ZeroHour

Indicators of compromise

4,251 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
md51b67183acc18d7641917f4fe07c1b053ampaign, we were unable to acquire one of the samples (MD5: 1b67183acc18d7641917f4fe07c1b053) from common malware multiscanner repositories at the timeRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
md5e6c0ac26b473d1e0fa9f74fdf1d01af8nce executed, the lure document loads an embedded DLL (MD5: e6c0ac26b473d1e0fa9f74fdf1d01af8) that drops the validator implant into the users “Temp” dirRedAlpha: New Campaigns Discovered Targeting the Tibetan Community
Recorded Future
· Jun 26, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
md541acb30b9d662d48b7b4fc0ac3d4b79f1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://talosintelligence.com/talos_file_reputatBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
md5cc4d231df34e57f59eb970353c7d9de2a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputatBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
md5dbd8dbecaa80795c135137d69921fdba05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputatBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
sha256853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453tection Name: W32.Variant:MalwareXgenMisc.29d4.1201 SHA256: 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://taBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fD001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
sha256afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://taBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
sha256e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33baexe Detection Name: PUA.Win.Tool.Kmsactivator::1201 SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://taBeyond IOCs: AI
Cisco Talos
· Jun 25, 2026
domainmarket0day.comcted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used toThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
The Hacker News
· Jun 25, 2026
domainspoxy.usistrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertisThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
The Hacker News
· Jun 25, 2026
domainoleview.nettub information, and method layouts registered on a system. OleView.NET , developed by James Forshaw, is particularly useful sinceIntroduction to COM usage by Windows threats
Cisco Talos
· Jun 25, 2026
ipv420.12.7.1Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.12.7.2earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and eCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.4xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.5arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (FixedCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.2ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.Cisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.3arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed iCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.18.3.10.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articlCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.9.9.1lable for the following versions of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (FixeCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.9.9.2s of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and eCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv426.1.1.1d earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interestCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv426.1.1.220.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interesting? Follow us on Google News ,Cisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
domainafrica.truefact.newsp identified another domain hosted on 72[.]14[.]185[.]187 , africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has tCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainalbertaseparatist.comntified at least two new CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was uCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainallstatesnews.usated content or have been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaincapitalcitydaily.combeen mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news ,CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainchat.darkpulsar.aio websites worldwide, like a pulsar beacon.” In March 2025, chat[.]darkpulsar[.]ai also hosted an Open WebUI login page, likely intended fCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainclearstory.newsryty[.]ru ) and previously identified CopyCop websites like clearstory[.]news . Other Truefact subdomains are identical to previously iCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaindarkpulsar.aits several of John Mark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaindarkquasar.techd to Dougan’s freelancing projects, such as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page fCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainde.truefact.newsing organization named “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaineu.comesearchers at Gnida Project noted CopyCop’s use of several *eu[.]com domains to create inauthentic websites and promote influeCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfldaily.newsmedia so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news .CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfranceencolere.frarget the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in the Truefact cluster arCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfrance.truefact.news.