{"type":"bundle","id":"bundle--622fdafa-1028-4ff8-9dfe-c5de7010ec70","objects":[{"type":"identity","spec_version":"2.1","id":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","created":"2026-09-16T06:58:46.400Z","modified":"2026-09-16T06:58:46.400Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--27314058-336a-4336-a4f0-57d5c992412b","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 5c92d3b8734b4f498752f735a1ca0987","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]","pattern":"[file:hashes.MD5 = '5c92d3b8734b4f498752f735a1ca0987']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ddd75e5-a826-4f8f-b8ef-53b897c76a65","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--115b6655-3fc6-471a-b781-447ab14b3a42","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c80024e-efd7-4240-af33-c8d04a0a97a2","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 9a47c4d379998ade2f8f99e23a630c06","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '9a47c4d379998ade2f8f99e23a630c06']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9effdef2-c67d-4190-a6e4-d28b9629fc8e","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dea0c6e1-a286-4249-93ac-fb15a5574a0a","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: f3e82419a43220a7a222fc01b7607adc","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: 8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'f3e82419a43220a7a222fc01b7607adc']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1cf4928b-fe96-40ef-a8aa-3ab08b30d861","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 0e39e8d7b641bcda4376ebbfeff7b12e","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: cluded in the malicious ISO File name / MD5 %TEMP%\\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message E","pattern":"[file:hashes.MD5 = '0e39e8d7b641bcda4376ebbfeff7b12e']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ae19430-fd6d-4093-8d73-f46cac60e9ae","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c124f794-05ac-42d1-af22-e465be0907aa","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 1ec9eff863dc4418d1498bc3d904899d","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: haos ransomware File name / MD5 %TEMP%\\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name /","pattern":"[file:hashes.MD5 = '1ec9eff863dc4418d1498bc3d904899d']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--400f99fb-9a5a-4c40-ba24-87716ee9bc62","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: %\\rockstargamescrashfixer.exe , %TEMP%\\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66d5ec86-6cc0-448c-af46-ddccd86252fb","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df67b17f-a7e1-48e0-92fd-ecb27b8a529a","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: TEMP%\\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc3a7880-80a5-46a6-8fc4-72e0554bbba5","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8850de1-a908-4c2d-9a8f-622925b07d74","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: ecutable File name / MD5 %TEMP%\\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File names","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4201df8a-6282-4b9c-aa84-6d022a635d2f","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 8da3fe3664d81226b0fb2a50a0537d4f","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: at , C:\\Users\\Default\\Local Settings\\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0.","pattern":"[file:hashes.MD5 = '8da3fe3664d81226b0fb2a50a0537d4f']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--690f4cd8-7fcb-4859-8730-4e4426cdc691","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP%","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8a1cf601-2a06-490e-a1b2-8610a887fcbb","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: b9648ec8cc806e7661aabcfc91dc836c","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: %TEMP%\\gta6.exe , %USERPROFILE%\\AppData\\Roaming\\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppe","pattern":"[file:hashes.MD5 = 'b9648ec8cc806e7661aabcfc91dc836c']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8e74748-1d58-402a-9972-9591768927de","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: dfdf5e5b78d2ec764c0e5641cf9a0d26","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: -control infrastructure File name / MD5 %TEMP%\\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]","pattern":"[file:hashes.MD5 = 'dfdf5e5b78d2ec764c0e5641cf9a0d26']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--459d2fc6-44b8-4533-90b2-a69413d99bd2","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associate","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7d98a89-5482-4f06-8617-a16b6259a32e","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c6eb05e-1d4a-4915-b095-06347f695833","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: ckstargamescrashfixer.exe %TEMP%\\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86434728-9a88-43d2-840e-1cd41d9a0c0c","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addresses","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12b6f965-a704-4596-a5bf-c8ed10291f17","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f932732b-db3b-4c48-aeeb-9903cedfad13","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b3cb3f2-95d5-41de-b55c-febe7351c824","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: llation executable %TEMP%\\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1db94305-c740-43d6-ad05-6e10dac6e24f","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: -clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\\checkinternetconnect","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b79f8b1-5637-4ede-90b6-04887a591e7b","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4acf2e26-1dfc-4dfe-a2f3-ad87ddd16e75","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 