ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainchess.comreact. Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a versiChess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping
Security Affairs
· Aug 14, 2026
domaingitlab.adswizz.comn the same dump, including a self-hosted GitLab instance at gitlab.adswizz.com, pointed to AdsWizz, a SiriusXM subsidiary. Hudson Rock sai153GB of stolen credentials surface after LiteLLM supply chain attack
Help Net Security
· Aug 13, 2026
domainsubscription-magnetic-recommended-meat.trycloudflare.comder (MemoryLoader.cs) references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure thSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
Security Affairs
· Aug 9, 2026
domainaddssopasskey.commain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining access, the attackers use automated tooHackers Impersonate IT Support to Breach Leading Financial Companies
Security Affairs
· Aug 7, 2026
domaincreatessopasskey.comlookalike credential-harvesting subdomain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining accesHackers Impersonate IT Support to Breach Leading Financial Companies
Security Affairs
· Aug 7, 2026
domainepplink.netendpoints: Role Endpoint Resolves to Hosting Primary zbtctl.epplink[.]net 47.100.190[.]96 Alibaba Cloud, Shanghai Primary hardcodedResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
Security Affairs
· Aug 7, 2026
domainrbdg4nzqadui.wikaba.comSecondary online-string.com 45.32.81[.]152 Vultr Secondary rbdg4nzqadui[.]wikaba[.]com 43.248.136[.]125 Jiangsu Dongyun Cloud VulnCheck skippeResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
Security Affairs
· Aug 7, 2026
domainpasskeydeploy.comorganizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across all theGoogle Links Redact Extortion Group to BlackFile Rebrand
Infosecurity Magazine
· Aug 7, 2026
domainpasskeyhelpdesk.comins across multiple target organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of theGoogle Links Redact Extortion Group to BlackFile Rebrand
Infosecurity Magazine
· Aug 7, 2026
domainmasscan.cloudfor Years The strongest infrastructure link identified was masscan[.]cloud, which appears across TA-NATALSTATUS activity, ShadowRayTeamPCP Traced Back to 2020 Cryptojacking Operation
Infosecurity Magazine
· Aug 6, 2026
domainbitsender.toptive ones. The main domain for Poison Claude, poison-claude.bitsender[.]top, ran behind Cloudflare’s CDN, hiding its originating IP aDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
domainclaudeopus.shopa phishing warning on the site, but had taken no action on claudeopus[.]shop even though that domain also runs behind Cloudflare. EcomDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
domainqq.comsed by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China,” Okta wrote. ThDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
domainbkofamerica.comid not point to Bank of America's legitimate domain, but to bkofamerica[.]com. The link in the message pointed, again, not to Bank of AFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainkleinschnitg.comthe message pointed, again, not to Bank of America, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from whiFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainsectioncompil.comica, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from which the malicious zip originated. The researchersFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainealerts.bkofamerica.comd account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com , tries to push them to follow the link without thinkinBank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainkleinschnitg.compages are easily identifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like theBank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainsectioncompil.comtifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the legitimate BoA domain.Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainhelprans.comegistrar that accepts cryptocurrency payments. Domain Name: HELPRANS[.]COM Registry Domain ID: 3106477703_DOMAIN_COM-VRSN RegistrarINC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero
Security Affairs
· Aug 4, 2026
domainwhois.ordertld.commain ID: 3106477703_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.ordertld.com Registrar URL: http://www.ordertld.com Updated Date: 2026-0INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero
Security Affairs
· Aug 4, 2026
domainbraintree.nett Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braint⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
The Hacker News
· Aug 4, 2026
domaindweb.linkention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk assocPhishers are hijacking legitimate cloud infrastructure
Kaspersky Securelist
· Aug 4, 2026
domainipfs.iont close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The princiPhishers are hijacking legitimate cloud infrastructure
Kaspersky Securelist
· Aug 4, 2026
domaintubely.comigBasket set of "shoppers," a gaming set, and others). The “tubely[.]com” domain is not new, and neither is the behavior. Public f“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Cisco Talos
· Aug 4, 2026
domainsocket.iorol server through a public blockchain transaction, opens a Socket.IO remote access channel, and stages a Python credential stealTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.js
The Hacker News
· Aug 4, 2026
domainip-api.coma blockchain SmartLoader starts by sending a GET request to ip-api.com to collect the victim’s IP address, country, city, time zonAI developers targeted via trojanized GitHub repositories
Help Net Security
· Aug 4, 2026
domaincontent.powerapps.comand the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That saPNLD Confirms Data Breach Affecting UK Police and Justice Staff
Security Affairs
· Aug 3, 2026
domainus.zoom.06webin.usinvestor/partnership call." The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for theiBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The Hacker News
· Aug 1, 2026