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spaiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainfr.truefact.newsd “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaingermany.truefact.newsuefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkeyCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaingreenarmenia.orgParty used to promote influence content targeting Armenia, greenarmenia[.]org . Insikt Group also identified several website registratiCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaininsider.eu.cominauthentic websites and promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identifCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainmexico.truefact.newst[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukrainCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainndc.eu.comd promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identify any larger clusteCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainnewsguard.techs registered a domain almost certainly targeting NewsGuard, newsguard[.]tech , named “News Guard Parody.” NewsGuard has previously covCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainpartiroyaliste.frto link older, unreported activity to CopyCop. For example, partiroyaliste[.]fr , an inauthentic website posing as a French royalist poliCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainproton.meparty first registered in August 2024 using partiroyaliste@proton[.]me, is likely linked to CopyCop. The website is hosted on thCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainreg.skryty.ruLLMs. Figures 3 and 4 : Login form on darkquasar[.]tech and reg[.]skryty[.]ru (Left) and darkpulsar[.]ai (Right) (Source: URLscan 1 ,CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainsilvercity.newsstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 weCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainskryty.comch as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page for “SKRYTY” and requiring a regisCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainskryty.ruark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websites like clearstCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainspain.truefact.newst[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news TheCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaintorontojournal.caCopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was used in July 2024 toCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domaintruefact.newsafrica[.]truefact[.]news . First registered in March 2025, truefact[.]news has the following nine subdomains, which began hosting CoCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainturkey.truefact.newsact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefactCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainukraine.truefact.newsact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact[.]news is hosted on 89[.]CopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainusatimes.newspitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of thisCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainveritecachee.frs previously used to target the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites inCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainvideo.darkpulsar.aii ) tied to a self-hosted PeerTube video hosting platform ( video[.]darkpulsar[.]ai ). In January 2025, darkpulsar[.]ai also briefly featurCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
domainwval.newsfldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this writing, are repuCopyCop Deepens Its Playbook with New Websites and Targets
Recorded Future
· Jun 25, 2026
md51f65544978b8ea0e745e573b8ee9684ber sample, discovered on a machine located in Lebanon (MD5: 1F65544978B8EA0E745E573B8EE9684B), the dropper extracts and decompresses SystemSettings.dllStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md524fcebdeecba65004fdb0923763d74fdlicious dropper named 一种异常状况的截图(包括操作系统和输入法版本).pdf.exe (MD5: 24FCEBDEECBA65004FDB0923763D74FD), which was identified in a campaign targeting a governmentStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md59cbd560f820c95d7c38342cd558cb5c6DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL Hijacking” technique Once the malicious DLL isStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md5a514d1bb62d7916475946fe7c07ac0aamSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL HStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md5aa3086be652c8b20b0b29b2730d57119ngs.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.datStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md5d98f568496512e4f98670c61c97cb07aovernment entity in Taiwan. Filename MD5 SystemSettings.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreStrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky Securelist
· Jun 24, 2026
md595b3ec0a4e539efaa1faa3d4e25d51demachine on the network to execute a file with the MD5 hash 95b3ec0a4e539efaa1faa3d4e25d51de. A quick search in Recorded Future shows that this hash isEnriching User Behavior Analytics With Threat Intelligence
Recorded Future
· Jun 24, 2026
domainstitch-design.aich SDK" by following the documentation at an external link, stitch-design.ai, a domain AIR controls, not Google (the real Stitch lives aFake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
The Hacker News
· Jun 23, 2026
domainstitch.withgoogle.coma domain AIR controls, not Google (the real Stitch lives at stitch.withgoogle.com). At first, the link led to the genuine Stitch docs, so theFake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
The Hacker News
· Jun 23, 2026
domainnvidiadriver.netdownloaded a payload from a domain posing as a driver site, nvidiadriver[.]net. It downloaded a ZIP archive disguised as a Windows patchLookalike npm Package Hides a Multi
Infosecurity Magazine
· Jun 23, 2026
domainnvidiadriver.netor a next-stage payload retrieved from an external server ("nvidiadriver[.]net") using the "curl.exe." The retrieved payload is a ZIP arMalicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
The Hacker News
· Jun 23, 2026
