Classification: TLP:CLEAR | Publication Date: 2026-10-09 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
Executive Summary
On 2026-10-09, the ARCUSMEDIA ransomware operation listed three organizations on its dark web leak site: Ladrillera Mecanizada (Manufacturing, Mexico), mblllp (Canada), and AETHOS (Brazil). These are claims made by a criminal actor and have not been independently confirmed as breaches. The listings show a Latin America-weighted geographic pattern (Mexico, Brazil) alongside a North American entry, with manufacturing as the only confirmed sector tag in this batch. All three listings currently appear on a single monitoring source only, so readers should treat both the existence of the postings and the underlying claims with appropriate skepticism while still using the gang's known tradecraft to drive defensive posture.
Sourcing & Verification
- Corroboration status: 0 of 3 listings in this dataset were independently observed by a second leak-site crawler. All 3 listings (Ladrillera Mecanizada, mblllp, AETHOS) are single-source, appearing on ransomware.live only. Single-source status means we cannot yet confirm the postings themselves exist as observed, let alone the claims behind them.
- What inclusion means: Inclusion in this briefing reflects a threat actor's claim published on a criminal leak site. It is not confirmation of a breach, and nothing in this dataset — at any corroboration tier — confirms that a compromise occurred. Only the named organization or its regulator can confirm an incident.
- Disputes and denials: A named organization may dispute the listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question, and we make no assertion either way.
- Corrections: Security Arsenal will publish corrections as additional sourcing becomes available. We welcome contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — ARCUSMEDIA
ARCUSMEDIA operates as a double-extortion ransomware crew: data theft first, encryption second, and a public leak-site countdown to pressure payment. Public reporting on this group remains comparatively thin relative to larger RaaS ecosystems, so the profile below reflects observed patterns and should be read with that caveat.
- Aliases: The group is tracked publicly under the ARCUSMEDIA name; no widely accepted alternative aliases have been established in open reporting.
- Operating model: Appears to operate as a closed or semi-closed group rather than a broad affiliate-driven RaaS, based on the relatively low posting cadence and lack of affiliate recruitment chatter observed on monitored forums. This assessment is low-confidence.
- Ransom demands: Not consistently documented. Groups with a similar victim profile (mid-market, LATAM-heavy) typically open demands in the low-to-mid six figures USD, scaling with perceived victim revenue.
- Initial access methods (typical for this class of actor): Spear-phishing with macro-enabled or HTML-smuggled payloads, exploitation of exposed remote access services (VPN appliances, RDP), and purchase of valid credentials from initial access brokers. No specific vector is confirmed for any listing in this dataset.
- Double extortion: Yes — the leak site itself is the extortion mechanism, with staged data-publication threats.
- Dwell time: Not publicly established for ARCUSMEDIA specifically. Comparable mid-tier crews typically show 3–14 days between initial access and detonation, with data staging occurring in the final 48–96 hours.
Current Campaign Analysis
Sector targeting: Of the three organizations ARCUSMEDIA listed in this batch, one carries a confirmed sector tag: Ladrillera Mecanizada in Manufacturing (MX). The other two — mblllp (CA) and AETHOS (BR) — are tagged 'Not Found' in the source data, meaning sector attribution was unavailable at collection time. Do not infer sectors for unclassified listings.
Geographic concentration: Two of three listings are Latin American organizations (MX, BR), with one Canadian entry. This is consistent with a pattern seen across mid-tier ransomware crews in 2025–2026: LATAM organizations are increasingly listed as gangs diversify away from heavily defended US/EU targets and as regional regulatory pressure (and thus negotiation leverage) grows.
Victim profile: The single confirmed-sector listing is an industrial/manufacturing firm in Mexico — brick and construction materials production. Manufacturing remains the most-listed sector across ransomware leak sites globally because of low downtime tolerance, OT/IT convergence risk, and historically weaker segmentation. Absent revenue data in the source feed, we do not estimate victim revenue for the named organizations; the pattern (regional mid-market industrial firms) is consistent with crews targeting organizations large enough to pay but below the threshold of mature 24/7 SOC coverage.
