Classification: TLP:CLEAR | Publication Date: 2026-10-03 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
Executive Summary
Monitoring of the WALLSTREET ransomware group's dark web leak site shows four new listings published between 2026-09-29 and 2026-10-03. WALLSTREET claims to have compromised the following organizations:
- St. Francis Healthcare Systems of Hawaii (Healthcare, US) — listed 2026-10-03
- World Cup 2034 (Other, SA) — listed 2026-10-03
- Tronex A/S (Manufacturing, DK) — listed 2026-10-02
- Gibson Area Hospital & Health Services (Healthcare, US) — listed 2026-09-29
Half of the claimed victims in this batch are healthcare providers, and all four listings appeared within a five-day window, suggesting an active campaign pulse. Enterprise defenders in healthcare, manufacturing, and large-scale event/logistics operations should treat this as a prompt to validate perimeter exposure, review the CVEs WALLSTREET is known to exploit, and deploy the detection content in this briefing.
Every listing above is an unverified accusation by a criminal actor. Inclusion on a leak site is not confirmation of a breach.
Sourcing & Verification
- 3 of 4 listings (St. Francis Healthcare Systems of Hawaii, World Cup 2034, Tronex A/S) were independently observed by a second leak-site crawler, meaning two separate monitoring sources saw WALLSTREET publish the claim.
- 1 of 4 listings (Gibson Area Hospital & Health Services) appears on a single source only — ransomware.live — with no second-crawler confirmation that the posting even exists.
- Multi-source corroboration confirms only that the gang made the claim. It does NOT confirm a breach occurred. No tier in our data confirms a breach — only the named organization or its regulator can do that.
- A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — neither silence nor denial settles the question.
- Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — WALLSTREET
| Attribute | Assessment |
|---|---|
| Aliases | No widely documented aliases; the "WALLSTREET" branding appears consistent across its leak-site presence |
| Operating model | Assessed as a Ransomware-as-a-Service (RaaS) operation with affiliates conducting intrusions and the core team managing the leak site and negotiation infrastructure |
| Ransom demands | Typically scaled to victim revenue; demands in observed campaigns range from low six figures to multi-million USD equivalents in cryptocurrency |
| Initial access methods | Exploitation of internet-facing remote services (VPN concentrators, RDP, firewall management interfaces), spear-phishing with malicious attachments, and purchased access from initial access brokers (IABs) |
| Extortion model | Double extortion — data exfiltration prior to encryption, with leak-site publication used as pressure against non-payers |
| Dwell time | Observed dwell time ranges from days to roughly two weeks between initial access and detonation, with exfiltration typically staged in the final 48–72 hours |
WALLSTREET follows the modern post-2023 ransomware playbook: quiet ingress via edge-device exploitation, credential harvesting, lateral movement via legitimate admin tooling (living-off-the-land), bulk data staging to attacker-controlled cloud storage, then mass encryption during off-hours.
Current Campaign Analysis
Sector Targeting
- Healthcare (2 of 4 listings): St. Francis Healthcare Systems of Hawaii (US) and Gibson Area Hospital & Health Services (US). Healthcare remains a high-pressure extortion target due to patient-safety sensitivity and regulatory exposure. Note that the Gibson Area Hospital listing is single-source only.
- Manufacturing (1 of 4): Tronex A/S (DK). Manufacturing victims typically face operational-technology downtime pressure.
- Other (1 of 4): World Cup 2034 (SA) — a high-profile, deadline-driven target where reputational and schedule pressure may be the extortion lever.
Geographic Concentration
The US accounts for 2 of 4 listings, with single listings in Saudi Arabia and Denmark. This is consistent with a gang that pursues opportunity over geography, but the US healthcare weighting is notable.
Victim Profile
The claimed victims skew toward mid-size regional organizations (community hospital systems, a mid-market manufacturer) alongside one large, internationally visible entity. This mixed profile is typical of affiliate-driven RaaS operations: affiliates hit what their access allows, not a curated target list.
Posting Frequency & Escalation
Four listings in five days (2026-09-29 → 2026-10-03), including two on the same day, indicates a campaign pulse rather than baseline trickle. Watch for a follow-on wave: gangs often batch-publish after a negotiation deadline expires.
CVE Exposure — Hypothesis Only
We have no evidence tying any specific CVE to any specific named listing above. However, WALLSTREET's known tradecraft — edge-device and remote-access exploitation — aligns with several vulnerabilities currently on the CISA Known Exploited Vulnerabilities catalog with confirmed ransomware use. Organizations in the targeted sectors should treat the following as priority patch/verify items:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Directly relevant to VPN-gate initial access.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise enables full network visibility and policy manipulation.
- CVE-2026-59310 — VMware vCenter path traversal. vCenter compromise is a force multiplier for mass encryption of virtualized estates.
- CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style payload delivery and credential theft.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation ingress via compromised tooling.
