, backup immutability, and endpoint response-time metrics; reduce precursor-cascade alert-acknowledgement SLA to 1 hour.
Threat intelligence observed two named Mozi-class botnet operators producing 1,169 attributed indicators across the Week-40 (28 September – 4 October 2026) window. The characteristic URL pattern (
/Mozi.m binary fetch and /i bot-identification endpoint on non-standard high ports) and sustained multi-day deployment indicate an active infrastructure build event. Botnet recruitment phase typically follows the build phase across 2-6 weeks, during which compromised consumer-router / IoT / SOHO-edge endpoints are recruited into the botnet via known router-firmware CVE exploitation (CVE-2017-17215, CVE-2014-8361, CVE-2020-25506 among others). Enterprise exposure during recruitment phase includes compromised employee-home routers producing attack traffic reaching enterprise infrastructure. Risk owner: Head of Security Architecture / Head of Perimeter joint. Treatment plan: deploy Mozi-pattern URL detection at proxy and SIEM layer; add IoT and consumer-router firmware monitoring where branch / employee-home visibility exists; prioritise ingest of botnet-tier IOCs across firewall, EDR and threat-intelligence enrichment layers.If a ransomware event in your environment traces to Week-39 initial access, the after-action will note the following. (a) Threat intelligence dated 4 October 2026 explicitly warned that the Week-39 ransomware cohort had completed its deployment phase and transitioned to consumption-phase operations inside already-compromised environments. (b) The recommended defender posture (maintain IR readiness through Week 43, reduce precursor-cascade alert SLA to 1 hour) was named in the advisory. (c) The 10-21 day new-affiliate deployment-to-encryption timeline was documented and dated.
If the organisation stood down ransomware IR readiness during Week 40 (operator count visibly collapsed from 36 to 2), the after-action will additionally note that the collapse was explicitly framed in the Week-40 advisory as deployment-phase completion rather than risk reduction. Board-level questions in that scenario are not about the technical outcome; they are about why the explicit warning in the advisory was not acted upon.
17 · Four Production-Ready Sigma Rules
title: Windows Hook Installation Consistent With RAT-Category Keylogging
id: hfl-2026-040-01
status: experimental
description: Detects SetWindowsHookEx API usage from processes not on the known-good hook-consumer list. Validated by W40's 1,053 RAT-category IOCs across 6 families.
logsource:
category: sysmon_apicall
product: windows
detection:
selection_hook:
API|contains:
- 'SetWindowsHookExA'
- 'SetWindowsHookExW'
HookType|in: [WH_KEYBOARD, WH_KEYBOARD_LL, WH_MOUSE, WH_MOUSE_LL]
filter_good:
Image|endswith:
- '\explorer.exe'
- '\lsass.exe'
- '\logonui.exe'
condition: selection_hook and not filter_good
fields: [Image, API, HookType, User]
level: high
tags: [attack.collection, attack.t1056_001]
title: Mozi-Family Botnet URL Pattern Detection
id: hfl-2026-040-02
status: experimental
description: Detects outbound HTTP requests matching Mozi-family botnet URL signatures — Mozi.m binary fetch or /i bot-identification endpoints on non-standard high ports.
logsource:
category: proxy
detection:
selection_mozi_binary:
request_url|contains: '/Mozi.m'
selection_mozi_ident:
request_url|re: ':[0-9]{4,5}/i$'
request_url|re: '^http://[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+'
selection_stage_url:
request_url|re: ':[0-9]{4}/\?h=[0-9.]+&p=[0-9]+&t=(tcp|ws)&a=(w32|w64|l32|l64)&stage=true'
condition: selection_mozi_binary or selection_mozi_ident or selection_stage_url
fields: [src_host, dst_url, user_agent, response_code]
level: high
tags: [attack.command_and_control, attack.t1105, attack.resource_development, attack.t1584]
title: Phishing Kit Deployment Three-IOC-Type Burst Detection
id: hfl-2026-040-03
status: experimental
description: Detects correlated bursts of fresh domain registrations, URL IOCs and hash IOCs within a 48-hour window attributed to a single phishing-kit operator identifier.
