ZeroHour
Vendor

Infoblox

2 mentions in 7 days · 5 in 30 days · 6 total · first seen · last

Timeline

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.

Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.

Cyber Security News · 14h agoThreat actor 2 sources

China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites

Infoblox found China-aligned actors hiding PeckBirdy malware C2 inside fake Chinese-language casino and adult websites, evading security scans via service workers and WebSockets.

Infoblox reported that China-aligned actors behind the PeckBirdy JScript C2 framework conceal command-and-control inside low-quality Chinese-language casino and adult websites, extending Trend Micro's earlier findings that tied the framework to backdoors including MKDOOR and HOLODONUT. One decoy, vip311[.]cc, embedded JavaScript linked to cache-mcp[.]com and registered a service worker connecting to mcp-source[.]online over WebSocket; at publication mcp-source[.]online had zero VirusTotal detections, showing how the layered design evades conventional scanning. The campaign has been active since at least 2023, and just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with education, IT, banking and government among observed sectors.

GBHackersupdated · 14h agofirst · 17h agoThreat actor in the wild 2 sources

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Infoblox reports Sable Squirrel spent nearly $7 million on expired domains to redirect traffic to illegal sports streaming, gambling, and malware infrastructure.

Infoblox tracked 50,400 dropcatch domains re-registered daily in gTLDs during H1 2026, nearly 20% of all registrations, with .net and .xyz leading. The threat actor Sable Squirrel has acquired more than 10,000 expired domains supporting Asian sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom while promoting betting services like VSBet, ColaScore, and 8xbet. The operation, assessed as Vietnam-based and overlapping the dismantled Xoi Lac TV streaming network, targets users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia via a traffic distribution system, publishes Android apps through suspected compromised Google Play developer accounts, and deployed over 31,000 malware samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and njRAT.

The Hacker News · 8d agoThreat actor in the wild1

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

SOCRadar details AnonyMousKIT, a phishing-as-a-service platform using AI voice agents posing as Apple Support to steal passcodes and 2FA codes.

SOCRadar's Threat Research Unit documented AnonyMousKIT, a credit-metered phishing-as-a-service platform that strips Activation Lock from stolen Apple devices across email, SMS, WhatsApp, recorded calls and AI voice agents. The 'Alice from Apple Support' personas request the device passcode, Apple ID credentials and a live 2FA code, with lures citing the handset's model identifier and live Find My status. Of 200 recovered AI calls made between August 31, 2025 and May 30, 2026, 179 targeted Brazil, and the calls cost $19.24 total via voice platform Vapi. Exposed log paths revealed 30 kit installations on 42 domains and 6,092 send attempts family-wide between March and July 2026.

The Hacker News · 21d agoPhishing & fraud

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A hacker or insider leaked GTA VI gameplay footage before launch, triggering Take-Two DMCA subpoenas against Discord, Google, Microsoft and X.

The persona "CyberLeek" published stolen Grand Theft Auto VI gameplay footage and a manifesto, in what experts call a familiar data extortion playbook with monetization via watermarks, crypto wallets and a memecoin. Take-Two Interactive obtained DMCA subpoenas against Discord, Microsoft and X, and sent copyright notices to Google, treating the case like an insider threat investigation. GTA VI is projected to earn $3.3–5.2 billion in launch-week sales, raising financial and reputational stakes. Related leak websites went offline after the subpoenas.

CyberScoop · 22d agoData breach

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Infoblox finds dropcatch expired domains fuel malware delivery and C2, with actor Sable Squirrel spending ~$7M on 10,000+ domains.

Infoblox Threat Intel reports that in H1 2026 dropcatch (re-registered expired) domains made up nearly 20% of all new registrations, about 65,000 per day, inheriting reputation and traffic that attackers exploit. Threat actor Sable Squirrel spent nearly $7 million on 10,000+ expired domains, running Vietnamese, Korean, Japanese and Australian streaming platforms (Xoilac, Cakhia, 90phut) that double as C2 servers for Quasar RAT, AsyncRAT, DCRat and Remcos RAT. Scavenger actors like Shady Squirrel acquire previously compromised domains and feed inherited traffic to SocGholish and tech support scam networks.

Security Affairs · Aug 16, 2026Threat actor