domaindns.multitoconference.comhen creates a stream socket using a hard‑coded C2 address ( dns[.]multitoconference[.]com ) and port 443. It gathers the following information frOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
domaindns.ssentialserv.xyze, the attacker at first checked connectivity to the domain dns[.]ssentialserv[.]xyz as shown below. At the time of our research, the domainOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
domainhunt.io, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started wiResearchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Security Affairs
· Jul 30, 2026
domainrg-telemetry.sbsfiguration responsible for fetching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract wasDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto
The Hacker News
· Jul 30, 2026
domainth-updates.sbstching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was created by a throwaway walDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto
The Hacker News
· Jul 30, 2026
domainfwgcloud.comevices. AI DIGITAL HUMANS The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of humRead This Before You Buy That TV Streaming Stick
Krebs on Security
· Jul 30, 2026
domaincubepilot.orgnknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercepThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
The Hacker News
· Jul 30, 2026
domainjshosting.mesame reverse-tunnelling address 176.65.128[.]26. The domain jshosting[.]me was used to distribute exploit scripts in both sets of atHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
domainnpmjs.storen XOR cipher keyed to 01042025 . The network indicators are npmjs[.]store and 216[.]74[.]123[.]126 . Amazon's post cites the OSV reAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
The Hacker News
· Jul 30, 2026
domainagrocenter-eurohem.rut where the scammers had created a fraudulent website ("www.agrocenter-eurohem[.]ru") that was a near-perfect virtual copy of the legitimateNine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
The Hacker News
· Jul 29, 2026
domain110gongan.comune 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal paymentFlying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The Hacker News
· Jul 29, 2026
domainlogin.trees4sale.netnode reports its status to a heartbeat collection server at login.trees4sale.net:9000, sending a JSON health report with connection count anDysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Security Affairs
· Jul 28, 2026
domainaecert.orgfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealthMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbuisness-centeral-transportation.comhshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-deegital.azurewebsites.netlobal-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessdeegital.azurewebsites.netness-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]comMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-deegital.combusinessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessmixture.comPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-startup.azurewebsites.netalthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]netMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessstartup.azurewebsites.net]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]netMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainglobal-reds.comPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegiMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoom-centeral.azurewebsites.netthehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcareMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoomcenteral.azurewebsites.netrtation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoomcenteral.orgwebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azureMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainmaadinglobal.comazurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.azurewebsites.net]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.coml[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.eastus.cloudapp.azure.comnet neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]cMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainrealhealthshop.comGET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallbackMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainsmartconnect.azurewebsites.net14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainthehealth-life.comecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-cenMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domaintjconsultingservices.comerfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2. When a valid C2 response is received, tMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domaintoadreport.azurewebsites.netcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhunt.iol prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructu⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
The Hacker News
· Jul 28, 2026
domain24carnforth2merseyside.sol]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample asDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainburrberry.ethat resolves C2 through the same domain. XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainm3rnbvs5d.ethator falling back to an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2). XLab's Dysphoria timelineDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainpurelogicbox.orgd decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the conMalvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
The Hacker News
· Jul 27, 2026
domaincorychase.orgd policy, and directed users to a live PHP phishing page on corychase[.]org," the company said . "The landing page was not a MicrosofOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domaingithub.iodev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.github[.]io") and a repository named "Bluedashltd" that contains theOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainsupport.berrydev.xyzlow." Further analysis of the threat actor infrastructure ("support[.]berrydev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.githuOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainteamvem.comt published last week. The bogus Teams page in question is "teamvem[.]com." The active download is used to deliver "supportdev.exe,Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainhunt.iowords and interact with specific internal systems. Although Hunt.io found evidence that the attackers had already compromised mHackers used autonomous AI agent to spy on Thailand's finance ministry
