Indicators of compromise
1,181 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5 | 8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8c | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f | 80a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f stage2.dll VenomRAT .NET DLL Install directory %APPDATA%\Mi | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38 | 7e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38 Related sample: Tax_Notice_99674.img Sister lure domain dgd | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237 | e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86 | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3 | 4c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014 | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d | ociated with the modified v6.0.3 builder SHA-256 thumbprint f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d73 | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b | {seq}} Unrendered variable in the From display name SHA-256 f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| sha256 | fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c | 14ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09 | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| url | https://dsfgssd[ | tpman[.]cn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landin | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 1d ago |
| domain | 11168833.com | ersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding Casino | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | 11170011.com | he researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated bra | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | 1862.cc | ently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected them | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | 312zym001.cc | ntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | 80074.cc | om Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | 843470.cc | different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino dom | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | am125.cc | ites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirectin | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | appcasino.online | site promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gambling | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | asg78.com | mbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciou | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | cache-cdn.org | ated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal dete | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | cache-mcp.com | m/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pag | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | dollycasino.com | ing 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdra | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | dragobet.net | h complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam R | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | githubassets.net | VirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidenta | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | js.cache-mcp.com | ng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain c | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | mcp-source.online | mmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connecti | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | puqxr.com | ino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80 | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | realz.com | ambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoy | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | vip311.cc | operators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associa | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | zenplay77-x.space | casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infob | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | zzyud.com | n hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with Peck | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| ipv4 | 146.103.91.133 | en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a Ja | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| ipv4 | 157.185.143.150 | printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a Ho | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 1d ago |
| domain | github.com | s and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip htt | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| md5 | 1dcafb7f8448683281106b06dd22409a | ateral movement across the network Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| md5 | 1f3034b706c78b35d8e34044e68c693a | f compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56ca | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| md5 | 3ecd1cd627d0340c92901a478a7caad8 | AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4a | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| md5 | 4aa9fb1bf9223dfcdac920759bc7a3c7 | d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe https://gi | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| md5 | 631fb131a56caf4ca0f287ed73e876ab | 34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c | NightEagle targets Russian companies Kaspersky Securelist | · 1d ago |
| domain | ferncore13.com | in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9 | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| domain | getmacouscloud.com | ng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in Figure | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| domain | grove-89.com | m the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2 | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9 | fection persistent on the infected macOS host SHA-256 hash: 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9 File size: 568,368 bytes File location: /Users/[username]/L | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | 608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 | a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 . That Zsh script contains Base64-encoded text for a GZIP-c | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 | fection persistent on the infected macOS host SHA-256 hash: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 File size: 438,576 bytes File location: /Users/[username]/L | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c | a command run from the macOS Terminal window SHA-256 hash: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c File size: 1,991 bytes File type: Zsh script text executabl | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a | cted from the initially downloaded Zsh script SHA-256 hash: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a File size: 1,213 bytes File type: Zsh script text executabl | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| sha256 | a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 | y long lines (323) Installer for AMOS stealer SHA-256 hash: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 File size: 330,768 bytes File location: /tmp/helper File ty | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| url | https://ferncore13[ | e command in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50 | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| url | https://getmacouscloud[ | with instructions that will infect a vulnerable macOS host: hxxps[:]//getmacouscloud[.]com URL for the initial download decoded from Base64 tex | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| url | https://grove-89[ | racted from the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.] | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 1d ago |
| domain | 17dlz.cn | [.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresse | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| domain | hsaui.cc | promise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17d | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| domain | smtpman.cn | g MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defanged | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| ipv4 | 154.36.188.201 | ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + Steal | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| ipv4 | 155.94.154.195 | Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hos | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| domain | 11170011.com | ity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into Engl | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | 80074.cc | Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc Decoy | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | appcasino.online | Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011 | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | cache-cdn.org | ly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as o | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | cache-mcp.com | embedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected to | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | dollycasino.com | l pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Languag | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | dragobet.net | y and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a bl | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | githubassets.net | is not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through c | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | mcp-source.online | ervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design ma | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | puqxr.com | gal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311 | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | vip311.cc | the threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casino | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 1d ago |
| domain | api.telegram.org | a space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated whe | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | backblazeb2.com | e domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | iproyal.com | io Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | lightningproxies.net | om Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: I | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | storjshare.io | d object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | vultrobjects.com | om Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigation | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 1d ago |
| domain | acrobat-updater.com | n[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | codecaudiog.site | rastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | codecvideowin.online | udiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat- | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | connection.upgradeonline.site | 51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | cremeb.com | itily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | donalurdesconfeitos.site | xtension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | granderevolucao.store | yfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | graph.checkeligibitily.workers.dev | nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[ | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | harialurdes.site | ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | lojinhadoluiz.online | com Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | luizestrelhashapr.online | gibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | marialurdes.site | tos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[. | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | orange-sun-195a.checkeligibitily.workers.dev | .]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | seguranca.versionnova.site | .]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | volmira.site | derevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | www.creamp1eonlyfans.net | ader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | zaviro.online | n hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 | s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8a | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c | 70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca | 81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 | fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connec | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 | aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f | 3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 | 89910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648b | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 | a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | api.telegram.org | orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[. | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | backblazeb2.com | uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | iproyal.com | backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.