Classification: TLP:CLEAR | Publication Date: 2026-10-09 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
ECLIPSE Ransomware Gang: 5 New Leak-Site Listings Across Manufacturing, Professional Services & Transportation
Executive Summary
Between 2026-10-05 and 2026-10-08, the ECLIPSE ransomware operation published five new victim listings on its dark web leak site, spanning four countries (India, United States, Brazil, Singapore) and five sectors: Manufacturing, Professional Services, Other, Transportation, and Technology. Only two of the five listings were independently corroborated by a second leak-site crawler; the remaining three appear on a single source. Every listing in this briefing is an unverified accusation by a criminal group — none constitute confirmation that any organization suffered a breach.
For defenders, the actionable signal is not the individual claims but the campaign pattern: ECLIPSE is pacing listings in a short burst across geographically and sector-diverse targets, consistent with an access-driven (rather than industry-driven) operation exploiting internet-facing infrastructure. This briefing provides the group's profile, campaign analysis, and deployable detection engineering content — Sigma, KQL, and PowerShell — mapped to ECLIPSE's known playbook.
Sourcing & Verification
- Corroboration status: 2 of 5 listings (DIPECARR; Global AirFreight International) were independently observed by a second leak-site crawler, confirming the gang published the claim. 3 of 5 listings (simplexengg.in; sanjoseattorneys.com; part02.simplexengg.in) appear on ransomware.live only, with no second-crawler confirmation that the posting even exists.
- What this means: Inclusion on a leak site reflects the threat actor's claim and is not confirmation of a breach. No corroboration tier in this data — including multi-source — verifies that an intrusion occurred. Only the named organization or its regulator can confirm an incident.
- Disputes and denials: A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and not every incident is reportable, so neither silence nor denial settles the question.
- Corrections: Security Arsenal will publish corrections to this briefing and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — ECLIPSE
- Aliases: ECLIPSE operates under a single consistent brand on its leak infrastructure; no widely adopted alias set has been attributed at this time. Analysts should track the group's .onion mirrors and negotiation portals by brand string rather than alias.
- Operating model: Assessed as a Ransomware-as-a-Service (RaaS) operation with a small core team handling leak-site administration and negotiations, and affiliates conducting intrusions. The sector-diverse, opportunistic victimology in this campaign is consistent with affiliate-driven access procurement rather than curated target selection.
- Ransom demands: Typical demands scale to victim revenue, ranging from low six figures USD for mid-market professional services firms to seven figures for manufacturing and logistics organizations with high downtime sensitivity. Negotiation pages commonly include countdown timers and staged data-release threats.
- Initial access methods (historical): Exploitation of internet-facing remote access (VPN concentrators, RDP exposure), phishing with macro-enabled attachments, and purchase of access from initial access brokers (IABs). RDP brute forcing and credential stuffing against edge devices appear repeatedly in ECLIPSE-attributed intrusions.
- Extortion model: Double extortion — exfiltration of sensitive data prior to encryption, with leak-site publication used as leverage against non-payers.
- Dwell time: Estimated 3–14 days from initial access to detonation, with data staging typically beginning 24–72 hours before encryption. The T-minus detection window below is built around this behavior.
Current Campaign Analysis
Listings observed (2026-10-05 to 2026-10-08):
| Organization | Sector | Country | Published | Corroboration |
|---|---|---|---|---|
| simplexengg.in | Manufacturing | IN | 2026-10-08 | Single-source |
| sanjoseattorneys.com | Professional Services | US | 2026-10-08 | Single-source |
| DIPECARR | Other | BR | 2026-10-08 | Multi-source (claim observed by second crawler; breach unconfirmed) |
| Global AirFreight International | Transportation | SG | 2026-10-08 | Multi-source (claim observed by second crawler; breach unconfirmed) |
| part02.simplexengg.in | Technology | IN | 2026-10-05 | Single-source |
Sector targeting: Manufacturing and adjacent industrial services dominate, with professional services, transportation/logistics, and technology rounding out the set. Notably, two listings share the simplexengg.in domain root (one listed under Manufacturing, a "part02" subdomain under Technology), suggesting either staged leak publication against a single claimed victim or affiliate re-listing — a pattern ransomware crews use to increase negotiation pressure.
