ZeroHour

Indicators of compromise

270 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
md541444d7018601b599beac0c60ed1bf83dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago
md561e046145ee5cf45aeb033cd71e8b07cd5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago
md59a47c4d379998ade2f8f99e23a630c06a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago
md52ec37a7cc8daf20b10e1ad6221061ca5the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a faHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
SANS Internet Storm Center
· 14d ago
md53612f843a42db38f48f59d2a3597e19cd75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f843a42db38f48f59d2a3597e19c ” , algorithm =“ MD5 ” , qop =“ auth ” , nc = 00000001 , cnHome & Small Office Wireless Routers Exploited to Attack Gaming Servers
Palo Alto Unit 42
· Aug 18, 2026
md588645cefb1f9ede0e336e3569d75ee30“ dslf - config ” , realm =“ HuaweiHomeGateway ” , nonce =“ 88645cefb1f9ede0e336e3569d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f84Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
Palo Alto Unit 42
· Aug 18, 2026
md5f1c099d65bf94e009f5e65238caac46818b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de1076Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
Palo Alto Unit 42
· Aug 18, 2026
md5fb93601f8d4e0228276edff1c6fe635dtinuity. Indicators of Compromise Original JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07Home & Small Office Wireless Routers Exploited to Attack Gaming Servers
Palo Alto Unit 42
· Aug 18, 2026
md579ad2084b057847ce2ec2e48fda6407380154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-22 11:54:03 UTC One of the first modifPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
md5dd1876848203d9e10abceec07282ff37d using AES-128 and the following static key (hex-encoded): DD1876848203D9E10ABCEEC07282FF37 Conclusion The Patchwork group continues to plague victimsPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
md5e3e7e71a0b28b5e96cc492e636722f73cation with the C2 (note the additional forward slashes): //e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php In the event data is uploadedPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
md56fa5bcedaf124cdaccfa5548eed7f4b04d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md57c65565dcf5b40bd8358472d032bc8fb32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md5a5164c686c405734b7362bc6b02488cbf9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md5d5679158937ce288837efe62bc1d9693a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md57cc0b212d1b8ceb808c250495d83bae4remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md58d42c01180be7588a2a68ad96dd0cf85remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md5a1bdb1889d960e424920e57366662a59remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md576429f8515768f9f5def697e71071f51l 80386, for MS Windows Architecture : 32 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 775New Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
md5b5aa366f452feb9f4dff3c72157ca1f9LuO7bIWjRO5gjPNq:JarSKu6yzoF8rpAqXYv3XOgQLfnpLuOu imphash : b5aa366f452feb9f4dff3c72157ca1f9 Date : 0x5637227B [Mon Nov 2 08:44:43 2015 UTC] Language :New Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
md541ee612602833345fc5bd2b98103811chash value of the string, MD5("Test_PC0B0D040612345678") = 41EE612602833345FC5BD2B98103811C It then appends the volume serial to the hash value and getAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
md505d43d417a8f50e7b23246643fc7e03dAfter decryption, the following payload was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee06NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· Aug 17, 2026
md50f1d3ed85fee2acc23a8a26e0dc12e0ftion is provided after it is decrypted by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· Aug 17, 2026
md5a2fe5dcb08ae8b72e8bc98ddc0b918e7oject(20180108)\Final1stspy\LoadDll\Release\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c7NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· Aug 17, 2026
md5e02024f38dfb6290ce0d693539a285a9was identified. This file had the following properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c2NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· Aug 17, 2026
md53e4015366126dcdbdcc8b5c508a6d25cs For the analysis below, the following sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92bThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
md5a943e196b83c4acd9c5ce13e4c43b4f4l The downloaded CAB file has the following properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
md50304674e9876530dfbea5a9b4fec7b98Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 Additional C2 Servers: 0 GUID: '\xd6\x04hr\x9a\xedLN\xae\xeCardinal RAT Sins Again, Targets Israeli Fin
Palo Alto Unit 42
· Aug 17, 2026
md5723df0296951abd2aeed01361cec6b0d5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6Exploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md5082d49ef9f14e6811d68c7e0e82e5069IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entrOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md52a571f6cee42a17d873f4c942649813fogger located at C:\Users\Public\Pictures\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to runOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md532a5985543433a4f60da2fafd873b927tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s secOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md537dc84e4bcad92fa28f1e7778d088283rd Decryptor tool C:\users\[username]\libraries\64.exe (MD5 37dc84e4bcad92fa28f1e7778d088283 ) is used to extract passwords from browsers. The tool offeOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md545cf5916fab4272a1313c26e67aa9220executing the script located at C:\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the taskOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md54e6d5c4770d5a822d7fcce6a74f7ad73\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task’s status, the attacker triggers iOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md55e26df131ff0a679a0a2699b723b46e3ther C:\Users\[username]\1.bat or C:\ProgramData\1.bat (MD5 5e26df131ff0a679a0a2699b723b46e3). The task’s status is first queried, then it is executed,OctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md56ecf84fb18f6747ed08d7598364d853atch script located at C:\Users\<username>\Videos\1.bat (MD5 6ecf84fb18f6747ed08d7598364d853a ). Prior to executing the task, the actor queries its statuOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md5b874123a80fc4f40e06872b9cb54ebc6the batch script C:\Users\[username]\Desktop\auto.bat (MD5 b874123a80fc4f40e06872b9cb54ebc6 ). The script created a