Detection Engineering
The following content targets WALLSTREET's known TTPs: edge/VPN exploitation, phishing-driven execution, lateral movement via PsExec/WMI, and pre-encryption data staging.
---
title: WALLSTREET Ransomware - PsExec Service Creation for Lateral Movement
id: 9f3a1c2e-7b4d-4e1a-a5f6-2c8d9e0b1a34
status: experimental
description: Detects PsExec-style remote service creation consistent with WALLSTREET affiliate lateral movement tradecraft
author: Security Arsenal Threat Intel
logsource:
category: service_creation
product: windows
detection:
selection_psexec:
ServiceName:
- 'PSEXESVC'
- 'PAExec*'
- 'RemComSvc'
selection_generic_admin:
ImagePath|contains:
- '\\ADMIN$\\'
- '\\IPC$\\'
condition: selection_psexec or selection_generic_admin
falsepositives:
- Legitimate administrative remote management tools
level: high
date: 2026/10/03
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
---
title: WALLSTREET Ransomware - Data Staging via Rclone or Archiving Before Exfiltration
id: 4b7e2d1f-3a9c-4f8b-b2e1-6d5c7a8f9e01
status: experimental
description: Detects use of rclone, 7zip/rar mass archiving, or suspicious cloud sync tools associated with pre-encryption data staging observed in WALLSTREET campaigns
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_rclone:
Image|endswith:
- '\\rclone.exe'
CommandLine|contains:
- 'copy'
- 'sync'
- 'move'
selection_archive:
Image|endswith:
- '\\7z.exe'
- '\\rar.exe'
- '\\winrar.exe'
CommandLine|contains:
- ' a '
- '-p'
selection_renamed:
CommandLine|contains:
- '--config'
- 'mega'
- 'dropbox'
- 'gdrive'
condition: selection_rclone or selection_archive or selection_renamed
falsepositives:
- Legitimate backup or file synchronization operations
level: high
date: 2026/10/03
tags:
- attack.collection
- attack.t1560.001
- attack.exfiltration
- attack.t1567.002
---
title: WALLSTREET Ransomware - VPN Edge Exploitation Followed by Anomalous Authentication
id: 7c1d5e9a-2f4b-4a6c-8d3e-1b9a7c5f3e28
status: experimental
description: Detects successful VPN authentication from unusual geographies or TOR/hosting ASNs shortly after edge-device scanning or exploit attempts - WALLSTREET initial access pattern
author: Security Arsenal Threat Intel
logsource:
category: authentication
product: firewall
detection:
selection_success:
action: 'success'
service:
- 'vpn'
- 'sslvpn'
- 'ikev1'
- 'ikev2'
filter_internal:
src_ip|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection_success and not filter_internal
timeframe: 15m
falsepositives:
- Traveling employees, legitimate remote users on residential ISPs
level: medium
date: 2026/10/03
tags:
- attack.initial_access
- attack.t1133
- attack.t1190
The following KQL query for Microsoft Sentinel hunts pre-ransomware staging behavior: compressed archive creation on servers followed by high-volume outbound transfers within a 6-hour window.
// WALLSTREET pre-encryption staging hunt: mass archiving + outbound exfil within 6h
let Archiving =
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ ("7z.exe", "rar.exe", "winrar.exe", "rclone.exe")
or ProcessCommandLine has_any ("rclone copy", "rclone sync", " a -p", "-mx9")
| summarize ArchiveCommands = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
Commands = make_set(ProcessCommandLine, 10) by DeviceName, AccountName;
let Outbound =
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteIPType == "Public"
| where RemotePort in (443, 22, 21, 990) or RemoteUrl has_any ("mega.nz", "dropbox", "drive.google", "file.io", "transfer.sh")
| summarize Connections = count(), RemoteIPs = make_set(RemoteIP, 20), RemoteURLs = make_set(RemoteUrl, 20)
by DeviceName, bin(TimeGenerated, 1h);
Archiving
| join kind=inner (Outbound) on DeviceName
| where TimeGenerated between (FirstSeen .. datetime_add("hour", 6, FirstSeen))
| project DeviceName, AccountName, FirstSeen, LastSeen, ArchiveCommands, Connections, RemoteIPs, RemoteURLs, Commands
| order by FirstSeen desc;
The following PowerShell script performs rapid-response checks: exposed RDP listeners, scheduled tasks created in the last 7 days, and Volume Shadow Copy tampering — three of the highest-signal pre/post-intrusion artifacts for this playbook.
