Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | gobf.mx | mpaign targeting Mexican users The MDR alert traced back to gobf[.]mx , a typosquat of the government's CURP national-ID lookup | Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign The Hacker News | · Jul 21, 2026 |
| domain | summerartcamp.net | losely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the origina | Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign The Hacker News | · Jul 21, 2026 |
| domain | acortaurl.com | ing on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised emai | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | cort.as | ts or clicking on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | duckdns.org | ther enhanced by the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has als | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | gtly.to | d using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised email accounts to s | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | ip-ddns.com | y the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advanta | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | noip.com | c DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantage of legitimate | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | cloudlanecdn.com | ues from IPv6 AAAA records sent back by an attacker domain, cloudlanecdn[.]com , then writes them to logAzure.txt , a file dressed up as | HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 The Hacker News | · Jul 20, 2026 |
| domain | wp2shell.com | lly, Searchlight Cyber has released a free scanning tool at wp2shell.com so that administrators can safely check if their servers re | Researchers Build WordPress Exploit Using OpenAI's GPT Infosecurity Magazine | · Jul 20, 2026 |
| domain | disroot.org | download two payloads from a public Forgejo instance ("git.disroot[.]org/git-ecosystem"): a shell script ("deploy.sh") and a nativ | SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News | · Jul 20, 2026 |
| domain | mend.io | ed them as a data exfiltration channel. Earlier this month, Mend.io disclosed details of an undocumented software supply chain | SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News | · Jul 20, 2026 |
| domain | microsoft-toolkit.com | g : Spoofing legitimate brand names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedd | How Threat Actors Are Rizzing Up Your AI for Profit Recorded Future | · Jul 20, 2026 |
| domain | microsofttoolkit.com | nd names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedding malicious links within | How Threat Actors Are Rizzing Up Your AI for Profit Recorded Future | · Jul 20, 2026 |
| domain | socket.io | ware designed to exfiltrate valuable data and configuring a Socket.IO backdoor. Specifically, the repositories distributed as par | Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images The Hacker News | · Jul 19, 2026 |
| domain | steamcommunity.com | data from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew m | UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware The Hacker News | · Jul 19, 2026 |
| domain | cdnorigin.net | XLab's indicators are a C2 at 209.99.186[.]235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f3 | New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens The Hacker News | · Jul 17, 2026 |
| domain | polygon-rpc.com | triggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4 | New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT Security Affairs | · Jul 17, 2026 |
| domain | claude-desktop.gitlab.io | CR Stealer through fake Claude Code pages on GitLab such as claude-desktop[.]gitlab[.]io . The other chain leaves fingerprints Microsoft's first | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | creativecommunityinfo.art | es the lure. Two of the indicators in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host an | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | enhanceblabber.cc | rs in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host and a C2. The Hacker News | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | in.net | \Windows\system32\rundll32.exe" \\sphere-api.dialectosphere.in[.]net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe645 | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | codebasecode.com | the Telegram channel. By running a DNS query for the domain codebasecode[.]com, it extracts and decrypts the fallback C2 address. By ext | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | hurgadatour.shop | e." Both the stager and main DLL binary are retrieved from "hurgadatour[.]shop" domain. Written in C, TELEPUZ is lightweight and modular | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | t.me | By extracting an encrypted URL from a Telegram profile's ("t[.]me/chanadarkpart") description. The channel was created on A | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | asp.net | romising an internet-facing IIS web server and uploading an ASP.NET web shell. From there, they ran commands through the IIS wo | Spirals ransomware locks down victim systems in under 24 hours Help Net Security | · Jul 17, 2026 |
| domain | digikalas.online | ointing to an Iranian-hosted machine, and the parent domain digikalas[.]online resolves to Iran’s Arvan Cloud CDN. Shared dropper infras | TuxBot v3: The IoT Botnet Built With AI Security Affairs | · Jul 16, 2026 |
| domain | aipythondevs.com | [.]com” (which is also likely to be a hijacked domain) and “aipythondevs[.]com” serve as the primary C2 for the Starland Python RAT. All | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | eorthopaedics.com | itimate traffic categories. The staging domains, including “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resemb | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | ipify.org | includes the victim's public IP address sourced from “api64.ipify[.]org”, the build name, region locale, computer name presented | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | polygon-rpc.com | triggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4 | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | sastoro.com | erving a narrow functional role: “eorthopaedics[.]com” and “sastoro[.]com” hosts the PowerShell stage chain under “/feed/” and “/al | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | web-devtools.com | ncluding “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembles a developer tooling portal), and “zynaris[.]i | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | windowscreenrepairnearme.com | C2 infrastructure used for the same campaign. The domains “windowscreenrepairnearme[.]com” (which is also likely to be a hijacked domain) and “aipy | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | zynaris.io | evtools[.]com” (resembles a developer tooling portal), and “zynaris[.]io” (resembles a technology start-up), with each domain serv | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | hunt.io | cause those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second C | Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign Security Affairs | · Jul 16, 2026 |
