Indicators of compromise
1,885 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | grok.com | : shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s | How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface BleepingComputer | · 6d ago |
| domain | domainlify.net | om Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address Note | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | eemusicclass.co.uk | address used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lifeones.com | ail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails Domain | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lumalisboa.com | address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | mctci.com | address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | nuf.co.jp | ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | service-nowinc.com | rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tivityhealth.com | ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tovimbatista.pt | ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | uinsure.co.uk | associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | apimantax.otax.fun | bound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved | New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims Cyber Security News | · 6d ago |
| domain | gitclone.org | xploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/ | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 6d ago |
| domain | backup-ubt.s3.us-east-1.amazonaws.com | ws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blo | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | hostfxr.dll | L URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | linked4x.com | fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | skipraid.com | Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTr | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | stro7121.blob.core.windows.net | id[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stro | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | telephoneip.net | ible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | truesmart.org | Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are in | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | windows.net | m/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 Slopp | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | gitclone.org | .184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 6d ago |
| domain | domainlify.net | t in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | eemusicclass.co.uk | uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lifeones.com | info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lumalisboa.com | ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | mctci.com | k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.] | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | nuf.co.jp | th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | service-nowinc.com | onsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | tivityhealth.com | ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.] | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | tovimbatista.pt | nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | uinsure.co.uk | ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | noht1ng.top | il.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server, | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| domain | uaiubifas.top | hind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| domain | apimantax.otax.fun | Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as | Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files GBHackers | · 6d ago |
| domain | hunt.io | e automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open director | UK Council Attack Linked to Mass Exploitation of SonicWall Flaw Security Affairs | · 6d ago |
| domain | linked4x.com | irectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage pa | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| domain | skipraid.com | the download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. Cas | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| domain | gitclone.org | -2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026 | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 6d ago |
| domain | domainlify.net | also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informa | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | eemusicclass.co.uk | uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | lifeones.com | info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | lumalisboa.com | ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | mctci.com | k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.] | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | nuf.co.jp | th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | service-nowinc.com | registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign ac | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | tivityhealth.com | ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.] | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | tovimbatista.pt | nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | uinsure.co.uk | ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 6d ago |
| domain | 9342371634011778.com | following command line: "C:\Users\[redacted]\AppData\Local\9342371634011778.com" -s -L --tlsv1.2 --ssl-no-revoke -o "C:\Users\[redacted]\Ap | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | hostfxr.dll | from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.py | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | linked4x.com | nger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: "C:\windows\system32\ | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | skipraid.com | CastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside Castle | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | stro7121.blob.core.windows.net | mory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | system.net | ieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or d | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | windows.net | and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’s | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | 7.tcp.eu | 67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | discord.com | 41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | flow.lavasoft.com | le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | mobile-service.segment.com | .com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | ngrok.io | 69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | telemetry.servers.getgo.com | 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0. | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | xsph.ru | he Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | bloom.io | f compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft Teams | Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers Cyber Security News | · 7d ago |
| domain | login.microsoftonline.com | st loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial red | Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers Cyber Security News | · 7d ago |
| domain | add-passkey.com | y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | integratedsso.com | ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | keysyncos.com | O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | myconnectkey.com | istration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oktasession.com | om Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeyconnect.com | hronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeyregister.com | ey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeysetup.com | onization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeysync.com | r session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | passkeyhelpdesk.com | m becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | portalsetuphub.com | validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | secure-passkey.com | on Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | setupmypasskey.com | rt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | syncmykey.com | ey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | validationsetupac.com | connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | ip-109-091-184-021.um37.pools.vodafone-ip.de | utsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (A | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| domain | mail3.kekew.info | erse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10 | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| domain | bloom.io | r ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal external | New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners GBHackers | · 7d ago |
| domain | example.com | >/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identity | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| domain | asia.newsinweb.com | drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.ne | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | drivinguber.com | ist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.c | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | newsinweb.com | m Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI / | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | usa.newsinweb.com | eb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain n | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | clck.ru | t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connect | Fake GTA 6 download delivers malware-packed bundle to impatient gamers Help Net Security | · 7d ago |
| domain | add-passkey.com | helpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operator | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | contoso.add-passkey.com | e operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more cre | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | integratedsso.com | ure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organi | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | keysyncos.com | ins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domain | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | oktasession.com | ypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs su | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | passkeyhelpdesk.com | subdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[ | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | secure-passkey.com | observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[. | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | setupmypasskey.com | ucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[ | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.