The drive-by wave doubled. A single fake-update campaign registered 906 attacker-controlled domains this week — up 2.5x from the prior week’s 371-domain output. Concurrently: a massive new phishing-framework infrastructure surge (657 IOCs with full 4-type coverage), three concurrent DPRK-linked APT clusters active in parallel, a coordinated 737-extension browser-extension abuse campaign, novel NFC-relay malware, and 14+ concurrent ransomware operators sustaining post-compromise pressure.
3,269 unique high-confidence indicators across 118 tracked clusters. 72.7% High-severity — the intelligence this cycle is concentrated on high-confidence signals. Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, adversary analytics with operator-console screenshots, top IOCs per indicator type, four production-ready Sigma rules, real-world hunting lessons, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
3,269 unique high-confidence indicators across 118 tracked clusters this cycle — up 63% in IOC count from the prior week (1,999 → 3,269) and up in cluster count (116 → 118). DOMAIN dominance at 56% share (1,831 domains) — driven by two campaigns: the drive-by fake-update wave (906 domains) and the new phishing-framework infrastructure surge. Severity distribution: 72.7% High-severity (2,377 records) — the intelligence this cycle prioritises high-confidence signals over commodity noise.
Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · Drive-by fake-update wave scales 2.5x
The drive-by fake-update campaign from the prior week doubled its infrastructure footprint. 906 attacker-controlled domains this week alone — up from 371 last week. Same automated provisioning pattern (random-string subdomain + compromised legitimate parent site), now at even greater scale. That is roughly 129 new domains registered per day from a single operator over the seven-day window.
Defensive answer: web-proxy pattern-detection is now non-optional. Individual-IOC blocking cannot keep pace with 129 fresh domains per day. Regex block on subdomain-format signature at the outer boundary; alert on any installer download from a subdomain younger than 30 days.
Headline 02 · Massive phishing-framework infrastructure surge
A single phishing-framework operator produced 657 IOCs across four IOC types (DOMAIN + HASH + IP + URL) this cycle. Full 4-type coverage from a single actor is the mature-infrastructure signal — this operator has a stable domain-registration pipeline, hash-family variants, IP-tier rotation, and URL patterns all coordinated. Framework signature this large indicates either a rented Phishing-as-a-Service platform with many affiliates or a well-resourced single operator running a broad-audience credential-harvesting operation.
Defensive answer: mail-gateway link-inspection with reputation enrichment on newly-registered domains; browser-side warnings on credential-form submissions to first-seen domains; user-awareness bulletin on the current lure pattern.
Headline 03 · DPRK-linked APT triple-track
Three concurrent DPRK-linked APT clusters active this cycle. Combined footprint: 136 IOCs across three clusters with full 3-4 IOC-type coverage each. One long-established cluster (44 IOCs, 3 IOC types), one credential-focused cluster (72 IOCs, 4 IOC types), one variant-tracking malware family (20 IOCs, 3 IOC types). Target profiles include cryptocurrency-adjacent finance, government-adjacent research, defence-industrial-base, and diplomatic missions.
Defensive answer: if your organisation operates in cryptocurrency-adjacent, government-adjacent, defence-industrial-base, or diplomatic verticals, treat these clusters as MUST-block infrastructure. Real-time alerting on first-seen contact from any of the three attributed IOC lists.
Headline 04 · Coordinated 737-extension browser abuse
A single browser-extension abuse campaign produced 86 IOCs across DOMAIN + HASH types, associated with 737 malicious browser extensions published to the marketplace under attacker-controlled publisher identities. Extensions deliver credential theft, cryptocurrency wallet draining, and covert C2. The 737-extension scale is the signal — it indicates automated extension-generation tooling rather than manual submission, and it suggests marketplace moderation is being outrun.
Defensive answer: restrict browser-extension installation to allowlisted publisher list; enforce browser-extension policy via managed browser configuration (block sideload, block dev-mode extensions on managed endpoints); audit installed extensions across the workstation fleet for any recent additions matching the attributed publisher list.
Headline 05 · Novel NFC-relay malware + 14+ concurrent ransomware operators
Two parallel signals worth calling out. A novel NFC-based relay malware family (26 IOCs across DOMAIN + HASH) targets contactless-payment terminals — a vector this catalogue has not previously observed at scale. And the concurrent-ransomware pressure continues: 14+ ransomware operators active in parallel this cycle (up from 12 last week) — combined footprint 155+ IOCs with TOR-based negotiation-portal infrastructure the common thread.
Defensive answer: for NFC exposure — audit contactless-payment terminal firmware currency, network-segment payment infrastructure. For ransomware pressure — verify backup immutability and test restore procedures. The probability that at least one of the 14+ operators reaches your environment in any given quarter is high.
