ZeroHour

Indicators of compromise

4,251 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fD001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taCatan and Mouse
Cisco Talos
· Jul 2, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taCatan and Mouse
Cisco Talos
· Jul 2, 2026
sha256afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638mple.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://taCatan and Mouse
Cisco Talos
· Jul 2, 2026
sha256c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978feexe Detection Name: PUA.Win.Tool.Kmsactivator::1201 SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe MD5: bf9672ec85283fdf002d83662f0b08b7 Talos Rep: https://taCatan and Mouse
Cisco Talos
· Jul 2, 2026
domaingoogle.comorization code request to direct the browser to a "accounts.google[.]com/o/oauth2/v2/auth/identifier" URL containing a "client_id"ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The Hacker News
· Jul 2, 2026
domainproton.mess: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy; contact e78393397[@]proton[.]me; ransom table named README_RANSOM Sysdig calls JADEPUFFERAI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
The Hacker News
· Jul 2, 2026
urlhttp://45.131.66[ion) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 6AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
The Hacker News
· Jul 2, 2026
domainmora1987.workmalware then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infecSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
The Hacker News
· Jul 1, 2026
domainwork.gdthen establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infectedSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
The Hacker News
· Jul 1, 2026
domainrentry.coor serverless workers. These include - Telegra.ph Teletype Rentry.co Write.as Dropbox GoFile DEV Community (dev.to) Mastodon LesGamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
The Hacker News
· Jul 1, 2026
domainsocket.ioconnects to attacker-controlled infrastructure, launches a socket.io backdoor, and eventually deploys a Python infostealer. TheHijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
The Hacker News
· Jul 1, 2026
domainduckdns.orgC2 domains lean on free dynamic DNS services, specifically duckdns.org, which is where the name comes from. Once a device checks iRustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Security Affairs
· Jul 1, 2026
ipv4192.0.2.1worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respoRustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Security Affairs
· Jul 1, 2026
domainpamconj.comgagement, we identified a management panel at “dashboard-bl.pamconj[.]com” serving a React single-page application (SPA) with a 1.7ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainsharepoint.comhe vendor's genuine SharePoint tenant: “https[:]//mononapfp.sharepoint[.]com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYvARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainworkers.devflare Workers accounts including “clear90489058903-document.workers[.]dev”. Linking ARToken to EvilTokens The connection between ARARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos
· Jul 1, 2026
domainbabybon.cfde payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does noResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domaincomicstar.latalso listed three payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one ofResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domainmerkantalolol.asiaers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does not prove infection. ItResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API
The Hacker News
· Jul 1, 2026
domainatlasregister.netty of the domains registered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]neCyber
Recorded Future
· Jul 1, 2026
domainatlasregister.orggistered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]comCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.bje and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.cong the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s originalCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.inare operated by the same threat actors: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 202Cyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.nete Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original investigation. ResearCyber
Recorded Future
· Jul 1, 2026
domainbeninmaritime.orgflags and impersonating the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not includedCyber
Recorded Future
· Jul 1, 2026
domainbma.gov.bjfiles shared by three of the Oceaniek-attributed websites ( bma[.]gov[.]bj, beninmaritime[.]net , and beninmaritime[.]bj) and fourCyber
Recorded Future
· Jul 1, 2026
domaincadredevie.gouv.bjs part of the Ministère du Cadre de Vie et des Transports ( cadredevie[.]gouv[.]bj ). The three inauthentic Benin Maritime AdministrationCyber
Recorded Future
· Jul 1, 2026
domainepnicaragua.comatlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]netCyber
Recorded Future
· Jul 1, 2026
domainepnicaragua.orgrg beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]oCyber
Recorded Future
· Jul 1, 2026
domaingouv.bjreal email address listed for Benin on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : ScreensCyber
Recorded Future
· Jul 1, 2026
domaingove.bj]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links tCyber
Recorded Future
· Jul 1, 2026
domainguve.bjon GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screenshot from the Benin Maritime AdministCyber
Recorded Future
· Jul 1, 2026
domainhellasnaval.netCluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacCyber
Recorded Future
· Jul 1, 2026
domainimsag.orga website impersonating a Guyanese maritime administration, imsag[.]org . The CENM websites claim that they provide IMO-mandatedCyber
Recorded Future
· Jul 1, 2026
domainisithin.comp IP range as Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medllCyber
Recorded Future
· Jul 1, 2026
domainmalawi.marinegov.orgral subdomains impersonating Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By defaulCyber
Recorded Future
· Jul 1, 2026
domainmalawi.shipregistry.marinegov.orgMalawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By default, the latter displays a page showing shipCyber
