ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaingrked.onlineySnake Stealer. The malware requests tunnel parameters from grked[.]online , receives an SSH private key and command string from theAI-Generated Malware Powers New Armored Likho APT Campaign
Security Affairs
· Jul 7, 2026
domainhospitalinstallation.comion DLL module ("n-HTCommp.dll") to contact the C2 server ("hospitalinstallation[.]com") and fetch additional post-exploitation modules on the fIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
The Hacker News
· Jul 6, 2026
domainasp.nettion module (CAV3RN_Http_Module) that uses a webshell-style ASP.NET handler, cac.aspx, hosted on a separate IIS server at one oNew Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Infosecurity Magazine
· Jul 6, 2026
domainhospitalinstallation.comthe root domain observed in the Cavern Manticore campaign, hospitalinstallation[.]com, showed that it was registered through Fars Data, an IranNew Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Infosecurity Magazine
· Jul 6, 2026
domaindebank.auctionralized finance portfolio tracker. The fraudulent domain is debank[.]auction. “The fraudulent website is optimized to rank for DeBank-Hidden Web Prompts Trick AI Agents Into Sending Money
Security Affairs
· Jul 6, 2026
domainbooking.comy has been attributed to an Indonesian-origin threat actor. Booking.com Partner Firms Targeted in TONResolver Campaign — Attackers⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
The Hacker News
· Jul 6, 2026
domaincacoo.comnfrastructure. The proxy link routes through the legitimate Cacoo.com domain before redirecting to the phishing site Translated fWhen checking the URL isn't enough: phishing via the Microsoft identity platform
Kaspersky Securelist
· Jul 6, 2026
domaincheckmarx.zonealso includes 27 file hashes and a set of domains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hacFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
domaingit-tanstack.comdomains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, among others. The indicatFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
domainhackmoltrepeat.com]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, among others. The indicators in this alert are derived fFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
domainlitellm.cloudhes and a set of domains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, amongFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
domaingroq.comtor message is forwarded to a public LLM API endpoint ("api.groq[.]com/openai/v1/chat/completions"), which then translates the nNew Avalon Malware Framework Packs CrownX Ransomware Capabilities
The Hacker News
· Jul 3, 2026
domainhelloxcherry.coms cpassword artifacts. Exfiltrate data to a remote server ("helloxcherry[.]com") and poll the server for receiving tasking commands. PerNew Avalon Malware Framework Packs CrownX Ransomware Capabilities
The Hacker News
· Jul 3, 2026
domainproton.meess 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy, contact e78393397[@]proton[.]me, and the ransom table name README_RANSOM, which doesn’t mJADEPUFFER: First End-to-End AI
Security Affairs
· Jul 3, 2026
domaincontext.airty software supply chain compromise. An AI tooling vendor, Context.ai, was breached via an employee account, allowing attackers tThe Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Security Affairs
· Jul 3, 2026
domainavenger-sync.liveted and exfiltrated to attacker-controlled infrastructure ("avenger-sync[.]live") over an outbound HTTP request. Besides coercing the usePamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
The Hacker News
· Jul 3, 2026
domainmaccy.appis a lookalike site ("maccyapp[.]com") that mimics Maccy ("maccy[.]app"). The AppleScript ("Maccy.scpt") present within the diskPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
The Hacker News
· Jul 3, 2026
domainmaccyapp.cominitial access vector for the malware is a lookalike site ("maccyapp[.]com") that mimics Maccy ("maccy[.]app"). The AppleScript ("MaPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
The Hacker News
· Jul 3, 2026
domainmaccyapp.netfake websites impersonating Maccy. Malicious sites (such as maccyapp[.]net and maccyapp[.]com) distribute malware disguised as MaccyPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
The Hacker News
· Jul 3, 2026
domainnetnut.comand seized hundreds of domains. Banner shown when visiting netnut.com. Source: Infosecurity Magazine How the Popa Botnet Turned SFBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors
Infosecurity Magazine
· Jul 3, 2026
domainnetnut.ioappeared on netnut.com, NetNut’s primary commercial domain, netnut.io, temporarily remained active and accessible. Some online coFBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors
Infosecurity Magazine
· Jul 3, 2026
domainblogspot.comng a next-stage payload hosted on Blogger ("htlwub00klocate.blogspot[.]com"), allowing the attackers to bypass reputation-based defeVEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
The Hacker News
· Jul 3, 2026
domainalarum.ioJuly 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The coFBI Seizes NetNut Proxy Platform, Popa Botnet
Krebs on Security
· Jul 2, 2026
domaingoogle.comorization code request to direct the browser to a "accounts.google[.]com/o/oauth2/v2/auth/identifier" URL containing a "client_id"ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The Hacker News
· Jul 2, 2026
domainproton.mess: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy; contact e78393397[@]proton[.]me; ransom table named README_RANSOM Sysdig calls JADEPUFFERAI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
The Hacker News
· Jul 2, 2026
domainmora1987.workmalware then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infecSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
The Hacker News
· Jul 1, 2026
domainwork.gdthen establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infectedSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
The Hacker News
· Jul 1, 2026
domainrentry.coor serverless workers. These include - Telegra.ph Teletype Rentry.co Write.as Dropbox GoFile DEV Community (dev.to) Mastodon LesGamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
The Hacker News
· Jul 1, 2026
domainsocket.ioconnects to attacker-controlled infrastructure, launches a socket.io backdoor, and eventually deploys a Python infostealer. TheHijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