03 · Indicator type, severity, and category mix
Domain dominance at 56% share signals infrastructure-heavy campaign activity — the drive-by fake-update campaign alone contributed 906 domains. Hash volume at 593 (18% share) is elevated by APT + info-stealer activity. Severity: 72.7% High-severity because the weekly-tier feed prioritises high-confidence signals. Category dominance: Malware-Activity at 32.4% share, Framework tier at 18% share (phishing-framework surge), APT at 9.6%.
Bars scaled relative to the dominant Domain volume. The 56% Domain share (1,831 domains) is unusually high vs baseline — driven by two campaigns: the drive-by fake-update wave and the new phishing-framework surge. Hash share at 18% and IP share at 12% reflect elevated APT + info-stealer activity.
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| Domains | 1,831 | 56.01% | |
| File hashes | 593 | 18.14% | |
| IPs | 400 | 12.24% | |
| URLs | 371 | 11.35% | |
| Other artefacts | 43 | 1.32% | |
| Emails | 29 | 0.89% | |
| Process names | 2 | 0.06% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 2,377 | 72.71% | |
| Medium | 189 | 5.78% | |
| Low | 703 | 21.51% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| Malware-Activity | 1,269 | 38.55% | |
| Framework | 707 | 21.48% | |
| APT | 376 | 11.42% | |
| Spyware | 178 | 5.41% | |
| C&C Server | 158 | 4.80% | |
| Ransomware-as-a-service | 146 | 4.43% | |
| Malicious-Infrastructure | 139 | 4.22% | |
| Botnet | 103 | 3.13% | |
| RAT | 101 | 3.07% | |
| Backdoor | 65 | 1.97% | |
| Loader | 25 | 0.76% | |
| Supply Chain | 16 | 0.49% | |
| Phishing | 5 | 0.15% | |
| Vulnerability | 4 | 0.12% |
04 · Cluster footprint — ranked by unique-IOC count
38 clusters ranked by unique IOC footprint. Framework-infrastructure entries shown in grey to preserve visual clarity of the campaign-attributed clusters. All labels sanitised into category descriptors.
| # | Cluster descriptor | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Drive-by fake-update campaign (Week 2 · scaled 2.5x)
Malware Campaign · DOMAIN, HASH
|
906 | HIGH | |
| 02 | Phishing-framework infrastructure (Cluster A)
Phishing Framework · DOMAIN, HASH, IP, URL
|
657 | LOW | |
| 03 | Open remote-agent C2 framework
C2 · IP
|
141 | MEDIUM | |
| 04 | Browser-vendor-impersonation malware campaign
Malware Campaign · HASH, IP
|
136 | HIGH | |
| 05 | Attributed APT cluster (Cluster B · regional)
APT · DOMAIN, HASH, IP
|
134 | HIGH | |
| 06 | Info-stealer family (Cluster C · 4-type coverage)
Malware · DOMAIN, HASH, IP, URL
|
129 | HIGH | |
| 07 | Coordinated browser-extension abuse (Cluster D · 737 exts)
Malware Campaign · DOMAIN, HASH
|
86 | HIGH | |
| 08 | DPRK-linked APT cluster (Cluster E)
APT · DOMAIN, HASH, IP, URL
|
72 | HIGH | |
| 09 | Malware family (Cluster F · 6-type IOC coverage)
Malware · DOMAIN, EMAIL, HASH, IP, OTHERS, URL
|
62 | HIGH | |
| 10 | Attributed APT cluster (Cluster G)
APT · DOMAIN, HASH, IP, URL
|
52 | HIGH | |
| 11 | DPRK-linked APT cluster (Cluster H · long-established)
APT · DOMAIN, HASH, IP
|
44 | HIGH | |
| 12 | Open-framework C2 infrastructure (framework tier)
C2 · DOMAIN, HASH, IP, URL
|
39 | MEDIUM | |
| 13 | Info-stealer family (Cluster J)
Malware · DOMAIN, HASH, IP, URL
|
36 | HIGH | |
| 14 | Ransomware operator (Cluster K)
Ransomware · DOMAIN, HASH, IP, URL
|
31 | HIGH | |
| 15 | Regional-tracked APT cluster (South Asia)
APT · DOMAIN, HASH, IP
|
30 | HIGH | |
| 16 | Info-stealer family (Cluster L · re-brand)
Malware · DOMAIN, IP
|
29 | HIGH | |
| 17 | Multi-stage campaign (Cluster M)
Malware Campaign · DOMAIN, HASH, IP
|
28 | HIGH | |
| 18 | Botnet family (Cluster N)
Botnet · DOMAIN, HASH
|
27 | HIGH | |
| 19 | Webshell / open-source-framework family
Backdoor · IP
|
26 | HIGH | |
| 20 | NFC-based relay malware (novel vector)
Malware · DOMAIN, HASH
|
26 | HIGH | |
| 21 | Social-engineering malware chain (recurring)
