Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | grked.online | ySnake Stealer. The malware requests tunnel parameters from grked[.]online , receives an SSH private key and command string from the | AI-Generated Malware Powers New Armored Likho APT Campaign Security Affairs | · Jul 7, 2026 |
| domain | hospitalinstallation.com | ion DLL module ("n-HTCommp.dll") to contact the C2 server ("hospitalinstallation[.]com") and fetch additional post-exploitation modules on the f | Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations The Hacker News | · Jul 6, 2026 |
| domain | asp.net | tion module (CAV3RN_Http_Module) that uses a webshell-style ASP.NET handler, cac.aspx, hosted on a separate IIS server at one o | New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors Infosecurity Magazine | · Jul 6, 2026 |
| domain | hospitalinstallation.com | the root domain observed in the Cavern Manticore campaign, hospitalinstallation[.]com, showed that it was registered through Fars Data, an Iran | New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors Infosecurity Magazine | · Jul 6, 2026 |
| domain | debank.auction | ralized finance portfolio tracker. The fraudulent domain is debank[.]auction. “The fraudulent website is optimized to rank for DeBank- | Hidden Web Prompts Trick AI Agents Into Sending Money Security Affairs | · Jul 6, 2026 |
| domain | booking.com | y has been attributed to an Indonesian-origin threat actor. Booking.com Partner Firms Targeted in TONResolver Campaign — Attackers | ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More The Hacker News | · Jul 6, 2026 |
| domain | cacoo.com | nfrastructure. The proxy link routes through the legitimate Cacoo.com domain before redirecting to the phishing site Translated f | When checking the URL isn't enough: phishing via the Microsoft identity platform Kaspersky Securelist | · Jul 6, 2026 |
| domain | checkmarx.zone | also includes 27 file hashes and a set of domains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hac | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| domain | git-tanstack.com | domains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, among others. The indicat | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| domain | hackmoltrepeat.com | ]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, among others. The indicators in this alert are derived f | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| domain | litellm.cloud | hes and a set of domains including checkmarx[.]zone, models.litellm[.]cloud, git-tanstack[.]com, and recv.hackmoltrepeat[.]com, among | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| domain | groq.com | tor message is forwarded to a public LLM API endpoint ("api.groq[.]com/openai/v1/chat/completions"), which then translates the n | New Avalon Malware Framework Packs CrownX Ransomware Capabilities The Hacker News | · Jul 3, 2026 |
| domain | helloxcherry.com | s cpassword artifacts. Exfiltrate data to a remote server ("helloxcherry[.]com") and poll the server for receiving tasking commands. Per | New Avalon Malware Framework Packs CrownX Ransomware Capabilities The Hacker News | · Jul 3, 2026 |
| domain | proton.me | ess 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy, contact e78393397[@]proton[.]me, and the ransom table name README_RANSOM, which doesn’t m | JADEPUFFER: First End-to-End AI Security Affairs | · Jul 3, 2026 |
| domain | context.ai | rty software supply chain compromise. An AI tooling vendor, Context.ai, was breached via an employee account, allowing attackers t | The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident Security Affairs | · Jul 3, 2026 |
| domain | avenger-sync.live | ted and exfiltrated to attacker-controlled infrastructure ("avenger-sync[.]live") over an outbound HTTP request. Besides coercing the use | PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords The Hacker News | · Jul 3, 2026 |
| domain | maccy.app | is a lookalike site ("maccyapp[.]com") that mimics Maccy ("maccy[.]app"). The AppleScript ("Maccy.scpt") present within the disk | PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords The Hacker News | · Jul 3, 2026 |
| domain | maccyapp.com | initial access vector for the malware is a lookalike site ("maccyapp[.]com") that mimics Maccy ("maccy[.]app"). The AppleScript ("Ma | PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords The Hacker News | · Jul 3, 2026 |
| domain | maccyapp.net | fake websites impersonating Maccy. Malicious sites (such as maccyapp[.]net and maccyapp[.]com) distribute malware disguised as Maccy | PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords The Hacker News | · Jul 3, 2026 |
| domain | netnut.com | and seized hundreds of domains. Banner shown when visiting netnut.com. Source: Infosecurity Magazine How the Popa Botnet Turned S | FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors Infosecurity Magazine | · Jul 3, 2026 |