logsource:
category: threat_intel_feed_correlation
detection:
selection_burst:
adversary_type: 'Phishing Kit'
ioc_types_distinct|gte: 3
timeframe_within: 48h
volume_threshold|gte: 100
condition: selection_burst and timeframe_within and volume_threshold
fields: [adversary_id, ioc_types, ioc_count, first_seen, last_seen]
level: high
tags: [attack.resource_development, attack.t1584, attack.t1656]
title: Ransomware Precursor Cascade - Shadow-Copy Delete + Defender Disable + Boot Config Tamper
id: hfl-2026-040-04
status: production
description: Canonical ransomware pre-encryption cascade. Stays live through consumption-phase windows (W40-W43) and new-cohort entry windows (W42-W45). Reduce alert SLA to 1h.
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
selection_defender_off:
CommandLine|contains:
- 'Set-MpPreference -DisableRealtimeMonitoring'
- 'Set-MpPreference -DisableBehaviorMonitoring'
selection_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'safeboot'
- 'bootstatuspolicy ignoreallfailures'
timeframe: 10m
condition: selection_vssadmin or selection_defender_off or selection_bcdedit
fields: [Image, CommandLine, ParentImage, User]
level: critical
tags: [attack.impact, attack.t1486, attack.t1490, attack.defense_evasion, attack.t1562_001]
18 · The 60-Minute Ops Plan
What to do this week — before Wednesday
- MINUTES 0-10 · Ship Sigma-02 Mozi-pattern URL detection to proxy and SIEM. The
/Mozi.mand/ipatterns on high ports are high-signal, low-false-positive. Verify at least one test alert fires on a known-pattern test URL. - MINUTES 10-25 · Verify Sigma-04 production tier across all endpoints — the ransomware consumption-phase window is open now through Week 43. Any endpoint where Sigma-04 is still in test tier is uncovered against the exact scenario this week warns about. Audit + remediate within the hour.
- MINUTES 25-35 · Reduce ransomware precursor-cascade alert-acknowledgement SLA to 1 hour during Weeks 40-43. Document the SLA change in change-management with return-to-normal criteria (ransomware operator count stable 15+ for two consecutive weeks).
- MINUTES 35-45 · Import this week’s hash-tier IOC set (1,705 fresh hashes) into EDR — the Botnet + RAT + Backdoor concentration this week makes the endpoint hash set the single highest-value coverage addition. Prioritise over domain-tier and URL-tier this week.
- MINUTES 45-55 · Draft Week-41 hunt-abstract for Mozi-class recruitment-phase traffic — hypothesis: compromised consumer / SOHO routers in employee home-network environments will begin producing Mozi-pattern URL requests reaching enterprise infrastructure across Weeks 41-45. Deploy the hunt immediately for Week-41 execution.
- MINUTES 55-60 · Executive brief prep · the burn-out narrative — Section 13 cross-week trend table (W33-W40) is the strategic slide. Combined with Sections 04-05 deep dives on the ransomware consumption-phase window and Mozi-class botnet build, this is the right board-level framing. Schedule the brief within 48 hours.
See this week’s threat surface inside the operator console
HuntIntel exposes the same corpus this advisory is built from — continuously updated. Per-cluster fingerprint, actor migration timeline, Mozi-pattern URL live feed, ransomware consumption-phase tracking, sector heatmap, country attribution atlas.
19 · Top IOCs per Indicator Type
Operator-grade extractions for the 28 September – 4 October window · high-severity attributed indicators only · filtered to named-adversary sources. Rendered defanged per standard IOC-publishing practice (re-fang on import: [.] → .; hxxp → http).
