Just added ASN Emissions Index (AEI). A leaderboard that ranks networks by how much probes they send to the Honeylabs honeypots.

https://honeylabs.net/asn-index

#ThreatIntel #IOCs #OSINT #BlueTeam #InfoSec #CyberSecurity #MCP #Golang #Python #Automation

Threat actors are leveraging shared infrastructure together with subdomain abuse to control and serve hundreds of malicious websites with minimal management.

This week we were investigating a cluster of crypto brand lookalike domains.Through subdomain abuse โ€“ often powered by wildcard DNS configurations โ€“ just 34 registered domains expand to over 500 scam sites.

Investigating website content across that cluster allowed us to find several additional clusters running the same playbook. Thousands of domains on them.

This initial cluster impersonated dozens of brands โ€” Binance, Coinbase, Kraken, KuCoin, Bybit, Bitmart. Several of these sites push fake app downloads, making malware delivery and crypto wallet theft a likely component of the broader operation.

A sample of the domains associated:

cryptocoinsx[.]cfd
bmarkit[.]com
zznyusbsgo.bitmart[.]pw
4pzyy6n7log71mm0.bitmarts[.]cc
5etxkk2aeh8jfgl0.bitstamptc[.]com

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Scams #malware #crypto #lookalikes #subdomains #iocs

๐Ÿšจ #๐—ž๐—ฎ๐—น๐—ถ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ถ๐˜๐˜† ๐—ฆ๐˜‚๐—ฟ๐—ด๐—ฒ๐˜€: ๐——๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—œ๐˜€ ๐—ฆ๐—ฐ๐—ฎ๐—น๐—ถ๐—ป๐—ด ๐—™๐—ฎ๐˜€๐˜
Weโ€™re seeing a growing Device Code #phishing activity, with Kali365 emerging as one of the most active PhaaS. In the last 24 hours alone, #ANYRUN recorded 100+ related analysis sessions.

โš ๏ธ The attack abuses legitimate Microsoft device authentication flows. Victims are shown a user code and instructed to enter it into a real Microsoft device auth page, allowing attackers to capture OAuth access tokens instead of passwords. The risk shifts from credential theft to token abuse, while significantly reducing the number of traditional phishing indicators typically used for detection and triage.

โ—๏ธ Deobfuscated Kali365 JavaScript revealed that after a verification gate, the lure deploys a phishing page, launches a legitimate Microsoft device authentication flow, and then polls /api/status/<session_id> for session states such as captured, expired, and declined.

๐Ÿ“Œ The code also contains lure-template generators for OneDrive, SharePoint, Teams, Outlook, and Voicemail, and a separate Google device-code authentication flow.

โšก๏ธ #ANYRUN lets analysts safely reconstruct the flow, validate suspicious OAuth activity faster, and identify related phishing infrastructure before campaigns scale further, helping SOC teams reduce investigation time, improve detection accuracy, and lower MTTR.

๐Ÿ‘จโ€๐Ÿ’ป See the full phishing flow, validate detection logic, and collect #IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoservice&utm_term=270526

๐Ÿ” Track Kali365 activity using this TI Lookup search query: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktotilookup&utm_term=270526#%7B%2522query%2522:%2522threatName:%255C%2522kali365%255C%2522%2522,%2522dateRange%2522:7%7D%20

๐Ÿš€ Scale your SOCโ€™s triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoplans&utm_term=270526

#cybersecurity #infosec

New IOCs observed from breached threat actor logs:

mavpaprokla[.]lat
smackit[.]lat

Recommend:
โ€ข Block/sinkhole at DNS and proxy layers
โ€ข Hunt across DNS, HTTP/S, EDR, and firewall telemetry
โ€ข Check for historical resolutions and outbound connections
โ€ข Review related infrastructure, certificates, and passive DNS pivots

If seen in your environment, treat as potentially malicious pending further enrichment.