The Hacker News
· Jul 1, 2026
domainduckdns.orgC2 domains lean on free dynamic DNS services, specifically duckdns.org, which is where the name comes from. Once a device checks iRustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Security Affairs
· Jul 1, 2026
domainpamconj.comgagement, we identified a management panel at “dashboard-bl.pamconj[.]com” serving a React single-page application (SPA) with a 1.7ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainsharepoint.comhe vendor's genuine SharePoint tenant: “https[:]//mononapfp.sharepoint[.]com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYvARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainworkers.devflare Workers accounts including “clear90489058903-document.workers[.]dev”. Linking ARToken to EvilTokens The connection between ARARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainbabybon.cfde payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does noResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domaincomicstar.latalso listed three payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one ofResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domainmerkantalolol.asiaers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does not prove infection. ItResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domainatlasregister.netty of the domains registered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]neCyber
Recorded Future
· Jul 1, 2026
domainatlasregister.orggistered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]comCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.bje and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.cong the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s originalCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.inare operated by the same threat actors: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 202Cyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.nete Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original investigation. ResearCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.orgflags and impersonating the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not includedCyber
Recorded Future
· Jul 1, 2026
domainbma.gov.bjfiles shared by three of the Oceaniek-attributed websites ( bma[.]gov[.]bj, beninmaritime[.]net , and beninmaritime[.]bj) and fourCyber
Recorded Future
· Jul 1, 2026
domaincadredevie.gouv.bjs part of the Ministère du Cadre de Vie et des Transports ( cadredevie[.]gouv[.]bj ). The three inauthentic Benin Maritime AdministrationCyber
Recorded Future
· Jul 1, 2026
domainepnicaragua.comatlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]netCyber
Recorded Future
· Jul 1, 2026
domainepnicaragua.orgrg beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]oCyber
Recorded Future
· Jul 1, 2026
domaingouv.bjreal email address listed for Benin on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : ScreensCyber
Recorded Future
· Jul 1, 2026
domaingove.bj]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links tCyber
Recorded Future
· Jul 1, 2026
domainguve.bjon GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screenshot from the Benin Maritime AdministCyber
Recorded Future
· Jul 1, 2026
domainhellasnaval.netCluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacCyber
Recorded Future
· Jul 1, 2026
domainimsag.orga website impersonating a Guyanese maritime administration, imsag[.]org . The CENM websites claim that they provide IMO-mandatedCyber
Recorded Future
· Jul 1, 2026
domainisithin.comp IP range as Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medllCyber
Recorded Future
· Jul 1, 2026
domainmalawi.marinegov.orgral subdomains impersonating Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By defaulCyber
Recorded Future
· Jul 1, 2026
domainmalawi.shipregistry.marinegov.orgMalawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By default, the latter displays a page showing shipCyber
Recorded Future
· Jul 1, 2026
domainmarinegov.neter of fraudulent ship registries centered around the domain marinegov[.]net. This activity also aligns with prior reporting from indeCyber
Recorded Future
· Jul 1, 2026
domainmarinegov.orgins, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nautCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.onlinelink to another domain hosted on different infrastructure, medlloyd[.]online . This domain is co-hosted on 159[.]198[.]36[.]123 with tCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.online.beninmaritime.netubdomain on the Cluster Alpha website beninmaritime[.]net , medlloyd[.]online[.]beninmaritime[.]net , indicates a link to another domain hosted on differCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.orgn[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry mariCyber
Recorded Future
· Jul 1, 2026
domainnauticacentro.comaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has seveCyber
Recorded Future
· Jul 1, 2026
domainnauticacentro.mx[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has several subdomains impeCyber
Recorded Future
· Jul 1, 2026
domainniataregister.netnet epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies InsiktCyber
Recorded Future
· Jul 1, 2026
domainniataregister.orgm epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt Group identified PDCyber
Recorded Future
· Jul 1, 2026
domainoceaniektechnologies.coml as document authors and creators. Oceaniek Technologies ( oceaniektechnologies[.]com ) is an Indian web development company listed throughoutCyber
Recorded Future
· Jul 1, 2026
domainpalaureg.comata for similar PDFs distributed on PISR’s official website palaureg[.]com , which likely indicates that the operators behind epnicaCyber
Recorded Future
· Jul 1, 2026
domainpamconj.comlos published the operation’s domains and addresses, led by pamconj[.]com, for defenders to hunt on.The ARToken phishing panel targets Microsoft 365 accounts
Help Net Security
· Jul 1, 2026
domainpdf.beninmaritime.cobeninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Certificate PDF Generator” ( Figure 3 ). FCyber
Recorded Future
· Jul 1, 2026
domainregistry.zmgov.org: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Cyber
Recorded Future
· Jul 1, 2026
domainthesecure.bizint about spam from “thesecure.biz,” is itself an artefact: thesecure.biz is the encrypted Jabber server Europol later said the arresXSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn't
