Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | chess.com | react. Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a versi | Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping Security Affairs | · Aug 14, 2026 |
| domain | gitlab.adswizz.com | n the same dump, including a self-hosted GitLab instance at gitlab.adswizz.com, pointed to AdsWizz, a SiriusXM subsidiary. Hudson Rock sai | 153GB of stolen credentials surface after LiteLLM supply chain attack Help Net Security | · Aug 13, 2026 |
| domain | subscription-magnetic-recommended-meat.trycloudflare.com | der (MemoryLoader.cs) references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure th | SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access Security Affairs | · Aug 9, 2026 |
| domain | addssopasskey.com | main (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining access, the attackers use automated too | Hackers Impersonate IT Support to Breach Leading Financial Companies Security Affairs | · Aug 7, 2026 |
| domain | createssopasskey.com | lookalike credential-harvesting subdomain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining acces | Hackers Impersonate IT Support to Breach Leading Financial Companies Security Affairs | · Aug 7, 2026 |
| domain | epplink.net | endpoints: Role Endpoint Resolves to Hosting Primary zbtctl.epplink[.]net 47.100.190[.]96 Alibaba Cloud, Shanghai Primary hardcoded | Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access Security Affairs | · Aug 7, 2026 |
| domain | rbdg4nzqadui.wikaba.com | Secondary online-string.com 45.32.81[.]152 Vultr Secondary rbdg4nzqadui[.]wikaba[.]com 43.248.136[.]125 Jiangsu Dongyun Cloud VulnCheck skippe | Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access Security Affairs | · Aug 7, 2026 |
| domain | passkeydeploy.com | organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across all the | Google Links Redact Extortion Group to BlackFile Rebrand Infosecurity Magazine | · Aug 7, 2026 |
| domain | passkeyhelpdesk.com | ins across multiple target organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the | Google Links Redact Extortion Group to BlackFile Rebrand Infosecurity Magazine | · Aug 7, 2026 |
| domain | masscan.cloud | for Years The strongest infrastructure link identified was masscan[.]cloud, which appears across TA-NATALSTATUS activity, ShadowRay | TeamPCP Traced Back to 2020 Cryptojacking Operation Infosecurity Magazine | · Aug 6, 2026 |
| domain | bitsender.top | tive ones. The main domain for Poison Claude, poison-claude.bitsender[.]top, ran behind Cloudflare’s CDN, hiding its originating IP a | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| domain | claudeopus.shop | a phishing warning on the site, but had taken no action on claudeopus[.]shop even though that domain also runs behind Cloudflare. Ecom | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| domain | qq.com | sed by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China,” Okta wrote. Th | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| domain | bkofamerica.com | id not point to Bank of America's legitimate domain, but to bkofamerica[.]com. The link in the message pointed, again, not to Bank of A | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | kleinschnitg.com | the message pointed, again, not to Bank of America, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from whi | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | sectioncompil.com | ica, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from which the malicious zip originated. The researchers | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | ealerts.bkofamerica.com | d account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com , tries to push them to follow the link without thinkin | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | kleinschnitg.com | pages are easily identifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | sectioncompil.com | tifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the legitimate BoA domain. | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | helprans.com | egistrar that accepts cryptocurrency payments. Domain Name: HELPRANS[.]COM Registry Domain ID: 3106477703_DOMAIN_COM-VRSN Registrar | INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero Security Affairs | · Aug 4, 2026 |
| domain | whois.ordertld.com | main ID: 3106477703_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.ordertld.com Registrar URL: http://www.ordertld.com Updated Date: 2026-0 | INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero Security Affairs | · Aug 4, 2026 |
| domain | braintree.net | t Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braint | ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More The Hacker News | · Aug 4, 2026 |
| domain | dweb.link | ention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk assoc | Phishers are hijacking legitimate cloud infrastructure Kaspersky Securelist | · Aug 4, 2026 |
| domain | ipfs.io | nt close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The princi | Phishers are hijacking legitimate cloud infrastructure Kaspersky Securelist | · Aug 4, 2026 |
| domain | tubely.com | igBasket set of "shoppers," a gaming set, and others). The “tubely[.]com” domain is not new, and neither is the behavior. Public f | “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos | · Aug 4, 2026 |
| domain | socket.io | rol server through a public blockchain transaction, opens a Socket.IO remote access channel, and stages a Python credential steal | Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js The Hacker News | · Aug 4, 2026 |
| domain | ip-api.com | a blockchain SmartLoader starts by sending a GET request to ip-api.com to collect the victim’s IP address, country, city, time zon | AI developers targeted via trojanized GitHub repositories Help Net Security | · Aug 4, 2026 |
| domain | content.powerapps.com | and the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That sa | PNLD Confirms Data Breach Affecting UK Police and Justice Staff Security Affairs | · Aug 3, 2026 |
| domain | us.zoom.06webin.us | investor/partnership call." The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for thei | BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery The Hacker News | · Aug 1, 2026 |