hxxp/hxxps replacement. Note the Mozi-pattern URLs clearly visible in the top-15 URL set.Top 15 · IP addresses · high-severity · named-adversary
// Botnet · Backdoor · RAT · APT attribution
| # | Indicator | Category | Severity |
|---|---|---|---|
| 1 | 1.34.200.85 |
RAT | HIGH |
| 2 | 101.108.97.215 |
Botnet | HIGH |
| 3 | 101.109.81.93 |
Botnet | HIGH |
| 4 | 101.42.255.92 |
Backdoor | HIGH |
| 5 | 101.99.91.180 |
Backdoor | HIGH |
| 6 | 102.129.165.178 |
Backdoor | HIGH |
| 7 | 102.220.160.122 |
Backdoor | HIGH |
| 8 | 102.220.160.40 |
Backdoor | HIGH |
| 9 | 103.106.230.190 |
Backdoor | HIGH |
| 10 | 103.115.49.68 |
Botnet | HIGH |
| 11 | 103.125.31.101 |
Botnet | HIGH |
| 12 | 103.151.42.13 |
Botnet | HIGH |
| 13 | 103.160.59.97 |
APT | HIGH |
| 14 | 103.166.103.151 |
Botnet | HIGH |
| 15 | 103.203.210.102 |
Botnet | HIGH |
Top 15 · Domains · high-severity · defanged
// Phishing-kit domains · Malware-Activity + RAT + Backdoor delivery domains
| # | Indicator (defanged) | Category | Severity |
|---|---|---|---|
| 1 | 03webzoominvite[.]us |
RAT | HIGH |
| 2 | 044shs8u[.]tapkita[.]com |
Botnet | HIGH |
| 3 | 095b8b1d[.]imzural[.]info |
Malware-Activity | HIGH |
| 4 | 0fbw5tqk[.]imzural[.]info |
Malware-Activity | HIGH |
| 5 | 0gnu5zak[.]edebiyatkonulari[.]com |
Malware-Activity | HIGH |
| 6 | 0nmf90it[.]sallysprattstudio[.]com |
Malware-Activity | HIGH |
| 7 | 0ygn6edx[.]exploringvirtualreality[.]com |
Malware-Activity | HIGH |
| 8 | 1089813[.]us31[.]myftpupload[.]com |
Malware-Activity | HIGH |
| 9 | 110digitech[.]com[.]au |
Malware-Activity | HIGH |
| 10 | 14fet9qp[.]hwgrouppik[.]com |
Malware-Activity | HIGH |
| 11 | 15fc73d7[.]wignalllindor[.]wiki |
Malware-Activity | HIGH |
| 12 | 16sondra[.]workers[.]dev |
Backdoor | HIGH |
| 13 | 1cujg0ph[.]nomoneynohoney[.]org |
Malware-Activity | HIGH |
| 14 | 1dollarbiz[.]store |
Malware-Activity | HIGH |
| 15 | 1ms3zuoc[.]hwgrouppik[.]com |
Malware-Activity | HIGH |
Top 15 · File hashes · SHA-256 · high-severity
// Botnet payload hashes · Backdoor samples · Loader + Malware-Activity variants
| # | SHA-256 | Category | Severity |
|---|---|---|---|
| 1 | 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 |
Loader | HIGH |
| 2 | 0026d4ecdb0b8eeda2f86c5d8e4442abb5f6601a8976ae1621a44ecbdc202e4e |
Botnet | HIGH |
| 3 | 005b92682ff4e21cd81ea7a62dec1768ceed06a08f9b862698295bf4b5f2e9db |
Botnet | HIGH |
| 4 | 0088148d6f726d00c3a46ea821e313615f11ad08e553f2081c3e0cd0ac06cfb5 |
Botnet | HIGH |
| 5 | 00e531a66d4f0763b70298f3b5c6e76a91e5cc744dad375c71cacc201b3d5f1e |
Botnet | HIGH |
| 6 | 0116035ec7b3089b35231c75dc558547337e99bb99319c52241905a2c968f341 |
Botnet | HIGH |
| 7 | 017b90428f16fb8e760b958459463f6cd99109553ebfafe7b9192be9fb531ace |
Botnet | HIGH |
| 8 | 018d208b4763b6ad17ae9c9b6f6464bcc4a2de3289f50e24b1a6da1ffef289e1 |
Botnet | HIGH |
| 9 | 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a |
Backdoor | HIGH |
| 10 | 02c05faa97ebc77db971a14b06fd99ec004e669b662a55d520031b1bed808199 |