Security Affairs
· Jun 30, 2026
domainduckdns.orghe control addresses lean on free dynamic-DNS services like duckdns.org, which is where the "Duck" in the name comes from. This fitRustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
The Hacker News
· Jun 30, 2026
domaininternal.corp.com/page?ref=youtube.com bank.example.com/search?q=youtube.com internal.corp.com/redirect?from=youtube.com "The concern is not a single suspChrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
The Hacker News
· Jun 30, 2026
domainipinfo.ios wiped from the file system. It further sends a request to ipinfo[.]io to obtain the host's public IP address and location, alloLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
The Hacker News
· Jun 30, 2026
domainperplexity-ai.onlinebkiofojicogddingbdmcmkpbplcd) and used a look-alike domain, perplexity-ai[.]online, to pass for the real service at perplexity.ai. MicrosoftMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
The Hacker News
· Jun 30, 2026
domaindev-tunnels.comablishing encrypted communications with a remote server ("a.dev-tunnels[.]com"), and retrieving and executing additional JavaScript payAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
The Hacker News
· Jun 30, 2026
domainbooking.comCyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails thatHackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com
Infosecurity Magazine
· Jun 30, 2026
domaindomain.comLateral movement flag using specified domain credentials (“domain.com\user:pass”) or a single space (” “) to leverage the currentThe Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky Securelist
· Jun 30, 2026
domainsysinternals.comshell . exe - Command "Invoke-WebRequest -Uri 'https://live.sysinternals[.]com/PsExec.exe' -OutFile 'C:\Temp\psexec.exe'" The ransomwareThe Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky Securelist
· Jun 30, 2026
domainaccounts.google.comto direct the browser to the following URL: 1 https [ : ] //accounts[.]google[.]com/o/oauth2/v2/auth/identifier?response_type=code&client_iHow the ToddyCat APT group gains access to Gmail accounts
Kaspersky Securelist
· Jun 30, 2026
domaincabsecnow.comation. Additionally, the hosting IP for the PlugX C2 domain cabsecnow[.]com was switched from 167.88.180[.]32 to 103.85.24[.]149 on ABack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainipsoftwarelabs.comng universities. This IP address currently hosts the domain ipsoftwarelabs[.]com, which was previously noted within reporting on activityBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainquochoice.comhttp://103.85.24[.]158/hk097.dat , before ultimately using quochoice[.]com for command and control. This domain is currently hostedBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainsysteminfor.comamples. When loaded into memory, the PlugX payload uses www.systeminfor[.]com for command and control — the same domain used across theBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domaincouldinstallup.comkeys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser proMustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The Hacker News
· Jun 29, 2026
domainfaq-whatsapp-center.comCenter using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishing and credential collection tha236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
The Hacker News
· Jun 29, 2026
domainwhats-zwp.vipsApp's Security Help Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishin236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
The Hacker News
· Jun 29, 2026
domainmitarchive.infoKoi Security has linked the credential exfiltration domain mitarchive.info to DarkSpectre , a Chinese operation previously connected tStegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
Security Affairs
· Jun 29, 2026
domaintrycloudflare.comare Tunnel hosted on the domain amsterdam-sheet-veteran-aka.trycloudflare[.]com. For its part, GammaLoad makes use of DNS-over-HTTPS ( DoHackers Leveraging Cloudflare Tunnels, DNS Fast
The Hacker News
· Jun 29, 2026
domainmitarchive.infoface on a known one. Its credential payload exfiltrates to mitarchive.info, a domain Koi Security ties to DarkSpectre , the Chinese opMicrosoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
The Hacker News
· Jun 29, 2026
domainweedhack.toCentral to the campaign is an enterprise-grade dashboard ("weedhack[.]to") that enables customers to view stolen credentials and sWeedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
The Hacker News
· Jun 29, 2026
domainallcryptotalk.netis IP address also hosted a defunct crypto news site called allcryptotalk[.]net, which has not posted new content since June 2015, and thShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domaincontraloria.gob.penetwork of the Comptroller General of the Republic of Peru (contraloria[.]gob[.]pe). As of April 25, 2022, the BlackByte ransomware operatLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domaindigimin.gob.pePeru that affected the General Directorate of Intelligence (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe)Latin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainfazenda.rj.gov.bre Secretary of State for Finance of Rio De Janeiro, Brazil (fazenda[.]rj[.]gov[.]br). Neither of these incidents were widely reported inLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainfodesaf.go.cro[.]cr), the Development Fund and Family Allowances Bureau (fodesaf[.]go[.]cr), and the Interuniversity Headquarters of Alajuela, CosLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainhacienda.go.crral Costa Rican entities including the Ministry of Finance (hacienda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[Latin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainmarine-chain.ioother site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. DomainShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainmef.gob.pe(digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe). Figure 3: Announcements of attacks on Costa Rican andLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainmtss.go.crenda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (foLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainquito.gob.ecromised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a goveLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.