| domain | netnut.io | appeared on netnut.com, NetNut’s primary commercial domain, netnut.io, temporarily remained active and accessible. Some online co | FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors Infosecurity Magazine | · Jul 3, 2026 |
| domain | blogspot.com | ng a next-stage payload hosted on Blogger ("htlwub00klocate.blogspot[.]com"), allowing the attackers to bypass reputation-based defe | VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer The Hacker News | · Jul 3, 2026 |
| domain | alarum.io | July 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The co | FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security | · Jul 2, 2026 |
| domain | google.com | orization code request to direct the browser to a "accounts.google[.]com/o/oauth2/v2/auth/identifier" URL containing a "client_id" | ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The Hacker News | · Jul 2, 2026 |
| domain | proton.me | ss: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy; contact e78393397[@]proton[.]me; ransom table named README_RANSOM Sysdig calls JADEPUFFER | AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack The Hacker News | · Jul 2, 2026 |
| domain | mora1987.work | malware then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infec | SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT The Hacker News | · Jul 1, 2026 |
| domain | work.gd | then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infected | SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT The Hacker News | · Jul 1, 2026 |
| domain | rentry.co | or serverless workers. These include - Telegra.ph Teletype Rentry.co Write.as Dropbox GoFile DEV Community (dev.to) Mastodon Les | Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Hacker News | · Jul 1, 2026 |
| domain | socket.io | connects to attacker-controlled infrastructure, launches a socket.io backdoor, and eventually deploys a Python infostealer. The | Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer The Hacker News | · Jul 1, 2026 |
| domain | duckdns.org | C2 domains lean on free dynamic DNS services, specifically duckdns.org, which is where the name comes from. Once a device checks i | RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow Security Affairs | · Jul 1, 2026 |
| domain | pamconj.com | gagement, we identified a management panel at “dashboard-bl.pamconj[.]com” serving a React single-page application (SPA) with a 1.7 | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | sharepoint.com | he vendor's genuine SharePoint tenant: “https[:]//mononapfp.sharepoint[.]com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYv | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | workers.dev | flare Workers accounts including “clear90489058903-document.workers[.]dev”. Linking ARToken to EvilTokens The connection between AR | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | babybon.cfd | e payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does no | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | comicstar.lat | also listed three payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | merkantalolol.asia | ers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does not prove infection. It | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | atlasregister.net | ty of the domains registered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]ne | Cyber Recorded Future | · Jul 1, 2026 |
| domain | atlasregister.org | gistered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.bj | e and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org g | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.co | ng the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.in | are operated by the same threat actors: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 202 | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.net | e Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original investigation. Resear | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.org | flags and impersonating the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included | Cyber Recorded Future | · Jul 1, 2026 |
| domain | bma.gov.bj | files shared by three of the Oceaniek-attributed websites ( bma[.]gov[.]bj, beninmaritime[.]net , and beninmaritime[.]bj) and four | Cyber Recorded Future | · Jul 1, 2026 |
| domain | cadredevie.gouv.bj | s part of the Ministère du Cadre de Vie et des Transports ( cadredevie[.]gouv[.]bj ). The three inauthentic Benin Maritime Administration | Cyber Recorded Future | · Jul 1, 2026 |
| domain | epnicaragua.com | atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net | Cyber Recorded Future | · Jul 1, 2026 |
| domain | epnicaragua.org | rg beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]o | Cyber Recorded Future | · Jul 1, 2026 |
| domain | gouv.bj | real email address listed for Benin on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screens | Cyber Recorded Future | · Jul 1, 2026 |
| domain | gove.bj | ]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links t | Cyber Recorded Future | · Jul 1, 2026 |
