Indicators of compromise
1,892 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | mtss.go.cr | enda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (fo | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | quito.gob.ec | romised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a gove | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | saludparatodos.ssm.gob.mx | to the Secretary of Health of the State of Morelos, Mexico (saludparatodos[.]ssm[.]gob[.]mx), a breach that was initially disclosed on or around | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | shipowner.io | owner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain registration histo | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | siua.ac.cr | d the Interuniversity Headquarters of Alajuela, Costa Rica (siua[.]ac[.]cr). Previous Conti posts also made vague references to co | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | www.marine-chain.io | le users and owners. Users on other forums pointed out that www[.]marine-chain[.]io was a near mirror image of another site, www[.]shipowne | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | www.shipowner.io | ]marine-chain[.]io was a near mirror image of another site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipow | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | clo4shara.xyz | eving the main payload at runtime from an external domain ("clo4shara[.]xyz/11z77u3.php"). This architecture offers added flexibility | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | com-apps.cc | ported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of "clo4shara[.]xyz/11z77u3.php"), | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | restrictes.com | ection point to two previously unreported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | web-telegram.ug | designed to achieve persistence and poll a remote server ("web-telegram[.]ug") every 30 seconds to process instructions issued by the | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | ackques.com | on port 80, as well as issuing POST requests to the <index.ackques[.]com> C2 server with the specific User-Agent, pictured below: | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | acques.com | ation about the victim system while POST requests to “index.acques[.]com/index.html” primarily uploaded zlib compressed files from | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | cheacker.store | a protected business document. The March 16 registration of cheacker[.]store suggests the domain was created for a short-lived phishin | Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Help Net Security | · Jun 26, 2026 |
| domain | hktechy.com | creating a separate thread with an open socket to the < www.hktechy[.]com> server on port 80, as well as issuing POST requests to t | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | internetdocss.com | s; however, malware from both campaigns made use of the doc.internetdocss[.]com C2 domain, thus tying both campaigns together. A maliciou | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | ukr.net | t had sent malicious emails to roughly one million users of Ukr.net, a widely used Ukrainian email service, and compromised mor | Pro-Russian hackers pose as Ukraine's cyber agency to target government, businesses The Record | · Jun 26, 2026 |
| domain | user.cheacker.store | ond-stage script from attacker-controlled infrastructure at user[.]cheacker[.]store,” the researchers explained. The second-stage phishing | Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Help Net Security | · Jun 26, 2026 |
| domain | market0day.com | cted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used to | ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories The Hacker News | · Jun 25, 2026 |
| domain | spoxy.us | istrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertis | ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories The Hacker News | · Jun 25, 2026 |
| domain | oleview.net | tub information, and method layouts registered on a system. OleView.NET , developed by James Forshaw, is particularly useful since | Introduction to COM usage by Windows threats Cisco Talos | · Jun 25, 2026 |
| domain | africa.truefact.news | p identified another domain hosted on 72[.]14[.]185[.]187 , africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has t | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | albertaseparatist.com | ntified at least two new CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was u | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | allstatesnews.us | ated content or have been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.] | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | capitalcitydaily.com | been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | chat.darkpulsar.ai | o websites worldwide, like a pulsar beacon.” In March 2025, chat[.]darkpulsar[.]ai also hosted an Open WebUI login page, likely intended f | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | clearstory.news | ryty[.]ru ) and previously identified CopyCop websites like clearstory[.]news . Other Truefact subdomains are identical to previously i | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | darkpulsar.ai | ts several of John Mark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websi | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | darkquasar.tech | d to Dougan’s freelancing projects, such as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page f | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | de.truefact.news | ing organization named “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[. | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | eu.com | esearchers at Gnida Project noted CopyCop’s use of several *eu[.]com domains to create inauthentic websites and promote influe | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | fldaily.news | media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | franceencolere.fr | arget the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in the Truefact cluster ar | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | france.truefact.news | .]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spai | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | fr.truefact.news | d “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexi | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | germany.truefact.news | uefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | greenarmenia.org | Party used to promote influence content targeting Armenia, greenarmenia[.]org . Insikt Group also identified several website registrati | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | insider.eu.com | inauthentic websites and promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identif | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | mexico.truefact.news | t[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukrain | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | ndc.eu.com | d promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identify any larger cluste | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | newsguard.tech | s registered a domain almost certainly targeting NewsGuard, newsguard[.]tech , named “News Guard Parody.” NewsGuard has previously cov | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | partiroyaliste.fr | to link older, unreported activity to CopyCop. For example, partiroyaliste[.]fr , an inauthentic website posing as a French royalist poli | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | proton.me | party first registered in August 2024 using partiroyaliste@proton[.]me, is likely linked to CopyCop. The website is hosted on th | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | reg.skryty.ru | LLMs. Figures 3 and 4 : Login form on darkquasar[.]tech and reg[.]skryty[.]ru (Left) and darkpulsar[.]ai (Right) (Source: URLscan 1 , | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | silvercity.news | statesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 we | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | skryty.com | ch as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page for “SKRYTY” and requiring a regis | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | skryty.ru | ark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websites like clearst | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | spain.truefact.news | t[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | torontojournal.ca | CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was used in July 2024 to | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | truefact.news | africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has the following nine subdomains, which began hosting Co | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | turkey.truefact.news | act[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | ukraine.truefact.news | act[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact[.]news is hosted on 89[.] | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | usatimes.news | pitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | veritecachee.fr | s previously used to target the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | video.darkpulsar.ai | i ) tied to a self-hosted PeerTube video hosting platform ( video[.]darkpulsar[.]ai ). In January 2025, darkpulsar[.]ai also briefly featur | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | wval.news | fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this writing, are repu | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | stitch-design.ai | ch SDK" by following the documentation at an external link, stitch-design.ai, a domain AIR controls, not Google (the real Stitch lives a | Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents The Hacker News | · Jun 23, 2026 |
| domain | stitch.withgoogle.com | a domain AIR controls, not Google (the real Stitch lives at stitch.withgoogle.com). At first, the link led to the genuine Stitch docs, so the | Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents The Hacker News | · Jun 23, 2026 |
| domain | nvidiadriver.net | downloaded a payload from a domain posing as a driver site, nvidiadriver[.]net. It downloaded a ZIP archive disguised as a Windows patch | Lookalike npm Package Hides a Multi Infosecurity Magazine | · Jun 23, 2026 |
| domain | nvidiadriver.net | or a next-stage payload retrieved from an external server ("nvidiadriver[.]net") using the "curl.exe." The retrieved payload is a ZIP ar | Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT The Hacker News | · Jun 23, 2026 |
| domain | stitch-production.org | on) and exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1"). A cluster of five packages ("procwire," "routec | Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT The Hacker News | · Jun 23, 2026 |
| domain | node-js.prentiva99.info | h engines like Google, redirecting them to a fake website ("node-js[.]prentiva99[.]info") surfaced via bogus ads published under the verified n | New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer The Hacker News | · Jun 23, 2026 |
| domain | 2faplugin.org | LC, tied to Russian-based entities. The exfiltration domain 2faplugin.org was updated on May 10th, about eleven days before the backd | ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates Security Affairs | · Jun 23, 2026 |
| domain | generate.2faplugin.org | the report. Attackers send the stolen passwords and 2FA to generate.2faplugin.org, a domain that blends in with legitimate two-factor traffic | ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates Security Affairs | · Jun 23, 2026 |
| domain | continuetogo.me | ential theft), but the apex domain used for the attack was “continuetogo[.]me”. This domain was referenced in a report by Google’s Thre | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | de-ma.online | ivity attributed to the Phosphorus APT in 2020. The domain “de-ma[.]online” underlined in Figure 4 has not had an active DNS “A” rec | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | fileskeeper.org | -related group named “Keeper” (due to the use of the domain fileskeeper[.]org to inject malicious JS into the website’s HTML code) was | Credit Card ‘Sniffers’ Pose Persistent Threat to Growing E Recorded Future | · Jun 23, 2026 |
| domain | litby.us | trolled infrastructure also included a fake URL shortener, “litby[.]us”. This suggests that TAG-56 operators prefer to acquire p | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.live | e 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected mailer-daemon[.]live 199.188.200[.]217 9 November 2021 Namecheap Privacy Prote | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.me | 162.0.232[.]252 11 October 2022 Namecheap Privacy Protected mailer-daemon[.]me 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailerdaemon.me | pen-source reporting reveals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members o | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon-message.co | eals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members of the Phosphorus APT group to lea | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.net | d, would redirect them to a URL with the apex domain name — mailer-daemon[.]net — where the spoofed registration page is hosted. Figure 1 | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.online | . Domain IP Address First Seen Registrar WHOIS Registration mailer-daemon[.]online 198.54.115[.]217 23 November 2022 Namecheap Privacy Prote | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.org | aming convention as mailer-daemon[.]net. All but 1 domain, “mailer-daemon[.]org”, use Namecheap's shared hosting services. The domain “ma | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | tinyurl.com | inyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]com), was identified as part of our research. The fake URL sh | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | tinyurl.ink | orded Future) The Fake URL Shortener A fake URL shortener, “tinyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.] | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | web-hosting.com | e October 11, 2022. The reverse DNS for 162.0.232[.]252 is “web-hosting[.]com”, which is associated with Namecheap's shared hosting ser | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | socradar.io | &CK mapping, IoC lists, and infrastructure breakdown, is at socradar.io . Follow me on Twitter: @securityaffairs and Facebook and M | FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential Security Affairs | · Jun 22, 2026 |
| domain | aliyuncs.com | p shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-s | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | amazonaws.com | ss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-southeast-1.amazonaws[.]com hksha3.s3.ap-southeast-1.amazonaws[.]com sjdkjj23.s3.ap-s | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | backblazeb2.com | .s3.ap-southeast-1.amazonaws[.]com caiwuascw.s3.us-east-005.backblazeb2[.]com facaia.s3.us-east-005.backblazeb2[.]com Attacker-controll | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | baoxis.cc | top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-a | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | baskwms.top | d0d01b75e04e784953c5e2b sleestak_payload_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one b | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | msopsa.top | b sleestak_payload_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | shaaslong.one | temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | shoppes.help | d_1.vbs Domains temu.baskwms[.]top invoice.msopsa[.]top qse.shoppes[.]help shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1 | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | ajb8.com | s to AryStinger’s C2 and download infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp | 4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware Security Affairs | · Jun 22, 2026 |
| domain | dataexplore.cc | nger’s C2 and download infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp/bin for binaries | 4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware Security Affairs | · Jun 22, 2026 |
| domain | dataexplore.co | d infrastructure, primarily ajb8.com , dataexplore.cc , and dataexplore.co hostnames. Check /tmp/bin for binaries you didn’t put there | 4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware Security Affairs | · Jun 22, 2026 |
| domain | ajb8.com | nd connections to AryStinger's C2 and download domains (the ajb8.com and related hosts in XLab's IOC list ), check /tmp/bin for | AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network The Hacker News | · Jun 22, 2026 |
| domain | securitydiscovery.com | dwide, and security researcher Volodymyr “Bob” Diachenko of SecurityDiscovery.com caught them only because they left their own infrastructure | FortiBleed Exposes Global Credential Security Affairs | · Jun 20, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.