Recorded Future
· Jul 1, 2026
domainmarinegov.neter of fraudulent ship registries centered around the domain marinegov[.]net. This activity also aligns with prior reporting from indeCyber
Recorded Future
· Jul 1, 2026
domainmarinegov.orgins, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nautCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.onlinelink to another domain hosted on different infrastructure, medlloyd[.]online . This domain is co-hosted on 159[.]198[.]36[.]123 with tCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.online.beninmaritime.netubdomain on the Cluster Alpha website beninmaritime[.]net , medlloyd[.]online[.]beninmaritime[.]net , indicates a link to another domain hosted on differCyber
Recorded Future
· Jul 1, 2026
domainmedlloyd.orgn[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry mariCyber
Recorded Future
· Jul 1, 2026
domainnauticacentro.comaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has seveCyber
Recorded Future
· Jul 1, 2026
domainnauticacentro.mx[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has several subdomains impeCyber
Recorded Future
· Jul 1, 2026
domainniataregister.netnet epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies InsiktCyber
Recorded Future
· Jul 1, 2026
domainniataregister.orgm epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt Group identified PDCyber
Recorded Future
· Jul 1, 2026
domainoceaniektechnologies.coml as document authors and creators. Oceaniek Technologies ( oceaniektechnologies[.]com ) is an Indian web development company listed throughoutCyber
Recorded Future
· Jul 1, 2026
domainpalaureg.comata for similar PDFs distributed on PISR’s official website palaureg[.]com , which likely indicates that the operators behind epnicaCyber
Recorded Future
· Jul 1, 2026
domainpamconj.comlos published the operation’s domains and addresses, led by pamconj[.]com, for defenders to hunt on.The ARToken phishing panel targets Microsoft 365 accounts
Help Net Security
· Jul 1, 2026
domainpdf.beninmaritime.cobeninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Certificate PDF Generator” ( Figure 3 ). FCyber
Recorded Future
· Jul 1, 2026
domainregistry.zmgov.org: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Cyber
Recorded Future
· Jul 1, 2026
domainthesecure.bizint about spam from “thesecure.biz,” is itself an artefact: thesecure.biz is the encrypted Jabber server Europol later said the arresXSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn't
Security Affairs
· Jun 30, 2026
domainduckdns.orghe control addresses lean on free dynamic-DNS services like duckdns.org, which is where the "Duck" in the name comes from. This fitRustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
The Hacker News
· Jun 30, 2026
domaininternal.corp.com/page?ref=youtube.com bank.example.com/search?q=youtube.com internal.corp.com/redirect?from=youtube.com "The concern is not a single suspChrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
The Hacker News
· Jun 30, 2026
domainipinfo.ios wiped from the file system. It further sends a request to ipinfo[.]io to obtain the host's public IP address and location, alloLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
The Hacker News
· Jun 30, 2026
domainperplexity-ai.onlinebkiofojicogddingbdmcmkpbplcd) and used a look-alike domain, perplexity-ai[.]online, to pass for the real service at perplexity.ai. MicrosoftMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
The Hacker News
· Jun 30, 2026
domaindev-tunnels.comablishing encrypted communications with a remote server ("a.dev-tunnels[.]com"), and retrieving and executing additional JavaScript payAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
The Hacker News
· Jun 30, 2026
domainbooking.comCyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails thatHackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com
Infosecurity Magazine
· Jun 30, 2026
domaindomain.comLateral movement flag using specified domain credentials (“domain.com\user:pass”) or a single space (” “) to leverage the currentThe Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky Securelist
· Jun 30, 2026
domainsysinternals.comshell . exe - Command "Invoke-WebRequest -Uri 'https://live.sysinternals[.]com/PsExec.exe' -OutFile 'C:\Temp\psexec.exe'" The ransomwareThe Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky Securelist
· Jun 30, 2026
domainaccounts.google.comto direct the browser to the following URL: 1 https [ : ] //accounts[.]google[.]com/o/oauth2/v2/auth/identifier?response_type=code&client_iHow the ToddyCat APT group gains access to Gmail accounts
Kaspersky Securelist
· Jun 30, 2026
domaincabsecnow.comation. Additionally, the hosting IP for the PlugX C2 domain cabsecnow[.]com was switched from 167.88.180[.]32 to 103.85.24[.]149 on ABack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainipsoftwarelabs.comng universities. This IP address currently hosts the domain ipsoftwarelabs[.]com, which was previously noted within reporting on activityBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainquochoice.comhttp://103.85.24[.]158/hk097.dat , before ultimately using quochoice[.]com for command and control. This domain is currently hostedBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domainsysteminfor.comamples. When loaded into memory, the PlugX payload uses www.systeminfor[.]com for command and control — the same domain used across theBack Despite Disruption: RedDelta Resumes Operations
Recorded Future
· Jun 30, 2026
domaincouldinstallup.comkeys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser proMustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The Hacker News
· Jun 29, 2026
domainfaq-whatsapp-center.comCenter using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishing and credential collection tha236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
The Hacker News
· Jun 29, 2026
domainwhats-zwp.vipsApp's Security Help Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishin236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
The Hacker News
· Jun 29, 2026
domainmitarchive.infoKoi Security has linked the credential exfiltration domain mitarchive.info to DarkSpectre , a Chinese operation previously connected tStegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
Security Affairs
· Jun 29, 2026
