ZeroHour

Indicators of compromise

1,892 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainmtss.go.crenda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (foLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainquito.gob.ecromised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a goveLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainsaludparatodos.ssm.gob.mxto the Secretary of Health of the State of Morelos, Mexico (saludparatodos[.]ssm[.]gob[.]mx), a breach that was initially disclosed on or aroundLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainshipowner.ioowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain registration histoShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainsiua.ac.crd the Interuniversity Headquarters of Alajuela, Costa Rica (siua[.]ac[.]cr). Previous Conti posts also made vague references to coLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainwww.marine-chain.iole users and owners. Users on other forums pointed out that www[.]marine-chain[.]io was a near mirror image of another site, www[.]shipowneShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainwww.shipowner.io]marine-chain[.]io was a near mirror image of another site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainclo4shara.xyzeving the main payload at runtime from an external domain ("clo4shara[.]xyz/11z77u3.php"). This architecture offers added flexibilityGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domaincom-apps.ccported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of "clo4shara[.]xyz/11z77u3.php"),Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainrestrictes.comection point to two previously unreported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead ofGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainweb-telegram.ugdesigned to achieve persistence and poll a remote server ("web-telegram[.]ug") every 30 seconds to process instructions issued by theGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainackques.comon port 80, as well as issuing POST requests to the <index.ackques[.]com> C2 server with the specific User-Agent, pictured below:RedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domainacques.comation about the victim system while POST requests to “index.acques[.]com/index.html” primarily uploaded zlib compressed files fromRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domaincheacker.storea protected business document. The March 16 registration of cheacker[.]store suggests the domain was created for a short-lived phishinMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Help Net Security
· Jun 26, 2026
domainhktechy.comcreating a separate thread with an open socket to the < www.hktechy[.]com> server on port 80, as well as issuing POST requests to tRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domaininternetdocss.coms; however, malware from both campaigns made use of the doc.internetdocss[.]com C2 domain, thus tying both campaigns together. A maliciouRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domainukr.nett had sent malicious emails to roughly one million users of Ukr.net, a widely used Ukrainian email service, and compromised morPro-Russian hackers pose as Ukraine's cyber agency to target government, businesses
The Record
· Jun 26, 2026
domainuser.cheacker.storeond-stage script from attacker-controlled infrastructure at user[.]cheacker[.]store,” the researchers explained. The second-stage phishingMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Help Net Security
· Jun 26, 2026
domainmarket0day.comcted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used toThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
The Hacker News
· Jun 25, 2026
domainspoxy.usistrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertisThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
The Hacker News
· Jun 25, 2026
domainoleview.nettub information, and method layouts registered on a system. OleView.NET , developed by James Forshaw, is particularly useful sinceIntroduction to COM usage by Windows threats
Cisco Talos
· Jun 25, 2026
domainafrica.truefact.newsp identified another domain hosted on 72[.]14[.]185[.]187 , africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has tCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainalbertaseparatist.comntified at least two new CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was uCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainallstatesnews.usated content or have been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaincapitalcitydaily.combeen mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news ,CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainchat.darkpulsar.aio websites worldwide, like a pulsar beacon.” In March 2025, chat[.]darkpulsar[.]ai also hosted an Open WebUI login page, likely intended fCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainclearstory.newsryty[.]ru ) and previously identified CopyCop websites like clearstory[.]news . Other Truefact subdomains are identical to previously iCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaindarkpulsar.aits several of John Mark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaindarkquasar.techd to Dougan’s freelancing projects, such as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page fCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainde.truefact.newsing organization named “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaineu.comesearchers at Gnida Project noted CopyCop’s use of several *eu[.]com domains to create inauthentic websites and promote influeCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfldaily.newsmedia so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news .CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfranceencolere.frarget the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in the Truefact cluster arCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfrance.truefact.news.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spaiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfr.truefact.newsd “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaingermany.truefact.newsuefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkeyCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaingreenarmenia.orgParty used to promote influence content targeting Armenia, greenarmenia[.]org . Insikt Group also identified several website registratiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaininsider.eu.cominauthentic websites and promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identifCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainmexico.truefact.newst[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukrainCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainndc.eu.comd promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identify any larger clusteCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainnewsguard.techs registered a domain almost certainly targeting NewsGuard, newsguard[.]tech , named “News Guard Parody.” NewsGuard has previously covCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainpartiroyaliste.frto link older, unreported activity to CopyCop. For example, partiroyaliste[.]fr , an inauthentic website posing as a French royalist poliCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainproton.meparty first registered in August 2024 using partiroyaliste@proton[.]me, is likely linked to CopyCop. The website is hosted on thCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainreg.skryty.ruLLMs. Figures 3 and 4 : Login form on darkquasar[.]tech and reg[.]skryty[.]ru (Left) and darkpulsar[.]ai (Right) (Source: URLscan 1 ,CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainsilvercity.newsstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 weCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainskryty.comch as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page for “SKRYTY” and requiring a regisCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainskryty.ruark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websites like clearstCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainspain.truefact.newst[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news TheCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaintorontojournal.caCopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was