| domain | guve.bj | on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screenshot from the Benin Maritime Administ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | hellasnaval.net | Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticac | Cyber Recorded Future | · Jul 1, 2026 |
| domain | imsag.org | a website impersonating a Guyanese maritime administration, imsag[.]org . The CENM websites claim that they provide IMO-mandated | Cyber Recorded Future | · Jul 1, 2026 |
| domain | isithin.com | p IP range as Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medll | Cyber Recorded Future | · Jul 1, 2026 |
| domain | malawi.marinegov.org | ral subdomains impersonating Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By defaul | Cyber Recorded Future | · Jul 1, 2026 |
| domain | malawi.shipregistry.marinegov.org | Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By default, the latter displays a page showing ship | Cyber Recorded Future | · Jul 1, 2026 |
| domain | marinegov.net | er of fraudulent ship registries centered around the domain marinegov[.]net. This activity also aligns with prior reporting from inde | Cyber Recorded Future | · Jul 1, 2026 |
| domain | marinegov.org | ins, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com naut | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.online | link to another domain hosted on different infrastructure, medlloyd[.]online . This domain is co-hosted on 159[.]198[.]36[.]123 with t | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.online.beninmaritime.net | ubdomain on the Cluster Alpha website beninmaritime[.]net , medlloyd[.]online[.]beninmaritime[.]net , indicates a link to another domain hosted on differ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.org | n[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry mari | Cyber Recorded Future | · Jul 1, 2026 |
| domain | nauticacentro.com | aval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has seve | Cyber Recorded Future | · Jul 1, 2026 |
| domain | nauticacentro.mx | [.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has several subdomains impe | Cyber Recorded Future | · Jul 1, 2026 |
| domain | niataregister.net | net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt | Cyber Recorded Future | · Jul 1, 2026 |
| domain | niataregister.org | m epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt Group identified PD | Cyber Recorded Future | · Jul 1, 2026 |
| domain | oceaniektechnologies.com | l as document authors and creators. Oceaniek Technologies ( oceaniektechnologies[.]com ) is an Indian web development company listed throughout | Cyber Recorded Future | · Jul 1, 2026 |
| domain | palaureg.com | ata for similar PDFs distributed on PISR’s official website palaureg[.]com , which likely indicates that the operators behind epnica | Cyber Recorded Future | · Jul 1, 2026 |
| domain | pamconj.com | los published the operation’s domains and addresses, led by pamconj[.]com, for defenders to hunt on. | The ARToken phishing panel targets Microsoft 365 accounts Help Net Security | · Jul 1, 2026 |
| domain | pdf.beninmaritime.co | beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Certificate PDF Generator” ( Figure 3 ). F | Cyber Recorded Future | · Jul 1, 2026 |
| domain | registry.zmgov.org | : beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | thesecure.biz | int about spam from “thesecure.biz,” is itself an artefact: thesecure.biz is the encrypted Jabber server Europol later said the arres | XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn't Security Affairs | · Jun 30, 2026 |
| domain | duckdns.org | he control addresses lean on free dynamic-DNS services like duckdns.org, which is where the "Duck" in the name comes from. This fit | RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS The Hacker News | · Jun 30, 2026 |
| domain | internal.corp.com | /page?ref=youtube.com bank.example.com/search?q=youtube.com internal.corp.com/redirect?from=youtube.com "The concern is not a single susp | Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability The Hacker News | · Jun 30, 2026 |
| domain | ipinfo.io | s wiped from the file system. It further sends a request to ipinfo[.]io to obtain the host's public IP address and location, allo | Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints The Hacker News | · Jun 30, 2026 |
| domain | perplexity-ai.online | bkiofojicogddingbdmcmkpbplcd) and used a look-alike domain, perplexity-ai[.]online, to pass for the real service at perplexity.ai. Microsoft | Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input The Hacker News | · Jun 30, 2026 |
| domain | dev-tunnels.com | ablishing encrypted communications with a remote server ("a.dev-tunnels[.]com"), and retrieving and executing additional JavaScript pay | Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer The Hacker News | · Jun 30, 2026 |
| domain | booking.com | Cyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails that | Hackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com Infosecurity Magazine | · Jun 30, 2026 |