Posting frequency / escalation: Three listings published on a single day (2026-10-09) in a monitored window of the gang's last ~100 postings suggests a batch-publication pattern — claims held and released together to maximize pressure and media pickup. Watch for follow-on postings within 7–14 days; gangs often re-list or escalate with partial data dumps if initial publication does not produce contact.
CVE linkage (hypothesis only): We have no evidence tying any named organization in this dataset to a specific CVE. That said, the currently exploited vulnerability landscape overlaps heavily with the access vectors mid-tier ransomware crews favor. Defenders in manufacturing and LATAM-facing enterprises should prioritize the following CISA KEV entries with confirmed ransomware use as sector-level exposure hypotheses, not victim-specific attribution:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Perimeter VPN exploitation is a top initial access vector for ransomware crews; patch or disable IKEv1 where feasible.
- CVE-2026-20316 — Cisco Secure FMC hard-coded password. Management-plane compromise of network security appliances enables stealthy persistence and lateral movement.
- CVE-2026-59310 — VMware vCenter path traversal. vCenter compromise is a force multiplier: gangs use it to detonate encryption across the virtual estate simultaneously and to destroy backups hosted as VMs.
- CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style downstream access and credential theft from build pipelines.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer workstation/tooling compromise provides initial footholds with high-value credential access.
Detection Engineering
The following detections target the TTPs ARCUSMEDIA's class of actor reliably exhibits: remote-access initial entry, living-off-the-land lateral movement (PsExec/WMI), and pre-encryption staging (shadow copy deletion, mass file access, archive creation).
---
title: RDP or VPN-Brute-Force Followed by Successful Logon — Ransomware Initial Access
description: Detects a burst of failed remote logons (4625) from a single source followed by a successful logon (4624 type 3/10), consistent with password spraying or brute force against RDP/VPN-integrated AD — a common ransomware initial access pattern.
logsource:
product: windows
service: security
category: authentication
detection:
selection_failed:
EventID: 4625
selection_success:
EventID: 4624
LogonType:
- 3
- 10
condition: selection_failed and selection_success
timeframe: 10m
falsepositives:
- Legitimate password expiry storms
- Misconfigured service accounts
level: high
tags:
- attack.initial_access
- attack.t1110
- attack.t1133
---
title: PsExec-Style Remote Service Creation for Lateral Movement
description: Detects creation of services with names or paths consistent with PsExec and similar admin-share lateral movement tooling used by ransomware operators pre-detonation.
logsource:
product: windows
service: system
category: service_installation
detection:
selection:
EventID: 7045
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
- 'csexec'
ServiceFileName|contains:
- '\\ADMIN$\\'
- '\\IPC$\\'
- 'psexec'
condition: selection
falsepositives:
- Legitimate administrative software deployment
- EDR/IT management tooling using remote service execution
level: high
tags:
- attack.lateral_movement
- attack.t1569.002
- attack.t1021.002
---
title: Volume Shadow Copy Deletion via vssadmin, wmic, or PowerShell
description: Detects deletion or resizing of Volume Shadow Copies — a near-universal pre-encryption step in ransomware operations including double-extortion crews like ARCUSMEDIA.
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\bcdedit.exe'
selection_cmd:
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'shadowstorage'
- 'Delete-WmiObject win32_shadowcopy'
- 'Remove-CimInstance'
- 'recoveryenabled no'
condition: selection_img and selection_cmd
falsepositives:
- Backup software maintenance
- Storage administrators reclaiming space
level: critical
tags:
- attack.impact
- attack.t1490
// ARCUSMEDIA-style pre-ransomware staging hunt — Microsoft Sentinel
// Looks for: admin-share writes + remote service execution + archive staging + shadow copy tampering
// correlated on a single host within a 6-hour window.
