Indicators of compromise
4,251 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| md5 | 1b67183acc18d7641917f4fe07c1b053 | ampaign, we were unable to acquire one of the samples (MD5: 1b67183acc18d7641917f4fe07c1b053) from common malware multiscanner repositories at the time | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| md5 | e6c0ac26b473d1e0fa9f74fdf1d01af8 | nce executed, the lure document loads an embedded DLL (MD5: e6c0ac26b473d1e0fa9f74fdf1d01af8) that drops the validator implant into the users “Temp” dir | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| md5 | 41acb30b9d662d48b7b4fc0ac3d4b79f | 1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://talosintelligence.com/talos_file_reputat | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| md5 | cc4d231df34e57f59eb970353c7d9de2 | a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputat | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| md5 | dbd8dbecaa80795c135137d69921fdba | 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| sha256 | 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 | tection Name: W32.Variant:MalwareXgenMisc.29d4.1201 SHA256: 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://ta | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| sha256 | afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://ta | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| sha256 | e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba | exe Detection Name: PUA.Win.Tool.Kmsactivator::1201 SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://ta | Beyond IOCs: AI Cisco Talos | · Jun 25, 2026 |
| domain | market0day.com | cted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used to | ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories The Hacker News | · Jun 25, 2026 |
| domain | spoxy.us | istrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertis | ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories The Hacker News | · Jun 25, 2026 |
| domain | oleview.net | tub information, and method layouts registered on a system. OleView.NET , developed by James Forshaw, is particularly useful since | Introduction to COM usage by Windows threats Cisco Talos | · Jun 25, 2026 |
| ipv4 | 20.12.7.1 | Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.12.7.2 | earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and e | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.4 | xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.5 | arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.2 | ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3. | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.3 | arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed i | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.18.3.1 | 0.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articl | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.9.9.1 | lable for the following versions of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixe | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.9.9.2 | s of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and e | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 26.1.1.1 | d earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interest | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 26.1.1.2 | 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interesting? Follow us on Google News , | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| domain | africa.truefact.news | p identified another domain hosted on 72[.]14[.]185[.]187 , africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has t | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | albertaseparatist.com | ntified at least two new CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was u | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | allstatesnews.us | ated content or have been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.] | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | capitalcitydaily.com | been mentioned on social media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | chat.darkpulsar.ai | o websites worldwide, like a pulsar beacon.” In March 2025, chat[.]darkpulsar[.]ai also hosted an Open WebUI login page, likely intended f | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | clearstory.news | ryty[.]ru ) and previously identified CopyCop websites like clearstory[.]news . Other Truefact subdomains are identical to previously i | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | darkpulsar.ai | ts several of John Mark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websi | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | darkquasar.tech | d to Dougan’s freelancing projects, such as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page f | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | de.truefact.news | ing organization named “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[. | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | eu.com | esearchers at Gnida Project noted CopyCop’s use of several *eu[.]com domains to create inauthentic websites and promote influe | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | fldaily.news | media so far: allstatesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | franceencolere.fr | arget the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in the Truefact cluster ar | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | france.truefact.news | .]