9678f71ea4cccbc3d511dc8d7f24b113","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: 25f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6","pattern":"[file:hashes.MD5 = '9678f71ea4cccbc3d511dc8d7f24b113']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0070848-f654-4196-8300-73a9d0d3aab8","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: de62a2f47d1c7dec2997f931a050a615","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-Agen","pattern":"[file:hashes.MD5 = 'de62a2f47d1c7dec2997f931a050a615']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--797fc8c4-d738-4cdf-86ea-b7b2686518ab","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 9678f71ea4cccbc3d511dc8d7f24b113","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5f","pattern":"[file:hashes.MD5 = '9678f71ea4cccbc3d511dc8d7f24b113']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a529992d-f085-40b9-841f-5d9c0706f980","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 528cd4e69ecfa5191adbcf6ef28667bf","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: Infrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d","pattern":"[file:hashes.MD5 = '528cd4e69ecfa5191adbcf6ef28667bf']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9582b036-d7aa-4313-a143-a3b03b732b1a","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 974decb9ff4c8f9ccb0937c96d513347","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse t","pattern":"[file:hashes.MD5 = '974decb9ff4c8f9ccb0937c96d513347']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b05b8e11-73d4-4539-ab3d-45dcbd63f094","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a6437ac3d6798090a218520985d36a3f","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: 687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hash","pattern":"[file:hashes.MD5 = 'a6437ac3d6798090a218520985d36a3f']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6913617f-db53-4acf-bebc-e041ff85f53e","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ce870a91e8d27e8f663f0687abc60b04","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67","pattern":"[file:hashes.MD5 = 'ce870a91e8d27e8f663f0687abc60b04']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77f66356-65c1-456b-ad2d-94399dedf8c9","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: fc92dfafa7aa741c5f2b9cbcf75d1d19","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File has","pattern":"[file:hashes.MD5 = 'fc92dfafa7aa741c5f2b9cbcf75d1d19']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--026a272a-543e-41d0-a473-7e749890e38d","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 0e39e8d7b641bcda4376ebbfeff7b12e","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 18d1498bc3d904899d Yandex web browser %TEMP%\\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a \"license not found\" message","pattern":"[file:hashes.MD5 = '0e39e8d7b641bcda4376ebbfeff7b12e']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3852115d-6a54-4711-b2f8-e31d92e021b1","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d10937c-d753-4b99-99b7-44c710ee9120","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 1ec9eff863dc4418d1498bc3d904899d","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: ansomware-encrypted files %TEMP%\\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\\find.vbs MD5 : 0e39e8d7b641bcda43","pattern":"[file:hashes.MD5 = '1ec9eff863dc4418d1498bc3d904899d']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--862e1238-1629-4044-8601-9db4071ae9da","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: ckstargamescrashfixer.exe %TEMP%\\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5288b61e-d4e5-4eda-85e7-f913ec57e0c7","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a22e6bf8-048a-4d28-931e-939d8e437759","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b0f2b52-3d27-4682-bd65-133c45a6ec14","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd8076d1-f7d8-4376-8b90-5cd0b5c83b41","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: llation executable %TEMP%\\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9568a29e-b26a-4b1a-87f0-0eb6e403cdca","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 8da3fe3664d81226b0fb2a50a0537d4f","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: :\\Users\\Default\\Local Settings\\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 app","pattern":"[file:hashes.MD5 = '8da3fe3664d81226b0fb2a50a0537d4f']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e440562-1280-47a0-bd19-fac72c191586","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\\checkinternetconnect","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e87f6992-93e5-4aac-a061-b591eeccc71c","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: b9648ec8cc806e7661aabcfc91dc836c","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: MP%\\gta6.exe %USERPROFILE%\\AppData\\Roaming\\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note left","pattern":"[file:hashes.MD5 = 'b9648ec8cc806e7661aabcfc91dc836c']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34471647-023d-4af7-85e9-4e62e65e2a35","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: dfdf5e5b78d2ec764c0e5641cf9a0d26","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: IP address that DCRAT connects to %TEMP%\\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/","pattern":"[file:hashes.MD5 = 'dfdf5e5b78d2ec764c0e5641cf9a0d26']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60a2e247-8155-4130-b04a-5ed2cd3eb9d4","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd990a73-883a-4bad-aa4c-6b2bd6146aaf","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 