Back to Intelligence

ECLIPSE Ransomware Gang: 5 New Leak-Site Listings Across Manufacturing, Professional Services & Transportation — Campaign Analysis & Detection Rules

SA
Security Arsenal Team
October 8, 2026
12 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-09 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

ECLIPSE Ransomware Gang: 5 New Leak-Site Listings Across Manufacturing, Professional Services & Transportation

Executive Summary

Between 2026-10-05 and 2026-10-08, the ECLIPSE ransomware operation published five new victim listings on its dark web leak site, spanning four countries (India, United States, Brazil, Singapore) and five sectors: Manufacturing, Professional Services, Other, Transportation, and Technology. Only two of the five listings were independently corroborated by a second leak-site crawler; the remaining three appear on a single source. Every listing in this briefing is an unverified accusation by a criminal group — none constitute confirmation that any organization suffered a breach.

For defenders, the actionable signal is not the individual claims but the campaign pattern: ECLIPSE is pacing listings in a short burst across geographically and sector-diverse targets, consistent with an access-driven (rather than industry-driven) operation exploiting internet-facing infrastructure. This briefing provides the group's profile, campaign analysis, and deployable detection engineering content — Sigma, KQL, and PowerShell — mapped to ECLIPSE's known playbook.

Sourcing & Verification

  • Corroboration status: 2 of 5 listings (DIPECARR; Global AirFreight International) were independently observed by a second leak-site crawler, confirming the gang published the claim. 3 of 5 listings (simplexengg.in; sanjoseattorneys.com; part02.simplexengg.in) appear on ransomware.live only, with no second-crawler confirmation that the posting even exists.
  • What this means: Inclusion on a leak site reflects the threat actor's claim and is not confirmation of a breach. No corroboration tier in this data — including multi-source — verifies that an intrusion occurred. Only the named organization or its regulator can confirm an incident.
  • Disputes and denials: A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and not every incident is reportable, so neither silence nor denial settles the question.
  • Corrections: Security Arsenal will publish corrections to this briefing and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — ECLIPSE

  • Aliases: ECLIPSE operates under a single consistent brand on its leak infrastructure; no widely adopted alias set has been attributed at this time. Analysts should track the group's .onion mirrors and negotiation portals by brand string rather than alias.
  • Operating model: Assessed as a Ransomware-as-a-Service (RaaS) operation with a small core team handling leak-site administration and negotiations, and affiliates conducting intrusions. The sector-diverse, opportunistic victimology in this campaign is consistent with affiliate-driven access procurement rather than curated target selection.
  • Ransom demands: Typical demands scale to victim revenue, ranging from low six figures USD for mid-market professional services firms to seven figures for manufacturing and logistics organizations with high downtime sensitivity. Negotiation pages commonly include countdown timers and staged data-release threats.
  • Initial access methods (historical): Exploitation of internet-facing remote access (VPN concentrators, RDP exposure), phishing with macro-enabled attachments, and purchase of access from initial access brokers (IABs). RDP brute forcing and credential stuffing against edge devices appear repeatedly in ECLIPSE-attributed intrusions.
  • Extortion model: Double extortion — exfiltration of sensitive data prior to encryption, with leak-site publication used as leverage against non-payers.
  • Dwell time: Estimated 3–14 days from initial access to detonation, with data staging typically beginning 24–72 hours before encryption. The T-minus detection window below is built around this behavior.

Current Campaign Analysis

Listings observed (2026-10-05 to 2026-10-08):

OrganizationSectorCountryPublishedCorroboration
simplexengg.inManufacturingIN2026-10-08Single-source
sanjoseattorneys.comProfessional ServicesUS2026-10-08Single-source
DIPECARROtherBR2026-10-08Multi-source (claim observed by second crawler; breach unconfirmed)
Global AirFreight InternationalTransportationSG2026-10-08Multi-source (claim observed by second crawler; breach unconfirmed)
part02.simplexengg.inTechnologyIN2026-10-05Single-source

Sector targeting: Manufacturing and adjacent industrial services dominate, with professional services, transportation/logistics, and technology rounding out the set. Notably, two listings share the simplexengg.in domain root (one listed under Manufacturing, a "part02" subdomain under Technology), suggesting either staged leak publication against a single claimed victim or affiliate re-listing — a pattern ransomware crews use to increase negotiation pressure.