| domain | dns.multitoconference.com | hen creates a stream socket using a hard‑coded C2 address ( dns[.]multitoconference[.]com ) and port 443. It gathers the following information fr | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| domain | dns.ssentialserv.xyz | e, the attacker at first checked connectivity to the domain dns[.]ssentialserv[.]xyz as shown below. At the time of our research, the domain | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| domain | hunt.io | , uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started wi | Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App Security Affairs | · Jul 30, 2026 |
| domain | rg-telemetry.sbs | figuration responsible for fetching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was | DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto The Hacker News | · Jul 30, 2026 |
| domain | th-updates.sbs | tching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was created by a throwaway wal | DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto The Hacker News | · Jul 30, 2026 |
| domain | fwgcloud.com | evices. AI DIGITAL HUMANS The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of hum | Read This Before You Buy That TV Streaming Stick Krebs on Security | · Jul 30, 2026 |
| domain | cubepilot.org | nknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercep | ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories The Hacker News | · Jul 30, 2026 |
| domain | jshosting.me | same reverse-tunnelling address 176.65.128[.]26. The domain jshosting[.]me was used to distribute exploit scripts in both sets of at | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| domain | npmjs.store | n XOR cipher keyed to 01042025 . The network indicators are npmjs[.]store and 216[.]74[.]123[.]126 . Amazon's post cites the OSV re | Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet The Hacker News | · Jul 30, 2026 |
| domain | agrocenter-eurohem.ru | t where the scammers had created a fraudulent website ("www.agrocenter-eurohem[.]ru") that was a near-perfect virtual copy of the legitimate | Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments The Hacker News | · Jul 29, 2026 |
| domain | 110gongan.com | une 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal payment | Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates The Hacker News | · Jul 29, 2026 |
| domain | login.trees4sale.net | node reports its status to a heartbeat collection server at login.trees4sale.net:9000, sending a JSON health report with connection count an | Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure Security Affairs | · Jul 28, 2026 |
| domain | aecert.org | folio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | buisness-centeral-transportation.com | hshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarez | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-deegital.azurewebsites.net | lobal-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessdeegital.azurewebsites.net | ness-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-deegital.com | businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessmixture.com | PAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-startup.azurewebsites.net | althcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]net | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessstartup.azurewebsites.net | ]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]net | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | global-reds.com | Ps smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegi | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoom-centeral.azurewebsites.net | thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcare | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoomcenteral.azurewebsites.net | rtation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoomcenteral.org | websites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azure | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | maadinglobal.com | azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.azurewebsites.net | ]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[. | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.com | l[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.eastus.cloudapp.azure.com | net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]c | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | realhealthshop.com | GET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | smartconnect.azurewebsites.net | 14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | thehealth-life.com | ecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-cen | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | tjconsultingservices.com | erfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2. When a valid C2 response is received, t | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | toadreport.azurewebsites.net | centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | hunt.io | l prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructu | ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More The Hacker News | · Jul 28, 2026 |
| domain | 24carnforth2merseyside.sol | ]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample as | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | burrberry.eth | at resolves C2 through the same domain. XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24 | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | m3rnbvs5d.eth | ator falling back to an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2). XLab's Dysphoria timeline | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | purelogicbox.org | d decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the con | Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable The Hacker News | · Jul 27, 2026 |
| domain | corychase.org | d policy, and directed users to a live PHP phishing page on corychase[.]org," the company said . "The landing page was not a Microsof | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | github.io | dev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.github[.]io") and a repository named "Bluedashltd" that contains the | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | support.berrydev.xyz | low." Further analysis of the threat actor infrastructure ("support[.]berrydev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.githu | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | teamvem.com | t published last week. The bogus Teams page in question is "teamvem[.]com." The active download is used to deliver "supportdev.exe, | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | hunt.io | words and interact with specific internal systems. Although Hunt.io found evidence that the attackers had already compromised m | Hackers used autonomous AI agent to spy on Thailand's finance ministry The Record | · Jul 27, 2026 |