| domain | nasa.gov | ion rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning outpu | Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign Security Affairs | · Jul 16, 2026 |
| domain | booking.com | credential-stealing malware by cybercriminals impersonating Booking.com. In a phishing campaign that began in December 2024 and has | Phishing campaign impersonating Booking.com targets hospitality sector with malware The Record | · Jul 16, 2026 |
| domain | systeminfor.com | stomized PlugX payload that communicated with the C2 domain systeminfor[.]com. The document purported to be an official Vatican letter | Chinese State-Sponsored Group ‘RedDelta’ Targets the Vatican and Catholic Organizations Recorded Future | · Jul 16, 2026 |
| domain | agent01.xeox.com | Three entries it originally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | asp.net | romising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established pers | ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories The Hacker News | · Jul 15, 2026 |
| domain | extensions-hub.com | pdate, and uninstall, the extension pinged a second domain, extensions-hub[.]com, with the product, version, and browser. And a script tha | Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found The Hacker News | · Jul 15, 2026 |
| domain | geeked.wtf | ts were registered seconds apart, tied to a commit email at geeked[.]wtf and a Discord handle. Ninety of the 93 deployment hostnam | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | gov.br | sed systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplica | 20+ Hijacked Government Websites Became an Attack Channel The Hacker News | · Jul 15, 2026 |
| domain | gsnc.eu | instead. Group-IB traced this copy to an operator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The s | New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password The Hacker News | · Jul 15, 2026 |
| domain | gsocket.io | perator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The stealer payloads sit on three compromised domai | New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password The Hacker News | · Jul 15, 2026 |
| domain | hunt.io | filtration. 3,900 threat servers mapped A new analysis from Hunt.io has uncovered more than 3,900 threat activities enabling se | ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories The Hacker News | · Jul 15, 2026 |
| domain | ipfs.io | system-specific paths and executed. The downloader URL is "ipfs[.]io/ipfs/QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9." The | Compromised AsyncAPI npm Packages Deliver Multi The Hacker News | · Jul 15, 2026 |
| domain | logfriend.com | on utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campa | Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft The Hacker News | · Jul 15, 2026 |
| domain | lunaron.top | aimed each browser at 30 connections to a Wisp endpoint on lunaron[.]top, itself a live proxy busy injecting malvertising. Wisp is | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | moonsand.store | hooks the app's Electron internals. Then it asks its C2 at moonsand[.]store . If the server sets a Wait flag, SeedHunter scans USB by | OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps The Hacker News | · Jul 15, 2026 |
| domain | picis.net | ms since 2018, now running a Microsoft 365 AiTM platform on picis[.]net and monetizing access through a bulk mailer he wrote call | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | pipicka.xyz | tion with the remote server, including the server details ("pipicka[.]xyz") and the polling interval used by the implant. Alternati | LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts The Hacker News | · Jul 15, 2026 |
| domain | romnor.ca | ns alive on its own. Both phishing domains, picis[.]net and romnor[.]ca, were offline when The Hacker News checked ahead of publi | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | stanfordstudies.com | s the encrypted list with your fingerprint, posts it to api.stanfordstudies[.]com, and wipes the local copy. The upload time is offset per | Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found The Hacker News | · Jul 15, 2026 |
| domain | torproject.org | .122[.]124 C2 IP: 57.128.246[.]79 Tor infrastructure: check.torproject[.]org, archive.torproject[.]org On-host artifacts: a randomly n | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| domain | vipersfutbol.com | nt build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. Anyone who has loaded one o | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | werkbit.app | ized dropper that's distributed as a disk image file named "Werkbit.app." Because both the disk image and binary are notarized and | CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks The Hacker News | · Jul 15, 2026 |
| domain | werkbit.io | r checks. The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. In an interesting tw | CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks The Hacker News | · Jul 15, 2026 |
| domain | woofbeginner.com | nd script hosts the current build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. An | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | ws01.xeox.com | iginally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX vendor infrastru | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | moonsand.store | by the malware Then the malware communicates with the C2 ( moonsand[.]store ) over HTTPS, sending a Base64-encoded JSON request conta | OkoBot framework infection chain Kaspersky Securelist | · Jul 14, 2026 |
| domain | files.pythonhosted.org | During installation, the PyPI frontend redirects users to “files.pythonhosted.org”, where the actual files are stored. Download URLs are deri | The serpent’s tongue: Luring the Python out of its den Cisco Talos | · Jul 14, 2026 |
