{"type":"bundle","id":"bundle--4a9b87da-2165-4be2-9722-4dd418317ed7","objects":[{"type":"identity","spec_version":"2.1","id":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","created":"2026-09-16T10:13:02.968Z","modified":"2026-09-16T10:13:02.968Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--1d02676c-0463-4096-81ad-5a46b1ca741e","created":"2026-09-16T10:00:11.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: github.com","description":"Seen in \"NightEagle targets Russian companies\" (Kaspersky Securelist). Context: s and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip htt","pattern":"[domain-name:value = 'github.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:11.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9747ada9-bf11-4d0c-a530-20bbe40104a9","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: ferncore13.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9","pattern":"[domain-name:value = 'ferncore13.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--262393bf-038a-47ce-ba3c-1311eee55883","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: getmacouscloud.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: ng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in Figure","pattern":"[domain-name:value = 'getmacouscloud.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3acc581-39f4-4e29-8ee7-0ee367e60082","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: grove-89.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: m the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2","pattern":"[domain-name:value = 'grove-89.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1853c457-42b5-439c-bd8f-3f57373bbccc","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: 17dlz.cn","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: [.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresse","pattern":"[domain-name:value = '17dlz.cn']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--69cbbbcc-27f9-42a4-b415-b419fb61ab5f","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: hsaui.cc","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: promise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17d","pattern":"[domain-name:value = 'hsaui.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2c43284-e9a7-4e5e-b687-c90eb794ddee","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: smtpman.cn","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: g MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defanged","pattern":"[domain-name:value = 'smtpman.cn']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--714b389a-069e-449b-ad27-b7b75d433eda","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: 11170011.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into Engl","pattern":"[domain-name:value = '11170011.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--613be1b2-2fed-4b6b-9c27-6c47a93574dc","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: 80074.cc","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc Decoy","pattern":"[domain-name:value = '80074.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a7b39b0-b904-487b-9e50-09d5558731de","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: appcasino.online","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011","pattern":"[domain-name:value = 'appcasino.online']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd30c46e-6260-47d4-858f-57e9d7a8268e","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: cache-cdn.org","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as o","pattern":"[domain-name:value = 'cache-cdn.org']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--556ff51e-94af-41a7-81a9-e9d6f6b3e392","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: cache-mcp.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: embedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected to","pattern":"[domain-name:value = 'cache-mcp.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f466384a-be7e-49c6-99b1-3243b871887c","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: dollycasino.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: l pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Languag","pattern":"[domain-name:value = 'dollycasino.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5286f992-73db-4f28-981a-71ab87096a10","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: dragobet.net","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: y and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a bl","pattern":"[domain-name:value = 'dragobet.net']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--144d28d2-098a-461b-8f4c-5f8393aadfc4","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: githubassets.net","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: is not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through c","pattern":"[domain-name:value = 'githubassets.net']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98ddaef8-818f-44a6-bf8b-469b8d465b6c","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: mcp-source.online","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design ma","pattern":"[domain-name:value = 'mcp-source.online']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e214c477-0778-47dd-a3d6-3713570e737b","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: puqxr.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: gal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311","pattern":"[domain-name:value = 'puqxr.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b3064f4-082b-4f74-8ef3-5c81cae2f47b","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: vip311.cc","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: the threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casino","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9ed1d8d-f094-4351-81f4-5aa26a804be3","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: api.telegram.org","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: a space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated whe","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43d75947-8cda-4d33-8faf-4c23d66b7bc7","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: backblazeb2.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: e domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation Domain","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d439893e-bf11-47e4-b173-2466f7a041c7","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: iproyal.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: io Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation Domain","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4da791d-1142-4b8d-bfc8-72c3f8e7bb8c","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: lightningproxies.net","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: om Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: I","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f772812-5a56-48b3-9966-45ad242642ec","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: storjshare.io","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: d object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation Domain","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--832c63b5-18ec-4dba-85fd-d2f7ad64b546","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: vultrobjects.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: om Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigation","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f2b0b6c-453c-4574-8bbe-8fe176ad120b","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: acrobat-updater.com","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: n[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l","pattern":"[domain-name:value = 'acrobat-updater.com']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f331d29-10be-4794-9323-a9e0f7000287","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: codecaudiog.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: rastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo","pattern":"[domain-name:value = 'codecaudiog.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e18343a9-046d-45cf-884b-0a8d8e1cf652","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: codecvideowin.