| domain | hypersnet.com | lant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise ac | TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments The Hacker News | · Jul 27, 2026 |
| domain | chatgpt.com | of a phishing link that adheres to the following pattern: "chatgpt[.]com/agents/studio/new?template_name=[template name]&initial_a | ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link The Hacker News | · Jul 27, 2026 |
| domain | claude.ai | s). How attackers hosted a fake Claude download page on the claude.ai domain A threat actor abused Anthropic’s Claude Artifacts f | Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached Help Net Security | · Jul 26, 2026 |
| domain | woocommerce-check.com | min credentials and exfiltrate them to an external server ("woocommerce-check[.]com") that masquerades as WooCommerce, an open-source e-comme | ⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and Zero The Hacker News | · Jul 25, 2026 |
| domain | shutterstock.com | resolve real threats faster Image credit: Celia Ong / CKA / Shutterstock.com | ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks Infosecurity Magazine | · Jul 24, 2026 |
| domain | easysend.co | om where the request is sent to a file-sharing service like EasySend[.]co to retrieve a ZIP archive. The ZIP file contains a Visual | Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC The Hacker News | · Jul 24, 2026 |
| domain | hunt.io | different from Operation Roundish , which was disclosed by Hunt.io back in March and uses longstanding infrastructure that CER | Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC The Hacker News | · Jul 24, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | ng API. The binary contains a Cloudflare Workers endpoint (“is-01-ast[.]ols-img-12[.]workers[.]dev”), but rather than making HTTP connections to this do | Chaos ransomware deploys browser-based msaRAT to evade network detection Security Affairs | · Jul 23, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | hes STUN and TURN configuration from a Cloudflare Worker at is-01-ast[.]ols-img-12[.]workers[.]dev , with Origin and Referer headers disguised as traffi | Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Hacker News | · Jul 23, 2026 |
| domain | claude-pro.com | ther campaign impersonated Anthropic's Claude software from claude-pro[.]com, registered on March 28, 2026, serving a malicious MSI in | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | gouvvbo.top | [.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lo | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | license.claude-pro.com | r persistence. The Beagle backdoor it delivered reported to license[.]claude-pro[.]com. Sophos, working from the fake site, its hosting infras | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | sylverixstrategy.com | er's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three sec | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-crowdstrike.com | ity-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.1 | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-sentinelone.com | one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.106.71[.]28 on port 8000. Both | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-trellix.com | .]com, and three security-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. T | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | vertextrust-advisors.com | [.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP, upd | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | rambler.ru | previously observed activity associated with the "ischhfd83@rambler[.]ru" email address, which has been tracked under the moniker | Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers The Hacker News | · Jul 23, 2026 |
| domain | global.turn.twilio.com | cted host in order to traverse NAT, while the TURN server (“global.turn.twilio.com”) acts as a relay point when a direct Peer-to-Peer (P2P) co | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | mation First, a GET request is sent to Cloudflare Workers (“is-01-ast[.]ols-img-12[.]workers[.]dev”) to retrieve the STUN/TURN server configuration requ | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| domain | google.com | the Google Account, go to the Selfie video page (myaccount.google[.]com/video-verification) Turn Improve Google services (optiona | Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts The Hacker News | · Jul 23, 2026 |
| domain | download-app.us | n redirected victims to an external domain, first claude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | it.com | laude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win , from which they downloaded a bundle. It | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | polse.us | ed to ten domains going back to December 2025. One of them, polse[.]us , was seized by Microsoft as part of Operation Endgame af | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | cloudlanecdn.com | il" , // Compromised target Microsoft 365 mailbox "Host" : "cloudlanecdn[.]com" , // DNS bootstrap domain "PublicKey" : "-----BEGIN RSA | New Project CAV3RN .NET Native AOT communication module Kaspersky Securelist | · Jul 22, 2026 |
| domain | index.js | s behavior. The repository contains a JavaScript file named index[.]js . This file is encoded in Base64 with an XOR cipher, whic | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| domain | lumanagi.online | recruiter sent a document via Google Docs purportedly from lumanagi[.]online that contained information about their project, the job v | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| domain | routes.js | onas. This repository contained a similar malicious file to routes[.]js , which was observed in the Indian software development c | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.