Harley-Davidson Alleged Breach – CL0P Ransomware Adds Motorcycle Maker to the List
CL0P ransomware group listed Harley-Davidson on its extortion leak site, claiming a compromise; the motorcycle maker has not confirmed any breach.
The CL0P ransomware operation added Harley-Davidson to its public extortion portal, a listing highlighted by the ransomNews monitoring account on September 10, 2026. Harley-Davidson has not confirmed any compromise, and the initial access method, affected business unit, timing, and volume of stolen data remain unknown, with no sample files or technical indicators published. The article stresses that leak-site listings alone do not confirm a breach and can serve as negotiation pressure in double-extortion schemes. If verified, stolen data could fuel downstream phishing, BEC, credential-stuffing, and invoice fraud targeting dealers, suppliers, and customers.
New pro-Ukraine hacker group targets Russian companies with custom ransomware
F6 links new pro-Ukraine ransomware group VantaCore, likely a Thor rebrand, to seven attacks on Russian firms using custom tooling and multimillion-dollar demands.
Russian cybersecurity firm F6 reports that VantaCore, a ransomware group believed to be a rebrand of pro-Ukrainian group Thor, has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating as a ransomware-as-a-service operation with a Tor-based victim chat and a leak site. The group uses custom-built tooling including the VantaCore ransomware that encrypts servers and workstations, VantaCoreLoader for distribution, the VantaCoreRAT backdoor, and SnowKiller, which disables antivirus and security software. Initial access relies on poorly secured VPNs and remote-access tools, flaws in internet-facing applications, and credentials stolen from business partners. F6 notes pro-Ukrainian groups increasingly abandoned stock ransomware like LockBit 3 Black and Babuk in 2025-2026 in favor of custom malware.
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.
Zimperium reported a new Android threat, Mantax Otax, that combines ransomware with surveillance: it encrypts files with AES and adds a .enc extension on Android 9 and older, while abusing MediaProjection for screenshots and MP4 screen recording and using hidden camera previews to photograph victims. The malware intercepts SMS one-time passwords, WhatsApp and Telegram data, and lock-screen PINs through Accessibility abuse and a fake system-lock overlay, and can negotiate ransoms via an on-screen chat. Malicious APKs are hosted on third-party file-sharing services, and researchers linked the activity to Indonesian threat actors, with C2 dynamically retrieved from a GitHub repository (apimantax[.]otax[.]fun). A second variant adds WebSocket communications, app blocking, full-screen overlays, and remote text-to-speech messages.