| domain | cohezo.com | d to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID t | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | cohezo.io | nterfaces tied to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Devel | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | cordinex.io | aign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID to Apple after confi | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | crashreporter.app | ce indicator on its own. The downloaded disk image contains CrashReporter.app, which carries the bundle identifier com.apple.crashreporte | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | endpoint-api-v1.com | command the dropper runs next, pulling a shell script from endpoint-api-v1[.]com. The script isn’t written to disk in readable form: it ar | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.app | e ad-hoc-signed payload it installs.” When the victim opens Werkbit.app, it queries the GitHub API and fetches a file called sys.ca | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.io | Gatekeeper on first launch without any warning. The domain werkbit[.]io, which serves the installer, was registered in late June | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.io | irming its use in the campaign. The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build dat | New macOS malware steals passwords by posing as Apple's crash-reporting tool Help Net Security | · Jul 14, 2026 |
| domain | 7zip.com | with a trojanized 7-Zip installer hosted on a domain named "7zip[.]com," covertly recruiting compromised devices as proxy nodes. | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | 7-zip.org | tly referenced domain names (e.g., "7zip[.]com" instead of "7-zip[.]org") to use them to their advantage. Further analysis of the | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | iplogger.com | to their advantage. Further analysis of the IPLogger URL ("iplogger[.]com/mnWD") embedded within the samples tied to the 7-Zip camp | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | gov.pk | is the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolving | Hackers Weaponize Balochistan Police Portal in Multi The Hacker News | · Jul 11, 2026 |
| domain | injective.network | est to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon. StepSecurity noted the malicious re | Injective Labs GitHub Compromise Pushes Wallet-Key The Hacker News | · Jul 10, 2026 |
| domain | hunt.io | spilled the group's phishing tools and logs, in a campaign Hunt.io called Operation Roundish . What to do now If you run any o | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| domain | xxooonline.eu.cc | ucture: 137.175.93[.]126, 43.108.17[.]80, and the domain xs.xxooonline[.]eu[.]cc. What makes WP-SHELLSTORM worth attention is not how ad | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| domain | github.com | ted with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| domain | muckcoding.com | ed a hidden PowerShell command that downloaded content from muckcoding[.]com, saved it as api.db, decoded it using certutil, wrote the | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| domain | rambler.ru | low combined a threat actor-linked email address, ischhfd83@rambler[.]ru, with force-push automation, a schedule running every min | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| domain | camorreado.click | md.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that down | ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories The Hacker News | · Jul 9, 2026 |
| domain | govtop.one | urgency and trick users into clicking on a malicious link ("govtop[.]one/incometax") embedded within PDF attachments. The bogus la | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | kkxqbh.top | o take screenshots and exfiltrate data to a remote server ("kkxqbh[.]top"). Exactly who is behind the activity is unclear, but inf | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | ouewop.com | RAT belonging to the AsyncRAT malware family connecting to ouewop[.]com on port 6351 It's worth noting that DCRat is one of the s | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | 7zip.com | 2026: a fake version of the 7-Zip archive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers un | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | 7-zip.org | hive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers uncovered a years-long operation they’re | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | iplogger.com | itimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spanning | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | proxyreviews.org | t appear to be independent proxy review websites, including proxyreviews[.]org, to drive traffic to its own storefronts. The review site | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | smartproxy.com | real Smartproxy company. Decodo, which owns the legitimate smartproxy[.]com, publicly called out the domain squatter. The fake was go | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | smartproxy.org | illustrates how convincing the impersonation is. The domain smartproxy[.]org presents itself as a budget proxy service offering access | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | accenture.com | 121123_AtriasTalentAcademy”, hosted on a partially redacted accenture.com domain. The real danger isn’t the headline number: SSH and | A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach Security Affairs | · Jul 8, 2026 |
| domain | calvexagroup.com | LLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows tha | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | g2exchange.com | , and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based i | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | irisc2.com | /industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positio | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | bancaporinternetbbmx.online | the phishing landing page One such redirect destination, "'bancaporinternetbbmx[.]online," contains a page-load Telegram notification script that | SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users The Hacker News | · Jul 8, 2026 |
| domain | fakeupdate.net | mediately launches Microsoft Edge in kiosk mode pointing to fakeupdate[.]net, a well-known pentesting/red team site that renders a fak | SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users The Hacker News | · Jul 8, 2026 |
| domain | bleacherreport.com | German streaming guide service, and one that resembles the BleacherReport[.]com certificate. JustWatch itself has not been compromised, n | New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner Infosecurity Magazine | · Jul 8, 2026 |
| domain | accenture.com | tration from a private Azure DevOps repository hosted on an accenture.com -associated production URL. When contacted, an Accenture me | Accenture acknowledges security incident following 35GB data theft claim Help Net Security | · Jul 8, 2026 |
| domain | shapedplugin.com | r's Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are no | ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack The Hacker News | · Jul 7, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.