Threat Analysis: INC Ransomware, AI Malware, and Unpatched Network Hardware Hitting UK SMBs

Threats & Attacks

Threat Analysis: INC Ransomware, AI Malware, and Unpatched Network Hardware Hitting UK SMBs

This is your Daily Threat Analysis for Tuesday, 22nd September 2026.

Three items today. Each one is worth your attention. I will tell you what the reports say, and then I will tell you what they are not saying.


INC Ransomware: The Quiet Breach That Wasn’t

Huntress published a detailed timeline this week of an INC ransomware attack that compromised at least 175 endpoints at a single organisation during August 2026. The headline numbers are bad enough. What is more instructive is the shape of the attack.

The campaign began in early August with scheduled tasks bearing randomised names and lateral movement via RDP using a compromised account. Then it went quiet. For 17 days, nothing visible happened. In late August, a second wave of activity began, deploying the ransomware payload across the estate.

That gap is not nothing. It is a signature. A 17-day lull between initial access and ransomware deployment is consistent with an initial access broker selling the foothold to a separate ransomware affiliate. One group gets in. Another group buys access and handles the encryption. The organisation’s monitoring saw reduced activity and, this is the part that matters, may well have concluded the threat had passed.

What the report does not say directly, but what the TTPs make clear: by the time anyone saw a ransom note, the attackers had been inside long enough to map the estate, identify backup infrastructure, and position for maximum impact. AnyDesk was observed in the tooling, which is consistent with remote access persistence that can survive endpoint reboots and blend into legitimate remote support traffic.

What this means for UK SMBs: If you use RDP, and most SMBs running Windows Server environments do, and you have not restricted it to VPN-only access with MFA, you are running the same exposure profile as the organisation in this report. The initial compromise in cases like this is rarely sophisticated. A compromised credential, an exposed RDP port, an opportunistic scan. The sophistication comes later, when the affiliate arrives with ransomware tooling and the patience to deploy it properly.

The NCSC has guidance on securing remote access. It has had that guidance for years. If your IT provider has not implemented it, ask them why not.


CLOSEDQUORUM: The First Confirmed Autonomous AI C2 Implant

Cisco Talos published today on CLOSEDQUORUM, a malware binary they discovered through their CAIRN research project, a new toolkit they are also releasing today specifically to hunt and classify AI-integrated malware. I want to be precise about what is being claimed here, because precision matters with something this significant.

CLOSEDQUORUM is described as exhibiting fully autonomous command and control. That means the implant can make decisions about what to do next in an attack chain without requiring an operator to issue instructions. Talos characterises this as a shift in effort displacement: the attacker deploys the implant, and the implant handles portions of the attack chain independently.

I will be clear about what I am inferring and what the report states. Talos says this represents a documented first. They are not saying this is being used in widespread campaigns against UK SMBs today. What they are saying, and what the CAIRN project is designed to track, is that this capability now demonstrably exists in malware that has been found in the real world.

The operational implication, if you follow the logic through, is significant. Human-operated ransomware and intrusion campaigns are constrained by time zones, operational security habits, and the bandwidth of the operators running them. An autonomous C2 can, in principle, operate continuously, adapt to defensive responses in real time, and scale across targets without a proportional increase in attacker workload.

We are not at the point where every SMB faces this threat today. We may be closer to that point than the current press coverage suggests. Talos built an entire research programme around tracking this because they expect to see more of it.

What this means for UK SMBs: Your defences need to be capable of detecting behavioural anomalies, not just known signatures. Signature-based detection is already losing ground against human attackers who know how to evade it. Against an autonomous system that can adapt, it loses faster. Endpoint detection tools that use behavioural analysis, and that are actually configured and monitored, are not a luxury tier option. They are the baseline.

Also: if your IT provider tells you that your antivirus handles it, ask them specifically what behavioural monitoring is in place. Then ask when they last reviewed the alerts.


D-Link has disclosed CVE-2026-86296, a maximum-severity vulnerability in DIR-822A dual-band Wi-Fi routers. The vulnerability permits remote code execution. There is no patch. There is a public proof-of-concept exploit.

D-Link’s position is that the DIR-822A is a legacy product that has reached end of life, and they will not be issuing a fix. Their advice is to replace the device.

On this occasion, their advice is correct. There is nothing else to do with a device in this situation. A maximum-severity RCE with a public exploit and no vendor patch is not a risk to be managed, it is a device to be removed from the network.

The question worth asking is how many of these devices are still in service at UK SMBs. D-Link hardware is common at the lower end of the small business market, particularly where procurement decisions were made on price rather than lifecycle planning. A router bought four or five years ago and never revisited is exactly the kind of device that ends up running in a server cupboard until something goes wrong.

Separately, and I will flag this briefly because it also appeared today, a Windows Defender zero-day is circulating that blocks antivirus signature updates. Researcher Abdelhamid Naceri (who has a history of responsibly disclosing Microsoft vulnerabilities) published this over the weekend. Microsoft has not patched it. The attack requires local access to trigger, which limits its impact for most SMBs, but it is relevant context: if an attacker already has a foothold, they can use this to prevent Defender from receiving updated signatures and buy themselves additional time inside your environment. This is the kind of technique that would complement an autonomous implant nicely, which is worth noting given what Talos published today.

What this means for UK SMBs: Audit your network hardware. If you have a D-Link DIR-822A, it needs to come off the network today. If you do not know what hardware is on your network, that is the first problem to solve. A basic network inventory, which devices are connected, what firmware they are running, when vendor support ends, is not an advanced security control. It is table stakes.


The Common Thread

Three stories. Three different attack surfaces. But the same underlying condition.

The INC ransomware campaign relied on a 17-day window of apparent quiet to complete its preparation. The CLOSEDQUORUM implant is designed to operate in the gaps between human attention. The D-Link vulnerability is exploitable on hardware that has likely been forgotten about entirely.

Attackers do not announce themselves. They rely on the assumption, often a well-founded one, that nobody is watching carefully enough to notice them while they work. The organisations that tend to avoid the worst outcomes are not those with the most sophisticated tools. They are those with basic controls consistently applied and someone who actually reviews what those controls are telling them.

If the Threat Analysis briefing is useful to you, follow the show wherever you listen so tomorrow’s brief finds you automatically, and pass this one to someone in your network who needs the heads-up. The person running a small business on a D-Link router they bought in 2021 and haven’t thought about since would be a reasonable place to start.


Sources

SourceTitleURL
HuntressThe Tale of Two INC Ransom Notes: A Ransomware Timelinehttps://www.huntress.com/blog/two-inc-ransom-notes
Cisco TalosThe Closed Quorum: Inside the first reported autonomous AI C2 implanthttps://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
Cisco TalosIntroducing CAIRN: Frontier tracking for AI-integrated malwarehttps://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/
BleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routershttps://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
BleepingComputer / CISA KEVCISA orders feds to patch Zyxel flaw exploited for data thefthttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
BleepingComputerNew Windows Defender zero-day blocks Microsoft antivirus updateshttps://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/

Filed under

  • ransomware-groups
  • smb-security
  • uk-business
  • supply-chain-risk
  • incident-response
  • remote-access
  • business-risk