ZeroHour

Indicators of compromise

1,035 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainbroker.hivemq.comgin. The first version uses the public HiveMQ MQTT broker ( broker.hivemq.com ) as its C2 server. The free tier of this broker supports uAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
domainelement.tweir own Element server running on the Matrix protocol, meet.element[.]tw , as the C2 server. On this server, they created a room uAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
domaincrpx0.suthe group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromiThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The Hacker News
· 14d ago
domainwww.mxsetuplogi.comfake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouseThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The Hacker News
· 14d ago
domainacemlnd.comssage body to route through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicksASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainacems10.comaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% of messages matcheASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainactivehosted.come through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks do not point at the brASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainadvancefundingboost.comusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefundiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincatalystboostfunding.comrbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincatalystcapitalharbor.comtcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapitalASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindigitalcapitalboost.comomain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfundingASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindigitalrushcapital.comtcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindirectcapitalboost.comradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalhaASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindirectcapitalpulse.comuardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalruASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainelevatecapitalrush.comcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainemsd4.comending pool , shaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5%ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainfundingexpresscapital.comstboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 (by signature hits) of the 148 finASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardiancapitalway.comourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwavASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardiangrowthfunding.comand the per-domain volume: Sender domain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardianloccapital.cometboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardianlocchoice.comtalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainharboradvancefunding.comcefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainonlinedirectfinance.comtedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfundASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainourbusinessloans.comrdianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfundiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainrocketboostfunding.comrectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapitalASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainthebusinessloanexpress.comgrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainunitedfundingwave.comancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinancASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainyourlocfunding.compitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalwaASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincaixaentradas1inboxshop.siteft Edge and is downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." An analysis of the files associated with the domain hasBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
The Hacker News
· 14d ago
domaininfect.onlinetion for the Infected Marketplace (aka "Banco de Infects," "infect[.]online"), a platform where the threat actor monetizes initial acBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
The Hacker News
· 14d ago
domaindraw.iosers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious iCounterfeit installers turn routine software downloads into enterprise breaches
CSO Online
· 14d ago
domainnodejs.orgy, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a maliciouAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The Hacker News
· 14d ago
domainduckdns.orgLet's Encrypt TLS certificate using the domain m-doxa-apodo.duckdns[.]org and following a unique dynamic DNS naming standard. ShareAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
domainanondns.netnnected back to an attacker-controlled domain ( borertors92.anondns[.]net ). While the attack chain here also involved the ScreenCoRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
domainopik.netl, this IP address was associated with the domain tele-sync.opik[.]net during the month of August. Figure 3: According to VirusTRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
domainapp-microsoft-edge.com.cn.]com." Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawioFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainbaidu-pan.com.cnt websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaincalibre-ebook.com.cnbelow - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaincn-drawio.com.cnge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingehie246.comlure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below - appFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingw-sogou.com.cnan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainiualef.netand 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of thFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainkaspersky-lab.hl.cne-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainmindmoster.com.cnawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainocam-pc.com.cnou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainoijfwe.netomains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of the campaign is, as MFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainpc-razerzone.com.cnrsky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainsejda.hl.cnoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zhFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainsteelseries-cn.com.cnocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn TheFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaintranslate-youdao.hl.cnerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelitFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainzh-diskgenius.com.cnl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimatFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingov.brt it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pagesMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domainhunt.ioreverse-proxy technique on IIS servers in September 2025 . Hunt.io said in July 2025 that it had found more than 630,000 URLsMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domainregistro.brthorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whetherMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domaincdn.nerat.ccle - /usr/local/virtualizor/zzvirtservice Injected string - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-ratBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
domainconnect.ne-rat.xyzg - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat[.]xyz Injected string - jre-runtime.dat Command-and-control (BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
domainadvancedplacyncement.vu.51[.]x) and 104.37.188[.]94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunioInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainamstardmzsmc.vu94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalfInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainarandasoftzfdware.vuinfrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainavisoretentiunionllc.vudplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincapitalflwxinancialpartners.vumzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbceaInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincertififiycationedge.vuavisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainconnectivnqzityltd.vucapitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu excelteInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincrrbcearegroup.vuners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutionInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaindigitaltrafwwrficsystems.vucationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainexceltecbusinessbwpsolutions.vuyltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmiInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaingenamewwgdiamarketing.vutaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobaieflsoftinc.vuxceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltdInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobalmixeucbdmodetechnologyinc.vutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobalprojectspvtltd.vuglobaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufactuInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainidoej.coml panel host found by pivoting from the phishing page title idoej[.]com Domain of the phishing control panel host found via reverInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainjoinbusinessmanagementconsdjeulting.vubalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainkentmanqhfufacturingcompany.vurojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainkleepxrnlinecorporation.vunagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainknsinternacshtional.vuntmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestateInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmonday.comk the true destination by using an open direct parameter on Monday[.]com's tracking service. When clicked the link routes the victInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmonttmmlrustcompany.vu[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmtprormtductions.vution[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainrealestatecotblrp.vuhtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainsiottxgroup.vustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vuInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainsummitcapitaltrapojininggroup.vuprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu PhisInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaintechcompositnkoes.vurp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by thInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaintechromixsolutionlonsinc.vuu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by the threat actors involved in thInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainplayfootball.infod by the second Apache module brought us to a domain called playfootball[.]info that has a phishing page similar to the earlier ones. UnlGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Check Point Research
· 15d ago
domainapp-microsoft-edge.com.cnc-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security softCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainbaidu-pan.com.cns zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn SCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaincalibre-ebook.com.cnpc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonationCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaincc8ttkv35b.comand to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attackCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaincn-drawio.com.cnm Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn PeripCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaincom.cnbapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains imCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaingehie246.comnd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named aCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaingw-sogou.com.cning SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book MiCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainhl.cnl, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unrCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainkaspersky-lab.hl.cnalidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainmindmoster.com.cnibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtoolCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainn7b8t85zsg.comhosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba ClouCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainocam-pc.com.cnan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn DiagrammingCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainoijfwe.netled Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads AlibabCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainpc-razerzone.com.cnlemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the deliveryCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainsejda.hl.cnspersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdaoCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.