ZeroHour

Indicators of compromise

4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv47.2.11.1.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.4.7.111.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.6.5.1.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.7.12.1.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
md518f61c6d686cffd131c9fd3f3437064bAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md525480dad40152ef3d0c6d38eecc9bd9bFF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F34New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md534a7f28e0bb69b0d49bacc88bdf20ac1D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 run.exe, run2.exe, genie.exe 5D62C1349B8981C396C9A23F4F8F05New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md534b8828635f88078735799a3c1ac8e284F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB3New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md53a4479b51890373bfc4a011ef41fe376D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux andNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md558c0dda52b8f069660166d61fd74f9117CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and ESXi 9201E35E2993612612919A3C7130New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md55d62c1349b8981c396c9a23f4f8f053cTrojan for Windows The Windows version of GenieLocker (MD5: 5d62c1349b8981c396c9a23f4f8f053c) is primarily written in C, but compiled with the C++ libraNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5780c8f4c6f077da4da965829879203620C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exeNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md57dad78584795aa5c160520cc6accf260E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5824ca1e906cc073ee5b0f3519df69a8f50DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ANew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59201e35e2993612612919a3c71302cabounterpart, the Linux and ESXi version of GenieLocker (MD5: 9201e35e2993612612919a3c71302cab) is simpler: there is no secret argument, anti‑debugging teNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59969a8221312dba70dd5cbddf83a146cF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md59cd514ff2809ce0b993e3b8649e82a94C3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5a50eaaf514f4f84e61ca2455a8789753ntact: [email protected] . GenieLocker for Windows A50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5a8842616c9057d5cf6e1fe1fa8c3c160enie.exe 5D62C1349B8981C396C9A23F4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5b893eafed0659f70d4ac250f09073723221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5c68b6862725777651085650db34947fc8635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d3e06eb34d8eee7ef92cac3ad0a20ff516C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF280New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d661cf666b9acbab7cfeae1127a261a96E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F0696New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5d87d0b01d95acc936b7dc47b8f41937aB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5de3cfbb50f66079bfee20a6f64e594336F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8FNew GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5f08f476f26b01d142ca73923de65fc0c50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5f7b9e36e94163a9a303160945f99267a064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
md5fd46a80c2f45577263328984edf7f4dcftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987New GenieLocker ransomware for Windows, ESXi, and Linux
Kaspersky Securelist
· Jul 30, 2026
domainnpmjs.storen XOR cipher keyed to 01042025 . The network indicators are npmjs[.]store and 216[.]74[.]123[.]126 . Amazon's post cites the OSV reAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
The Hacker News
· Jul 30, 2026
domainagrocenter-eurohem.rut where the scammers had created a fraudulent website ("www.agrocenter-eurohem[.]ru") that was a near-perfect virtual copy of the legitimateNine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
The Hacker News
· Jul 29, 2026
domain110gongan.comune 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal paymentFlying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The Hacker News
· Jul 29, 2026
domainlogin.trees4sale.netnode reports its status to a heartbeat collection server at login.trees4sale.net:9000, sending a JSON health report with connection count anDysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Security Affairs
· Jul 28, 2026
sha13b4f44d8e3d9d5de35127b42dd449babe2d19fe5he main branches of both LuCI and uhttpd, using LuCI commit 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdcCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The Hacker News
· Jul 28, 2026
sha17b1bec45826bd78c8afc993435bdc0f1df2fe3999d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc0f1df2fe399 from June 13. It described three as pre-authentication pathCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The Hacker News
· Jul 28, 2026
domainaecert.orgfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealthMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbuisness-centeral-transportation.comhshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-deegital.azurewebsites.netlobal-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessdeegital.azurewebsites.netness-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]comMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-deegital.combusinessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessmixture.comPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusiness-startup.azurewebsites.netalthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]netMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainbusinessstartup.azurewebsites.net]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]netMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainglobal-reds.comPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegiMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoom-centeral.azurewebsites.netthehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcareMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoomcenteral.azurewebsites.netrtation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhealthcarezoomcenteral.orgwebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azureMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainmaadinglobal.comazurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.azurewebsites.net]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.coml[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainneexportfolio.eastus.cloudapp.azure.comnet neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]cMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainrealhealthshop.comGET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallbackMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainsmartconnect.azurewebsites.net14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainthehealth-life.comecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-cenMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domaintjconsultingservices.comerfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2. When