Malware Campaign · DOMAIN, HASH, IP
|
25 | HIGH | |
| 22 | Commodity RAT family (Cluster P)
RAT · DOMAIN, HASH, IP
|
25 | HIGH | |
| 23 | Commodity RAT family (Cluster Q)
RAT · DOMAIN, HASH, IP
|
25 | HIGH | |
| 24 | Ukrainian-tracked APT cluster (Cluster R · 5-type IOC)
APT · DOMAIN, EMAIL, HASH, IP, URL
|
23 | HIGH | |
| 25 | DPRK-associated malware family (v7)
Malware · DOMAIN, HASH, IP
|
20 | HIGH | |
| 26 | Multi-family espionage campaign
Malware Campaign · DOMAIN, HASH, IP
|
20 | HIGH | |
| 27 | Ransomware operator (Cluster S)
Ransomware · DOMAIN, HASH, IP
|
17 | HIGH | |
| 28 | Attributed APT cluster (Cluster T)
APT · DOMAIN, HASH
|
17 | HIGH | |
| 29 | Malicious package-registry campaign
Supply Chain · DOMAIN
|
16 | HIGH | |
| 30 | RAT family (Cluster U)
Malware · DOMAIN, HASH
|
15 | HIGH | |
| 31 | Commodity RAT family (Cluster V)
Malware · DOMAIN, HASH, IP
|
14 | HIGH | |
| 32 | Ransomware operator (Cluster W)
Ransomware · DOMAIN, HASH, IP
|
12 | HIGH | |
| 33 | Browser-extension scareware campaign
Malware Campaign · DOMAIN, HASH
|
12 | HIGH | |
| 34 | Multi-stage operation (Cluster X)
Malware Campaign · DOMAIN, HASH, IP
|
11 | HIGH | |
| 35 | Remote-desktop malware family
Malware · DOMAIN, HASH, IP
|
11 | HIGH | |
| 36 | ICS/manufacturing-tool-abuse malware
Malware · DOMAIN, HASH, IP
|
11 | HIGH | |
| 37 | Ransomware operator (Cluster Y)
Ransomware · DOMAIN
|
11 | HIGH | |
| 38 | Ransomware operator (Cluster Z)
Ransomware · DOMAIN, HASH
|
10 | HIGH |
05 · Themed deep-dives
05.1 · The drive-by fake-update wave doubled — 906 domains in seven days
The dominant infrastructure signal of the cycle. A single drive-by fake-update campaign registered 906 attacker-controlled domains this week, up 2.5x from the prior week’s 371-domain output. Structural pattern unchanged: [a-z0-9]{8}.[compromised-site].[tld]. The scale change is the story — ~129 new attacker domains per day from a single operator over seven days means the automated infrastructure-provisioning pipeline has been re-tuned for higher throughput, OR the operator has scaled their compromised-site inventory.
Defensive actions: web-proxy regex block on the subdomain-format signature is mandatory now. Alert on .exe, .msi, .dmg, .pkg downloads from subdomains younger than 30 days. Browser-plane hardening: disable auto-download prompts; require user confirmation for every file-type download.
05.2 · New phishing-framework infrastructure surge — 657 IOCs, full 4-type coverage
A single phishing-framework operator produced 657 IOCs across DOMAIN + HASH + IP + URL this cycle — full 4-type coverage from a single operator is the mature-infrastructure signal. Either a rented Phishing-as-a-Service platform with many affiliates or a well-resourced single operator running a broad-audience credential-harvesting campaign. Either way, mail-gateway defences alone are insufficient at that scale.
Defensive actions: mail-gateway link-inspection with reputation enrichment on newly-registered domains; browser-side warnings on credential-form submissions to first-seen domains; user-awareness bulletin on the current lure pattern; investigate any recent user-reported phishing attempts against the attributed IOC list.
05.3 · DPRK-linked APT triple-track
Three concurrent DPRK-linked APT clusters active. Combined footprint: 136 IOCs across three clusters.
- One long-established cluster (44 IOCs across three IOC types) with cryptocurrency-adjacent target profile.
- One credential-focused cluster (72 IOCs across four IOC types) with government-adjacent research targeting.
- One malware-family variant tracker (20 IOCs across three IOC types) representing next-generation tooling from a well-known family.
Defensive actions: if in cryptocurrency-adjacent, government-adjacent, defence-industrial-base, or diplomatic verticals, treat these clusters as MUST-block. Real-time alerting on first-seen contact from any attributed IOC.
