ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaingobf.mxmpaign targeting Mexican users The MDR alert traced back to gobf[.]mx , a typosquat of the government's CURP national-ID lookupExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
The Hacker News
· Jul 21, 2026
domainsummerartcamp.netlosely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the originaExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
The Hacker News
· Jul 21, 2026
domainacortaurl.coming on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised emaiBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaincort.asts or clicking on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use ofBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainduckdns.orgther enhanced by the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has alsBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaingtly.tod using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised email accounts to sBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainip-ddns.comy the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantaBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainnoip.comc DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantage of legitimateBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaincloudlanecdn.comues from IPv6 AAAA records sent back by an attacker domain, cloudlanecdn[.]com , then writes them to logAzure.txt , a file dressed up asHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
The Hacker News
· Jul 20, 2026
domainwp2shell.comlly, Searchlight Cyber has released a free scanning tool at wp2shell.com so that administrators can safely check if their servers reResearchers Build WordPress Exploit Using OpenAI's GPT
Infosecurity Magazine
· Jul 20, 2026
domaindisroot.orgdownload two payloads from a public Forgejo instance ("git.disroot[.]org/git-ecosystem"): a shell script ("deploy.sh") and a nativSleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
The Hacker News
· Jul 20, 2026
domainmend.ioed them as a data exfiltration channel. Earlier this month, Mend.io disclosed details of an undocumented software supply chainSleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
The Hacker News
· Jul 20, 2026
domainmicrosoft-toolkit.comg : Spoofing legitimate brand names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : EmbeddHow Threat Actors Are Rizzing Up Your AI for Profit
Recorded Future
· Jul 20, 2026
domainmicrosofttoolkit.comnd names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedding malicious links withinHow Threat Actors Are Rizzing Up Your AI for Profit
Recorded Future
· Jul 20, 2026
domainsocket.ioware designed to exfiltrate valuable data and configuring a Socket.IO backdoor. Specifically, the repositories distributed as parFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
The Hacker News
· Jul 19, 2026
domainsteamcommunity.comdata from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew mUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
The Hacker News
· Jul 19, 2026
domaincdnorigin.netXLab's indicators are a C2 at 209.99.186[.]235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f3New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
The Hacker News
· Jul 17, 2026
domainpolygon-rpc.comtriggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
Security Affairs
· Jul 17, 2026
domainclaude-desktop.gitlab.ioCR Stealer through fake Claude Code pages on GitLab such as claude-desktop[.]gitlab[.]io . The other chain leaves fingerprints Microsoft's firstACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domaincreativecommunityinfo.artes the lure. Two of the indicators in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host anACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domainenhanceblabber.ccrs in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host and a C2. The Hacker NewsACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domainin.net\Windows\system32\rundll32.exe" \\sphere-api.dialectosphere.in[.]net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe645ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domaincodebasecode.comthe Telegram channel. By running a DNS query for the domain codebasecode[.]com, it extracts and decrypts the fallback C2 address. By extNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domainhurgadatour.shope." Both the stager and main DLL binary are retrieved from "hurgadatour[.]shop" domain. Written in C, TELEPUZ is lightweight and modularNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domaint.meBy extracting an encrypted URL from a Telegram profile's ("t[.]me/chanadarkpart") description. The channel was created on ANew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domainasp.netromising an internet-facing IIS web server and uploading an ASP.NET web shell. From there, they ran commands through the IIS woSpirals ransomware locks down victim systems in under 24 hours
Help Net Security
· Jul 17, 2026
domaindigikalas.onlineointing to an Iranian-hosted machine, and the parent domain digikalas[.]online resolves to Iran’s Arvan Cloud CDN. Shared dropper infrasTuxBot v3: The IoT Botnet Built With AI
Security Affairs
· Jul 16, 2026
domainaipythondevs.com[.]com” (which is also likely to be a hijacked domain) and “aipythondevs[.]com” serve as the primary C2 for the Starland Python RAT. AllUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domaineorthopaedics.comitimate traffic categories. The staging domains, including “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainipify.orgincludes the victim's public IP address sourced from “api64.ipify[.]org”, the build name, region locale, computer name presentedUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainpolygon-rpc.comtriggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainsastoro.comerving a narrow functional role: “eorthopaedics[.]com” and “sastoro[.]com” hosts the PowerShell stage chain under “/feed/” and “/alUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainweb-devtools.comncluding “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembles a developer tooling portal), and “zynaris[.]iUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainwindowscreenrepairnearme.comC2 infrastructure used for the same campaign. The domains “windowscreenrepairnearme[.]com” (which is also likely to be a hijacked domain) and “aipyUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainzynaris.ioevtools[.]com” (resembles a developer tooling portal), and “zynaris[.]io” (resembles a technology start-up), with each domain servUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainhunt.iocause those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second CClaude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Security Affairs