# Security Arsenal - WALLSTREET Rapid Triage Script (run elevated)
# Checks: RDP exposure, recent scheduled tasks, shadow copy tampering
Write-Host "=== [1] RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) {
Write-Host "WARNING: RDP listening on 3389." -ForegroundColor Red
$rdpEnabled = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server').fDenyTSConnections
$nla = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue).UserAuthentication
Write-Host " fDenyTSConnections=$rdpEnabled (0=RDP enabled) | NLA=$nla (1=NLA on)"
Get-NetFirewallRule -DisplayGroup "Remote Desktop" -ErrorAction SilentlyContinue |
Where-Object Enabled -eq 'True' | Select-Object DisplayName, Profile | Format-Table
} else { Write-Host "OK: No RDP listener on 3389." -ForegroundColor Green }
Write-Host "=== [2] Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
if ($info -and $info.LastRunTime -gt $cutoff) {
[PSCustomObject]@{ TaskName=$_.TaskName; Path=$_.TaskPath; LastRun=$info.LastRunTime; Author=$_.Author }
}
} | Where-Object { $_.Path -notlike "\Microsoft*" } | Sort-Object LastRun -Descending | Format-Table -AutoSize
Write-Host "=== [3] Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) {
$shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table
} else {
Write-Host "ALERT: No shadow copies present. 'vssadmin delete shadows' is a hallmark pre-encryption action." -ForegroundColor Red
}
Write-Host "=== [4] Recent vssadmin/bcdedit/wbadmin Tampering in Event Log ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=$cutoff} -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match 'vssadmin.*delete|bcdedit.*recoveryenabled|wbadmin.*delete' } |
Select-Object TimeCreated, Message -First 20 | Format-List
Write-Host "Triage complete. Escalate any ALERT/WARNING findings to IR immediately." -ForegroundColor Cyan
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
- New or renamed admin tooling — PsExec, rclone, AnyDesk, ScreenConnect, or ngrok appearing on servers where they were never baselined.
- Mass archiving activity — 7z/rar jobs touching file shares, especially with password flags (
-p). - Shadow copy deletion —
vssadmin delete shadows,bcdeditrecovery-disabled changes,wbadmin delete catalog. - Anomalous VPN/edge authentication — successful logins from unfamiliar ASNs, TOR exits, or geographies inconsistent with the user base, particularly after edge-device patch windows were missed.
- EDR tampering — service stops, uninstall attempts, or exclusion additions on security tooling.
- Off-hours Kerberos/service anomalies — DCSync-style replication requests or golden-ticket indicators.
Assets WALLSTREET Historically Prioritizes for Exfiltration
- HR records, payroll, and PII/PHI databases (maximum regulatory leverage, especially against healthcare targets)
- Financial statements, contracts, and legal correspondence
- Email archives of executive and legal mailboxes
- Backup catalogs and disaster-recovery configurations (to sabotage recovery)
- For manufacturing: engineering drawings and IP repositories
Containment Actions — Ordered by Urgency
- Isolate affected segments immediately — disable switch ports / NAC-quarantine rather than powering off (preserve memory for forensics).
- Disable compromised accounts and force enterprise-wide credential resets, prioritizing domain admins, service accounts, and VPN users.
- Block known exfil destinations at the egress proxy/firewall (consumer cloud storage, file-transfer services not in business use).
- Snapshot and preserve evidence — firewall/VPN logs, EDR telemetry, and memory images before any remediation wipes them.
- Verify backup integrity offline before declaring recovery readiness; assume the attacker enumerated backup infrastructure.
- Engage counsel early on regulatory notification analysis — but remember: a leak-site claim alone is not proof a reportable incident occurred. Verify forensically.
Hardening Recommendations
Immediate (24 Hours)
- Patch or mitigate the KEV edge-device CVEs: CVE-2026-50751 (Check Point IKEv1), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter). If patching isn't possible in 24h, apply vendor workarounds and restrict management interfaces to jump-host-only access.
- Enforce phishing-resistant MFA (FIDO2/passkeys) on all remote access — VPN, RDP gateways, and webmail.
- Disable IKEv1 aggressive mode where legacy Check Point configurations remain.
- Block PsExec/rclone/AnyDesk execution via AppLocker/WDAC where not explicitly approved; alert on any execution.
- Enable tamper protection on EDR and alert on any shadow-copy deletion command.
Short-Term (2 Weeks)
- Segment identity from infrastructure: dedicated Privileged Access Workstations, tiered administration, and no domain-admin logons to general-purpose servers or workstations.
- Egress filtering by default: deny outbound 443 to uncategorized destinations; force all web traffic through authenticated proxy with TLS inspection where legally permissible.
- Immutable/offline backups with at least one copy unreachable from production identity (separate credentials, separate blast radius). Test restoration — not just backup success.
- CI/CD isolation: given exposure like CVE-2026-63077 (TeamCity) and CVE-2026-48027 (Nx Console), segment build infrastructure from production and require signed, verified dependencies.
- Deploy the detection content above into your SIEM and validate with purple-team simulation of the staging-and-encrypt sequence.
This briefing is based on unverified threat-actor claims observed on criminal infrastructure. Security Arsenal does not assert that any named organization has suffered a breach. Named organizations are invited to contact security@securityarsenal.com.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.