05.4 · Coordinated 737-extension browser abuse
A single campaign is associated with 737 malicious browser extensions published to marketplace platforms. The 737-extension scale suggests automated extension-generation tooling and marketplace-moderation bypass. Extensions deliver credential theft, cryptocurrency wallet draining, and covert C2. Related infrastructure footprint: 86 IOCs across DOMAIN + HASH.
Defensive actions: restrict browser-extension installation to allowlisted publishers via managed browser configuration; audit installed extensions across the workstation fleet against the attributed publisher list; alert on any user attempting to install an extension not on the allowlist.
05.5 · Novel NFC-relay malware + 14+ concurrent ransomware operators
NFC-relay malware family (26 IOCs across DOMAIN + HASH) targets contactless-payment terminals. Novel vector for this catalogue. If your organisation operates any NFC-based payment infrastructure, audit terminal firmware currency and network segmentation.
14+ ransomware operators active in parallel (up from 12 last week). Combined footprint 155+ IOCs. TOR-based negotiation portals remain the common infrastructure thread. Ensure backup immutability is verified and restore procedures tested.
05B · Adversary analytics — technique, geography, sector
Three cross-cutting analytics tell the story of adversary intent this cycle: which techniques are most prevalent across all clusters, which countries the intelligence signals are most likely targeting, and which sectors carry the highest concurrent-target attention. All three are extracted from this cycle’s full catalogue (not just the weekly-filtered high-confidence tier).
05B.1 · Top techniques (ATT&CK)
The single most-used technique this cycle: T1105 · Ingress Tool Transfer at 1,478 hits — the universal second-stage-payload-pull technique. Combined with T1071.001 (web-protocol C2) at 1,406 and T1059.001 (PowerShell) at 1,184, these three techniques form the persistent execution triad. T1189 (drive-by compromise) at 943 hits reflects this cycle’s scaled drive-by campaign.
T1105 · Ingress Tool TransferT1071.001 · Application Layer Protocol · WebT1059.001 · PowerShellT1204.002 · User Execution · Malicious FileT1027 · Obfuscated Files or InformationT1204.001 · User Execution · Malicious LinkT1566.002 · Phishing · Spearphishing LinkT1036 · MasqueradingT1189 · Drive-by CompromiseT1041 · Exfiltration Over C2 ChannelPercentages relative to the top-10 technique volume. T1105 leads at 1,478 hits — used by almost every multi-stage cluster. The T1071/T1059/T1204 combination reflects the phishing-to-execution-to-C2 pipeline dominant across commodity operators this week.
Technique-hit heatmap from the operator console. Coverage climbed from 44.1% last week to 52.5% this week — 15 additional distinct techniques observed. Every tactic column (Reconnaissance through Impact) is populated. T1547 · Boot or Logon Autostart (2,154 hits), T1204 · User Execution (2,154 hits), and T1027 · Obfuscation (1,126 hits) are the load-bearing dark-red squares.
05B.2 · Most-common targeted countries
The most-targeted country this cycle: United States (1,174 combined attributions) — edging out Germany (1,118), France (1,062), Canada (1,030), United Kingdom (1,028), Australia (1,001), and India (989). The distribution is unusually tight across the top-7 — a ~185-attribution band suggests broad-audience campaigns rather than surgical geographic targeting.
United States figure combines two representations from the source data. Top-7 concentration inside a ~185-attribution band = broad-target commodity-campaign signature, not narrow geographic focus. Same pattern as prior cycle.
Broad-target signature visible geographically — the top-7 countries (United States, Germany, France, Canada, United Kingdom, Australia, India) all show high-intensity coloring. Consistent with the country analytics above: broad-target commodity-tier cycle. Regional breakdown: Europe 3.4k IOCs · Americas 2.2k · Asia 1.2k · Oceania 1.0k · Africa 1.
05B.3 · Most-common targeted sectors
The most-targeted sector this cycle: Healthcare (1,305 attributions) — edging out Government (1,301), Technology (1,281), Manufacturing (1,256), and Financial Services (1,216). Same broad-target signature as the country distribution — the top-5 sectors sit inside a ~90-attribution band. Healthcare edging past Government + Tech + Manufacturing this cycle is worth watching — last cycle Tech led.
Healthcare edges into the top slot for the first time in the current cycle series. Broad target signature persists across top-5 sectors (all within 90 attributions). Critical Infrastructure and Defense enter top-15 at lower but non-zero volume.
The Threat Nova sunburst confirms the analytics table — Consumer, Manufacturing, Healthcare, Tech, Financial Services, Government carry the largest attributed footprints, with the top-5 within a tight ~90-attribution band. Broad-target commodity-tier cycle. 504 ransom-tagged IOCs across the sector view reflects the concurrent-ransomware-operator pressure from Headline 05.
