{"type":"bundle","id":"bundle--0ebc99ec-1f56-46ce-97dc-446a6d6ad9f6","objects":[{"type":"identity","spec_version":"2.1","id":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","created":"2026-09-15T22:16:05.625Z","modified":"2026-09-15T22:16:05.625Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--10c83aac-329c-4abd-b5e0-77964039ad2e","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a667937b-185b-4b61-8c6c-6247490a9a17","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3b9be57-0e36-4715-9af5-a0185a269f63","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://aa.amazingshield[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent","pattern":"[url:value = 'http://aa.amazingshield[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--686abcc2-beb5-44b0-b402-22b3c292c7fb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://drelto[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s","pattern":"[url:value = 'https://drelto[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f669e48-588c-4774-b2ff-3f7479403b1f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://stryper[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sHelper\\docro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R","pattern":"[url:value = 'https://stryper[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee36d460-8db8-4703-8d61-37c171548609","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://archive[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca","pattern":"[url:value = 'https://archive[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--beebe037-7b83-4e21-b413-b8ef0d075228","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://connection[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:","pattern":"[url:value = 'https://connection[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31e777e3-0bf5-496d-9f12-1ac15929ac0b","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://granderevolucao[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P","pattern":"[url:value = 'https://granderevolucao[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ec62dd6-b65b-40e2-bd6b-42e0adcb9894","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://ia601808[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel","pattern":"[url:value = 'https://ia601808[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c4190a5-40b6-487c-9785-773fc0666d24","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://volmira[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The","pattern":"[url:value = 'https://volmira[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc22aae6-019e-48fb-8cc3-b02b4852ebcb","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://zaviro[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa","pattern":"[url:value = 'https://zaviro[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81afae26-effc-40ab-8abe-b06a7f331c0e","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://www[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re","pattern":"[url:value = 'http://www[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15088fb2-b5e7-48cd-ac31-c3ff76466a9e","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://proof.gitprogram[","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin","pattern":"[url:value = 'https://proof.gitprogram[']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75f39b7c-55e7-48a0-a2cc-1b99c3e8bd8b","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://apimantax[","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9599ae91-9274-4856-b3cf-5382c26096ad","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://3.88.162[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e4da01b-5301-4ead-b3a9-0004c8c5e52b","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://log.gitclone[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1ce7b1a-d43d-4d9c-9683-1eca6fd55380","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://3.88.162[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ff89328-9437-4bdf-9768-3e72f5de0e57","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://log.gitclone[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40291729-bdc0-4de6-a34c-02cbdecffe9c","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://apimantax[","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2517cd07-c046-4837-89c2-d12e735f43f5","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://3.88.162[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--369783a5-b89e-4452-bf9e-b23d2adb4d0e","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://log.gitclone[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db77cb06-190f-4fd7-8d9a-a0cf16e7335e","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://stro7121.blob.core.windows[","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script","pattern":"[url:value = 'https://stro7121.blob.core.windows[']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--abe07059-b2cd-4e31-931d-c1aeb37b6539","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://167.148.195[","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi","pattern":"[url:value = 'http://167.148.195[']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a6db00b-919d-4e26-9b02-706a30e5e994","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: http://45.142.193[","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey","pattern":"[url:value = 'http://45.142.193[']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--162de5e6-ac04-4c0e-84e2-bd9fcd0480c9","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://api-prod.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid","pattern":"[url:value = 'https://api-prod.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7644ec39-5ff1-4118-8537-97a98b339c16","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://download.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-","pattern":"[url:value = 'https://download.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc63c077-62f1-49f4-ab6c-f85a99790411","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://evidence.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki","pattern":"[url:value = 'https://evidence.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80b09270-6047-4e33-86c1-923bd9c38ac3","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://project.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://project.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d62dde4-ba6b-4b8d-bab8-a7c3871bb777","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://recommendation-letter.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://recommendation-letter.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--526277ea-4d86-4664-9264-0a97dd79e512","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://zki0y83.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage","pattern":"[url:value = 'https://zki0y83.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--daae98c1-ff95-4d90-9c35-1ff0da4ce1c7","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://kr[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f","pattern":"[url:value = 'https://kr[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--065745d7-9eca-472d-9c9d-f07b677bcd8d","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://phys[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by","pattern":"[url:value = 'https://phys[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75ae2f2b-5dab-4efe-98dc-e95c6fb1366e","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://telegra[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch","pattern":"[url:value = 'https://telegra[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75d0f129-fc59-4d7a-bfa1-253092c70057","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-15T22:16:05.625Z","created_by_ref":"identity--bc4c18e8-98da-4eab-80a7-8c30ae0aa631","name":"url: https://146[","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr","pattern":"[url:value = 'https://146[']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]}]}