domainstitch-production.orgon) and exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1"). A cluster of five packages ("procwire," "routecMalicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
The Hacker News
· Jun 23, 2026
domainnode-js.prentiva99.infoh engines like Google, redirecting them to a fake website ("node-js[.]prentiva99[.]info") surfaced via bogus ads published under the verified nNew OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
The Hacker News
· Jun 23, 2026
domain2faplugin.orgLC, tied to Russian-based entities. The exfiltration domain 2faplugin.org was updated on May 10th, about eleven days before the backdShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
Security Affairs
· Jun 23, 2026
domaingenerate.2faplugin.orgthe report. Attackers send the stolen passwords and 2FA to generate.2faplugin.org, a domain that blends in with legitimate two-factor trafficShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
Security Affairs
· Jun 23, 2026
domaincontinuetogo.meential theft), but the apex domain used for the attack was “continuetogo[.]me”. This domain was referenced in a report by Google’s ThreSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainde-ma.onlineivity attributed to the Phosphorus APT in 2020. The domain “de-ma[.]online” underlined in Figure 4 has not had an active DNS “A” recSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainfileskeeper.org-related group named “Keeper” (due to the use of the domain fileskeeper[.]org to inject malicious JS into the website’s HTML code) wasCredit Card ‘Sniffers’ Pose Persistent Threat to Growing E
Recorded Future
· Jun 23, 2026
domainlitby.ustrolled infrastructure also included a fake URL shortener, “litby[.]us”. This suggests that TAG-56 operators prefer to acquire pSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.livee 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected mailer-daemon[.]live 199.188.200[.]217 9 November 2021 Namecheap Privacy ProteSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.me162.0.232[.]252 11 October 2022 Namecheap Privacy Protected mailer-daemon[.]me 199.188.200[.]217 31 May 2022 Namecheap Privacy ProtectedSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailerdaemon.mepen-source reporting reveals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members oSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon-message.coeals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members of the Phosphorus APT group to leaSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.netd, would redirect them to a URL with the apex domain name — mailer-daemon[.]net — where the spoofed registration page is hosted. Figure 1Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.online. Domain IP Address First Seen Registrar WHOIS Registration mailer-daemon[.]online 198.54.115[.]217 23 November 2022 Namecheap Privacy ProteSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainmailer-daemon.orgaming convention as mailer-daemon[.]net. All but 1 domain, “mailer-daemon[.]org”, use Namecheap's shared hosting services. The domain “maSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domaintinyurl.cominyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]com), was identified as part of our research. The fake URL shSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domaintinyurl.inkorded Future) The Fake URL Shortener A fake URL shortener, “tinyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
domainweb-hosting.come October 11, 2022. The reverse DNS for 162.0.232[.]252 is “web-hosting[.]com”, which is associated with Namecheap's shared hosting serSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
md5857ef30bf15ea3da9b94092da78ef0fcwiper used in the Middle East. It is likely that this file (857ef30bf15ea3da9b94092da78ef0fc) is the wiper in question. In 2012, APT33 deployed the destIranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
Recorded Future
· Jun 23, 2026
sha25669eb4fca412201039105d862d5f2bf12085d41cb18a93398afef0be8dfb9c229ps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx SHA256 Hash: 69eb4fca412201039105d862d5f2bf12085d41cb18a93398afef0be8dfb9c229 File: Iran nuke.docxSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
urlhttps://continuetogo[itten, TA453, and APT42 (along with its forerunner UNC788). hxxps[:]//continuetogo[.]me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
urlhttps://mailer-daemon[me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.php hxxps[:]//mailer-daemon[.]net/file=sharing=system/file.id.X=xxxxxx/continue-to-setSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
urlhttps://tinyurl[a412201039105d86 2d5f2bf12085d41cb18a933 98afef0be8dfb9c229 hxxps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx 28 February 2022 Table 2:Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
ipv4202.61.160.201ker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to ValleyWhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
Security Affairs
· Jun 22, 2026
domainsocradar.io&CK mapping, IoC lists, and infrastructure breakdown, is at socradar.io . Follow me on Twitter: @securityaffairs and Facebook and MFortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential
Security Affairs
· Jun 22, 2026
domainaliyuncs.comp shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-sAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainamazonaws.comss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-southeast-1.amazonaws[.]com hksha3.s3.ap-southeast-1.amazonaws[.]com sjdkjj23.s3.ap-sAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026
domainbackblazeb2.com.s3.ap-southeast-1.amazonaws[.]com caiwuascw.s3.us-east-005.backblazeb2[.]com facaia.s3.us-east-005.backblazeb2[.]com Attacker-controllAn unknown actor distributes malicious VBS scripts via WhatsApp
Kaspersky Securelist
· Jun 22, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.