Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | kffd3.vogueatelier.cc | contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | lb.propertyfind.cc | ring) function. During our analysis, the contract returned "lb[.]propertyfind[.]cc", which ZigCryptoStealer then used as its C2 domain. Th | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | leaguejazire.com | d command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com", places the victim identifier in the path, and executes | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | pkg.vogueatelier.cc | ue June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | riyazinikokar.xyz | acOS user-agent string. The request goes to a subdomain of "riyazinikokar[.]xyz". Since the subject of our initial research was a custome | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | static.quorashift.cc | elier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[.]propertyfind[.]cc Talos used Cisco Um | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | telegra.ph | n "pf.ch" branch constructs the dead drop C2 URL "https[:]//telegra[.]ph/Functions-04-03". At the time of analysis, the page looke | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | google.com | s — like a random executable making a DNS request for “docs.google[.]com”. But when the requests are made from within a browser se | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | obfuscator.io | r variable and function names, consistent with output from “Obfuscator[.]io” and similar Javascript obfuscation tools. However, it wa | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | pastebin.com | ined a link to the lure document. Figure 4. A comment on a “Pastebin[.]com” post advertising the lure, warning against trying more t | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | paste.sh | to the lure document, was copy the script shared through a “paste[.]sh” link into the navigation bar of the Chrome browser prece | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | simpleswap.io | ure but was rewritten to target a different trading site — “SimpleSwap[.]io”, another cryptocurrency trading aggregator. The fake exp | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | swapzone.io | rsion we observed targeted the cryptocurrency trading site “SwapZone[.]io”. It was formatted in the style of a vulnerability report | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | magento.com | tfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip "To help resolve th | Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell The Hacker News | · 9d ago |
| domain | dll.lat | for payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present w | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | github.io | hyperlinks to the lure pages (e.g., "viziocomsetupentercode.github[.]io"), urging readers to set up their smart TV "easily" by fo | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | pltechoo.pro | echnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is a JavaScript dropper for M | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | readthedocs.io | central how to login" to serve a fraudulent link hosted on readthedocs[.]io. The page features a prominent "Get Started" button that | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | reficon.pro | are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is a | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | u320.my | d delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | urlscan.io | ts.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io yields 1,112 results as of writing, down from 1,190 at the | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | us3.org | e client-side and send the information to the domain "stats.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | ustechnio.com | of the domains used for payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[. | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | wapp.live | ins." One account managing some of the redirector domains ("wapp[.]live") was suspended by Hostmaza earlier this year. The disclo | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | wc.ci | red email addresses linking them to Garage2Global domains ("wc[.]ci"). A sample of some of the GitHub accounts and their asso | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | annastudios-paros.com | shing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | arrmmy.com | omain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Histori | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | captelind.com | omain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Hi | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | ccpipharma.com | node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing d | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | cifutura.com | ishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domai | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | daengrentacar.com | domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dataclust.com | omain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dnsforward.com | omain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing d | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dronalms.com | Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | haliotisbar.com | in hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com H | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hnospascualfadon.com | main planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Histo | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hoaivt.com | hishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hotelmidtownsurat.com | shing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Do | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | kgsscans.com | n management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | knowncontractor.com | Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historic | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | konceptenterprises.com | s 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | management.daengrentacar.com | domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page File | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | management.michaelmarcotte.com | ing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | offtic.com | hishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | planisteradmin.com | in Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | rootreseller.com | Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | soil-management.com | hishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phi | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | valtteri.net | ain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | virextec.com | hishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domai | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | xfjcc.fun | ts command-and-control (C2) server ("206.237.30[.]232" or " xfjcc[.]fun ") every 30 seconds over plaintext HTTP for new commands, | PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution The Hacker News | · 10d ago |
| domain | 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site | scans. “Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and teste | StyleSmuggler: The Magento Zero-Day Behind New Store Attacks Security Affairs | · 10d ago |
