In case anyone needs them: These are some IOCs associated with current events.
Most are dated, but may give you a starting point in your threat hunts.
MuddyWater,C2 IP,185.236.234.161,DeepInstinct 2024
MuddyWater,C2 IP,185.216.13.242,DeepInstinct
MuddyWater,C2 IP,45.66.249.226,Cyberthint 2025
MuddyWater,C2 IP,91.121.240.102,NetSecurity
MuddyWater,C2 IP,137.74.131.19,SOCPrime 2026
MuddyWater,C2 IP,164.132.237.68,Protostellar
MuddyWater,C2 IP,185.94.108.91,ESET 2025
MuddyWater,C2 IP,45.159.104.13,USCYBERCOM
MuddyWater,C2 IP,185.162.231.46,Joint Advisory
MuddyWater,C2 IP,185.236.234.165,Radar Offseq
MuddyWater,C2 IP,82.117.255.29,Stormshield
MuddyWater,C2 Domain,oneskyapp[.]com,MITRE G0069
APT33,C2 IP,91.219.236.148,MITRE G0064
APT33,C2 Port,808,MITRE
APT33,Malware Hash,e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855,FireEye
APT33,Exploit CVE,CVE-2017-11774,Mandiant
APT33,Malware Hash,d41d8cd98f00b204e9800998ecf8427e,Microsoft
APT33,C2 Domain,elfin-team[.]org,Leak
APT35,C2 IP,84.200.193.20,Stormshield 2025
APT35,C2 IP,79.132.131.184,DomainTools
APT35,C2 IP,128.199.237.132,Internal Leak
APT35,C2 IP,212.175.168.58,Stormshield
APT35,C2 Domain,rohan63[.]xyz,GitHub Leak
APT35,Email Domain,irgc-leak[.]email,DTI Report
Even when there’s no accountability, the record matters. Credit to the Wikipedia editors maintaining this page.
Marimar Martinez was the first US citizen shot by ICE.
They claimed she was a terrorist. Said she was brandishing a weapon.
They lied. Video footage exonerated her and showed the ICE agent shot her five times.
He bragged to other agents “five shots, 7 holes”.
Silverio Villegas González was an undocumented immigrant who was shot and killed at close range while allegedly trying to flee.
He was dragged from his vehicle at a traffic stop after dropping his children off at school.
The bullet went through the back of his neck.
Keith Porter was shot and killed by an off duty ICE officer on New Years Eve in LA.
The officer alleges Porter pulled a weapon on him but the family and other witnesses deny that.
Renee Nicole Good was shot three times by an ICE agent who called her a “f*cking b*tch” after.
ICE claims she was using her vehicle as a weapon despite multiple videos showing she was trying to drive away from the agent.
2 of the 3 shots were through driver side door.
The ICE agent shot her through her windshield, moved out of the way of the vehicle and kept shooting.
He was in no danger. But he didn’t stop shooting until he got the kill shot.
Independent autopsy confirms it was through her left temple and out the right side of her skull.
There’s been so much documented abuse of power.
In addition to the shootings we have Liam Ramos, a five year old child who was used as bait and then taken by masked agents and sent from Minnesota to Texas.
There’s Geraldo Campos who was choked to death in an ICE camp in Texas.
The medical examiner officially ruled his death a homicide, and DHS moved to deport the witnesses!
Chaofeng Ge was found hanging in ICE custody.
They ruled it a suicide despite his arms and legs being tied behind his back.
Randall Gamboa Esquivel was in perfect health when detained by ICE.
He disappeared while in custody.
By the time his family located him, he was in a persistent vegetative state.
They deported him to Costa Rica and he died soon after.
David Courvelle worked as a detention officer in an ICE facility in Louisiana.
He sexually assaulted a Nicaraguan detainee for three months, forcing other detainees to keep watch while he abused her.
Silvia Reyna Mendoza, a mother of 8 who had been in the US for 40 years, was sexually harassed by an ICE contractor.
He reportedly would tell her if she was good to him, he would be good to her.
When she reported the harassment she was immediately detained.
Bayron Rovidio Marin had his leg broken during an ICE raid in LA.
He was then held in the hospital under a fake name so no one could find him.
He was chained to a hospital bed for 37 days until a court ordered his release.
There’s Rodney Taylor, a disabled double amputee who’s been in ICE custody for almost a year.
He was only two days away from receiving new prosthetic legs when they grabbed him.
He’s being denied his prosthetics, he’s been placed in solitary and his health is declining
Now there’s Alex Pretti, another US citizen shot and killed in broad daylight.
These are not just a few random incidents.
It’s not a few “bad apples”.
It’s a systemic problem.
These agents have been allowed to hide their identities, filled with hateful rhetoric and told they have immunity.
People are being abused, assaulted and killed by ICE.
This isn’t about immigration or crime, it’s about control & creating fear.
It’s tyranny and no one is safe under tyranny.
The scariest part is these are only the cases we know about.
At least 1,200 people are missing from Alligator Alcatraz.
Elected officials are regularly denied access into the camps.
We have to assume we are only seeing the tip of the iceberg.
Abolish ICE.
Close the camps.
Keep witnessing and speaking out.
Dear Journalists,
If a government official gives a statement that is easily disproven by multiple angles of high quality video, it is ok, encouraged even, to call them out on it in real time. That's called doing a journalism.
Secondly, although you all work for different media outlets, there is no reason why you can't sort of 'team up' and keep pressing the issue rather than letting them wriggle out by completely changing the line of questioning. This is also known as doing a Journalism.
Thanks!
Wikipedia is a jewel of the internet. Not social media, collaborative media. AI has been mining it for information, saturating it with requests, and diverting human traffic away with hallucinatory AI "summaries".
Grokipedia is the next phase of the assault. Replacing careful human work and balanced content with blatant, evil bias. It might mislead a human that wanders into its orbit, but it's real purpose is to seep into the AI responses of the chatbots. In general, AI has not been giving the "right" answers, and the billionaires are going to fix that. They are building "better" training data.
Presented for no reason at all, and certainly not if you intend on attending any protests: https://github.com/EFForg/rayhunter
It would be horrible if you had the ability to know if/when the government was attempting to identify people based on their cell phone activities.
It is almost time to check in to the #FediFridayWinlinkNet!
Send your #Winlink message between 0000-2359 UTC Friday January 16.
Try to use a different band or mode to check in each week.
To: FFWN
Subject: check-in
Message body line1: [callsign], [firstname], [city], [state/province/locale], [country], [mastodon username], [VHF/HF/APRS/Telnet, etc]
Message body line2: Besides Mastodon, what other online platforms, apps, or social media do you use for ham radio discussions? [open response]
Message body line3: Do you agree to have your callsign shared in the check-in list? [Y or N/opt-out]
Follow #FFWN on mastodon for details and conversation, and be sure to check the net webpage at https://w0rmt.net/ffwn/ for a list of weekly check-ins and responses to the question of the week.