Geographic concentration: No single-country concentration; the spread across IN, US, BR, and SG is characteristic of opportunistic edge-device exploitation rather than region-specific phishing.
Victim profile: Mid-market organizations — estimated revenue roughly $5M–$250M based on sector norms. Law firms, regional engineering/manufacturing firms, and freight/logistics operators are classic ECLIPSE-tier targets: large enough to pay, often lacking 24x7 SOC coverage.
Posting frequency / escalation: Four listings published on a single day (2026-10-08) following one on 2026-10-05 — a burst pattern that typically indicates either a batch of affiliates detonating in parallel or a negotiation-deadline dump. Watch for a second wave 7–14 days out as negotiations expire.
CVE linkage (hypothesis only): There is no evidence tying any specific CVE to any named listing above. However, ECLIPSE's known initial access tradecraft (edge-device exploitation, VPN/remote access abuse) aligns with several vulnerabilities on CISA's Known Exploited Vulnerabilities catalog with confirmed ransomware use, which defenders in the targeted sectors should treat as priority patch items:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Directly relevant to VPN-edge initial access.
- CVE-2026-20316 — Cisco Secure FMC hard-coded password. Management-plane takeover of firewall infrastructure.
- CVE-2026-59310 — Broadcom VMware vCenter path traversal. Relevant to the virtualization layer ECLIPSE operators target for mass encryption.
- CVE-2026-63077 — JetBrains TeamCity deserialization. Relevant to technology-sector victims and build-pipeline compromise.
- CVE-2026-50751 and CVE-2026-48027 (Nx Console embedded malicious code) round out supply-chain exposure.
Treat these as sector-level exposure hypotheses to drive patching priority — not as attribution of any specific intrusion.
Detection Engineering
The following rules target ECLIPSE's documented playbook: VPN/RDP initial access, macro execution, PsExec/WMI lateral movement, Cobalt Strike-style beaconing, and pre-encryption data staging with shadow copy deletion.
---
title: ECLIPSE Ransomware - RDP Brute Force Followed by Successful Logon
id: 8f3a1c2e-4b7d-4e91-a2c5-7d1f9e3b6a01
status: experimental
description: Detects burst of failed RDP authentications (EventID 4625 logon type 3/10) from a single source followed by a successful logon (4624 type 10), consistent with ECLIPSE RDP brute-force initial access.
author: Security Arsenal Threat Intel
logsource:
product: windows
service: security
detection:
failed:
EventID: 4625
LogonType:
- 3
- 10
successful:
EventID: 4624
LogonType: 10
condition: failed and successful
timeframe: 10m
fields:
- SourceAddress
- TargetUserName
falsepositives:
- Legitimate user password spray from misconfigured clients
level: high
tags:
- attack.initial_access
- attack.t1133
- attack.t1110
date: 2026/10/09
---
title: ECLIPSE Ransomware - PsExec or WMI Remote Service Execution
id: 2b9e4d71-6c3a-4f82-b1d8-5e7a0c9f2d44
status: experimental
description: Detects remote execution via PsExec-style service creation (EventID 7045 with PSEXESVC or random-name service binaries in ADMIN$) or WMI process creation, matching ECLIPSE lateral movement tradecraft.
author: Security Arsenal Threat Intel
logsource:
product: windows
service: system
detection:
selection_event:
EventID: 7045
selection_service:
Service_Name|contains:
- 'PSEXESVC'
- 'RemComSvc'
ImagePath|contains:
- '\ADMIN$\'
- '\IPC$\'
condition: selection_event and 1 of selection_service*
falsepositives:
- Legitimate administrative tooling (SCCM, PDQ) - baseline approved service names
level: critical
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
- attack.t1047
date: 2026/10/09
---
title: ECLIPSE Ransomware - Pre-Encryption Staging and Shadow Copy Deletion
id: 7c1f8a93-2d5b-4e60-9f3a-8b2c6d1e4a77
status: experimental
description: Detects vssadmin/wmic/bcdedit shadow copy deletion combined with mass archive creation (rar/7z to staging directories), the signature pre-detonation behavior of ECLIPSE double-extortion intrusions.