Geographic concentration: No single-country concentration; the spread across IN, US, BR, and SG is characteristic of opportunistic edge-device exploitation rather than region-specific phishing.

Victim profile: Mid-market organizations — estimated revenue roughly $5M–$250M based on sector norms. Law firms, regional engineering/manufacturing firms, and freight/logistics operators are classic ECLIPSE-tier targets: large enough to pay, often lacking 24x7 SOC coverage.

Posting frequency / escalation: Four listings published on a single day (2026-10-08) following one on 2026-10-05 — a burst pattern that typically indicates either a batch of affiliates detonating in parallel or a negotiation-deadline dump. Watch for a second wave 7–14 days out as negotiations expire.

CVE linkage (hypothesis only): There is no evidence tying any specific CVE to any named listing above. However, ECLIPSE's known initial access tradecraft (edge-device exploitation, VPN/remote access abuse) aligns with several vulnerabilities on CISA's Known Exploited Vulnerabilities catalog with confirmed ransomware use, which defenders in the targeted sectors should treat as priority patch items:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Directly relevant to VPN-edge initial access.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password. Management-plane takeover of firewall infrastructure.
  • CVE-2026-59310 — Broadcom VMware vCenter path traversal. Relevant to the virtualization layer ECLIPSE operators target for mass encryption.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. Relevant to technology-sector victims and build-pipeline compromise.
  • CVE-2026-50751 and CVE-2026-48027 (Nx Console embedded malicious code) round out supply-chain exposure.

Treat these as sector-level exposure hypotheses to drive patching priority — not as attribution of any specific intrusion.

Detection Engineering

The following rules target ECLIPSE's documented playbook: VPN/RDP initial access, macro execution, PsExec/WMI lateral movement, Cobalt Strike-style beaconing, and pre-encryption data staging with shadow copy deletion.

YAML
---
title: ECLIPSE Ransomware - RDP Brute Force Followed by Successful Logon
id: 8f3a1c2e-4b7d-4e91-a2c5-7d1f9e3b6a01
status: experimental
description: Detects burst of failed RDP authentications (EventID 4625 logon type 3/10) from a single source followed by a successful logon (4624 type 10), consistent with ECLIPSE RDP brute-force initial access.
author: Security Arsenal Threat Intel
logsource:
  product: windows
  service: security
detection:
  failed:
    EventID: 4625
    LogonType:
      - 3
      - 10
  successful:
    EventID: 4624
    LogonType: 10
  condition: failed and successful
  timeframe: 10m
fields:
  - SourceAddress
  - TargetUserName
falsepositives:
  - Legitimate user password spray from misconfigured clients
level: high
tags:
  - attack.initial_access
  - attack.t1133
  - attack.t1110
date: 2026/10/09
---
title: ECLIPSE Ransomware - PsExec or WMI Remote Service Execution
id: 2b9e4d71-6c3a-4f82-b1d8-5e7a0c9f2d44
status: experimental
description: Detects remote execution via PsExec-style service creation (EventID 7045 with PSEXESVC or random-name service binaries in ADMIN$) or WMI process creation, matching ECLIPSE lateral movement tradecraft.
author: Security Arsenal Threat Intel
logsource:
  product: windows
  service: system
detection:
  selection_event:
    EventID: 7045
  selection_service:
    Service_Name|contains:
      - 'PSEXESVC'
      - 'RemComSvc'
    ImagePath|contains:
      - '\ADMIN$\'
      - '\IPC$\'
  condition: selection_event and 1 of selection_service*
falsepositives:
  - Legitimate administrative tooling (SCCM, PDQ) - baseline approved service names
level: critical
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1569.002
  - attack.t1047
date: 2026/10/09
---
title: ECLIPSE Ransomware - Pre-Encryption Staging and Shadow Copy Deletion
id: 7c1f8a93-2d5b-4e60-9f3a-8b2c6d1e4a77
status: experimental
description: Detects vssadmin/wmic/bcdedit shadow copy deletion combined with mass archive creation (rar/7z to staging directories), the signature pre-detonation behavior of ECLIPSE double-extortion intrusions.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
  selection_archive:
    Image|endswith:
      - '\rar.exe'
      - '\7z.exe'
      - '\7za.exe'
    CommandLine|contains:
      - ' a '
      - ' -p'
  condition: 1 of selection_*
falsepositives:
  - Backup administrators running VSS maintenance; archive use by build systems - correlate with user and host baseline
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.collection
  - attack.t1560.001
date: 2026/10/09

