ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4eset is enough. Selected indicators of compromise: SHA-256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
sha256c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e57dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTEFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
domaincdnflare.xyz69bf220 (running in memory on one Disrex store) Domain: 247.cdnflare[.]xyz (malware download host) IP: 99.84.67[.]186:443 (command-aUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The Hacker News
· 12d ago
sha256251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store) Domain: 247.cdnflarUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The Hacker News
· 12d ago
sha2568334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06efb2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The Hacker News
· 12d ago
sha256e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7/gvfsd-user , with a variant pointing at /tmp/.kw_ SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The Hacker News
· 12d ago
domainapi.cadence.jetbrains.comtween August 8 and 24, 2026. The exploited Cadence server ("api.cadence.jetbrains.com") has since been taken offline. The company conceded that tAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv4150.109.230.104P addresses associated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv4152.233.30.1843.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpected IP addressAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv415.235.225.20550.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpecAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv4210.247.242.190tion activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activiAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv443.153.227.206ciated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
ipv462.210.127.48erved exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 AuthenticationAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News
· 12d ago
sha1286dd3ff41526b582ef48830de239dffbaa61f90Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, SalvatoreRe: Vulnerability fixes in util-linux-2.42.3
oss-security
· 12d ago
domain457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.siterameter. Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and testeStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
domainntp.timesysnc.netk like NTP server replies. As of September 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address toStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
domaintime.microsft.run) ntp.timesysnc.net:123 C2, custom NTP-shaped traffic (UDP) time.microsft.run:123 C2, custom NTP-shaped traffic (UDP) pool.microsft.studiStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
domainwindwsecurity.rund host # C2 servers 99.84.67.186:443 C2, WebSocket over TLS windwsecurity.run:443 remote shell, WebSocket over TLS (TCP) ntp.timesysnc.neStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv4182.182.152.48ces 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploiStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv4185.157.160.251tember 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to block if you cannot filter by namStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv4209.141.43.95axfileupload/mag.txt 247.cdnflare.xyz malware download host 209.141.43.95 malware download host # C2 servers 99.84.67.186:443 C2, WebStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv4209.73.130.148source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv476.31.99.207ce, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 attaStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv477.239.124.107209.73.130.148 attacker source, successful exploit attempt 77.239.124.107 attacker source, follow-up requests User-Agent: python-requStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv488.216.72.181llback ntp.syncstime.to:123 C2, fallback # attacker sources 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 atStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
ipv499.84.67.186launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands. So far, we have no indicaStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
md5fced27f6d57702565353ecc11722533b/cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5.StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha2561a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375da3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d chronyd variant, captured from /proc/<pid>/exe /tmp/.kw_<raStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha2564352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e60e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e kworker-linux-x64 (new build, 209.141.43.95), 2270031 bytesStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha256b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f755142061ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb547StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha256d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82-linux-x64 (new build, 209.141.43.95), 2270031 bytes sha256 d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a337StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha256d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6ed second attacker (unrelated tooling, same victims): sha256 d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e PHP dropper pub/media/catalog/product/cache/ss_<10hex>/syncStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
sha256e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7n-requests 2.15.0 on the implant operator's requests sha256 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4eStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
domainacemlnd.comsage body to be routed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part,Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainactivehosted.comed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part, said it has tested its cPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainadvancefundingboost.comost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitePhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domaindigitalcapitalboost.comhe most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancePhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domaindirectcapitalboost.comay[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails fromPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainguardiancapitalway.comxpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainguardiangrowthfunding.come top 10 sender domains by the most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yoPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainharboradvancefunding.comng[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinediPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainonlinedirectfinance.comding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from these finance-themed domaiPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainthebusinessloanexpress.comlow - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancaPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainunitedfundingwave.comt[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What'sPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domainyourlocfunding.com]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harborPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
· 13d ago
domaincleanos.onlinein.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanos[.]online. Rapid7 has not said whether theNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domaindarklights.storeerhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.sociNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domaingrip-cdns.spacebut not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanosNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainmonderhouse.spacehe following indicators of compromise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainprimgs.lolin the same two maltrail entries but not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainpstatic.autosite Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainsmartnords.sitemise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.pNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainsocialteams.store]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-100New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainworksongo.storetatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
md5c8c68e629bba773a10ac80012d10bf19tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 -New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
sha2564bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f59142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 The Hacker News confirmed on September 4 that none of the sNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
sha25672e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 13d ago
domainimg.darklights.storepreviously recorded, it reaches out to a secondary domain – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
domainimg.monderhouse.spaced fast-poll flag. If the validation fails, the C2 resets to img.monderhouse.space 2 staged payload drop Issues an authenticated HTTP POST toDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
md5c8c68e629bba773a10ac80012d10bf19and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd()DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
md5ecd427ea8330a4ff73618483e00b9b41main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetchDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha25609739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbeaudit / audit.log , cmd.log , secure , syslog , auth.log . 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109adDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha2564bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5hrough it, completing the watering-hole loop. SSH keylogger 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 intercepts legitimate users' plaintext passwords and savesDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha2565db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91ound to be delivered by a stager. CurlRAT Stager The stager 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 starts by decrypting its configuration strings using a 1-byDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha25672e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558er. Ted backdoor The TA recompiled the HAProxy build 2.8.12 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 (18MB) to include a custom plugin (named ted_plugin ) leaviDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha2568f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66cryption (Figure 8). Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c ⠀ The atd_get_info() is a recon routine likely used to deciDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha256fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61d4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 are a different variant of the stager that fetches backdoorDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
sha256feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3epath used to hide config/staging files. As for the stager, feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 starts by decrypting configuration strings using a 1-byte XDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
domainhunt.iobecause its own AI infrastructure was not properly secured. Hunt.io found a backend that anyone could access without authenticaChinese Hackers Use AI Agents in Multi
Security Affairs
· 13d ago
domainniestools.comrouted requests through private proxy servers linked to the niestools.com domain. The AI models did not break into systems on their oChinese Hackers Use AI Agents in Multi
Security Affairs
· 13d ago
domainbroker.hivemq.comgin. The first version uses the public HiveMQ MQTT broker ( broker.hivemq.com ) as its C2 server. The free tier of this broker supports uAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
domainelement.tweir own Element server running on the Matrix protocol, meet.element[.]tw , as the C2 server. On this server, they created a room uAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
md57916c33688385525078bee504c90f359upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\Software\synapse\Config\SAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
md5bfadbeee63a4f0bf19ec9deb8fa58f58t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tomAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
ipv4103.154.152.178he following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.164.182.1227 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun onOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.168.146.131riginated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 12Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.168.147.235ms plugin have originated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.170.97.7addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 1Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.84.230.85the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.1Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4103.90.148.202ddresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.25Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4114.10.17.2533.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners usiOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4114.10.45.15116.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners using the two pluOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4129.227.46.14331 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious actOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4167.254.240.75185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d1Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4167.254.241.119103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress sOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4182.10.130.5103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4185.196.220.85riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4189.4.122.140103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 ThOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv4216.126.225.208:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv437.9.33.62189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
ipv464.176.209.104178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said tOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 13d ago
domaincrpx0.suthe group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromiThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The Hacker News
· 14d ago
domainwww.mxsetuplogi.comfake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouseThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The Hacker News
· 14d ago
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago
md541444d7018601b599beac0c60ed1bf83dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago
md561e046145ee5cf45aeb033cd71e8b07cd5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago
md59a47c4d379998ade2f8f99e23a630c06a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 14d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.