ThreatLabz surfaced on our tracker in early July 2026 and has claimed four victims to date, two of them in the past 30 days, with activity concentrated in the US and spread across transportation, energy, and manufacturing targets. The group's tracker entry ties it to the Money Message lineage, described elsewhere as targeting both Windows and Linux environments and running a double-extortion model that pairs encryption with publication of stolen data on a leak blog when ransom demands go unpaid. Its most recent claims, Yourway Transportation on July 25 and Indigo Energy on July 23, suggest a pattern of hitting operationally sensitive US infrastructure and logistics firms in quick succession. No MITRE ATT&CK techniques have been catalogued for this group yet, leaving its actual intrusion and encryption tradecraft undocumented beyond what the group itself claims. At four total victims and a two-week claim cadence, the group's scale remains small but its sector spread indicates opportunistic rather than niche targeting.