· Jul 16, 2026
domainnasa.govion rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning outpuClaude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Security Affairs
· Jul 16, 2026
domainbooking.comcredential-stealing malware by cybercriminals impersonating Booking.com. In a phishing campaign that began in December 2024 and hasPhishing campaign impersonating Booking.com targets hospitality sector with malware
The Record
· Jul 16, 2026
domainsysteminfor.comstomized PlugX payload that communicated with the C2 domain systeminfor[.]com. The document purported to be an official Vatican letterChinese State-Sponsored Group ‘RedDelta’ Targets the Vatican and Catholic Organizations
Recorded Future
· Jul 16, 2026
domainagent01.xeox.comThree entries it originally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOXMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainasp.netromising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established persThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
The Hacker News
· Jul 15, 2026
domainextensions-hub.compdate, and uninstall, the extension pinged a second domain, extensions-hub[.]com, with the product, version, and browser. And a script thaGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
The Hacker News
· Jul 15, 2026
domaingeeked.wtfts were registered seconds apart, tied to a commit email at geeked[.]wtf and a Discord handle. Ninety of the 93 deployment hostnam148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domaingov.brsed systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplica20+ Hijacked Government Websites Became an Attack Channel
The Hacker News
· Jul 15, 2026
domaingsnc.euinstead. Group-IB traced this copy to an operator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The sNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
The Hacker News
· Jul 15, 2026
domaingsocket.ioperator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The stealer payloads sit on three compromised domaiNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
The Hacker News
· Jul 15, 2026
domainhunt.iofiltration. 3,900 threat servers mapped A new analysis from Hunt.io has uncovered more than 3,900 threat activities enabling seThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
The Hacker News
· Jul 15, 2026
domainipfs.iosystem-specific paths and executed. The downloader URL is "ipfs[.]io/ipfs/QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9." TheCompromised AsyncAPI npm Packages Deliver Multi
The Hacker News
· Jul 15, 2026
domainlogfriend.comon utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campaForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
The Hacker News
· Jul 15, 2026
domainlunaron.topaimed each browser at 30 connections to a Wisp endpoint on lunaron[.]top, itself a live proxy busy injecting malvertising. Wisp is148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainmoonsand.storehooks the app's Electron internals. Then it asks its C2 at moonsand[.]store . If the server sets a Wait flag, SeedHunter scans USB byOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
The Hacker News
· Jul 15, 2026
domainpicis.netms since 2018, now running a Microsoft 365 AiTM platform on picis[.]net and monetizing access through a bulk mailer he wrote callMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainpipicka.xyztion with the remote server, including the server details ("pipicka[.]xyz") and the polling interval used by the implant. AlternatiLabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
The Hacker News
· Jul 15, 2026
domainromnor.cans alive on its own. Both phishing domains, picis[.]net and romnor[.]ca, were offline when The Hacker News checked ahead of publiMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainstanfordstudies.coms the encrypted list with your fingerprint, posts it to api.stanfordstudies[.]com, and wipes the local copy. The upload time is offset perGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
The Hacker News
· Jul 15, 2026
domaintorproject.org.122[.]124 C2 IP: 57.128.246[.]79 Tor infrastructure: check.torproject[.]org, archive.torproject[.]org On-host artifacts: a randomly nCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
domainvipersfutbol.comnt build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. Anyone who has loaded one o148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainwerkbit.appized dropper that's distributed as a disk image file named "Werkbit.app." Because both the disk image and binary are notarized andCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
The Hacker News
· Jul 15, 2026
domainwerkbit.ior checks. The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. In an interesting twCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
The Hacker News
· Jul 15, 2026
domainwoofbeginner.comnd script hosts the current build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. An148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainws01.xeox.comiginally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX vendor infrastruMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainmoonsand.storeby the malware Then the malware communicates with the C2 ( moonsand[.]store ) over HTTPS, sending a Base64-encoded JSON request contaOkoBot framework infection chain
Kaspersky Securelist
· Jul 14, 2026
domainfiles.pythonhosted.orgDuring installation, the PyPI frontend redirects users to “files.pythonhosted.org”, where the actual files are stored. Download URLs are deriThe serpent’s tongue: Luring the Python out of its den
Cisco Talos
· Jul 14, 2026
