Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future details Tajin Group, a Chinese-speaking vendor on Telegram guarantee marketplaces running phishing, carding, and money laundering operations targeting Chinese banks.
Insikt Group analyzed Tajin Group, a Chinese-speaking threat actor operating on Telegram-based guarantee marketplaces Dabai Guarantee and, since May 2026, Xinbi Guarantee. The group conducts phishing, payment card theft, and money laundering targeting mainland Chinese citizens and banks, testing stolen cards from twelve countries on platforms like CCAvenue and Geidea. Operators bought and sold at least 100 Telegram usernames and anonymous virtual numbers via Fragment Market to strengthen OPSEC, linking multiple usernames to single Telegram accounts. Recorded Future warns Tajin Group's TTPs are likely to be replicated by other vendors on Chinese-language guarantee marketplaces at global scale.
Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Russian e-commerce giant Wildberries says a DDoS attack and subsequent security measures delayed seller payments, leaving roughly $240 million unpaid.
Wildberries, one of Russia's largest online marketplaces, said a distributed denial-of-service attack on systems used to track and withdraw seller earnings delayed payments, with funds to be transferred after technical procedures complete. The Russian Union of Marketplace Sellers reported about 20 billion rubles ($240 million) unpaid, and 95.6% of nearly 2,000 surveyed sellers had not received expected payments. Ukraine's military intelligence (HUR) previously claimed an operation with the hacker group Cyber Corps disrupted Wildberries' payment and customer service systems, though the company has not confirmed whether the DDoS attacks were connected.
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security reclassify North Korea's Lazarus umbrella into six clusters spanning espionage, financial theft, and fake IT worker operations.
New research by Sekoia and Kudelski Security, published September 7, divides the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, mostly under North Korea's military intelligence bureau (GRIB). The former APT38 likely split into CryptoCore and Jade Sleet, focused on cryptocurrency, Web3, and blockchain targets. Moonstone Sleet combines espionage with financially motivated operations, using custom malware alongside Qilin ransomware-as-a-service. Thousands of fake IT workers generate regime revenue and provide access, linked to incidents like the $62.5M Munchables protocol theft.
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
INTERPOL's Operation Jackal IV made 58 arrests across 22 countries, disrupting Black Axe-linked networks laundering scam, BEC and sextortion proceeds.
INTERPOL's Operation Jackal IV (November 2025–June 2026) involved 22 countries and led to 58 arrests and 263 suspects identified tied to West African organized crime networks such as Black Axe. Key actions included 39 arrests in South Africa with $2.67 million seized and 257 bank accounts frozen, 17 arrests in Argentina against a crime-as-a-service laundering network, and a Romanian call-center investment scam with estimated global losses around €143 million. The operation also flagged rising sextortion of minors as young as 14 by these networks.
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
GuidePoint reports a ransomware affiliate posing as 'Ransom Busters' charges victims $20,000-$60,000 to delete stolen data, and details UNC6671's $8M AitM extortion wave.
GuidePoint's GRIT team reports that 'Ransom Busters', likely a ransomware affiliate active across multiple RaaS operations including DragonForce, Settra and Anubis, proactively emails victims claiming it deleted their stolen data and backups for a $20,000-$60,000 fee, citing claimed access to RaaS administrative panels for over three years. Two analyzed intrusions shared tooling: SoftPerfect Network Scanner for reconnaissance, s5cmd-based exfiltration to AWS cloud storage, an RMM tool installed via PowerShell, a backdoor account with password 'Numlock!123' and the same attacker hostname DESKTOP-BBETH6K. Separately, GRIT detailed UNC6671's (Cordial Spider) adversary-in-the-middle vishing operation running since April under five extortion brands, with more than $8 million across 15 Bitcoin wallets, an average of $600,000 per payment, and 78 phishing sub-domains across 76 organizations, 40% in financial services.
New Malware 'Rover' Targets Indian Ambassador to Afghanistan
Unit 42 reports a spearphishing attack delivering the custom Rover Trojan to India's Ambassador to Afghanistan, exploiting CVE-2010-3333 in Word.
On December 24, 2015, Unit 42 identified a targeted spearphishing email spoofing Indian Defence Minister Manohar Parrikar, sent to India's Ambassador to Afghanistan. The RTF attachment exploited CVE-2010-3333 in Microsoft Word to download a downloader from newsumbrella.net, which retrieved the Rover Trojan and DLL plugins from 46.166.165.254. Rover uses OpenCV for webcam capture, OpenAL for audio recording and libsndfile for audio files, with data exfiltration over its C2 channel; separate payload versions target Windows XP and later systems.