Botnet | HIGH |
| 11 | 03df04299cc3d2b5ce3b87f4369690f3721e152abc4f173d2dbd65c0e797c697 |
Backdoor | HIGH |
| 12 | 040fe79af10373a4a2680b5fbfd439dc7afca68c0bf9bc12144a4e9e33430292 |
Botnet | HIGH |
| 13 | 0452f9b557ddc5621efd0af6997491c753525a72ad083f55e0ebca9cba2e429c |
Botnet | HIGH |
| 14 | 0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f |
Malware-Activity | HIGH |
| 15 | 04b96731fa4b3e21fefe24ad7b84bb9db6b3fac6e5f99b63c5ea7a16d35fe888 |
Botnet | HIGH |
Top 15 · URLs · high-severity · defanged
// Mozi-pattern botnet URLs (/Mozi.m and /i endpoints) · Backdoor staging URLs
| # | Indicator (defanged) | Category | Severity |
|---|---|---|---|
| 1 | hxxp[://]101[.]108[.]97[.]215:48064/Mozi[.]m |
Botnet | HIGH |
| 2 | hxxp[://]101[.]108[.]97[.]215:48064/i |
Botnet | HIGH |
| 3 | hxxp[://]101[.]109[.]81[.]93:36236/i |
Botnet | HIGH |
| 4 | hxxp[://]101[.]33[.]45[.]136:8084/?h=101[.]33[.]45[.]136&p=8084&t=ws&a=l32&stage=true |
Botnet | HIGH |
| 5 | hxxp[://]101[.]33[.]45[.]136:8084/?h=101[.]33[.]45[.]136&p=8084&t=ws&a=l64&stage=true |
Botnet | HIGH |
| 6 | hxxp[://]101[.]99[.]91[.]180/?h=101[.]99[.]91[.]180&p=80&t=ws&a=w64&stage=true |
Backdoor | HIGH |
| 7 | hxxp[://]102[.]129[.]165[.]178:8443/?h=102[.]129[.]165[.]178&p=8443&t=tcp&a=w32&stage=true |
Backdoor | HIGH |
| 8 | hxxp[://]103[.]125[.]31[.]101:40307/i |
Botnet | HIGH |
| 9 | hxxp[://]103[.]151[.]42[.]13:38028/i |
Botnet | HIGH |
| 10 | hxxp[://]103[.]166[.]103[.]151:55118/i |
Botnet | HIGH |
| 11 | hxxp[://]103[.]203[.]210[.]102:45595/i |
Botnet | HIGH |
| 12 | hxxp[://]103[.]249[.]199[.]3:58152/i |
Botnet | HIGH |
| 13 | hxxp[://]103[.]249[.]199[.]4:52748/i |
Botnet | HIGH |
| 14 | hxxp[://]103[.]31[.]103[.]204:53154/i |
Botnet | HIGH |
| 15 | hxxp[://]103[.]44[.]137[.]13:40411/bin[.]sh |
Botnet | HIGH |
Full-corpus access: the 4,812 unique attributed IOCs surfaced this week are available in the HuntIntel operator console under the Adversary Intel Search view. Filter by adversary_type, category, first_seen date range, and severity band; export as STIX, MISP, or CSV. Open the operator console →
20 · Frequently Asked Questions
Is ransomware risk actually lower this week?
No. Visible-operator count is lower; underlying risk is not. The 36 operators from Week 39 completed their deployment phase and transitioned to consumption-phase operations inside previously-compromised environments. Those operations produce no fresh external IOCs but produce incident outcomes. Risk is at the same elevated level as last week; visibility has reduced.
How do we know this is a Mozi-class botnet and not something new?
The URL patterns (/Mozi.m binary fetch and /i bot-identification endpoint on non-standard high ports like 36236, 40307, 48064, 55118) are specific to the Mozi botnet codebase family and its direct derivatives. Both W40 operators show these patterns across their IOC sets. The patterns are rare enough in legitimate traffic that attribution is high-confidence.