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spai | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | fr.truefact.news | d “Truefact”: africa[.]truefact[.]news de[.]truefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexi | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | germany.truefact.news | uefact[.]news fr[.]truefact[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | greenarmenia.org | Party used to promote influence content targeting Armenia, greenarmenia[.]org . Insikt Group also identified several website registrati | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | insider.eu.com | inauthentic websites and promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identif | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | mexico.truefact.news | t[.]news france[.]truefact[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukrain | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | ndc.eu.com | d promote influence content, such as insider[.]eu[.]com and ndc[.]eu[.]com . Insikt Group was unable to identify any larger cluste | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | newsguard.tech | s registered a domain almost certainly targeting NewsGuard, newsguard[.]tech , named “News Guard Parody.” NewsGuard has previously cov | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | partiroyaliste.fr | to link older, unreported activity to CopyCop. For example, partiroyaliste[.]fr , an inauthentic website posing as a French royalist poli | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | proton.me | party first registered in August 2024 using partiroyaliste@proton[.]me, is likely linked to CopyCop. The website is hosted on th | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | reg.skryty.ru | LLMs. Figures 3 and 4 : Login form on darkquasar[.]tech and reg[.]skryty[.]ru (Left) and darkpulsar[.]ai (Right) (Source: URLscan 1 , | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | silvercity.news | statesnews[.]us , capitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 we | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | skryty.com | ch as three domains ( darkquasar[.]tech , skryty[.]ru , and skryty[.]com ) hosting a login page for “SKRYTY” and requiring a regis | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | skryty.ru | ark Dougan’s personal projects (such as darkpulsar[.]ai and skryty[.]ru ) and previously identified CopyCop websites like clearst | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | spain.truefact.news | t[.]news germany[.]truefact[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | torontojournal.ca | CopyCop websites targeting Canada: albertaseparatist[.]com torontojournal[.]ca The website torontojournal[.]ca was used in July 2024 to | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | truefact.news | africa[.]truefact[.]news . First registered in March 2025, truefact[.]news has the following nine subdomains, which began hosting Co | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | turkey.truefact.news | act[.]news mexico[.]truefact[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | ukraine.truefact.news | act[.]news spain[.]truefact[.]news turkey[.]truefact[.]news ukraine[.]truefact[.]news The domain germany[.]truefact[.]news is hosted on 89[.] | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | usatimes.news | pitalcitydaily[.]com , fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | veritecachee.fr | s previously used to target the 2024 French snap elections, veritecachee[.]fr and franceencolere[.]fr , respectively. Other websites in | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | video.darkpulsar.ai | i ) tied to a self-hosted PeerTube video hosting platform ( video[.]darkpulsar[.]ai ). In January 2025, darkpulsar[.]ai also briefly featur | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| domain | wval.news | fldaily[.]news , silvercity[.]news , usatimes[.]news , and wval[.]news . The remaining 29 websites, as of this writing, are repu | CopyCop Deepens Its Playbook with New Websites and Targets Recorded Future | · Jun 25, 2026 |
| md5 | 1f65544978b8ea0e745e573b8ee9684b | er sample, discovered on a machine located in Lebanon (MD5: 1F65544978B8EA0E745E573B8EE9684B), the dropper extracts and decompresses SystemSettings.dll | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | 24fcebdeecba65004fdb0923763d74fd | licious dropper named 一种异常状况的截图(包括操作系统和输入法版本).pdf.exe (MD5: 24FCEBDEECBA65004FDB0923763D74FD), which was identified in a campaign targeting a government | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | 9cbd560f820c95d7c38342cd558cb5c6 | DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL Hijacking” technique Once the malicious DLL is | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | a514d1bb62d7916475946fe7c07ac0aa | mSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL H | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | aa3086be652c8b20b0b29b2730d57119 | ngs.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | d98f568496512e4f98670c61c97cb07a | overnment entity in Taiwan. Filename MD5 SystemSettings.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCore | StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon Kaspersky Securelist | · Jun 24, 2026 |
| md5 | 95b3ec0a4e539efaa1faa3d4e25d51de | machine on the network to execute a file with the MD5 hash 95b3ec0a4e539efaa1faa3d4e25d51de. A quick search in Recorded Future shows that this hash is | Enriching User Behavior Analytics With Threat Intelligence Recorded Future | · Jun 24, 2026 |
| domain | stitch-design.ai | ch SDK" by following the documentation at an external link, stitch-design.ai, a domain AIR controls, not Google (the real Stitch lives a | Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents The Hacker News | · Jun 23, 2026 |
| domain | stitch.withgoogle.com | a domain AIR controls, not Google (the real Stitch lives at stitch.withgoogle.com). At first, the link led to the genuine Stitch docs, so the | Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents The Hacker News | · Jun 23, 2026 |
| domain | nvidiadriver.net | downloaded a payload from a domain posing as a driver site, nvidiadriver[.]net. It downloaded a ZIP archive disguised as a Windows patch | Lookalike npm Package Hides a Multi Infosecurity Magazine | · Jun 23, 2026 |
| domain | nvidiadriver.net | or a next-stage payload retrieved from an external server ("nvidiadriver[.]net") using the "curl.exe." The retrieved payload is a ZIP ar | Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT The Hacker News | · Jun 23, 2026 |
| domain | stitch-production.org | on) and exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1"). A cluster of five packages ("procwire," "routec | Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT The Hacker News | · Jun 23, 2026 |