#ThreatIntel #IOC #IOCs #CyberThreatIntelligence #DFIR #BlueTeam #SOC #ThreatHunting #Malware #Infosec #CyberSecurity #OSINT #DetectionEngineering #IncidentResponse #CTI #NetworkSecurity #DNS #ThreatResearch #CyberDefense #SIEM #EDR #MalwareAnalysis

๐Ÿšจ Update Your Detection Rules: New In-Memory Loader

We caught a highly evasive #HanGhost loader, designed to bypass traditional detection through layered obfuscation and in-memory execution. This activity targets corporate users handling payments, logistics, and contract workflows, expanding exposure across critical operations.

โš ๏ธ The delivery chain combines obfuscated JavaScript, hidden PowerShell execution, and environment-variable staging.

In the second stage, the loader retrieves an image file and extracts an encrypted payload embedded at the end of the file, combining steganography with in-memory loading and making detection significantly harder โ—๏ธ

๐Ÿ‘พ The loader is used to deliver multiple malware families: #PureHVNC, #XWorm, #Meduza, #AgentTesla, and #Phantom, with some chains also deploying #UltraVNC, extending the impact from initial access to persistent remote control.

โšก๏ธ#ANYRUN Sandbox allows analysts to reconstruct the full execution chain, helping confirm complex multi-stage activity earlier and reduce MTTR.

๐Ÿ”— JavaScript-to-Payload execution chain:

JS โžก๏ธ PowerShell โžก๏ธ in-memory .NET assembly โžก๏ธ PNG payload โžก๏ธ Malware

๐Ÿ“ˆ The campaign shows wave-based activity, indicating ongoing development and scaling:

March 26 โ€” early cluster

April 1โ€“2 โ€” first large multi-family wave

April 3 โ€” focused wave (PureHVNC / AgentTesla / Phantom)

April 6 โ€” PureHVNC-heavy activity

April 7 โ€” new peak with split between PureHVNC and XWorm/Meduza clusters

April 8 โ€” multi-family wave (PureHVNC / Phantom / AgentTesla)

April 9โ€“13 โ€” more focused wave dominated by PureHVNC, with Phantom, DarkCloud, Formbook, and Meduza also present

๐Ÿ‘จโ€๐Ÿ’ป See the analysis session and collect #IOCs to speed up detection and response: https://app.any.run/tasks/cc26155e-e8e9-442b-b000-8d1a1435e7db?utm_source=mastodon&utm_medium=post&utm_campaign=hanghost&utm_content=linktoservice&utm_term=130426

๐Ÿ” Use this TI Lookup query to pivot from IOCs, review related activity, and validate your detection coverage: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=hanghost&utm_content=linktotilookup&utm_term=130426#%7B%2522query%2522:%2522commandLine:%255C%2522bYPaSS%2520-Command%2520*iex%2520$env:%255C%2522%2522,%2522dateRange%2522:180%7D%20

๐Ÿ‘จโ€๐Ÿ’ป Equip your SOC with faster decisions and lower workload. See how #ANYRUN fits your workflows: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=hanghost&utm_content=linktoenterprise&utm_term=130426

#cybersecurity #infosec

๐Ÿšจ ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐˜ƒ๐—ถ๐—ฎ ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—ฆ๐˜๐—ผ๐—ฟ๐—ฎ๐—ด๐—ฒ ๐—”๐—ฏ๐˜‚๐˜€๐—ฒ ๐—Ÿ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด ๐˜๐—ผ ๐—ฅ๐—”๐—ง ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜†๐—บ๐—ฒ๐—ป๐˜: ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜ ๐—œ๐˜ ๐—˜๐—ฎ๐—ฟ๐—น๐˜†
We identified a multi-stage #phishing campaign using a Google Drive-themed lure and delivering #Remcos RAT. Attackers place the HTML on storage[.]googleapis[.]com, abusing trusted infrastructure instead of hosting the phishing page on a newly registered domain.