What does Mozi-class recruitment phase actually look like for enterprise defenders?
Expect: scanner traffic from recruited bot IPs targeting known router CVEs (particularly CVE-2017-17215, CVE-2014-8361, CVE-2020-25506), gradual expansion of attributed botnet IP footprint on third-party reputation feeds, and attack traffic from compromised employee-home / branch-office routers hitting enterprise perimeter. The attack-tier impact is enterprise employees’ home networks being used as proxies and scanner sources against enterprise targets.
Should we deploy Sigma-02 before Wednesday?
Yes. The pattern is high-signal, low-false-positive, and matches current attack traffic. The sooner it is in production, the sooner it catches Mozi-pattern traffic from already-recruited bots in your employees’ home networks.
When does the next ransomware cohort enter?
Base case: Weeks 42-45 (3-5 week typical gap between cohorts). Earlier than Week 42 would indicate accelerated ecosystem rhythm. Later than Week 45 would indicate ecosystem contraction. Hold Sigma-04 ransomware precursor-cascade detection in production regardless of timing.
Why did APT concurrency go up this week?
Two new APT clusters surfaced on 2 October as first-time observations. One week of +1 cluster is noise. Two consecutive weeks of +1 or multiple new-identifier emergences in a single week would be recovery signal. Watch Weeks 41-42 to determine whether this is cycle-trough end or statistical fluctuation.
Nineteen malware families is high — should coverage expand?
Technique-based coverage (T1105, T1027, T1189, T1041, T1036, T1059) covers 19 families inherently. Family-specific coverage expands slower than operators enter the market. Prioritise technique content; expand family-specific content only for the top 3-5 observed families each week.
How do the anonymised Cluster IDs relate across weeks?
Cluster IDs rotate weekly. Week 40’s C-series does not map to Week 39’s B-series or Week 38’s A-series. No cluster label carries over unless explicitly stated. Treat C01, C02, C03 as fresh identifiers.
What’s on the HuntIntel platform that this document does not show?
Live Mozi-pattern URL feed with per-operator attribution. Ransomware consumption-phase tracking. Actor migration timelines. Sector heatmaps. Country attribution atlas. Cohesive-IP view. Full CVE-exploitation attribution. Custom TaHiTI-abstract templates. Detection-content marketplace. This document is a weekly snapshot; HuntIntel is the continuous surface.
21 · Close
Week 40 is burn-out week. The Week-39 ransomware cohort completed its deployment phase and transitioned to consumption. Two Mozi-class botnet operators filled the vacated infrastructure surface with a 1,169-indicator build event. Nineteen malware families produced the largest Malware-tier reading of the trailing eight weeks. APT concurrency showed early recovery signal. C2 continued contracting from the September cycle. The strategic signal to communicate upward is that visible-operator-count variance is deployment-phase visibility, not risk variance.
Detection engineers: ship Sigma-02 Mozi-pattern URL detection before Wednesday. Verify Sigma-04 ransomware precursor cascade is production-tier across all endpoints. Reduce precursor-cascade alert SLA to 1 hour through Week 43.
CTI / hunt leads: deploy the Mozi-class recruitment-phase hunt-abstract for Week-41 execution. Draft a continuation hunt for the APT cluster emergence pattern across Weeks 41-42.
CISOs / risk officers: the burn-out-plus-build narrative is boardroom-ready material. Section 13’s cross-week trend table (W33-W40) is the strategic slide. Communicate that the ransomware consumption-phase window is open NOW — risk is not lower, visibility is lower. Add R-2026-CY-RANSOMWARE-CONSUMPTION-PHASE and R-2026-CY-BOTNET-INFRASTRUCTURE-BUILD from Section 16 to the Q4 enterprise risk register.
Next week’s Week-41 briefing publishes on Sunday. Predictive framing is in Section 15. Bookmark huntintel.hackforlab.com for continuous intelligence between briefings.
Cite this document as: HackForLab CTI Research. “Weekly Threat Advisory · September 28 – October 4, 2026.” huntintel.hackforlab.com.