used in July 2024 toCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaintruefact.newsafrica[.]truefact[.]news . First registered in March 2025, truefact[.]news has the following nine subdomains, which began hosting CoCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainturkey.truefact.newsact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefactCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainukraine.truefact.newsact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact[.]news is hosted on 89[.]CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainusatimes.newspitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of thisCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainveritecachee.frs previously used to target the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites inCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainvideo.darkpulsar.aii ) tied to a self-hosted PeerTube video hosting platform ( video[.]darkpulsar[.]ai ). In January 2025, darkpulsar[.]ai also briefly featurCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainwval.newsfldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this writing, are repuCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainstitch-design.aich SDK" by following the documentation at an external link, stitch-design.ai, a domain AIR controls, not Google (the real Stitch lives aFake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
The Hacker News
· Jun 23, 2026
domainstitch.withgoogle.coma domain AIR controls, not Google (the real Stitch lives at stitch.withgoogle.com). At first, the link led to the genuine Stitch docs, so theFake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
The Hacker News
· Jun 23, 2026
domainnvidiadriver.netdownloaded a payload from a domain posing as a driver site, nvidiadriver[.]net. It downloaded a ZIP archive disguised as a Windows patchLookalike npm Package Hides a Multi
Infosecurity Magazine
· Jun 23, 2026
domainnvidiadriver.netor a next-stage payload retrieved from an external server ("nvidiadriver[.]net") using the "curl.exe." The retrieved payload is a ZIP arMalicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
The Hacker News
· Jun 23, 2026
domainstitch-production.orgon) and exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1"). A cluster of five packages ("procwire," "routecMalicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
The Hacker News
· Jun 23, 2026
domainnode-js.prentiva99.infoh engines like Google, redirecting them to a fake website ("node-js[.]prentiva99[.]info") surfaced via bogus ads published under the verified nNew OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
The Hacker News
· Jun 23, 2026
domain2faplugin.orgLC, tied to Russian-based entities. The exfiltration domain 2faplugin.org was updated on May 10th, about eleven days before the backdShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
Security Affairs
· Jun 23, 2026
domaingenerate.2faplugin.orgthe report. Attackers send the stolen passwords and 2FA to generate.2faplugin.org, a domain that blends in with legitimate two-factor trafficShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
Security Affairs
· Jun 23, 2026
domaincontinuetogo.meential theft), but the apex domain used for the attack was “continuetogo[.]me”. This domain was referenced in a report by Google’s ThreSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainde-ma.onlineivity attributed to the Phosphorus APT in 2020. The domain “de-ma[.]online” underlined in Figure 4 has not had an active DNS “A” recSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainfileskeeper.org-related group named “Keeper” (due to the use of the domain fileskeeper[.]org to inject malicious JS into the website’s HTML code) wasCredit Card ‘Sniffers’ Pose Persistent Threat to Growing E
Recorded Future
· Jun 23, 2026
domainlitby.ustrolled infrastructure also included a fake URL shortener, “litby[.]us”. This suggests that TAG-56 operators prefer to acquire pSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.livee 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected mailer-daemon[.]live 199.188.200[.]217 9 November 2021 Namecheap Privacy ProteSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.me162.0.232[.]252 11 October 2022 Namecheap Privacy Protected mailer-daemon[.]me 199.188.200[.]217 31 May 2022 Namecheap Privacy ProtectedSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailerdaemon.mepen-source reporting reveals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members oSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon-message.coeals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members of the Phosphorus APT group to leaSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.netd, would redirect them to a URL with the apex domain name — mailer-daemon[.]net — where the spoofed registration page is hosted. Figure 1Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.online. Domain IP Address First Seen Registrar WHOIS Registration mailer-daemon[.]online 198.54.115[.]217 23 November 2022 Namecheap Privacy ProteSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.orgaming convention as mailer-daemon[.]net. All but 1 domain, “mailer-daemon[.]org”, use Namecheap's shared hosting services. The domain “maSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domaintinyurl.cominyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]com), was identified as part of our research. The fake URL shSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domaintinyurl.inkorded Future) The Fake URL Shortener A fake URL shortener, “tinyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainweb-hosting.come October 11, 2022. The reverse DNS for 162.0.232[.]252 is “web-hosting[.]com”, which is associated with Namecheap's shared hosting serSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainsocradar.io&CK mapping, IoC lists, and infrastructure breakdown, is at socradar.io . Follow me on Twitter: @securityaffairs and Facebook and MFortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential
Security Affairs
· Jun 22, 2026
domainaliyuncs.comp shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-sAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainamazonaws.comss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-southeast-1.amazonaws[.]com hksha3.s3.ap-southeast-1.amazonaws[.]com sjdkjj23.s3.ap-sAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainbackblazeb2.com.s3.ap-southeast-1.amazonaws[.]com caiwuascw.s3.us-east-005.backblazeb2[.]com facaia.s3.us-east-005.backblazeb2[.]com Attacker-controllAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainbaoxis.cctop invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-aAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainbaskwms.topd0d01b75e04e784953c5e2b sleestak_payload_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one bAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainmsopsa.topb sleestak_payload_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwesAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainshaaslong.onetemu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]comAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainshoppes.helpd_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1An unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainajb8.coms to AryStinger’s C2 and download infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
Security Affairs
· Jun 22, 2026
domaindataexplore.ccnger’s C2 and download infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp/bin for binaries4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
Security Affairs
· Jun 22, 2026
domaindataexplore.cod infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp/bin for binaries you didn’t put there4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
Security Affairs
· Jun 22, 2026
domainajb8.comnd connections to AryStinger's C2 and download domains (the ajb8.com and related hosts in XLab's IOC list ), check /tmp/bin forAryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
The Hacker News
· Jun 22, 2026
domainsecuritydiscovery.comdwide, and security researcher Volodymyr “Bob” Diachenko of SecurityDiscovery.com caught them only because they left their own infrastructureFortiBleed Exposes Global Credential
Security Affairs
· Jun 20, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.