The Record
· Jul 27, 2026
domainhypersnet.comlant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise acTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
The Hacker News
· Jul 27, 2026
domainchatgpt.comof a phishing link that adheres to the following pattern: "chatgpt[.]com/agents/studio/new?template_name=[template name]&initial_aChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
The Hacker News
· Jul 27, 2026
domainclaude.ais). How attackers hosted a fake Claude download page on the claude.ai domain A threat actor abused Anthropic’s Claude Artifacts fWeek in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
Help Net Security
· Jul 26, 2026
domainwoocommerce-check.commin credentials and exfiltrate them to an external server ("woocommerce-check[.]com") that masquerades as WooCommerce, an open-source e-comme⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and Zero
The Hacker News
· Jul 25, 2026
domainshutterstock.comresolve real threats faster Image credit: Celia Ong / CKA / Shutterstock.comChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks
Infosecurity Magazine
· Jul 24, 2026
domaineasysend.coom where the request is sent to a file-sharing service like EasySend[.]co to retrieve a ZIP archive. The ZIP file contains a VisualFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC
The Hacker News
· Jul 24, 2026
domainhunt.iodifferent from Operation Roundish , which was disclosed by Hunt.io back in March and uses longstanding infrastructure that CERFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC
The Hacker News
· Jul 24, 2026
domainis-01-ast.ols-img-12.workers.devng API. The binary contains a Cloudflare Workers endpoint (“is-01-ast[.]ols-img-12[.]workers[.]dev”), but rather than making HTTP connections to this doChaos ransomware deploys browser-based msaRAT to evade network detection
Security Affairs
· Jul 23, 2026
domainis-01-ast.ols-img-12.workers.devhes STUN and TURN configuration from a Cloudflare Worker at is-01-ast[.]ols-img-12[.]workers[.]dev , with Origin and Referer headers disguised as traffiChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Hacker News
· Jul 23, 2026
domainclaude-pro.comther campaign impersonated Anthropic's Claude software from claude-pro[.]com, registered on March 28, 2026, serving a malicious MSI inChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domaingouvvbo.top[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor loChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainlicense.claude-pro.comr persistence. The Beagle backdoor it delivered reported to license[.]claude-pro[.]com. Sophos, working from the fake site, its hosting infrasChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainsylverixstrategy.comer's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three secChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-crowdstrike.comity-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.1China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-sentinelone.comone IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.106.71[.]28 on port 8000. BothChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-trellix.com.]com, and three security-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. TChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainvertextrust-advisors.com[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP, updChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainrambler.rupreviously observed activity associated with the "ischhfd83@rambler[.]ru" email address, which has been tracked under the monikerAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
The Hacker News
· Jul 23, 2026
domainglobal.turn.twilio.comcted host in order to traverse NAT, while the TURN server (“global.turn.twilio.com”) acts as a relay point when a direct Peer-to-Peer (P2P) coChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
domainis-01-ast.ols-img-12.workers.devmation First, a GET request is sent to Cloudflare Workers (“is-01-ast[.]ols-img-12[.]workers[.]dev”) to retrieve the STUN/TURN server configuration requChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
domaingoogle.comthe Google Account, go to the Selfie video page (myaccount.google[.]com/video-verification) Turn Improve Google services (optionaGoogle Adds Selfie Video Recovery for Users Locked Out of Their Accounts
The Hacker News
· Jul 23, 2026
domaindownload-app.usn redirected victims to an external domain, first claude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/winHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domainit.comlaude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win , from which they downloaded a bundle. ItHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domainpolse.used to ten domains going back to December 2025. One of them, polse[.]us , was seized by Microsoft as part of Operation Endgame afHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domaincloudlanecdn.comil" , // Compromised target Microsoft 365 mailbox "Host" : "cloudlanecdn[.]com" , // DNS bootstrap domain "PublicKey" : "-----BEGIN RSANew Project CAV3RN .NET Native AOT communication module
Kaspersky Securelist
· Jul 22, 2026
domainindex.jss behavior. The repository contains a JavaScript file named index[.]js . This file is encoded in Base64 with an XOR cipher, whicPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
domainlumanagi.onlinerecruiter sent a document via Google Docs purportedly from lumanagi[.]online that contained information about their project, the job vPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
domainroutes.jsonas. This repository contained a similar malicious file to routes[.]js , which was observed in the Indian software development cPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.