a valid C2 response is received, tMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domaintoadreport.azurewebsites.netcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md542f847597109da2a220391bb09d00676e WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md55fa15ef96808ea82f0a6176f0bb4b386DBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md56038d42af0affd1fb263f470c0956f6b606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5a239e655709a2518dd0b7bdbed163679[email protected] . File hashes NightLedger backdoor A239E655709A2518DD0B7BDBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF968Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5ae628efa305387b633dce82f9364875btunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthreaMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5afb1c1583606599c7272cfb33cc6f498F96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F47Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5c832ecd135781b11f59e3fffb3d2b6acocess of threat hunting, we detected another variant ( MD5: C832ECD135781B11F59E3FFFB3D2B6AC ) that shares the same dynamic-resolve stub pattern. This vMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5c90f0efadbf322e5eb1c4103a38c30e6.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5d09b14a2fe01c7363ecc56f5d046162c.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsitesMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
md5f7d36cc5904a53252d2bb3d21615134f6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – liMirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools
Kaspersky Securelist
· Jul 28, 2026
domainhunt.iol prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructu⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
The Hacker News
· Jul 28, 2026
ipv4206.72.242.124iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators shoulAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv4206.72.242.162determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators should preserve VCOAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv45.2.3.14llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prioAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv46.1.3.4.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prioAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv46.4.2.46.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged thaAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv47.0.0.16.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally dAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv48.19.75.217them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected,Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv451.89.204.28ative networking functions, and the command server address, 51.89.204.28 on port 4444, is baked directly into the binary rather thanMedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
Security Affairs
· Jul 27, 2026
domain24carnforth2merseyside.sol]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample asDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainburrberry.ethat resolves C2 through the same domain. XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainm3rnbvs5d.ethator falling back to an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2). XLab's Dysphoria timelineDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Hacker News
· Jul 27, 2026
domainpurelogicbox.orgd decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the conMalvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
The Hacker News
· Jul 27, 2026
domaincorychase.orgd policy, and directed users to a live PHP phishing page on corychase[.]org," the company said . "The landing page was not a MicrosofOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domaingithub.iodev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.github[.]io") and a repository named "Bluedashltd" that contains theOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainsupport.berrydev.xyzlow." Further analysis of the threat actor infrastructure ("support[.]berrydev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.githuOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainteamvem.comt published last week. The bogus Teams page in question is "teamvem[.]com." The active download is used to deliver "supportdev.exe,Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
The Hacker News
· Jul 27, 2026
domainhunt.iowords and interact with specific internal systems. Although Hunt.io found evidence that the attackers had already compromised mHackers used autonomous AI agent to spy on Thailand's finance ministry
The Record
· Jul 27, 2026
domainhypersnet.comlant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise acTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
The Hacker News
· Jul 27, 2026
md5c99f29ac08454855b3d538960bb2f34fctive loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have beeTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
The Hacker News
· Jul 27, 2026
domainchatgpt.comof a phishing link that adheres to the following pattern: "chatgpt[.]com/agents/studio/new?template_name=[template name]&initial_aChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
The Hacker News
· Jul 27, 2026
ipv48.8.8.8people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptopHackers Hijack Hotel Wi
Security Affairs
· Jul 26, 2026
domainclaude.ais). How attackers hosted a fake Claude download page on the claude.ai domain A threat actor abused Anthropic’s Claude Artifacts fWeek in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
Help Net Security
· Jul 26, 2026
ipv4104.194.9.14.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 21CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4104.243.35.131associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.2CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4104.243.35.63185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control address) Web shelCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4172.111.38.31icators of compromise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4185.227.83.236.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4209.222.98.445.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4216.152.148.54promise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4216.152.151.20414 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control addCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv438.60.157.212/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker commandCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv45.180.41.35- 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 7CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv474.50.76.146the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv478.128.113.105 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (AtCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.