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'recoveryenabled no'
selection_archive:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\7za.exe'
CommandLine|contains:
- ' a '
- ' -p'
condition: 1 of selection_*
falsepositives:
- Backup administrators running VSS maintenance; archive use by build systems - correlate with user and host baseline
level: critical
tags:
- attack.impact
- attack.t1490
- attack.collection
- attack.t1560.001
date: 2026/10/09
The following Sentinel hunt query identifies the pre-detonation sequence: anomalous remote logon, followed by admin-share service execution, followed by archive creation — chained per host within a 72-hour window.
// ECLIPSE pre-ransomware staging chain hunt - 72h window
let lookback = 7d;
let SuspiciousLogons = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4624 and LogonType in (3, 10)
| where IpAddress !startswith "10." and IpAddress !startswith "192.168." or Account has "svc"
| summarize FirstLogon=min(TimeGenerated) by Computer, Account, IpAddress;
let RemoteSvcExec = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 7045
| where ServiceFileName has_any ("ADMIN$", "PSEXESVC", "\\Windows\\TEMP")
| project Computer, ServiceStart=TimeGenerated, ServiceName, ServiceFileName;
let ArchiveStaging = SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4688
| where Process has_any ("rar.exe", "7z.exe", "7za.exe")
| project Computer, ArchiveTime=TimeGenerated, ArchiveCmd=CommandLine, Account4688=Account;
SuspiciousLogons
| join kind=inner RemoteSvcExec on Computer
| where ServiceStart between (FirstLogon .. FirstLogon + 72h)
| join kind=inner ArchiveStaging on Computer
| where ArchiveTime between (ServiceStart .. ServiceStart + 72h)
| project Computer, Account, IpAddress, FirstLogon, ServiceName, ServiceFileName, ArchiveCmd, ArchiveTime
| order by Computer, FirstLogon;
Run the following on any host exhibiting the above chain, or proactively across critical servers, to enumerate the last 7 days of persistence and tampering artifacts associated with ECLIPSE pre-detonation activity.
# ECLIPSE Rapid Triage: persistence + anti-recovery artifacts (last 7 days)
$cutoff = (Get-Date).AddDays(-7)
Write-Host "=== Scheduled tasks created/modified since $cutoff ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
$t = $_
try {
$xml = Export-ScheduledTask -TaskName $t.TaskName -TaskPath $t.TaskPath -ErrorAction Stop
[xml]$x = $xml
$reg = [datetime]$x.Task.RegistrationInfo.Date
if ($reg -gt $cutoff) {
[PSCustomObject]@{ TaskName=$t.TaskName; Path=$t.TaskPath; Registered=$reg;
Action=($x.Task.Actions.Exec.Command -join '; ') }
}
} catch {}
} | Format-List
Write-Host "=== Run-key / service persistence written since $cutoff ===" -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
if (Test-Path $k) {
$item = Get-Item $k
if ($item.LastWriteTime -gt $cutoff) {
Write-Host "MODIFIED: $k (LastWrite: $($item.LastWriteTime))"
Get-ItemProperty $k | Format-List
}
}
}
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'TEMP|AppData|ProgramData' } |
Select-Object Name, State, StartMode, PathName | Format-List
Write-Host "=== Volume Shadow Copy status (ECLIPSE deletes these pre-encryption) ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Host "WARNING: No shadow copies present - investigate possible anti-recovery tampering" -ForegroundColor Red }
else { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table }
vssadmin list shadows 2>&1 | Out-String | Write-Host
Write-Host "=== External-facing RDP exposure check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) { Write-Host "RDP LISTENING on this host - verify it is NOT internet-exposed" -ForegroundColor Yellow }
Incident Response Priorities
T-minus detection checklist (before encryption fires):
- Burst of failed then successful RDP/VPN logons from unusual geographies or ASNs, especially outside business hours.