| domain | node-js.prentiva99.info | h engines like Google, redirecting them to a fake website ("node-js[.]prentiva99[.]info") surfaced via bogus ads published under the verified n | New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer The Hacker News | · Jun 23, 2026 |
| domain | 2faplugin.org | LC, tied to Russian-based entities. The exfiltration domain 2faplugin.org was updated on May 10th, about eleven days before the backd | ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates Security Affairs | · Jun 23, 2026 |
| domain | generate.2faplugin.org | the report. Attackers send the stolen passwords and 2FA to generate.2faplugin.org, a domain that blends in with legitimate two-factor traffic | ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates Security Affairs | · Jun 23, 2026 |
| domain | continuetogo.me | ential theft), but the apex domain used for the attack was “continuetogo[.]me”. This domain was referenced in a report by Google’s Thre | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | de-ma.online | ivity attributed to the Phosphorus APT in 2020. The domain “de-ma[.]online” underlined in Figure 4 has not had an active DNS “A” rec | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | fileskeeper.org | -related group named “Keeper” (due to the use of the domain fileskeeper[.]org to inject malicious JS into the website’s HTML code) was | Credit Card ‘Sniffers’ Pose Persistent Threat to Growing E Recorded Future | · Jun 23, 2026 |
| domain | litby.us | trolled infrastructure also included a fake URL shortener, “litby[.]us”. This suggests that TAG-56 operators prefer to acquire p | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.live | e 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected mailer-daemon[.]live 199.188.200[.]217 9 November 2021 Namecheap Privacy Prote | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.me | 162.0.232[.]252 11 October 2022 Namecheap Privacy Protected mailer-daemon[.]me 199.188.200[.]217 31 May 2022 Namecheap Privacy Protected | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailerdaemon.me | pen-source reporting reveals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members o | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon-message.co | eals similar domains, specifically “mailerdaemon[.]me” and “mailer-daemon-message[.]co”, were used by members of the Phosphorus APT group to lea | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.net | d, would redirect them to a URL with the apex domain name — mailer-daemon[.]net — where the spoofed registration page is hosted. Figure 1 | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.online | . Domain IP Address First Seen Registrar WHOIS Registration mailer-daemon[.]online 198.54.115[.]217 23 November 2022 Namecheap Privacy Prote | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | mailer-daemon.org | aming convention as mailer-daemon[.]net. All but 1 domain, “mailer-daemon[.]org”, use Namecheap's shared hosting services. The domain “ma | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | tinyurl.com | inyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.]com), was identified as part of our research. The fake URL sh | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | tinyurl.ink | orded Future) The Fake URL Shortener A fake URL shortener, “tinyurl[.]ink”, which spoofs the legitimate service TinyURL (tinyurl[.] | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| domain | web-hosting.com | e October 11, 2022. The reverse DNS for 162.0.232[.]252 is “web-hosting[.]com”, which is associated with Namecheap's shared hosting ser | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| md5 | 857ef30bf15ea3da9b94092da78ef0fc | wiper used in the Middle East. It is likely that this file (857ef30bf15ea3da9b94092da78ef0fc) is the wiper in question. In 2012, APT33 deployed the dest | Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access Recorded Future | · Jun 23, 2026 |
| sha256 | 69eb4fca412201039105d862d5f2bf12085d41cb18a93398afef0be8dfb9c229 | ps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx SHA256 Hash: 69eb4fca412201039105d862d5f2bf12085d41cb18a93398afef0be8dfb9c229 File: Iran nuke.docx | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| url | https://continuetogo[ | itten, TA453, and APT42 (along with its forerunner UNC788). hxxps[:]//continuetogo[.]me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings. | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| url | https://mailer-daemon[ | me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.php hxxps[:]//mailer-daemon[.]net/file=sharing=system/file.id.X=xxxxxx/continue-to-set | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| url | https://tinyurl[ | a412201039105d86 2d5f2bf12085d41cb18a933 98afef0be8dfb9c229 hxxps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx 28 February 2022 Table 2: | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| ipv4 | 202.61.160.201 | ker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to Valley | WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools Security Affairs | · Jun 22, 2026 |
| domain | socradar.io | &CK mapping, IoC lists, and infrastructure breakdown, is at socradar.io . Follow me on Twitter: @securityaffairs and Facebook and M | FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential Security Affairs | · Jun 22, 2026 |
| domain | aliyuncs.com | p shaaslong[.]one baoxis[.]cc baolongwes.oss-ap-southeast-1.aliyuncs[.]com sdcwww.oss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-s | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | amazonaws.com | ss-ap-southeast-1.aliyuncs[.]com baoyuw2s.s3.ap-southeast-1.amazonaws[.]com hksha3.s3.ap-southeast-1.amazonaws[.]com sjdkjj23.s3.ap-s | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
| domain | backblazeb2.com | .s3.ap-southeast-1.amazonaws[.]com caiwuascw.s3.us-east-005.backblazeb2[.]com facaia.s3.us-east-005.backblazeb2[.]com Attacker-controll | An unknown actor distributes malicious VBS scripts via WhatsApp Kaspersky Securelist | · Jun 22, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.