Reading the three dimensions together. Top technique = Ingress Tool Transfer (universal second-stage). Top country = United States (broad Western + India + Australia distribution). Top sector = Healthcare (edging into top slot; broad commodity-tier signature persists). All three point to: this cycle’s adversary attention remains broad, not narrow. High-volume commodity campaigns hitting the widest possible audience across industries and geographies. Same defensive-answer template as prior weeks: signature-level content and behavioural detectors that catch the pattern regardless of who runs it.
06 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Initial Access | T1189 · T1566 · T1195 · T1195.002 · T1078 · T1133 | Drive-by compromise (943 hits · dominant), phishing (attachment + link), supply-chain compromise | 943 |
| Command and Control | T1071 · T1071.001 · T1105 · T1090 · T1573 · T1132.001 | Web-protocol C2 (1406 hits) + ingress tool transfer (1478 hits) — the universal cross-cluster techniques this cycle | 1,406 |
| Execution | T1059 · T1059.001 · T1204 · T1204.001 · T1204.002 · T1218 | PowerShell (1184 hits), user execution (994+1156 hits combined), signed-binary proxy execution | 1,184 |
| Defense Evasion | T1027 · T1036 · T1055 · T1070.004 · T1140 · T1562 | Obfuscation (1115 hits) + masquerading (963 hits) + indicator removal on host (127 hits) | 1,115 |
| Ingress Tool Transfer | T1105 | Second-stage payload pull — 1,478 hits · universal across every multi-stage cluster | 1,478 |
| Credential Access | T1003 · T1555 · T1555.003 · T1552 · T1539 | Browser credential store theft (140 hits) + session cookie theft (166 hits) — info-stealer families dominant | 306 |
| Persistence | T1547.001 · T1543.003 · T1053.005 · T1505.003 | Registry-run keys (221 hits), service creation, scheduled tasks, webshell | 221 |
| Impact | T1486 · T1489 · T1490 · T1491 | Data encryption for impact (164 hits) — 14+ concurrent ransomware operators driving impact tactic pressure | 164 |
| Discovery | T1082 · T1057 · T1083 · T1018 · T1046 | System info (133 hits), file discovery (112 hits), process, remote-system, network config | 245 |
| Exfiltration | T1041 · T1567 · T1090 | Exfil over C2 (488 hits) — the volume signal of the cycle | 488 |
| Defense-in-Depth-Evasion | T1070.004 · T1562 | Indicator removal (127 hits) + disable defenses — post-compromise cleanup | 127 |
| Resource Development | T1583.001 · T1584.001 · T1585 · T1195.002 | Adversary-acquired domains (906 in a single campaign) + supply-chain compromise | 906 |
Detection-engineering takeaway. Ingress Tool Transfer (T1105) leads at 1,478 hits — the universal second-stage-payload-pull technique. Combined with Web-Protocol C2 (T1071.001, 1,406 hits) and PowerShell (T1059.001, 1,184 hits), these three techniques form the persistent commodity-execution triad. Drive-by Compromise (T1189) at 943 hits reflects this cycle’s dominant drive-by campaign. Data Encrypted for Impact (T1486) at 164 hits reflects the 14+ concurrent ransomware operators.
07 · Real-world threat intelligence lessons
Beyond the specific IOCs, this cycle’s data carries lessons that will still matter next month and next quarter.
Lesson 01 · When drive-by domain volume doubles week-over-week, pattern detection is no longer optional
Last week: 371 attacker-controlled domains from one campaign. This week: 906. If your defensive architecture blocks individual IOCs, the operator’s provisioning pipeline outpaces you by ~10x. The mature program deploys web-proxy regex pattern matching on subdomain format signatures — blocking the pattern rather than the IOC.
Lesson 02 · A single phishing framework at 657 IOCs is a Phishing-as-a-Service ecosystem
Full 4-type IOC coverage from a single operator at that volume indicates either a rented PhaaS platform with many affiliates or a well-resourced single operator. Either way, the operator is running an automation pipeline. The defensive answer is not to chase individual phishing lures — it’s to invest in browser-side credential-form protection and mail-gateway link-inspection with real-time reputation enrichment.
Lesson 03 · Three concurrent DPRK-linked APT clusters is a strategic-target-vertical signal
When three DPRK-linked clusters run in parallel with credential-focused, cryptocurrency-adjacent, and government-research target profiles, the operator ecosystem is signalling coordinated strategic attention on those verticals. Organisations in those verticals should treat these clusters as MUST-block infrastructure — not as passive threat-intel context.
Lesson 04 · A 737-extension marketplace-abuse campaign means moderation is being outrun
Marketplace-abuse at 737-extension scale from a single campaign indicates automated extension-generation tooling. The defensive answer must operate at policy layer, not at signature layer — enforce browser-extension allowlisting via managed browser configuration; make ad-hoc extension installation blocked-by-default.