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: udiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat-","pattern":"[domain-name:value = 'codecvideowin.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3278971f-52a0-43ec-b958-c3fd98cbb88c","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: connection.upgradeonline.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13696e2d-95dd-47e6-8c55-47cd38ba420a","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: cremeb.com","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: itily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure","pattern":"[domain-name:value = 'cremeb.com']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fb7e15c-2e60-4a44-9edf-a306003a4757","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: donalurdesconfeitos.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: xtension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur","pattern":"[domain-name:value = 'donalurdesconfeitos.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc24d592-c251-484e-8b09-55e829d4d52c","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: granderevolucao.store","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: yfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0661d893-3007-454f-a575-fddff8d5f063","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: graph.checkeligibitily.workers.dev","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[","pattern":"[domain-name:value = 'graph.checkeligibitily.workers.dev']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe909b63-1cf8-4037-8bfc-69ab99bd70c2","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: harialurdes.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16","pattern":"[domain-name:value = 'harialurdes.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f294d307-1fa7-47fb-a2d7-261d0a6b0ed1","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: lojinhadoluiz.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: com Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange","pattern":"[domain-name:value = 'lojinhadoluiz.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e151776-3226-4092-a954-d7b35b9e6917","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: gibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a7d0c143-c1c6-43ad-b32b-f0709ff98655","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: marialurdes.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: tos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.","pattern":"[domain-name:value = 'marialurdes.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ad511ed-8fc1-4a53-aa14-c6a16d5f75c2","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: orange-sun-195a.checkeligibitily.workers.dev","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: .]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR","pattern":"[domain-name:value = 'orange-sun-195a.checkeligibitily.workers.dev']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7366f89d-0a12-453e-a3c6-7e0e83883fea","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: seguranca.versionnova.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: .]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch","pattern":"[domain-name:value = 'seguranca.versionnova.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b1e3e1e-bbd3-4269-b115-73a383318a6c","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: derevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8720d652-5066-4502-b8e4-d9bcedf022e9","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: ader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d681c7e-b1a5-4bdc-9e9b-6bd6239bf6b8","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: n hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c3bbe5a-fb21-4ba3-906e-4056dcd518db","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: api.telegram.org","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70bda71b-1773-4759-904e-e36975ebc2fd","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: backblazeb2.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91b47b5e-1dda-4335-a7b1-96fc2cc117b5","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: iproyal.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59310b26-1635-43d0-88ca-2ad00c3b4c41","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: lightningproxies.net","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b027b21a-c094-4baa-9f42-419e44e7283f","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: storjshare.io","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0665f5e2-be5d-48ce-8f47-f23761eaee90","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: vultrobjects.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--618f8ebb-442e-4088-919e-be1c16a61db8","created":"2026-09-16T05:18:06.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: github.com","description":"Seen in \"Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens\" (The Hacker News). Context: ilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-a","pattern":"[domain-name:value = 'github.com']","pattern_type":"stix","valid_from":"2026-09-16T05:18:06.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/active-exploitation-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f96bf754-e182-477c-bf55-d5fb9fbb8efb","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4761df4-99ac-47e7-9cb8-2177f0bea362","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af734580-8325-4671-9222-ced4fb99f4cf","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c9ffab32-d66a-4f51-bdc0-673264fce763","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29ef56ba-2658-4ec9-8865-28663f9cc91e","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5637e98f-4d31-4226-9c20-cc4d1647e22a","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2954a1f-d3b6-47cb-8f63-91131433289e","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--357e4e5e-0874-40ce-a287-6467e19b07c4","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--326cde0e-0294-4b22-b9bc-488814a083e5","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12eaede0-857a-4ed7-979f-69f9d765cc40","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc6c3be5-95fa-486d-ac01-ea5ecf4f9c97","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--743d973a-1695-463b-8b3c-c737362f8523","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--377f8dc5-fad5-4d40-885a-c800a525090c","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81eee9cf-faba-414f-ac88-140cc5538370","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--170cb606-c640-4ad0-9560-e1c83fe455b1","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c87af9c1-ae6c-4492-8131-dc392c1e618a","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--127d12c2-dc37-43b7-be6c-561945633673","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ec013eb-9097-4299-a855-9f685d1eb075","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--961c84b6-2085-4da1-821f-c1fbff9dbdd4","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd23e16b-7c95-466b-ab47-d16f851e2bc0","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1d5bae6-9a20-483c-9282-370168d7198d","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12c074e8-5607-480a-b7b4-ee36c6509621","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ff3d7c2-98dc-4d9d-bbb6-6d341a563953","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f57b4585-0826-48a9-8153-4e4177541018","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba936565-5818-4509-9a92-96c72cda41f3","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f46601f-f3be-4f68-94f2-06b666e30aad","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a539e6f-a9a2-4f20-8d9f-73551622f291","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f648759-a7ca-4fe7-a6c0-b19831d26afa","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53a6fd38-1ab1-4e2d-ab4b-f2bcca91092c","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68ab002c-e71f-45bc-8525-057a1dacbac7","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f13ee9b-4517-49d8-988d-43cf50098453","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90d0375f-29dc-43f6-afce-3aa17c7d9d1c","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61a30dfc-15b9-4aca-aa00-77d4abff4767","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-16T10:13:02.968Z","created_by_ref":"identity--83851ec4-0a9a-484b-8327-939c604b50a3","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]}]}