ZeroHour

Indicators of compromise

1,885 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaingrok.com: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these sHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer
· 6d ago
domaindomainlify.netom Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address NoteHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaineemusicclass.co.ukaddress used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlifeones.comail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails DomainHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlumalisboa.comaddress used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainmctci.comaddress used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainnuf.co.jpail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainservice-nowinc.comrs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@serviHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintivityhealth.comail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintovimbatista.ptail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainuinsure.co.ukassociated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainapimantax.otax.funbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrievedNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 6d ago
domaingitclone.orgxploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
domainbackup-ubt.s3.us-east-1.amazonaws.comws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.bloHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainhostfxr.dllL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-eastHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainlinked4x.comfffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoaderHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainskipraid.comDomain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTrHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainstro7121.blob.core.windows.netid[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stroHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintelephoneip.netible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRATHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintruesmart.orgDomain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are inHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainwindows.netm/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 SloppHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaingitclone.org.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HashJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
domaindomainlify.nett in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perioHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainservice-nowinc.comonsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing aHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnoht1ng.topil.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainuaiubifas.tophind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambledChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainapimantax.otax.funMantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published asMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 6d ago
domainhunt.ioe automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open directorUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
· 6d ago
domainlinked4x.comirectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage paHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
domainskipraid.comthe download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. CasHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
domaingitclone.org-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
domaindomainlify.netalso registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informaProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainservice-nowinc.comregistered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign acProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domain9342371634011778.comfollowing command line: "C:\Users\[redacted]\AppData\Local\9342371634011778.com" -s -L --tlsv1.2 --ssl-no-revoke -o "C:\Users\[redacted]\ApSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainhostfxr.dllfrom hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.pySloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainlinked4x.comnger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: "C:\windows\system32\SloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainskipraid.comCastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside CastleSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainstro7121.blob.core.windows.netmory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export nameSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainsystem.netieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or dSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainwindows.netand execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’sSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domain7.tcp.eu67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File namHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domaindiscord.com41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-YHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainflow.lavasoft.comle-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwaHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainmobile-service.segment.com.com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / IHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainngrok.io69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domaintelemetry.servers.getgo.com0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainxsph.ruhe Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure FHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainbloom.iof compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft TeamsHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News
· 7d ago
domainlogin.microsoftonline.comst loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial redHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News
· 7d ago
domainadd-passkey.comy security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO DomainHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainintegratedsso.comey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session DoHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainkeysyncos.comO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronizHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainmyconnectkey.comistration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection DHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoktasession.comom Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key syncHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeyconnect.comhronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account valHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeyregister.comey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizatiHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeysetup.comonization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration DomHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeysync.comr session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup DomHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainpasskeyhelpdesk.comm becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com PasskeyHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainportalsetuphub.comvalidationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intentionHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsecure-passkey.comon Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setuHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsetupmypasskey.comrt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollmentHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsyncmykey.comey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connectHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainvalidationsetupac.comconnection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]comHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainip-109-091-184-021.um37.pools.vodafone-ip.deutsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (ARedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
domainmail3.kekew.infoerse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
domainbloom.ior ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal externalNew Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
GBHackers
· 7d ago
domainexample.com>/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identityThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 7d ago
domainasia.newsinweb.comdrivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.neHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domaindrivinguber.comist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.cHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainnewsinweb.comm Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI /Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainusa.newsinweb.comeb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain nHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainclck.rut file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connectFake GTA 6 download delivers malware-packed bundle to impatient gamers
Help Net Security
· 7d ago
domainadd-passkey.comhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operatorHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domaincontoso.add-passkey.come operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more creHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainintegratedsso.comure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organiHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainkeysyncos.comins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domainHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainoktasession.comypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs suHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainpasskeyhelpdesk.comsubdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainsecure-passkey.comobserved lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainsetupmypasskey.comucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.