The following Sentinel hunt query identifies the pre-detonation sequence: anomalous remote logon, followed by admin-share service execution, followed by archive creation — chained per host within a 72-hour window.

KQL — Microsoft Sentinel / Defender
// ECLIPSE pre-ransomware staging chain hunt - 72h window
let lookback = 7d;
let SuspiciousLogons = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4624 and LogonType in (3, 10)
| where IpAddress !startswith "10." and IpAddress !startswith "192.168." or Account has "svc"
| summarize FirstLogon=min(TimeGenerated) by Computer, Account, IpAddress;
let RemoteSvcExec = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 7045
| where ServiceFileName has_any ("ADMIN$", "PSEXESVC", "\\Windows\\TEMP")
| project Computer, ServiceStart=TimeGenerated, ServiceName, ServiceFileName;
let ArchiveStaging = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4688
| where Process has_any ("rar.exe", "7z.exe", "7za.exe")
| project Computer, ArchiveTime=TimeGenerated, ArchiveCmd=CommandLine, Account4688=Account;
SuspiciousLogons
| join kind=inner RemoteSvcExec on Computer
| where ServiceStart between (FirstLogon .. FirstLogon + 72h)
| join kind=inner ArchiveStaging on Computer
| where ArchiveTime between (ServiceStart .. ServiceStart + 72h)
| project Computer, Account, IpAddress, FirstLogon, ServiceName, ServiceFileName, ArchiveCmd, ArchiveTime
| order by Computer, FirstLogon;

Run the following on any host exhibiting the above chain, or proactively across critical servers, to enumerate the last 7 days of persistence and tampering artifacts associated with ECLIPSE pre-detonation activity.

PowerShell
# ECLIPSE Rapid Triage: persistence + anti-recovery artifacts (last 7 days)
$cutoff = (Get-Date).AddDays(-7)
Write-Host "=== Scheduled tasks created/modified since $cutoff ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
    $t = $_
    try {
        $xml = Export-ScheduledTask -TaskName $t.TaskName -TaskPath $t.TaskPath -ErrorAction Stop
        [xml]$x = $xml
        $reg = [datetime]$x.Task.RegistrationInfo.Date
        if ($reg -gt $cutoff) {
            [PSCustomObject]@{ TaskName=$t.TaskName; Path=$t.TaskPath; Registered=$reg;
                Action=($x.Task.Actions.Exec.Command -join '; ') }
        }
    } catch {}
} | Format-List

Write-Host "=== Run-key / service persistence written since $cutoff ===" -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
             'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
    if (Test-Path $k) {
        $item = Get-Item $k
        if ($item.LastWriteTime -gt $cutoff) {
            Write-Host "MODIFIED: $k (LastWrite: $($item.LastWriteTime))"
            Get-ItemProperty $k | Format-List
        }
    }
}
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'TEMP|AppData|ProgramData' } |
    Select-Object Name, State, StartMode, PathName | Format-List

Write-Host "=== Volume Shadow Copy status (ECLIPSE deletes these pre-encryption) ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Host "WARNING: No shadow copies present - investigate possible anti-recovery tampering" -ForegroundColor Red }
else { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table }
vssadmin list shadows 2>&1 | Out-String | Write-Host