| domain | assignpasskey.com | the lure domains flagged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.] | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | mfaregister.com | agged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.] | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | nowsso.com | lf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeyde | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | oskeysetup.com | below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com regist | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | oursso.com | sskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | passkeydeploy.com | owsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | passkey-mfa.com | faregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | registermymfa.com | up[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controll | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | setpasskey.com | m passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controlled AitM Microsoft | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | coder-infra.com | rds. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder | ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More The Hacker News | · 10d ago |
| domain | pstatic.net | elivery traffic into normal web browsing, mimicking Naver’s pstatic.net static content domain. “Ted backdoor and curlRAT were desig | North Korean Hackers Deploy New Linux Espionage Toolkit SecurityWeek | · 10d ago |
| domain | anondns.net | nConnect.Client.exe"), which then connected to "borertors92.anondns[.]net." The session then uses "wscript.exe" to execute the four | Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts The Hacker News | · 10d ago |
| domain | opik.net | ontrol (C2) server located at "45.13.237[.]190" ("tele-sync.opik[.]net"). Hosted on the IP address is a RAR archive containing t | Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts The Hacker News | · 10d ago |
| domain | asp.net | g exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute | Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released The Hacker News | · 10d ago |
| domain | gardenpark.click | : health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftManager C2) Gen Threat Labs first documented REVSTEA | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | hubdisplay.lol | onitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinU | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | journal-metric.lol | ain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftMan | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | roast-core85.click | 66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManag | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | cdnflare.xyz | 69bf220 (running in memory on one Disrex store) Domain: 247.cdnflare[.]xyz (malware download host) IP: 99.84.67[.]186:443 (command-a | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 11d ago |
| domain | api.cadence.jetbrains.com | tween August 8 and 24, 2026. The exploited Cadence server ("api.cadence.jetbrains.com") has since been taken offline. The company conceded that t | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| domain | 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site | rameter. Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and teste | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | ntp.timesysnc.net | k like NTP server replies. As of September 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | time.microsft.run | ) ntp.timesysnc.net:123 C2, custom NTP-shaped traffic (UDP) time.microsft.run:123 C2, custom NTP-shaped traffic (UDP) pool.microsft.studi | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | windwsecurity.run | d host # C2 servers 99.84.67.186:443 C2, WebSocket over TLS windwsecurity.run:443 remote shell, WebSocket over TLS (TCP) ntp.timesysnc.ne | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | acemlnd.com | sage body to be routed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part, | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | activehosted.com | ed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part, said it has tested its c | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | advancefundingboost.com | ost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unite | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | digitalcapitalboost.com | he most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advance | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | directcapitalboost.com | ay[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | guardiancapitalway.com | xpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com direct | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | guardiangrowthfunding.com | e top 10 sender domains by the most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yo | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | harboradvancefunding.com | ng[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedi | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | onlinedirectfinance.com | ding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from these finance-themed domai | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | thebusinessloanexpress.com | low - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardianca | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | unitedfundingwave.com | t[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | yourlocfunding.com | ]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harbor | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | cleanos.online | in.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanos[.]online. Rapid7 has not said whether the | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | darklights.store | erhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.soci | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | grip-cdns.space | but not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanos | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | monderhouse.space | he following indicators of compromise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.] | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | primgs.lol | in the same two maltrail entries but not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.] | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | pstatic.autos | ite Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[. | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | smartnords.site | mise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.p | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | socialteams.store | ]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-100 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | worksongo.store | tatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | img.darklights.store | previously recorded, it reaches out to a secondary domain – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00 | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| domain | img.monderhouse.space | d fast-poll flag. If the validation fails, the C2 resets to img.monderhouse.space 2 staged payload drop Issues an authenticated HTTP POST to | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| domain | hunt.io | because its own AI infrastructure was not properly secured. Hunt.io found a backend that anyone could access without authentica | Chinese Hackers Use AI Agents in Multi Security Affairs | · 13d ago |
| domain | niestools.com | routed requests through private proxy servers linked to the niestools.com domain. The AI models did not break into systems on their o | Chinese Hackers Use AI Agents in Multi Security Affairs | · 13d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.