- New services installed with binaries in
ADMIN$,TEMP, orProgramData(PsExec/RemCom signatures). - Cobalt Strike-style beaconing: periodic outbound HTTPS to low-reputation domains at fixed intervals (30–120s jittered).
- Mass archive creation (
rar/7zwith password flags) targeting file shares, followed by outbound transfer spikes to cloud storage (MEGA, Rclone endpoints, anonymous VPS). vssadmin delete shadows,bcdedit recoveryenabled no, or backup-catalog deletion — ECLIPSE's final pre-detonation step. Alert on this as a page-the-on-call event.- Enumeration bursts:
nltest /dclist,net group "Domain Admins", ADFind/SharpHound output files.
Assets ECLIPSE historically prioritizes for exfiltration:
- File servers holding financial records, contracts, and HR/PII data (leverage for double extortion).
- Email archives of executives and legal counsel (especially relevant given the professional-services targeting in this campaign).
- Backup infrastructure credentials and backup catalogs — both for destruction and to demonstrate data access.
- Domain controllers (for credential theft and mass deployment), and virtualization management planes (vCenter — see CVE-2026-59310 exposure hypothesis) enabling fleet-wide encryption.
Containment actions, ordered by urgency:
- Isolate affected hosts from the network at the switch/EDR level — do not power off (preserve memory for forensics).
- Disable the compromised account(s) and force enterprise-wide credential reset for any account that authenticated to an affected host; prioritize privileged and service accounts.
- Block identified C2 and exfil destinations at egress; throttle or suspend outbound traffic to consumer cloud storage.
- Snapshot and isolate backup infrastructure; verify offline/immutable copies are intact before any recovery decision.
- Preserve evidence: memory captures, Windows event logs, VPN/firewall logs, and EDR telemetry before remediation wipes artifacts.
- Engage legal counsel on disclosure obligations in the relevant jurisdictions (IN/US/BR/SG regimes differ materially); do not communicate with the threat actor without counsel.
Hardening Recommendations
Immediate (24 hours):
- Audit internet-facing RDP and VPN services; disable RDP exposure entirely or gate it behind VPN + MFA. Patch edge devices against CVE-2026-50751 (Check Point IKEv1 improper authentication) and CVE-2026-20316 (Cisco Secure FMC hard-coded password) — both are CISA KEV entries with confirmed ransomware exploitation and map directly to ECLIPSE's access model.
- Enable MFA on all remote access and privileged accounts; lock out legacy authentication.
- Deploy the Sigma rules and KQL query above; specifically page on
vssadmin delete shadowsexecution outside approved backup windows. - Verify backup immutability and test one restore of a critical system today, not during an incident.
- Block outbound traffic to known exfiltration channels (Rclone-default endpoints, MEGA, newly registered VPS ASNs) at the proxy/firewall.
Short-term (2 weeks):
- Patch CVE-2026-59310 (vCenter) and CVE-2026-63077 (TeamCity); segment virtualization management and CI/CD build infrastructure away from general user networks. Review CVE-2026-48027 (Nx Console) exposure in developer environments and pin/purge affected package versions.
- Implement tiered administration: dedicated privileged access workstations, no domain-admin logons to member servers, LAPS on all endpoints.
- Deploy application control (WDAC/AppLocker) blocking
rar.exe/7z.exeexecution by non-approved users on servers, and restrict PsExec-class tooling to an allowlist of admin service accounts. - Establish network micro-segmentation between user VLANs, server segments, and backup infrastructure; deny SMB/RDP lateral movement except from designated jump hosts.
- Stand up dark-web monitoring for your organization's domains and executive names so leak-site listings are detected in hours, not discovered by customers.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.