Indicators of compromise
4,104 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e | de Python component of the Insomnia RAT dual payload SHA256 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aa.js , Node.js component of the Insomnia RAT dual payload | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c | rs of Compromise (IoCs):- Type Indicator Description SHA256 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c Trojanized windirstat.exe OfferLoader installer delivered t | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 | 9d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 a.dll , PowerShell downloader for Insomnia RAT stages SHA25 | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 | , Node.js component of the Insomnia RAT dual payload SHA256 aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22af | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c | Trex.zip , archive extracted from the bitmap payload SHA256 b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e | .dll , PowerShell downloader for Insomnia RAT stages SHA256 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31f | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de | 0b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de Python component of the Insomnia RAT dual payload SHA256 62 | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf | c87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0af | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d | 90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d procorTrex.zip , archive extracted from the bitmap payload | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 | fferLoader installer delivered through SEO poisoning SHA256 fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| sha256 | fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 | c15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 Adblock.dll , Chrome Secure Preferences bypass DLL File nam | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| url | http://aa.amazingshield[ | per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| url | https://drelto[ | yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| url | https://stryper[ | sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 3d ago |
| domain | ttvnw.net | es so by routing Twitch's video-playlist requests to "usher.ttvnw[.]net" through operator-controlled proxy servers along with the | Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users The Hacker News | · 3d ago |
| domain | 128.200.178.68.host.secureserver.net | 94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserve | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| domain | 13.189.202.64.host.secureserver.net | ain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.] | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| sha256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd | 76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2ea | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| sha256 | 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 | o financial websites. IOCs Indicator type Value PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355 | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| sha256 | debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 | c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc6 | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| sha256 | eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 | 0b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Dom | Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users GBHackers | · 3d ago |
| sha256 | 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda | 122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda Note: IP addresses and domains are intentionally defanged ( | AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process GBHackers | · 3d ago |
| sha256 | 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a | d5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f | AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process GBHackers | · 3d ago |
| sha256 | 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c | 1fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b | AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process GBHackers | · 3d ago |
| sha256 | ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 | Cs Filename SHA-256 Right-click to open Invoice Details.bat ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c74 | AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process GBHackers | · 3d ago |
| domain | archive.org | 35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanne | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | connection.upgradeonline.site | passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and th | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | granderevolucao.store | licious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Inj | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | ia601808.us.archive.org | legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After the | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | volmira.site | abA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | www.creamp1eonlyfans.net | ting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, a | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | zaviro.online | xtension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated on | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| md5 | 5c92d3b8734b4f498752f735a1ca0987 | n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.] | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| sha256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 | tection For this analysis, we examine the following script: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 . The obfuscation is fairly basic: function names are repla | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| sha256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 | ful pivot for finding additional first-stage samples (e.g., 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 ). The sandbox-detection heuristic consists of two checks. | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| sha256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 | ugging. For this analysis, we examine the following binary: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 . KREMLIN string decryption algorithm As noted at the begin | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://archive[ | 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://connection[ | dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://granderevolucao[ | r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://ia601808[ | er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://volmira[ | intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | https://zaviro[ | two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| url | http://www[ | attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 3d ago |
| domain | add-passkey.com | keyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com por | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | domainlify.net | of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromi | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | integratedsso.com | secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | oktasession.com | setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting th | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | passkeyhelpdesk.com | in the pattern: "<company name>.<malicious domain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]c | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | portalsetuphub.com | .]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | secure-passkey.com | any name>.<malicious domain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]co | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | service-nowinc.com | and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | setupmypasskey.com | domain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com s | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| domain | syncmykey.com | com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus op | Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data The Hacker News | · 4d ago |
| sha1 | 072558bc1a539e9936584647df51fb1797c982b0 | mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I' | Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations oss-security | · 4d ago |
| [email protected] | You can contact or verify outreach from Jagmeet by emailing [email protected] . View Bio | Revolut confirms customer data breach through fake government requests TechCrunch · Security | · 5d ago | |
| domain | gemini-advertisers.com | iated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to dri | When the Whole Company Adopts AI: What It Does to Your SOC The Hacker News | · 5d ago |
| domain | rubydoc.info | The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from | OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers The Hacker News | · 5d ago |
| domain | gitprogram.com | address UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 in | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| domain | ocr.opusaccel.top | 0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2 | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| domain | shinewrist.net | Compromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control in | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| sha256 | 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 | 256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensi | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| sha256 | 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc | mber 2 phishing URL serving the shared Chrome exploit chain 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc SHA-256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 execut | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| url | https://proof.gitprogram[ | gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 5d ago |
| domain | abre.ai | shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspicious traffic involv | New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets GBHackers | · 5d ago |
| domain | abrir.link | to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspiciou | New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets GBHackers | · 5d ago |
| domain | archivogratuito.online | g the victim environment. Mitigation Defenders should block archivogratuito[.]online and monitor or restrict traffic to associated URL-shorten | New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets GBHackers | · 5d ago |
| domain | goo.su | ict traffic to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also invest | New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets GBHackers | · 5d ago |
| domain | policenationale.cc | . Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stol | Hackers abused Claude to extract secrets from 1.8M Android apps BleepingComputer | · 5d ago |
| domain | add-passkey.com | pdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]c | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | integratedsso.com | -passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]c | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | keysyncos.com | d-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | oktasession.com | mypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers c | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | oskeysync.com | gratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's name | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | passkeyhelpdesk.com | tity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passk | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | secure-passkey.com | examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedss | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | setupmypasskey.com | oft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[. | Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer | · 6d ago |
| domain | cdn.quickdelivr.com | n of the site’s source shows an external script loaded from cdn[.]quickdelivr[.]com, a domain less than a week old and vaguely resembling t | India’s STPI serves TerminalFix-style attack via fake Cloudflare check CSO Online | · 6d ago |
| domain | domaintools.com | address located in Hong Kong, according to data provided by domaintools.com. Dubey attributed both the fake overlay and clipboard manip | India’s STPI serves TerminalFix-style attack via fake Cloudflare check CSO Online | · 6d ago |
| domain | stpi.in | ector stakeholders. The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer Vibh | India’s STPI serves TerminalFix-style attack via fake Cloudflare check CSO Online | · 6d ago |
| sha256 | 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4 | 056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d54 | New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks Cyber Security News | · 6d ago |
| sha256 | 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f | ec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b3 | New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks Cyber Security News | · 6d ago |
| sha256 | 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 | 99c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 KATARU AMD64 sample IP address 160[.]191.242.92 Observed Te | New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks Cyber Security News | · 6d ago |
| sha256 | 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc | 92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a9 | New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks Cyber Security News | · 6d ago |
| sha256 | cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 | and executed after Telnet credential brute forcing SHA-256 cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2 | New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks Cyber Security News | · 6d ago |
| domain | chatgpt.com | ok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Ea | How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface BleepingComputer | · 6d ago |
| domain | claude.ai | started with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight de | How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface BleepingComputer | · 6d ago |
| domain | grok.com | : shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s | How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface BleepingComputer | · 6d ago |
| domain | domainlify.net | om Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address Note | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | eemusicclass.co.uk | address used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lifeones.com | ail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails Domain | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lumalisboa.com | address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | mctci.com | address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | nuf.co.jp | ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | service-nowinc.com | rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tivityhealth.com | ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tovimbatista.pt | ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | uinsure.co.uk | associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| sha256 | 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c | look ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installer | Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign GBHackers | · 6d ago |
| sha256 | fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 | at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage U | Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign GBHackers | · 6d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.