528cd4e69ecfa5191adbcf6ef28667bf","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: ute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0","pattern":"[file:hashes.MD5 = '528cd4e69ecfa5191adbcf6ef28667bf']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2302129e-5509-42fa-845f-a12c4e6475cc","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 974decb9ff4c8f9ccb0937c96d513347","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary cre","pattern":"[file:hashes.MD5 = '974decb9ff4c8f9ccb0937c96d513347']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42ad1204-311f-4330-9342-9946685650c5","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a6437ac3d6798090a218520985d36a3f","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: 27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c","pattern":"[file:hashes.MD5 = 'a6437ac3d6798090a218520985d36a3f']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c888cf44-9f70-40b3-bf54-c1faf20beb40","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ce870a91e8d27e8f663f0687abc60b04","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185","pattern":"[file:hashes.MD5 = 'ce870a91e8d27e8f663f0687abc60b04']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9609704-2397-40d8-807a-7b658c2d6626","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: fc92dfafa7aa741c5f2b9cbcf75d1d19","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9","pattern":"[file:hashes.MD5 = 'fc92dfafa7aa741c5f2b9cbcf75d1d19']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14581b89-365f-473e-af14-f86b7ebc8a0d","created":"2026-09-07T10:19:45.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 581e2e2265d0c1509b3799c5a9039374","description":"Seen in \"JSCeal Hides Crypto Malware in V8 Bytecode\" (Security Affairs). Context: encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself.","pattern":"[file:hashes.MD5 = '581e2e2265d0c1509b3799c5a9039374']","pattern_type":"stix","valid_from":"2026-09-07T10:19:45.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2657e8e1-0a23-4754-87c3-385e07cef2be","created":"2026-09-06T11:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 5568cd69c754b392121f1dbb8f900fda","description":"Seen in \"Critical N-able N-central Vulnerability and Active Exploitation\" (Huntress). Context: r IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5:","pattern":"[file:hashes.MD5 = '5568cd69c754b392121f1dbb8f900fda']","pattern_type":"stix","valid_from":"2026-09-06T11:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/n-able-vulnerability-exploitation"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7ae8e78-6da8-496d-a519-f7d936937d38","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: fced27f6d57702565353ecc11722533b","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: /cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5.","pattern":"[file:hashes.MD5 = 'fced27f6d57702565353ecc11722533b']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--186295d0-4270-4be1-bbb9-4bdaa9ab6ec6","created":"2026-09-04T14:51:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: c8c68e629bba773a10ac80012d10bf19","description":"Seen in \"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic\" (The Hacker News). Context: tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 -","pattern":"[file:hashes.MD5 = 'c8c68e629bba773a10ac80012d10bf19']","pattern_type":"stix","valid_from":"2026-09-04T14:51:13.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b981678-fe87-41d5-b83e-3ee6e76911a7","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: c8c68e629bba773a10ac80012d10bf19","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd()","pattern":"[file:hashes.MD5 = 'c8c68e629bba773a10ac80012d10bf19']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--595624d2-15c2-4cd5-a363-e438fd63241d","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: ecd427ea8330a4ff73618483e00b9b41","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetch","pattern":"[file:hashes.MD5 = 'ecd427ea8330a4ff73618483e00b9b41']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5a262cf-4c99-4fc3-9f49-b6a8c10da9b6","created":"2026-09-04T10:00:05.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 7916c33688385525078bee504c90f359","description":"Seen in \"Angry Birds: Toy Ghouls’ new toys\" (Kaspersky Securelist). Context: upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\\Software\\synapse\\Config\\S","pattern":"[file:hashes.MD5 = '7916c33688385525078bee504c90f359']","pattern_type":"stix","valid_from":"2026-09-04T10:00:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45849160-3da7-4b83-880c-3e0007b09d9a","created":"2026-09-04T10:00:05.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: bfadbeee63a4f0bf19ec9deb8fa58f58","description":"Seen in \"Angry Birds: Toy Ghouls’ new toys\" (Kaspersky Securelist). Context: t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tom","pattern":"[file:hashes.MD5 = 'bfadbeee63a4f0bf19ec9deb8fa58f58']","pattern_type":"stix","valid_from":"2026-09-04T10:00:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc699eb3-3b19-4d92-8be1-1ae1ac506853","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8bb8ac89-15cc-4fc2-99da-2daa03c8392b","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ccf6a38c-2b7c-45bb-8350-2b0cecdad58e","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 41444d7018601b599beac0c60ed1bf83","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '41444d7018601b599beac0c60ed1bf83']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78a5dda7-de54-4f49-83b9-22e22a845b44","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 61e046145ee5cf45aeb033cd71e8b07c","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '61e046145ee5cf45aeb033cd71e8b07c']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc92bb37-6dc7-4448-9d98-ef7cbdd73914","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 7bdbd180c081fa63ca94f9c22c457376","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '7bdbd180c081fa63ca94f9c22c457376']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dee13c3f-8fd4-48b0-9d29-9531459b84e1","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 9a47c4d379998ade2f8f99e23a630c06","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '9a47c4d379998ade2f8f99e23a630c06']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d99b9f6-73e5-4c2c-bc10-b0cfe294add4","created":"2026-09-03T02:02:56.