Lesson 05 · NFC-relay malware is a new frontier that most defensive programs don’t model
26 IOCs is small in absolute terms but the target profile (contactless-payment terminals) is significant. If your organisation operates NFC-based payment infrastructure, this vector belongs on your threat model this week — not next quarter.
Lesson 06 · 14+ concurrent ransomware operators means backup is the perimeter, restated
Third consecutive week with 12+ concurrent ransomware operators. The probability that at least one reaches your environment approaches certainty over a quarterly horizon. If your restore procedure has not been tested against a full-domain-encrypted scenario in the last 90 days — it has not been tested.
One-line synthesis. This week: pattern-detection at web proxy is now mandatory; browser-side credential-form protection is table stakes; DPRK-linked triple-track validates strategic-vertical monitoring; browser-extension allowlisting is a control worth enforcing; NFC-relay expands the payment-infrastructure attack surface; and backup remains the perimeter. Six takeaways from one week that will still be true next quarter.
08 · Top IOCs per indicator type
Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.] → . and hxxp → http).
Top 15 · IP addresses (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 1.14.193.53 | Backdoor | HIGH |
| 02 | 101.132.120.245 | Backdoor | HIGH |
| 03 | 101.32.34.248 | Backdoor | HIGH |
| 04 | 101.43.115.8 | Backdoor | HIGH |
| 05 | 103.125.234.14 | Ransomware | HIGH |
| 06 | 103.35.189.225 | Malicious-Infra | HIGH |
| 07 | 103.35.191.173 | Malicious-Infra | HIGH |
| 08 | 103.83.87.158 | RAT | HIGH |
| 09 | 103.87.9.62 | APT | HIGH |
| 10 | 104.194.133.210 | Malware-Activity | HIGH |
| 11 | 104.21.53.85 | Malware-Activity | HIGH |
| 12 | 104.223.98.68 | RAT | HIGH |
| 13 | 104.243.47.67 | RAT | HIGH |
| 14 | 106.75.178.185 | Backdoor | HIGH |
| 15 | 107.175.101.136 | RAT | HIGH |
Top domains (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 004wisu6[.]habbofutbol[.]com | Malware-Activity | HIGH |
| 02 | 0i16tvqj[.]foodpapajobs[.]com | Malware-Activity | HIGH |
| 03 | 0ksjitt3[.]hanovereyephotography[.]com | Malware-Activity | HIGH |
| 04 | 0rwgfz6h[.]finkfamilyautomotive[.]com | Malware-Activity | HIGH |
| 05 | 1188baij[.]com | Supply Chain | HIGH |
| 06 | 123[.]nsjdhmdjs[.]com | APT | HIGH |
| 07 | 19uir4dz[.]grannygshemporium[.]com | Malware-Activity | HIGH |
| 08 | 1point18[.]ch | Malware-Activity | HIGH |
| 09 | 1rtwg8k8ud[.]buzz | Malware-Activity | HIGH |
| 10 | 2[.]nsjdhmdjs[.]com | APT | HIGH |
| 11 | 2[.]potatouu[.]com | APT | HIGH |
| 12 | 28jk0aeb[.]eng-slimsounds[.]com | Malware-Activity | HIGH |
| 13 | 2ky85g4j[.]goldalignn[.]com | Malware-Activity | HIGH |
Top file hashes (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 00a9101514b7cf8fd974a7f3b4ebf6c1768ac9a257848cb9df95874cc984ae55 | APT | HIGH |
| 02 | 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | APT | HIGH |
| 03 | 01f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950 | Malware-Activity | HIGH |
| 04 | 02e7ede9b7bcc19506a4fa36fa66ecde2b8638422d7e711d525fb4a4fedc2f82 | APT | HIGH |
| 05 | 02ebc2356f9f700bbdac444cdefa0da2 | APT | HIGH |
| 06 | 036bcb62be72c4663b9564955f93b05f | Botnet | HIGH |
| 07 | 03b156e3ecd4234ce951eba59a32aee5 | RAT | HIGH |
| 08 | 03b1df2b08999262c772b67a7bd65e9e8f6058036b5e7a382f06d3aa672854d0 | APT | HIGH |
| 09 | 0400b20492be1fcf6d2128b5b8d50a6011279341394fafce1da1e69482e7a750 | APT | HIGH |
| 10 | 04db8e4dfecfc300a86614a2393bb768861196b18f17845b5765d06e1ba692c4 | APT | HIGH |
| 11 | 0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f | RAT | HIGH |
Top URLs (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | hxxp[://]216[.]203[.]20[.]36/debug[.]log | Ransomware | HIGH |