let Lookback = 7d;
let StageWindow = 6h;
let AdminShareWrites =
DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FolderPath has_any ("\\ADMIN$", "\\C$", "\\IPC$")
| where ActionType == "FileCreated"
| project FileHost=DeviceName, FileTime=TimeGenerated, FileName, InitiatingProcessFileName;
let RemoteSvcExec =
DeviceEvents
| where TimeGenerated > ago(Lookback)
| where ActionType == "ServiceInstalled"
| extend Parsed = parse_json(AdditionalFields)
| where tostring(Parsed.ServiceName) has_any ("PSEXESVC", "PAExec") or tostring(Parsed.ServiceFileName) has "ADMIN$"
| project SvcHost=DeviceName, SvcTime=TimeGenerated, SvcName=tostring(Parsed.ServiceName);
let ShadowTamper =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "recoveryenabled no")
| project ShadowHost=DeviceName, ShadowTime=TimeGenerated, ProcessCommandLine, AccountName;
let ArchiveStaging =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName has_any ("rclone.exe", "7z.exe", "rar.exe", "winscp.exe", "megacmd.exe")
| project ArchiveHost=DeviceName, ArchiveTime=TimeGenerated, FileName, ProcessCommandLine;
AdminShareWrites
| join kind=inner RemoteSvcExec on $left.FileHost == $right.SvcHost
| join kind=inner ShadowTamper on $left.FileHost == $right.ShadowHost
| join kind=inner ArchiveStaging on $left.FileHost == $right.ArchiveHost
| where (ShadowTime - FileTime) between (0min .. StageWindow)
| project FileHost, FileTime, SvcName, ArchiveProc=FileName1, ProcessCommandLine, ProcessCommandLine1, AccountName
| sort by FileTime desc
# Rapid pre-ransomware posture check — run on critical servers and hypervisor hosts
# 1) Exposed RDP listeners 2) Scheduled tasks created in last 7 days 3) Shadow copy status
# 4) Suspicious new local admins 5) Recent vssadmin/shadow deletions in event log
Write-Host "=== [1] RDP Exposure ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -State Listen -LocalPort 3389 -ErrorAction SilentlyContinue
if ($rdp) { Write-Host "WARNING: RDP listening on 3389 — verify it is not internet-exposed" -ForegroundColor Red }
else { Write-Host "OK: No RDP listener detected" -ForegroundColor Green }
$rdpReg = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue).fDenyTSConnections
Write-Host "fDenyTSConnections = $rdpReg (0 = RDP enabled)"
Write-Host "`n=== [2] Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
Select-Object TaskName, TaskPath, Date, @{N='RunAs';E={$_.Principal.UserId}} | Format-Table -AutoSize
Write-Host "`n=== [3] Volume Shadow Copies ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize }
else { Write-Host "WARNING: No shadow copies present — verify this is expected (backup policy)" -ForegroundColor Red }
Write-Host "`n=== [4] Local Administrators Added in Last 14 Days ===" -ForegroundColor Cyan
$since = (Get-Date).AddDays(-14)
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4732; StartTime=$since} -ErrorAction SilentlyContinue |
ForEach-Object { $_.Message } | Select-String -Pattern 'Administrators' -Context 0,4
Write-Host "`n=== [5] Shadow Copy Deletion Events (vssadmin/wmic, last 7 days) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=1; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match 'delete shadows|shadowcopy delete|recoveryenabled no' } |
Select-Object TimeCreated, Message | Format-List
Write-Host "`nDone. Any WARNING or unexpected hit above warrants escalation to IR." -ForegroundColor Cyan
Incident Response Priorities
T-minus detection checklist (before encryption fires):
- Shadow copy / backup tampering —
vssadmin delete shadows,bcdedit ... recoveryenabled no, backup console logins from unusual accounts. This is the strongest single pre-detonation signal. - Mass file read/rename bursts on file servers from a single host or service account — staging behavior.