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 2ec37a7cc8daf20b10e1ad6221061ca5","description":"Seen in \"Honeypot-Omaha and batch.py &#x5b;Guest Diary&#x5d;, (Wed, Sep 2nd)\" (SANS Internet Storm Center). Context: the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a fa","pattern":"[file:hashes.MD5 = '2ec37a7cc8daf20b10e1ad6221061ca5']","pattern_type":"stix","valid_from":"2026-09-03T02:02:56.000Z","labels":["auto-extracted","tooling"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33306"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--38a44d90-25cf-4149-bc63-4f5bbc43d7b2","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 3612f843a42db38f48f59d2a3597e19c","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f843a42db38f48f59d2a3597e19c ” , algorithm =“ MD5 ” , qop =“ auth ” , nc = 00000001 , cn","pattern":"[file:hashes.MD5 = '3612f843a42db38f48f59d2a3597e19c']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fe84f4a-7f38-4f64-9e55-77a3a89fdc68","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 88645cefb1f9ede0e336e3569d75ee30","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: “ dslf - config ” , realm =“ HuaweiHomeGateway ” , nonce =“ 88645cefb1f9ede0e336e3569d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f84","pattern":"[file:hashes.MD5 = '88645cefb1f9ede0e336e3569d75ee30']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--310c3335-e53a-495d-9f92-75a7accfffd4","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: f1c099d65bf94e009f5e65238caac468","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: 18b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de1076","pattern":"[file:hashes.MD5 = 'f1c099d65bf94e009f5e65238caac468']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40b369dc-a33d-4501-9bb5-90e104bb2fd1","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: fb93601f8d4e0228276edff1c6fe635d","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: tinuity. Indicators of Compromise Original JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07","pattern":"[file:hashes.MD5 = 'fb93601f8d4e0228276edff1c6fe635d']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4bac67a1-dea3-4bcb-b2b5-1de74bbdce1f","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 79ad2084b057847ce2ec2e48fda64073","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-22 11:54:03 UTC One of the first modif","pattern":"[file:hashes.MD5 = '79ad2084b057847ce2ec2e48fda64073']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--564901fd-3d9a-4a7a-adb1-91180a94c307","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: dd1876848203d9e10abceec07282ff37","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: d using AES-128 and the following static key (hex-encoded): DD1876848203D9E10ABCEEC07282FF37 Conclusion The Patchwork group continues to plague victims","pattern":"[file:hashes.MD5 = 'dd1876848203d9e10abceec07282ff37']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23bceccc-38af-46c8-a4a3-03adb783565f","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: e3e7e71a0b28b5e96cc492e636722f73","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: cation with the C2 (note the additional forward slashes): //e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php In the event data is uploaded","pattern":"[file:hashes.MD5 = 'e3e7e71a0b28b5e96cc492e636722f73']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--301736ba-056f-4156-a191-e76764af900a","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 6fa5bcedaf124cdaccfa5548eed7f4b0","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 4d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = '6fa5bcedaf124cdaccfa5548eed7f4b0']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14590510-db24-4814-8abc-ba1df3641091","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 7c65565dcf5b40bd8358472d032bc8fb","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = '7c65565dcf5b40bd8358472d032bc8fb']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--074adf38-e759-4281-920f-cffef13352d0","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a5164c686c405734b7362bc6b02488cb","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: f9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = 'a5164c686c405734b7362bc6b02488cb']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7cc69cd-98eb-4135-aece-73c4ae376463","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: d5679158937ce288837efe62bc1d9693","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = 'd5679158937ce288837efe62bc1d9693']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e7e2c8c-63a0-4975-b7ea-0896336dc2cc","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 7cc0b212d1b8ceb808c250495d83bae4","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0","pattern":"[file:hashes.MD5 = '7cc0b212d1b8ceb808c250495d83bae4']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--265da660-21d4-485f-a90e-ae8d64240c75","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 