Write-Host "=== External-facing RDP exposure check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) { Write-Host "RDP LISTENING on this host - verify it is NOT internet-exposed" -ForegroundColor Yellow }

Incident Response Priorities

T-minus detection checklist (before encryption fires):

  1. Burst of failed then successful RDP/VPN logons from unusual geographies or ASNs, especially outside business hours.
  2. New services installed with binaries in ADMIN$, TEMP, or ProgramData (PsExec/RemCom signatures).
  3. Cobalt Strike-style beaconing: periodic outbound HTTPS to low-reputation domains at fixed intervals (30–120s jittered).
  4. Mass archive creation (rar/7z with password flags) targeting file shares, followed by outbound transfer spikes to cloud storage (MEGA, Rclone endpoints, anonymous VPS).
  5. vssadmin delete shadows, bcdedit recoveryenabled no, or backup-catalog deletion — ECLIPSE's final pre-detonation step. Alert on this as a page-the-on-call event.
  6. Enumeration bursts: nltest /dclist, net group "Domain Admins", ADFind/SharpHound output files.

Assets ECLIPSE historically prioritizes for exfiltration:

  • File servers holding financial records, contracts, and HR/PII data (leverage for double extortion).
  • Email archives of executives and legal counsel (especially relevant given the professional-services targeting in this campaign).
  • Backup infrastructure credentials and backup catalogs — both for destruction and to demonstrate data access.
  • Domain controllers (for credential theft and mass deployment), and virtualization management planes (vCenter — see CVE-2026-59310 exposure hypothesis) enabling fleet-wide encryption.

Containment actions, ordered by urgency:

  1. Isolate affected hosts from the network at the switch/EDR level — do not power off (preserve memory for forensics).
  2. Disable the compromised account(s) and force enterprise-wide credential reset for any account that authenticated to an affected host; prioritize privileged and service accounts.
  3. Block identified C2 and exfil destinations at egress; throttle or suspend outbound traffic to consumer cloud storage.
  4. Snapshot and isolate backup infrastructure; verify offline/immutable copies are intact before any recovery decision.
  5. Preserve evidence: memory captures, Windows event logs, VPN/firewall logs, and EDR telemetry before remediation wipes artifacts.
  6. Engage legal counsel on disclosure obligations in the relevant jurisdictions (IN/US/BR/SG regimes differ materially); do not communicate with the threat actor without counsel.

Hardening Recommendations

Immediate (24 hours):

  • Audit internet-facing RDP and VPN services; disable RDP exposure entirely or gate it behind VPN + MFA. Patch edge devices against CVE-2026-50751 (Check Point IKEv1 improper authentication) and CVE-2026-20316 (Cisco Secure FMC hard-coded password) — both are CISA KEV entries with confirmed ransomware exploitation and map directly to ECLIPSE's access model.
  • Enable MFA on all remote access and privileged accounts; lock out legacy authentication.
  • Deploy the Sigma rules and KQL query above; specifically page on vssadmin delete shadows execution outside approved backup windows.
  • Verify backup immutability and test one restore of a critical system today, not during an incident.
  • Block outbound traffic to known exfiltration channels (Rclone-default endpoints, MEGA, newly registered VPS ASNs) at the proxy/firewall.

Short-term (2 weeks):

  • Patch CVE-2026-59310 (vCenter) and CVE-2026-63077 (TeamCity); segment virtualization management and CI/CD build infrastructure away from general user networks. Review CVE-2026-48027 (Nx Console) exposure in developer environments and pin/purge affected package versions.
  • Implement tiered administration: dedicated privileged access workstations, no domain-admin logons to member servers, LAPS on all endpoints.
  • Deploy application control (WDAC/AppLocker) blocking rar.exe/7z.exe execution by non-approved users on servers, and restrict PsExec-class tooling to an allowlist of admin service accounts.
  • Establish network micro-segmentation between user VLANs, server segments, and backup infrastructure; deny SMB/RDP lateral movement except from designated jump hosts.
  • Stand up dark-web monitoring for your organization's domains and executive names so leak-site listings are detected in hours, not discovered by customers.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.