domaintrycloudflare.comare Tunnel hosted on the domain amsterdam-sheet-veteran-aka.trycloudflare[.]com. For its part, GammaLoad makes use of DNS-over-HTTPS ( DoHackers Leveraging Cloudflare Tunnels, DNS Fast
The Hacker News
· Jun 29, 2026
domainmitarchive.infoface on a known one. Its credential payload exfiltrates to mitarchive.info, a domain Koi Security ties to DarkSpectre , the Chinese opMicrosoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
The Hacker News
· Jun 29, 2026
domainweedhack.toCentral to the campaign is an enterprise-grade dashboard ("weedhack[.]to") that enables customers to view stolen credentials and sWeedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
The Hacker News
· Jun 29, 2026
domainallcryptotalk.netis IP address also hosted a defunct crypto news site called allcryptotalk[.]net, which has not posted new content since June 2015, and thShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domaincontraloria.gob.penetwork of the Comptroller General of the Republic of Peru (contraloria[.]gob[.]pe). As of April 25, 2022, the BlackByte ransomware operatLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domaindigimin.gob.pePeru that affected the General Directorate of Intelligence (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe)Latin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainfazenda.rj.gov.bre Secretary of State for Finance of Rio De Janeiro, Brazil (fazenda[.]rj[.]gov[.]br). Neither of these incidents were widely reported inLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainfodesaf.go.cro[.]cr), the Development Fund and Family Allowances Bureau (fodesaf[.]go[.]cr), and the Interuniversity Headquarters of Alajuela, CosLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainhacienda.go.crral Costa Rican entities including the Ministry of Finance (hacienda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[Latin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainmarine-chain.ioother site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. DomainShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainmef.gob.pe(digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe). Figure 3: Announcements of attacks on Costa Rican andLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainmtss.go.crenda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (foLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainquito.gob.ecromised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a goveLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainsaludparatodos.ssm.gob.mxto the Secretary of Health of the State of Morelos, Mexico (saludparatodos[.]ssm[.]gob[.]mx), a breach that was initially disclosed on or aroundLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainshipowner.ioowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain registration histoShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainsiua.ac.crd the Interuniversity Headquarters of Alajuela, Costa Rica (siua[.]ac[.]cr). Previous Conti posts also made vague references to coLatin American Governments Targeted By Ransomware
Recorded Future
· Jun 29, 2026
domainwww.marine-chain.iole users and owners. Users on other forums pointed out that www[.]marine-chain[.]io was a near mirror image of another site, www[.]shipowneShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
domainwww.shipowner.io]marine-chain[.]io was a near mirror image of another site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowShifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite
Recorded Future
· Jun 29, 2026
sha25681e81f0bbbdb831eda215033b7a7dbf2eed3812f4e58118f181a8e99e613179ebe found in Appendix A. Figure 3: Configuration from sample 81e81f0bbbdb831eda215033b7a7dbf2eed3812f4e58118f181a8e99e613179e. (Source: Recorded Future) The builder is also responsibleNew Ransomware-as-a-Service Tool ‘Thanos’ Shows Connections to ‘Hakbit’
Recorded Future
· Jun 29, 2026
domainclo4shara.xyzeving the main payload at runtime from an external domain ("clo4shara[.]xyz/11z77u3.php"). This architecture offers added flexibilityGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domaincom-apps.ccported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of "clo4shara[.]xyz/11z77u3.php"),Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainrestrictes.comection point to two previously unreported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead ofGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainweb-telegram.ugdesigned to achieve persistence and poll a remote server ("web-telegram[.]ug") every 30 seconds to process instructions issued by theGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
The Hacker News
· Jun 26, 2026
domainackques.comon port 80, as well as issuing POST requests to the <index.ackques[.]com> C2 server with the specific User-Agent, pictured below:RedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domainacques.comation about the victim system while POST requests to “index.acques[.]com/index.html” primarily uploaded zlib compressed files fromRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domaincheacker.storea protected business document. The March 16 registration of cheacker[.]store suggests the domain was created for a short-lived phishinMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Help Net Security
· Jun 26, 2026
domainhktechy.comcreating a separate thread with an open socket to the < www.hktechy[.]com> server on port 80, as well as issuing POST requests to tRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domaininternetdocss.coms; however, malware from both campaigns made use of the doc.internetdocss[.]com C2 domain, thus tying both campaigns together. A maliciouRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
domainukr.nett had sent malicious emails to roughly one million users of Ukr.net, a widely used Ukrainian email service, and compromised morPro-Russian hackers pose as Ukraine's cyber agency to target government, businesses
The Record
· Jun 26, 2026
domainuser.cheacker.storeond-stage script from attacker-controlled infrastructure at user[.]cheacker[.]store,” the researchers explained. The second-stage phishingMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Help Net Security
· Jun 26, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.