- Archive tooling (rar/7z/rclone/megasync/WinSCP) appearing on servers where it has no business justification.
- New GPO pushes or PsExec/WMI service creation fanning out from a single workstation — the gang is positioning for simultaneous detonation.
- EDR/AV tampering — agent service stops, exclusion additions, or
Set-MpPreferencechanges. - Unusual egress volume to cloud storage or unfamiliar IPs from servers, especially overnight.
- vCenter/hypervisor logins from non-admin jump hosts — crews target the virtualization layer to encrypt the estate in one move (see CVE-2026-59310 exposure hypothesis).
Assets this class of gang prioritizes for exfiltration:
- Finance and legal file shares (contracts, payroll, banking details) — highest extortion leverage.
- HR data (PII of employees) — regulatory exposure multiplier, especially under Brazil's LGPD and Mexico's data protection law for LATAM-listed organizations.
- Customer databases and CAD/engineering drawings for manufacturing victims (IP theft angle).
- Email archives of executive leadership.
- Backup catalogs and credential stores — to both increase leverage and destroy recovery options.
Containment actions, ordered by urgency:
- Isolate, don't nuke: Network-isolate affected segments (disable switch ports / ACLs) rather than powering off — volatile memory holds keys and staging evidence.
- Disable compromised accounts and force enterprise-wide credential resets, prioritizing Domain Admins, service accounts, and VPN users. Assume Kerberos is poisoned: reset krbtgt twice if DA compromise is suspected.
- Block egress at the perimeter except to known-good destinations; kill rclone/megasync-style exfil paths immediately.
- Protect the virtualization and backup planes: isolate vCenter, verify offline/immutable backups are intact and unreachable from production credentials.
- Preserve evidence: capture memory and triage images from patient zero before remediation wipes staging artifacts.
- Engage counsel on notification obligations — for MX and BR entities, assess LGPD (ANPD notification in Brazil) and Mexican LFPDPPP duties; for CA, PIPEDA breach-of-record requirements.
- Do not visit the leak site from corporate infrastructure and do not engage the actor directly without an established negotiation/incident-response retainer.
Hardening Recommendations
Immediate (24 hours):
- Patch or mitigate the perimeter KEV entries above, in priority order: CVE-2026-50751 (Check Point IKEv1), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter). These are confirmed ransomware-exploited and map directly to the access and detonation layers.
- Audit and disable internet-exposed RDP entirely; require VPN + MFA for any remote administration. Block 3389 at the perimeter unconditionally.
- Enforce phishing-resistant MFA (FIDO2) on VPN, email, and all remote access — TOTP at minimum.
- Deploy the Sigma rules and KQL query above; alert on shadow copy deletion as critical.
- Verify backup immutability and test one restore today. Confirm backup credentials are separated from AD.
- Block execution of rclone, megacmd, WinSCP, and 7z on servers via AppLocker/WDAC unless explicitly justified.
Short-term (2 weeks):
- Segment manufacturing environments: enforce IT/OT segmentation with a hardened DMZ; flat networks are why manufacturing dominates leak sites. For organizations with plants in Mexico or Brazil, apply the same segmentation standard as headquarters sites — regional facilities are the common weak link.
- Tiered administration: implement tier-0 isolation for Domain Admins and vCenter admins; no DA logons on workstations or member servers.
- Disable legacy protocols: kill IKEv1 where unused (CVE-2026-50751 attack surface), disable NTLMv1, and restrict WMI/PsExec to admin jump hosts via host firewall rules.
- CI/CD and developer tooling review: patch TeamCity (CVE-2026-63077) and audit developer extensions (CVE-2026-48027); rotate all pipeline secrets if either was ever unpatched and internet-reachable.
- Egress filtering with TLS inspection on server VLANs; alert on first-seen destinations and cloud storage domains.
- Tabletop the leak-site scenario: rehearse the decision tree for a criminal claim naming your organization — legal, comms, regulator notification, and whether/when to confirm — before it happens.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.