ZeroHour

Indicators of compromise

4,104 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha25662d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8ede Python component of the Insomnia RAT dual payload SHA256 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aa.js , Node.js component of the Insomnia RAT dual payloadHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha2567f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112crs of Compromise (IoCs):- Type Indicator Description SHA256 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c Trojanized windirstat.exe OfferLoader installer delivered tHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha2569b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da699d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 a.dll , PowerShell downloader for Insomnia RAT stages SHA25Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1, Node.js component of the Insomnia RAT dual payload SHA256 aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989cTrex.zip , archive extracted from the bitmap payload SHA256 b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783fHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e.dll , PowerShell downloader for Insomnia RAT stages SHA256 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de0b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de Python component of the Insomnia RAT dual payload SHA256 62Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdfc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0afHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d procorTrex.zip , archive extracted from the bitmap payloadHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73fferLoader installer delivered through SEO poisoning SHA256 fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320aHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
sha256fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007c15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 Adblock.dll , Chrome Secure Preferences bypass DLL File namHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
urlhttp://aa.amazingshield[per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agentHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
urlhttps://drelto[yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain sHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
urlhttps://stryper[sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 3d ago
domainttvnw.netes so by routing Twitch's video-playlist requests to "usher.ttvnw[.]net" through operator-controlled proxy servers along with theMalicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
The Hacker News
· 3d ago
domain128.200.178.68.host.secureserver.net94ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserveCasbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
domain13.189.202.64.host.secureserver.netain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net IP address 72[.]167[.]48[.]63 IP address 209[.]Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
sha25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eaCasbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
sha2566bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73o financial websites. IOCs Indicator type Value PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
sha256debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc6Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
sha256eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca60572443900b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net DomCasbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
GBHackers
· 3d ago
sha25615700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda Note: IP addresses and domains are intentionally defanged (AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
GBHackers
· 3d ago
sha25622678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7ad5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52fAsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
GBHackers
· 3d ago
sha2564affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c1fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0bAsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
GBHackers
· 3d ago
sha256ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6Cs Filename SHA-256 Right-click to open Invoice Details.bat ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c74AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
GBHackers
· 3d ago
domainarchive.org35a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScanneThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainconnection.upgradeonline.sitepassing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: persistence and thThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domaingranderevolucao.storelicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE InjThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainia601808.us.archive.orglegit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel.jpg After theThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainvolmira.siteabA6740d07b . The extension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainwww.creamp1eonlyfans.netting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not return any content, aThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainzaviro.onlinextension and main-v2 parameters returned volmira[.]site and zaviro[.]online , respectively. Notably, the main-v2 value was updated onThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
md55c92d3b8734b4f498752f735a1ca0987n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
sha256106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42tection For this analysis, we examine the following script: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 . The obfuscation is fairly basic: function names are replaThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
sha2565ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552ful pivot for finding additional first-stage samples (e.g., 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 ). The sandbox-detection heuristic consists of two checks.The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
sha256c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268ugging. For this analysis, we examine the following binary: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 . KREMLIN string decryption algorithm As noted at the beginThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://archive[498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScaThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://connection[dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://granderevolucao[r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://ia601808[er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/SentinelThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://volmira[intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. TheThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttps://zaviro[two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request waThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
urlhttp://www[attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not reThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
domainadd-passkey.comkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com porAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domaindomainlify.netof the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud CompromiAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainintegratedsso.comsecure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com ItAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainoktasession.comsetupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting thAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainpasskeyhelpdesk.comin the pattern: "<company name>.<malicious domain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]cAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainportalsetuphub.com.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps withAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainsecure-passkey.comany name>.<malicious domain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]coAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainservice-nowinc.comand individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering LeadsAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainsetupmypasskey.comdomain>[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com sAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
domainsyncmykey.comcom add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus opAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
The Hacker News
· 4d ago
sha1072558bc1a539e9936584647df51fb1797c982b0mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
oss-security
· 4d ago
email[email protected]You can contact or verify outreach from Jagmeet by emailing [email protected] . View BioRevolut confirms customer data breach through fake government requests
TechCrunch · Security
· 5d ago
domaingemini-advertisers.comiated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to driWhen the Whole Company Adopts AI: What It Does to Your SOC
The Hacker News
· 5d ago
domainrubydoc.infoThe agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data fromOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News
· 5d ago
domaingitprogram.comaddress UTA0560 Host associated with cloud.shinewrist[.]net gitprogram[.]com Domain JungleBamboo Phishing, exploit delivery, and C2 inChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
domainocr.opusaccel.top0560 Exploit-hosting and command-and-control infrastructure ocr[.]opusaccel[.]top Domain UTA0560 GRIMWEDGE JScript backdoor C2 endpoint 2China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
domainshinewrist.netCompromise Indicator Type Actor Description / SHA256 cloud.shinewrist[.]net Domain UTA0560 Exploit-hosting and command-and-control inChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
sha2565eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensiChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
sha25669c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dcmber 2 phishing URL serving the shared Chrome exploit chain 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc SHA-256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
urlhttps://proof.gitprogram[gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servinChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 5d ago
domainabre.aishortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspicious traffic involvNew Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
GBHackers
· 5d ago
domainabrir.linkto associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investigate suspiciouNew Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
GBHackers
· 5d ago
domainarchivogratuito.onlineg the victim environment. Mitigation Defenders should block archivogratuito[.]online and monitor or restrict traffic to associated URL-shortenNew Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
GBHackers
· 5d ago
domaingoo.suict traffic to associated URL-shortening services including goo[.]su , abrir[.]link , and abre[.]ai . Teams should also investNew Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
GBHackers
· 5d ago
domainpolicenationale.cc. Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolHackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer
· 5d ago
domainadd-passkey.compdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]cPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainintegratedsso.com-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]cPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainkeysyncos.comd-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place thePasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainoktasession.commypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers cPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainoskeysync.comgratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's namePasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainpasskeyhelpdesk.comtity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainsecure-passkey.comexamples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedssPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domainsetupmypasskey.comoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.Passkey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer
· 6d ago
domaincdn.quickdelivr.comn of the site’s source shows an external script loaded from cdn[.]quickdelivr[.]com, a domain less than a week old and vaguely resembling tIndia’s STPI serves TerminalFix-style attack via fake Cloudflare check
CSO Online
· 6d ago
domaindomaintools.comaddress located in Hong Kong, according to data provided by domaintools.com. Dubey attributed both the fake overlay and clipboard manipIndia’s STPI serves TerminalFix-style attack via fake Cloudflare check
CSO Online
· 6d ago
domainstpi.inector stakeholders. The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer VibhIndia’s STPI serves TerminalFix-style attack via fake Cloudflare check
CSO Online
· 6d ago
sha25613382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d54New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 6d ago
sha2566fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35fec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b3New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 6d ago
sha2569d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d599c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 KATARU AMD64 sample IP address 160[.]191.242.92 Observed TeNew KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 6d ago
sha2569d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a9New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 6d ago
sha256cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218and executed after Telnet credential brute forcing SHA-256 cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 6d ago
domainchatgpt.comok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. EaHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer
· 6d ago
domainclaude.aistarted with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight deHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer
· 6d ago
domaingrok.com: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these sHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer
· 6d ago
domaindomainlify.netom Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address NoteHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaineemusicclass.co.ukaddress used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlifeones.comail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails DomainHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlumalisboa.comaddress used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainmctci.comaddress used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainnuf.co.jpail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainservice-nowinc.comrs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@serviHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintivityhealth.comail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintovimbatista.ptail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainuinsure.co.ukassociated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
sha2567f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112clook ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installerResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 6d ago
sha256fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage UResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.