โ—๏ธ ๐—ง๐—ต๐—ฒ ๐—ฐ๐—ต๐—ฎ๐—ถ๐—ป ๐—น๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐—ฎ๐—ด๐—ฒ๐˜€ ๐—ฅ๐—ฒ๐—ด๐—ฆ๐˜ƒ๐—ฐ๐˜€.๐—ฒ๐˜…๐—ฒ, ๐—ฎ ๐—น๐—ฒ๐—ด๐—ถ๐˜๐—ถ๐—บ๐—ฎ๐˜๐—ฒ ๐˜€๐—ถ๐—ด๐—ป๐—ฒ๐—ฑ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜/.๐—ก๐—˜๐—ง ๐—ฏ๐—ถ๐—ป๐—ฎ๐—ฟ๐˜† ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ฐ๐—น๐—ฒ๐—ฎ๐—ป ๐—ฉ๐—ถ๐—ฟ๐˜‚๐˜€๐—ง๐—ผ๐˜๐—ฎ๐—น ๐—ต๐—ฎ๐˜€๐—ต. Combined with trusted hosting, this makes reputation-based detection unreliable and lowers alert priority during triage. File reputation alone is not enough. Detection depends on behavioral analysis and sandboxing.

โš ๏ธ The page mimics a Google Drive login form, collecting email, password, and OTP. After a โ€œsuccessful login,โ€ the victim is prompted to download Bid-Packet-INV-Document.js, triggering a multi-stage delivery chain:

JS (WSH launcher + time-based evasion) โžก๏ธ VBS Stage 1 (download + hidden execution) โžก๏ธ VBS Stage 2 (%APPDATA%\WindowsUpdate + Startup persistence) โžก๏ธ DYHVQ.ps1 (loader orchestration) โžก๏ธ ZIFDG.tmp (obfuscated PE / Remcos payload) โžก๏ธ Textbin-hosted obfuscated .NET loader (in-memory via Assembly.Load) โžก๏ธ %TEMP%\RegSvcs.exe hollowing/injection โžก๏ธ Partially fileless Remcos + C2 ๐Ÿšจ

๐Ÿ‘จโ€๐Ÿ’ป See the analysis session and collect #IOCs to speed up detection and response: https://app.any.run/tasks/0efd1390-c17a-49ce-baef-44b5bd9c4a97/?utm_source=mastodon&utm_medium=post&utm_campaign=google_storage_abuse_phishing&utm_term=080426&utm_content=linktoservice

๐Ÿ” Use this TI Lookup query to pivot from IOCs, review related activity, and validate your detection coverage: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=google_storage_abuse_phishing&utm_content=linktotilookup&utm_term=08042026#%7B%22query%22:%22domainName:%5C%22www.freepnglogos.com%5C%22%20and%20domainName:%5C%22storage.googleapis.com%5C%22%20and%20threatLevel:%5C%22malicious%5C%22%22,%22dateRange%22:30%7D

โšก๏ธ Equip your SOC with stronger phishing detection and contain incidents faster: https://any.run/phishing/?utm_source=mastodon&utm_medium=post&utm_campaign=google_storage_abuse_phishing&utm_term=080426&utm_content=linktophishingpage

#cybersecurity #infosec

๐Ÿ“ข Incident Notepad++ : IOCs publiรฉs par l'ancien hรฉbergeur suite ร  une mise ร  jour malveillante
๐Ÿ“ ## ๐Ÿ” Contexte

Document publiรฉ le 02/04/2026 sur le site officiel de Notepad++ (notepad-plus-plus.org), รฉmanant de l'ancie...
๐Ÿ“– cyberveille : https://cyberveille.ch/posts/2026-02-04-incident-notepad-iocs-publies-par-l-ancien-hebergeur-suite-a-une-mise-a-jour-malveillante/
๐ŸŒ source : https://notepad-plus-plus.org/assets/data/IoCFromFormerHostingProvider.txt
#IOC #IOCs #Cyberveille

Incident Notepad++ : IOCs publiรฉs par l'ancien hรฉbergeur suite ร  une mise ร  jour malveillante

๐Ÿ” Contexte Document publiรฉ le 02/04/2026 sur le site officiel de Notepad++ (notepad-plus-plus.org), รฉmanant de lโ€™ancien fournisseur dโ€™hรฉbergement. Ce document partage des indicateurs de compromission (IOCs) observรฉs dans lโ€™environnement dโ€™hรฉbergement lors de lโ€™incident impliquant une mise ร  jour malveillante de Notepad++. Lโ€™hรฉbergeur prรฉcise ne pas avoir hรฉbergรฉ la mise ร  jour malveillante elle-mรชme et ne pas avoir de visibilitรฉ sur la chaรฎne dโ€™attaque complรจte ni sur lโ€™impact pour les utilisateurs finaux.