service named Cusrxsrv , which loadOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md5cf903e4a1629aa0582fd0363b5786676services. The executable is dropped to %TEMP%\fc.exe (MD5: cf903e4a1629aa0582fd0363b5786676) and writes its output to %TEMP%\result.txt . Using Fscan,OctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md5ded73d04bb3e3525226de64c38a332e36dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md518f61c6d686cffd131c9fd3f3437064bAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md525480dad40152ef3d0c6d38eecc9bd9bFF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F34New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md534a7f28e0bb69b0d49bacc88bdf20ac1D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 run.exe, run2.exe, genie.exe 5D62C1349B8981C396C9A23F4F8F05New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md534b8828635f88078735799a3c1ac8e284F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB3New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md53a4479b51890373bfc4a011ef41fe376D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux andNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md558c0dda52b8f069660166d61fd74f9117CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and ESXi 9201E35E2993612612919A3C7130New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md55d62c1349b8981c396c9a23f4f8f053cTrojan for Windows The Windows version of GenieLocker (MD5: 5d62c1349b8981c396c9a23f4f8f053c) is primarily written in C, but compiled with the C++ libraNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5780c8f4c6f077da4da965829879203620C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exeNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md57dad78584795aa5c160520cc6accf260E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5824ca1e906cc073ee5b0f3519df69a8f50DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ANew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59201e35e2993612612919a3c71302cabounterpart, the Linux and ESXi version of GenieLocker (MD5: 9201e35e2993612612919a3c71302cab) is simpler: there is no secret argument, anti‑debugging teNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59969a8221312dba70dd5cbddf83a146cF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59cd514ff2809ce0b993e3b8649e82a94C3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5a50eaaf514f4f84e61ca2455a8789753ntact: [email protected] . GenieLocker for Windows A50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5a8842616c9057d5cf6e1fe1fa8c3c160enie.exe 5D62C1349B8981C396C9A23F4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5b893eafed0659f70d4ac250f09073723221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5c68b6862725777651085650db34947fc8635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d3e06eb34d8eee7ef92cac3ad0a20ff516C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF280New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d661cf666b9acbab7cfeae1127a261a96E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F0696New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d87d0b01d95acc936b7dc47b8f41937aB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5de3cfbb50f66079bfee20a6f64e594336F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8FNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5f08f476f26b01d142ca73923de65fc0c50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5f7b9e36e94163a9a303160945f99267a064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5fd46a80c2f45577263328984edf7f4dcftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md542f847597109da2a220391bb09d00676e WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md55fa15ef96808ea82f0a6176f0bb4b386DBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md56038d42af0affd1fb263f470c0956f6b606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5a239e655709a2518dd0b7bdbed163679[email protected] . File hashes NightLedger backdoor A239E655709A2518DD0B7BDBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF968Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5ae628efa305387b633dce82f9364875btunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthreaMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5afb1c1583606599c7272cfb33cc6f498F96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F47Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5c832ecd135781b11f59e3fffb3d2b6acocess of threat hunting, we detected another variant ( MD5: C832ECD135781B11F59E3FFFB3D2B6AC ) that shares the same dynamic-resolve stub pattern. This vMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5c90f0efadbf322e5eb1c4103a38c30e6.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5d09b14a2fe01c7363ecc56f5d046162c.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5f7d36cc5904a53252d2bb3d21615134f6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – liMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5c99f29ac08454855b3d538960bb2f34fctive loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have beeTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
The Hacker News
· Jul 27, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5770dbe473180366d7b539ff2c188e551fd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5dbd8dbecaa80795c135137d69921fdba05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md519f8befcb035f52bf70094e6b4f5779a483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3BGoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md564e9d1950e42bc98486dfd9919463d1c95F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD5GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md57f223ee0716ce2ad56f55d37444194498486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5846ef7c1c7323849b2a778c5e4cda162E0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md593a1569d5d5ab2c4761fedf84f83709eB2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160[.]239 8.220.194[.]108 8.220.214[GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5cb6c4c70a3b171fa3404b8e1a33821166D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA356GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5cbbb6d483737ea3566726e51752dff40A3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5d08a059e8b815e3b891505bc8777fc28F70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5d6e86bf8a90e9b632add5fa495f97fbcA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D195GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5dc506ff7bb72735444fb3703a6bee6d8mise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5ebffd5a76aaa690bcdb922f82e0bacc5the future. Indicators of compromise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.