| domain | domain.com | Lateral movement flag using specified domain credentials (“domain.com\user:pass”) or a single space (” “) to leverage the current | The Gentlemen RaaS: rapid growth and a new ransomware variant Kaspersky Securelist | · Jun 30, 2026 |
| domain | sysinternals.com | shell . exe - Command "Invoke-WebRequest -Uri 'https://live.sysinternals[.]com/PsExec.exe' -OutFile 'C:\Temp\psexec.exe'" The ransomware | The Gentlemen RaaS: rapid growth and a new ransomware variant Kaspersky Securelist | · Jun 30, 2026 |
| domain | accounts.google.com | to direct the browser to the following URL: 1 https [ : ] //accounts[.]google[.]com/o/oauth2/v2/auth/identifier?response_type=code&client_i | How the ToddyCat APT group gains access to Gmail accounts Kaspersky Securelist | · Jun 30, 2026 |
| domain | cabsecnow.com | ation. Additionally, the hosting IP for the PlugX C2 domain cabsecnow[.]com was switched from 167.88.180[.]32 to 103.85.24[.]149 on A | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | ipsoftwarelabs.com | ng universities. This IP address currently hosts the domain ipsoftwarelabs[.]com, which was previously noted within reporting on activity | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | quochoice.com | http://103.85.24[.]158/hk097.dat , before ultimately using quochoice[.]com for command and control. This domain is currently hosted | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | systeminfor.com | amples. When loaded into memory, the PlugX payload uses www.systeminfor[.]com for command and control — the same domain used across the | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | couldinstallup.com | keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser pro | Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The Hacker News | · Jun 29, 2026 |
| domain | faq-whatsapp-center.com | Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishing and credential collection tha | 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers The Hacker News | · Jun 29, 2026 |
| domain | whats-zwp.vip | sApp's Security Help Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishin | 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers The Hacker News | · Jun 29, 2026 |
| domain | mitarchive.info | Koi Security has linked the credential exfiltration domain mitarchive.info to DarkSpectre , a Chinese operation previously connected t | StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years Security Affairs | · Jun 29, 2026 |
| domain | trycloudflare.com | are Tunnel hosted on the domain amsterdam-sheet-veteran-aka.trycloudflare[.]com. For its part, GammaLoad makes use of DNS-over-HTTPS ( Do | Hackers Leveraging Cloudflare Tunnels, DNS Fast The Hacker News | · Jun 29, 2026 |
| domain | mitarchive.info | face on a known one. Its credential payload exfiltrates to mitarchive.info, a domain Koi Security ties to DarkSpectre , the Chinese op | Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts The Hacker News | · Jun 29, 2026 |
| domain | weedhack.to | Central to the campaign is an enterprise-grade dashboard ("weedhack[.]to") that enables customers to view stolen credentials and s | Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content The Hacker News | · Jun 29, 2026 |
| domain | allcryptotalk.net | is IP address also hosted a defunct crypto news site called allcryptotalk[.]net, which has not posted new content since June 2015, and th | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | contraloria.gob.pe | network of the Comptroller General of the Republic of Peru (contraloria[.]gob[.]pe). As of April 25, 2022, the BlackByte ransomware operat | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | digimin.gob.pe | Peru that affected the General Directorate of Intelligence (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe) | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | fazenda.rj.gov.br | e Secretary of State for Finance of Rio De Janeiro, Brazil (fazenda[.]rj[.]gov[.]br). Neither of these incidents were widely reported in | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | fodesaf.go.cr | o[.]cr), the Development Fund and Family Allowances Bureau (fodesaf[.]go[.]cr), and the Interuniversity Headquarters of Alajuela, Cos | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | hacienda.go.cr | ral Costa Rican entities including the Ministry of Finance (hacienda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[ | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | marine-chain.io | other site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | mef.gob.pe | (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe). Figure 3: Announcements of attacks on Costa Rican and | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | mtss.go.cr | enda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (fo | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | quito.gob.ec | romised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a gove | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.