// 1 CRITICAL · 2 ZERO-DAY · 2 CVE IN THE LAST 24H→
Between September 21 and 25, 2026, three threat fronts collided: ShinyHunters defaced Clop's Tor leak site demanding an eight-figure ransom, the CARBONATO botnet automated theft of AI API keys from exposed Docker daemons, and SpyCloud found active infostealer exposure in 1,787 U.S. water utilities. The convergence signals a shift from data extortion to adversary infrastructure takeover, with AI access keys surpassing crypto wallets and banking credentials in priority.

Between September 21 and 25, 2026, three threat fronts collided with unprecedented intensity: ShinyHunters defaced Clop's Tor leak site demanding an eight-figure ransom, the CARBONATO botnet automated theft of AI API keys from exposed Docker daemons, and SpyCloud found active infostealer exposure in 1,787 U.S. water utilities. The convergence signals that cybercrime is shifting from data extortion to adversary infrastructure takeover, and that AI access keys have surpassed crypto wallets and banking credentials in priority.

Key Takeaways
  • ShinyHunters defaced Clop's Tor leak site with a banner reading "rooting your systems since '19 ;)" and demands an eight-figure payment plus a public apology, threatening to expose companies that paid Clop in the Oracle E-Business Suite campaign.
  • The CARBONATO botnet compromises unauthenticated Docker daemons on port 2375, installs the Hermes agent, and ranks AI API keys as top-priority loot, scanning nearby networks every five minutes.
  • SpyCloud detected active infostealer exposure in 1,787 water sector organizations out of roughly 10,000 analyzed, with 258 organizations exposing credentials for OT systems or remote access.
  • The sckit malware, delivered via malicious versions of the npm package @memtensor/memos-cloud-openclaw-plugin, activates on Python library import or plugin use, hunting secrets for npm, PyPI, GitHub, AWS, and Hugging Face.

Leak Site War: ShinyHunters vs. Clop

ShinyHunters turned Clop's Tor leak site into a battlefield. The group posted a defacement banner reading "rooting your systems since '19 ;)" and claims theft of server logs, source code, and the onion service's private keys. The feud traces back to the Oracle E-Business Suite campaign, with ShinyHunters asserting it identified the zero-day before Clop.

The financial demand is explicit and ruthless. In a message dated September 19, ShinyHunters demanded "all the money you made off the EBS campaign plus more AND WITH INTEREST," citing an eight-figure sum the group claims represents 2,333% of its own net worth. The Register quotes a group statement to Reuters: "We basically own them now." The threat extends beyond money: ShinyHunters threatens to expose companies that allegedly paid Clop, turning ransomware victims into second-tier hostages.

It is unverified whether ShinyHunters actually possesses the claimed onion private keys and payment logs, nor is it clear whether the threatened companies actually paid Clop or are merely targets of intimidation. The dossier does not specify whether the data has already been published or if the threat remains potential.

"ranking AI API keys first"

CARBONATO: When the Docker Daemon Becomes an AI Goldmine

The CARBONATO botnet has redefined the value of cyber loot. The malware scans the internet for Docker daemons exposed on TCP port 2375 without authentication, installs the Hermes Agent implant, and ranks AI API keys as the absolute priority in credential harvesting. Scanning of nearby networks occurs every five minutes, ensuring rapid propagation in misconfigured cloud environments.

Linguistic and timezone indicators suggest operators based in Costa Rica, but the dossier flags this as an unconfirmed assessment. It is unverified whether CARBONATO is actually operational in the wild or remains in a development and testing phase. ThreatDown, cited by SecurityWeek, analyzed the sample; Cisco Talos has not documented this botnet, focusing instead on CLOSEDQUORUM.

The mechanism exploits a standard misconfiguration: Docker daemons exposed without TLS or authentication are a known attack surface, but the pivot to AI API keys represents a paradigm shift. Access keys for models like Claude, GPT-4, and Gemini enable arbitrary use of compute resources and potentially access to training data or inference logs, with immediate economic impacts that are difficult to trace.

Water and Credentials: 1,787 Utilities with Active Exposure

SpyCloud analyzed stolen identity data linked to roughly 10,000 U.S. water and wastewater utilities, finding active infostealer exposure in 1,787 organizations. In 258 of these, the intercepted credentials allow access to OT systems or remote access tools. The most alarming data point emerges from a single case: malware on a vendor's device captured logins for approximately 167 metering portals.