domaincohezo.comd to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID tCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincohezo.ionterfaces tied to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the DevelCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincordinex.ioaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID to Apple after confiCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincrashreporter.appce indicator on its own. The downloaded disk image contains CrashReporter.app, which carries the bundle identifier com.apple.crashreporteCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainendpoint-api-v1.comcommand the dropper runs next, pulling a shell script from endpoint-api-v1[.]com. The script isn’t written to disk in readable form: it arCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.appe ad-hoc-signed payload it installs.” When the victim opens Werkbit.app, it queries the GitHub API and fetches a file called sys.caCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.ioGatekeeper on first launch without any warning. The domain werkbit[.]io, which serves the installer, was registered in late JuneCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.ioirming its use in the campaign. The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build datNew macOS malware steals passwords by posing as Apple's crash-reporting tool
Help Net Security
· Jul 14, 2026
domain7zip.comwith a trojanized 7-Zip installer hosted on a domain named "7zip[.]com," covertly recruiting compromised devices as proxy nodes.Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domain7-zip.orgtly referenced domain names (e.g., "7zip[.]com" instead of "7-zip[.]org") to use them to their advantage. Further analysis of theFake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domainiplogger.comto their advantage. Further analysis of the IPLogger URL ("iplogger[.]com/mnWD") embedded within the samples tied to the 7-Zip campFake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domaingov.pkis the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolvingHackers Weaponize Balochistan Police Portal in Multi
The Hacker News
· Jul 11, 2026
domaininjective.networkest to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon. StepSecurity noted the malicious reInjective Labs GitHub Compromise Pushes Wallet-Key
The Hacker News
· Jul 10, 2026
domainhunt.iospilled the group's phishing tools and logs, in a campaign Hunt.io called Operation Roundish . What to do now If you run any oExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
domainxxooonline.eu.ccucture: 137.175.93[.]126, 43.108.17[.]80, and the domain xs.xxooonline[.]eu[.]cc. What makes WP-SHELLSTORM worth attention is not how adExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
domaingithub.comted with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
domainmuckcoding.comed a hidden PowerShell command that downloaded content from muckcoding[.]com, saved it as api.db, decoded it using certutil, wrote the222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
domainrambler.rulow combined a threat actor-linked email address, ischhfd83@rambler[.]ru, with force-push automation, a schedule running every min222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
domaincamorreado.clickmd.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that downThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
The Hacker News
· Jul 9, 2026
domaingovtop.oneurgency and trick users into clicking on a malicious link ("govtop[.]one/incometax") embedded within PDF attachments. The bogus laSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domainkkxqbh.topo take screenshots and exfiltrate data to a remote server ("kkxqbh[.]top"). Exactly who is behind the activity is unclear, but infSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domainouewop.comRAT belonging to the AsyncRAT malware family connecting to ouewop[.]com on port 6351 It's worth noting that DCRat is one of the sSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domain7zip.com2026: a fake version of the 7-Zip archive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers unFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domain7-zip.orghive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers uncovered a years-long operation they’reFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainiplogger.comitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spanningFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainproxyreviews.orgt appear to be independent proxy review websites, including proxyreviews[.]org, to drive traffic to its own storefronts. The review siteFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainsmartproxy.comreal Smartproxy company. Decodo, which owns the legitimate smartproxy[.]com, publicly called out the domain squatter. The fake was goFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainsmartproxy.orgillustrates how convincing the impersonation is. The domain smartproxy[.]org presents itself as a budget proxy service offering accessFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainaccenture.com121123_AtriasTalentAcademy”, hosted on a partially redacted accenture.com domain. The real danger isn’t the headline number: SSH andA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Security Affairs
· Jul 8, 2026
domaincalvexagroup.comLLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows thaFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domaing2exchange.com, and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based iFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domainirisc2.com/industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positioFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domainbancaporinternetbbmx.onlinethe phishing landing page One such redirect destination, "'bancaporinternetbbmx[.]online," contains a page-load Telegram notification script thatSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The Hacker News
· Jul 8, 2026
domainfakeupdate.netmediately launches Microsoft Edge in kiosk mode pointing to fakeupdate[.]net, a well-known pentesting/red team site that renders a fakSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The Hacker News
· Jul 8, 2026
domainbleacherreport.comGerman streaming guide service, and one that resembles the BleacherReport[.]com certificate. JustWatch itself has not been compromised, nNew Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner
Infosecurity Magazine
· Jul 8, 2026
domainaccenture.comtration from a private Azure DevOps repository hosted on an accenture.com -associated production URL. When contacted, an Accenture meAccenture acknowledges security incident following 35GB data theft claim
Help Net Security
· Jul 8, 2026
domainshapedplugin.comr's Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are noShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
The Hacker News
· Jul 7, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.