| 02 | hxxp[://]2lb5n6bqncc4lu4grm46cpoqrq3yyuriyfzdwlemuajj6x6jbbsgrbqd[.]onion/ | Ransomware-as-a-service | HIGH |
| 03 | hxxp[://]31[.]77[.]227[.]121/bins/x86_64 | Malicious-Infra | HIGH |
| 04 | hxxp[://]3u2h3ingiz45yyiplgbuflp6jex4xd2wtubvgjdg44nlgllrjv6qxxid[.]onion/ | Ransomware | HIGH |
| 05 | hxxp[://]47h4pwve4scndaneljfnxdhzoulgsyfzbgayyonbwztfz74gsdprz5qd[.]onion/ | Malware-Activity | HIGH |
| 06 | hxxp[://]4n6h3qqewk6dlqribjmw64al5szeuyhcbbfoar37p3yr43hz365nwnyd[.]onion/ | Ransomware | HIGH |
| 07 | hxxp[://]5qmw6mv5ucbeskd3rv6vgn5dqgsuectmtqvz4paukmvhtlazzkuxuwqd[.]onion/ | Ransomware | HIGH |
| 08 | hxxp[://]6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad[.]onion | Malware-Activity | HIGH |
| 09 | hxxp[://]7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd[.]onion/ | Malware-Activity | HIGH |
| 10 | hxxp[://]apvc24autvavxuc6[.]onion/ | Malware-Activity | HIGH |
09 · Sigma detection rules
Sigma 01 · Scaled drive-by fake-update chain (HIGH)
title: Drive-By Fake-Update Chain (Scaled) — Random-Subdomain Installer Download
id: 4f2a8d6c-7b53-4820-9a71-3f5c1e2d8a42
status: experimental
description: |
Detects the drive-by fake-update chain — user browsing session leads to a
download of an installer file (.exe, .msi, .dmg, .pkg) from a random-string
subdomain of a low-reputation parent domain. This week the campaign scaled
2.5x, registering 906 domains in seven days. Pattern-level detection is
now mandatory — individual-IOC blocking cannot keep up.
references:
- https://hackforlab.com/weekly-threat-advisory-august-10-16-2026/
author: HackForLab Threat Intelligence
date: 2026/08/17
tags:
- attack.initial_access
- attack.t1189
- attack.execution
- attack.t1204.002
- attack.resource_development
- attack.t1583.001
logsource:
category: web_proxy
detection:
s1_random_subdomain:
destination_host|re: '^[a-z0-9]{6,10}\.[a-z0-9-]+\.[a-z]{2,10}$'
s2_installer_download:
request_uri|endswith:
- '.exe'
- '.msi'
- '.dmg'
- '.pkg'
- '.deb'
request_method: 'GET'
s3_low_reputation_parent:
destination_parent_domain_age: '<30d'
OR destination_parent_domain_reputation: 'unknown'
condition: s1_random_subdomain and s2_installer_download and s3_low_reputation_parent
falsepositives:
- Legitimate software installers from allowlisted publishers
level: high
Sigma 02 · Phishing-framework credential-form to first-seen domain (HIGH)
title: Phishing-Framework Credential-Form Submission to First-Seen Domain
id: 6b7c8d9e-1a2b-4c5d-9876-543210fedcba
status: experimental
description: |
Detects credential-form submission (POST with password field) to a domain
that is first-seen for the environment within 24 hours AND has domain
registration age under 30 days. Catches this cycle's massive phishing-
framework infrastructure surge (657 IOCs, 4-type coverage).
references:
- https://hackforlab.com/weekly-threat-advisory-august-10-16-2026/
author: HackForLab Threat Intelligence
date: 2026/08/17
tags:
- attack.initial_access
- attack.t1566
- attack.credential_access
- attack.t1056
logsource:
category: web_proxy
detection:
s1_credential_form_post:
request_method: 'POST'
request_body|contains:
- 'password='
- 'passwd='
- 'j_password='
s2_first_seen_destination:
destination_first_seen_in_env: '<24h'
destination_domain_age: '<30d'
condition: s1_credential_form_post and s2_first_seen_destination
falsepositives:
- New corporate SaaS onboarding (allowlist by tenant)
level: high
Sigma 03 · Browser extension install from non-allowlisted publisher (HIGH)
title: Browser Extension Install from Non-Allowlisted Publisher
id: 7d8e9f0a-2b3c-4d5e-8765-432109876543
status: experimental
description: |
Detects browser-extension install events where the extension's publisher
identity is not on the allowlisted-publisher list. Catches this cycle's
737-extension coordinated marketplace-abuse campaign at the endpoint
install layer.