The exposed credentials primarily concern remote administration tools such as TeamViewer, SonicWall, and Fortinet management portals. SpyCloud clarifies these are "potential access paths, not confirmed intrusions": credentials were intercepted by commodity infostealers, and no active breach of infrastructure is documented. The distinction is technical but not reassuring: systemic exposure of OT access in regulated sectors indicates insufficient identity management and a proliferation of remote access tools that are not adequately monitored.

Supply Chain and Database: sckit and CVE-2026-42542

Meanwhile, the supply chain threat hit the AI ecosystem. StepSecurity identified malicious versions 0.1.21, 0.1.23, and 0.1.25 of the npm package @memtensor/memos-cloud-openclaw-plugin, which introduce the Go implant sckit. The malware, approximately 43.6 MB versus roughly 272 KB for the clean version, does not activate during installation but on Python library import or npm plugin use, evading pre-install script checks.

The sample hunts secrets for npm, PyPI, GitHub, AWS, and Hugging Face. Semgrep and StepSecurity agree: "no evidence yet that it has propagated" beyond the published packages. The deferred activation mechanism represents a significant technical evolution, rendering static detection on installation insufficient.

On the vulnerability front, Ridge Security documented CVE-2026-42542 in TDengine, a time-series database used in industrial environments. The bug, rated CVSS 7.5 HIGH, is an integer underflow in pre-authentication message parsing leading to heap buffer overflow via a single malformed packet. Affected versions range from 3.4.0.0 to 3.4.1.5; the fix is available in 3.4.1.6.

Immediate Actions

Priority actions derive directly from documented facts:

  • Verify exposure of Docker daemons on port 2375 and enable TLS authentication, as CARBONATO explicitly exploits the lack of credentials on this port.
  • Audit installations of @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23, 0.1.25, remove them, and verify unauthorized import of linked Python libraries.
  • Update TDengine to version 3.4.1.6 to remediate CVE-2026-42542, as exploitation requires only a single pre-authentication packet.
  • Check for exposed credentials in remote management services (TeamViewer, SonicWall, Fortinet) in the water and utility sector, cross-referencing SpyCloud data with internal assets.

Why This Triangle Changes the Threat Perimeter

The week produced a rare convergence: criminals fighting on the same ground as their victims, cloud-native infrastructure becoming gateways for AI resources, and critical sectors exposing operational access through everyday administration tools. The novelty is not the isolated technique, but the simultaneity of the vectors.

ShinyHunters demonstrated that ransomware leak sites are contestable assets, with consequences for companies that paid thinking they had closed a chapter. CARBONATO formalized the loot transition: AI API keys have become liquid, transferable, and harder to revoke than banking credentials. SpyCloud quantified a structural exposure that does not require state-sponsored APTs, only commodity infostealers and reused passwords.

The technical reading is that the perimeter has shifted from network to identity, and from human identity to machine identity. API keys, service tokens, and remote access credentials have become the optic nerve of operations, and their exposure does not produce spectacular breaches but silent, persistent openings.

FAQ

Why is ShinyHunters attacking Clop instead of collecting ransoms directly?

The dossier does not specify the full strategic motive. The Register documents that ShinyHunters claims precedence in discovering the Oracle EBS zero-day and aims to recover the campaign's profits. The hypothesis is a market logic: stripping Clop of leak site control undermines the group's credibility as a ransomware operator and turns its victims into economic leverage.

Do the AI API keys stolen by CARBONATO allow access to models or only credit consumption?

SecurityWeek reports that CARBONATO is "ranking AI API keys first" without detailing post-compromise use. The dossier does not specify whether keys permit access to model weights, training data, or only paid inference. The direct economic consequence is unauthorized resource consumption regardless, with potential exfiltration of data inserted into queries.

Is CLOSEDQUORUM linked to CARBONATO?

No. CLOSEDQUORUM is a Go-based Windows implant documented by Cisco Talos that delegates C2 decisions to commercial LLMs (DeepSeek, Qwen, Mistral, Gemini). Talos has not confirmed use in real operations. No infrastructure overlaps with CARBONATO emerge at this stage.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. securityweek.com
  2. theregister.com
  3. radar.offseq.com
  4. itsecuritynews.info
  5. github.com
  6. stepsecurity.io
  7. ridgesecurity.ai