CyberVeille

โš ๏ธ #๐—ฆ๐˜๐—ฒ๐—ฎ๐—น๐—– ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐—ฑ๐—ฒ๐—น๐—ถ๐˜ƒ๐—ฒ๐—ฟ๐—ฒ๐—ฑ ๐˜ƒ๐—ถ๐—ฎ ๐—ฎ ๐—–๐—น๐—ผ๐˜‚๐—ฑ๐—ณ๐—น๐—ฎ๐—ฟ๐—ฒ ๐—–๐—น๐—ถ๐—ฐ๐—ธ๐—™๐—ถ๐˜… ๐—ณ๐—น๐—ผ๐˜„, masking malicious activity behind trusted services. Behavioral analysis exposed a PowerShell-based execution chain used to download and run the payload while attempting to evade detection.

๐Ÿ‘พ The Process Tree reveals the payload chain: powershell.exe โžก๏ธ powershell.exe โžก๏ธ y3gag2iu.3wq.exe (StealC ๐Ÿšจ)

Multi-stage PowerShell execution and hidden payload delivery make early confirmation harder, slowing triage. #ANYRUN Sandbox helps analysts quickly validate the attack and reduce investigation time.

๐Ÿ‘จโ€๐Ÿ’ป See the analysis session and collect #IOCs to speed up detection and response: https://app.any.run/tasks/48e6b68d-dfa2-423e-8e7c-24cf8a6ef85b/?utm_source=mastodon&utm_medium=post&utm_campaign=cloudflare_clickfix&utm_term=010426&utm_content=linktoservice

โšก๏ธ Learn how #ANYRUN helps SOCs detect complex threats and contain incidents faster: https://any.run/features/?utm_source=mastodon&utm_medium=post&utm_campaign=cloudflare_clickfix&utm_term=010426&utm_content=linktosandboxlanding

โš™๏ธ Technical details:
ClickFix flow on diddyparty[.]click triggers PowerShell via Win+X โžก๏ธ I. A hidden command (-NoProfile -WindowStyle Hidden) enforces TLS 1.2, stages a random EXE in %TEMP%, pulls the payload via Invoke-WebRequest, executes it, and attempts cleanup. Full execution details are available in the Script Tracer tab.

๐Ÿ” IOCs:
diddyparty[.]click
3f0fe92c0e1c4663dcb851ce0fc97ddaed25b559be1d6e2cc0f66304ac652e38

#cybersecurity #infosec

#NPM #axios maintainer has lost control of their account. Malicious versions 1.14.1 and 0.30.4 have been published which include a RAT.

NPM has pulled the effected versions and the payload. Time to clean up and see if you were effected.

StepSecurity has an awesome write up on this issue with #iocs

Link follows this toot.

#CTI #infosec #node #cybersecurity #security #nodejs #js #malware

A more sane and parseable list of indicators:

Landing page

httpX://macdev.slab[.]com/public/posts/insta-ั–ั–-with-termina-ั–-g40n4aau?shr=6etwxr0gksp2ltctcqv7gom7

Loaders

httpX://datasphere.us[.]com/debug/loader.sh?build=492f9e58358e8e2bc9e0414fa077e197
https://datasphere.us.com/debug/payload.applescript?build=492f9e58358e8e2bc9e0414fa077e197

Mocked User Agent for curls

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36

APIs

httpX://datasphere.us[.]com/api/debug/event # initial info gathering
httpX://datasphere.us[.]com/gate # stealer upload location
httpX://datasphere.us[.]com/gate/chunk # large file uploads
httpX://datasphere.us[.]com/api/bot/heartbeat # Persistence heartbeat API

api key 61cb9c3bd1a2faa7d6613dd8e5d09e79fe95e85ab09ed6bcd6406badff5a083f

#osx #stealer #iocs