ZeroHour

Indicators of compromise

1,181 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha2568c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb58eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8cPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f80a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f stage2.dll VenomRAT .NET DLL Install directory %APPDATA%\MiPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d387e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38 Related sample: Tax_Notice_99674.img Sister lure domain dgdPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e34c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66dociated with the modified v6.0.3 builder SHA-256 thumbprint f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d73PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b{seq}} Unrendered variable in the From display name SHA-256 f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0aPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
sha256fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c14ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
urlhttps://dsfgssd[tpman[.]cn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landinPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 1d ago
domain11168833.comersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding CasinoHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domain11170011.comhe researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated braHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domain1862.ccently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected themHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domain312zym001.ccntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examplesHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domain80074.ccom Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using differentHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domain843470.ccdifferent branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino domHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainam125.ccites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples RedirectinHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainappcasino.onlinesite promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gamblingHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainasg78.commbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciouHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaincache-cdn.orgated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal deteHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaincache-mcp.comm/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pagHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaindollycasino.coming 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdraHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaindragobet.neth complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam RHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaingithubassets.netVirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidentaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainjs.cache-mcp.comng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain cHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainmcp-source.onlinemmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connectiHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainpuqxr.comino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainrealz.comambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoyHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainvip311.ccoperators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainzenplay77-x.spacecasino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – InfobHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domainzzyud.comn hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
ipv4146.103.91.133en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a JaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
ipv4157.185.143.150printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a HoHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 1d ago
domaingithub.coms and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip httNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md51dcafb7f8448683281106b06dd22409aateral movement across the network Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exeNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md51f3034b706c78b35d8e34044e68c693af compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md53ecd1cd627d0340c92901a478a7caad8AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md54aa9fb1bf9223dfcdac920759bc7a3c7d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe https://giNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md5631fb131a56caf4ca0f287ed73e876ab34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1cNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
domainferncore13.comin Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
domaingetmacouscloud.comng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in FigureAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
domaingrove-89.comm the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha2564504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9fection persistent on the infected macOS host SHA-256 hash: 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9 File size: 568,368 bytes File location: /Users/[username]/LAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha256608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 . That Zsh script contains Base64-encoded text for a GZIP-cAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha2566bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620fection persistent on the infected macOS host SHA-256 hash: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 File size: 438,576 bytes File location: /Users/[username]/LAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha25671781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88ca command run from the macOS Terminal window SHA-256 hash: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c File size: 1,991 bytes File type: Zsh script text executablAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha2567ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3acted from the initially downloaded Zsh script SHA-256 hash: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a File size: 1,213 bytes File type: Zsh script text executablAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
sha256a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9y long lines (323) Installer for AMOS stealer SHA-256 hash: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 File size: 330,768 bytes File location: /tmp/helper File tyAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
urlhttps://ferncore13[e command in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
urlhttps://getmacouscloud[with instructions that will infect a vulnerable macOS host: hxxps[:]//getmacouscloud[.]com URL for the initial download decoded from Base64 texAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
urlhttps://grove-89[racted from the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 1d ago
domain17dlz.cn[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addressePAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
domainhsaui.ccpromise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
domainsmtpman.cng MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defangedPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
ipv4154.36.188.201ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + StealPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
ipv4155.94.154.195Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hosPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
domain11170011.comity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into EnglChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domain80074.ccLanguage Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc DecoyChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domainappcasino.onlineScambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domaincache-cdn.orgly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as oChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domaincache-mcp.comembedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected toChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domaindollycasino.coml pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-LanguagChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domaindragobet.nety and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a blChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domaingithubassets.netis not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through cChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domainmcp-source.onlineervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design maChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domainpuqxr.comgal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domainvip311.ccthe threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casinoChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 1d ago
domainapi.telegram.orga space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated wheIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainbackblazeb2.come domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainiproyal.comio Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainlightningproxies.netom Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: IIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainstorjshare.iod object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainvultrobjects.comom Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigationIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 1d ago
domainacrobat-updater.comn[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain lKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaincodecaudiog.siterastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideoKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaincodecvideowin.onlineudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat-KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainconnection.upgradeonline.site51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructureKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaincremeb.comitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructureKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaindonalurdesconfeitos.sitextension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialurKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaingranderevolucao.storeyfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site ExKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domaingraph.checkeligibitily.workers.devnline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainharialurdes.siteialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainlojinhadoluiz.onlinecom Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orangeKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainluizestrelhashapr.onlinegibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain seguraKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainmarialurdes.sitetos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainorange-sun-195a.checkeligibitily.workers.dev.]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QRKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainseguranca.versionnova.site.]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branchKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainvolmira.sitederevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastructKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainwww.creamp1eonlyfans.netader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain granderKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainzaviro.onlinen hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain graKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha25642a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connecKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha2565ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7cKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a426889910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bcKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainapi.telegram.orgorjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainbackblazeb2.comuld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com anHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainiproyal.combackblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.