8d42c01180be7588a2a68ad96dd0cf85","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79","pattern":"[file:hashes.MD5 = '8d42c01180be7588a2a68ad96dd0cf85']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fdeaf542-40d1-4a15-a91d-1827b19598f1","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a1bdb1889d960e424920e57366662a59","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42","pattern":"[file:hashes.MD5 = 'a1bdb1889d960e424920e57366662a59']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0d59b67-63c0-45a6-a7c1-96e8af441a35","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 76429f8515768f9f5def697e71071f51","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: l 80386, for MS Windows Architecture : 32 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 775","pattern":"[file:hashes.MD5 = '76429f8515768f9f5def697e71071f51']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e685da59-7940-401f-bf49-8d4d9e86296b","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: b5aa366f452feb9f4dff3c72157ca1f9","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: LuO7bIWjRO5gjPNq:JarSKu6yzoF8rpAqXYv3XOgQLfnpLuOu imphash : b5aa366f452feb9f4dff3c72157ca1f9 Date : 0x5637227B [Mon Nov 2 08:44:43 2015 UTC] Language :","pattern":"[file:hashes.MD5 = 'b5aa366f452feb9f4dff3c72157ca1f9']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25b8bcb6-995a-4608-91f0-f1f1e46d752f","created":"2026-08-17T12:54:22.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 41ee612602833345fc5bd2b98103811c","description":"Seen in \"Analysis of Smoke Loader in New Tsunami Campaign\" (Palo Alto Unit 42). Context: hash value of the string, MD5(\"Test_PC0B0D040612345678\") = 41EE612602833345FC5BD2B98103811C It then appends the volume serial to the hash value and get","pattern":"[file:hashes.MD5 = '41ee612602833345fc5bd2b98103811c']","pattern_type":"stix","valid_from":"2026-08-17T12:54:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/analysis-of-smoke-loader-in-new-tsunami-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d814ded7-eadc-46e9-8a5a-c80bd0e8acb1","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 05d43d417a8f50e7b23246643fc7e03d","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: After decryption, the following payload was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee06","pattern":"[file:hashes.MD5 = '05d43d417a8f50e7b23246643fc7e03d']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--17f89e74-402d-4fa8-87ba-1c21b5cb7d93","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 0f1d3ed85fee2acc23a8a26e0dc12e0f","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: tion is provided after it is decrypted by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5","pattern":"[file:hashes.MD5 = '0f1d3ed85fee2acc23a8a26e0dc12e0f']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--accc47de-2ddb-4dc2-a944-110161d8475a","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a2fe5dcb08ae8b72e8bc98ddc0b918e7","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: oject(20180108)\\Final1stspy\\LoadDll\\Release\\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c7","pattern":"[file:hashes.MD5 = 'a2fe5dcb08ae8b72e8bc98ddc0b918e7']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6c275d42-44eb-4b3e-871c-69a10e323b02","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: e02024f38dfb6290ce0d693539a285a9","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: was identified. This file had the following properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c2","pattern":"[file:hashes.MD5 = 'e02024f38dfb6290ce0d693539a285a9']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6c67aff-1d31-4c84-af98-0a848b21438b","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 3e4015366126dcdbdcc8b5c508a6d25c","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: s For the analysis below, the following sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92b","pattern":"[file:hashes.MD5 = '3e4015366126dcdbdcc8b5c508a6d25c']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7b673a1-dcb2-4b3c-9244-f83c1f7d5008","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: a943e196b83c4acd9c5ce13e4c43b4f4","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: l The downloaded CAB file has the following properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436","pattern":"[file:hashes.MD5 = 'a943e196b83c4acd9c5ce13e4c43b4f4']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e199f2e-8835-434d-b9ed-c3b9c8d6268a","created":"2026-08-17T12:21:44.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 0304674e9876530dfbea5a9b4fec7b98","description":"Seen in \"Cardinal RAT Sins Again, Targets Israeli Fin\" (Palo Alto Unit 42). Context: Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 Additional C2 Servers: 0 GUID: '\\xd6\\x04hr\\x9a\\xedLN\\xae\\xe","pattern":"[file:hashes.MD5 = '0304674e9876530dfbea5a9b4fec7b98']","pattern_type":"stix","valid_from":"2026-08-17T12:21:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cardinal-rat-sins-again-targets-israeli-fin-tech-firms/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d18a337-1140-487e-8a34-ee3e7a349963","created":"2026-08-17T11:46:22.000Z","modified":"2026-09-16T06:58:46.400Z","created_by_ref":"identity--50b3b257-c861-45a6-a50f-10ed784138ab","name":"md5: 723df0296951abd2aeed01361cec6b0d","description":"Seen in \"Exploring the Latest Mispadu Stealer Variant\" (Palo Alto Unit 42). Context: 5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6","pattern":"[file:hashes.MD5 = '723df0296951abd2aeed01361cec6b0d']","pattern_type":"stix","valid_from":"2026-08-17T11:46:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mispadu-infostealer-variant/"}]}]}