references:
- https://hackforlab.com/weekly-threat-advisory-august-10-16-2026/
author: HackForLab Threat Intelligence
date: 2026/08/17
tags:
- attack.persistence
- attack.t1176
- attack.initial_access
- attack.t1195
logsource:
category: browser_extension_event
detection:
s1_extension_install:
event_type: 'install'
browser: [chrome, edge, firefox, safari, brave]
s2_publisher_not_allowlisted:
publisher_identity|not:
- 'allowlisted_publisher_list'
condition: s1_extension_install and s2_publisher_not_allowlisted
falsepositives:
- Legitimate developer-tool extensions (extend allowlist per team)
level: high
Sigma 04 · Universal ransomware behaviour (CRITICAL)
title: Universal Ransomware Behaviour — Mass Encrypt + Shadow-Copy Delete
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a16
status: experimental
description: |
Detects universal ransomware behaviour — mass file-modification with new
extensions + shadow-copy deletion + backup-service stop within a short
window. Catches all 14+ concurrent ransomware operators this cycle
without requiring family-specific signatures.
references:
- https://hackforlab.com/weekly-threat-advisory-august-10-16-2026/
author: HackForLab Threat Intelligence
date: 2026/08/17
tags:
- attack.impact
- attack.t1486
- attack.t1490
- attack.t1489
logsource:
product: correlation
detection:
s1_mass_file_modify:
EventCount|file_modify_events: '>100_per_minute'
NewFileExtension|distinct_count: '<3'
s2_shadow_copy_delete:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'wmic shadowcopy delete'
- 'bcdedit /set recoveryenabled No'
s3_backup_service_stop:
Service|category: 'backup_or_shadowcopy'
ServiceAction: 'stop_or_disable'
condition: (s1_mass_file_modify and s2_shadow_copy_delete)
or (s1_mass_file_modify and s3_backup_service_stop)
level: critical
10 · Operationalise in 60 minutes
// Cyber-Ops Runbook · Deploy in 4 time-boxed sprints
▸ Minute 00 – 15 · Block + Policy
- Web-proxy regex block on the drive-by subdomain pattern (random 6-10 char subdomain + newly-registered parent). 906-domain scale demands pattern-level defence.
- Mail-gateway link-inspection with reputation enrichment on newly-registered domains — addresses the 657-IOC phishing-framework surge.
- Browser-extension policy: enforce allowlisted publishers via managed browser configuration — addresses the 737-extension abuse campaign.
- Verify backup immutability and test restore — 14+ concurrent ransomware operators makes this non-negotiable this week.
▸ Minute 15 – 30 · Detection Content
- Deploy Sigma 01 (drive-by installer chain, scaled) at web-proxy layer.
- Deploy Sigma 02 (phishing-framework credential-form to first-seen domain) at web-proxy layer.
- Deploy Sigma 03 (browser-extension install from non-allowlisted publisher) at endpoint layer.
- Deploy Sigma 04 (universal ransomware behaviour) at critical severity, direct-to-oncall.
▸ Minute 30 – 45 · Retrospective Hunt
- Hunt: any installer download from random-subdomain patterns over last 30 days.
- Hunt: credential-form submissions to first-seen domains over last 60 days.
- Hunt: browser-extension installs by publisher over last 90 days — audit against attributed publisher list.
- Hunt: any first-seen contact to DPRK-linked APT attributed IOCs over last 90 days.
▸ Minute 45 – 60 · Awareness + Policy
- Brief all users: legitimate browser updates come from the browser, not from a website prompt. Drive-by campaign at 906 domains this week.
- Brief users on credential-form vigilance: never enter credentials on a login page unless verified via the browser URL bar. Massive phishing-framework surge this cycle.
- Brief IT / desktop-admin team: audit browser-extension installations against attributed publisher list. 737-extension abuse this week.
- Cryptocurrency-adjacent + government-adjacent + defence-DIB verticals: escalate DPRK-linked APT monitoring to real-time alerting on any attributed IOC contact.
This briefing ships a selected subset per type. The catalogue carries the full 3,269 unique high-confidence IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.
11 · Frequently asked questions
The drive-by campaign doubled its domain count in one week — how is that possible?
Automation. The operator has an infrastructure-provisioning pipeline that generates and registers new subdomains at scale. 906 domains in 7 days = ~129 per day. That is well within the capacity of a script-driven registration workflow using bulk-registrar APIs. The signal is that the operator has scaled the pipeline throughput, likely by increasing budget or acquiring more compromised parent-site inventory.
A single phishing framework at 657 IOCs with 4-type coverage — is that unusual?
Yes. Most single-operator phishing campaigns produce dozens to a few hundred IOCs across 1-2 IOC types. 657 IOCs with full 4-type coverage (domain + hash + IP + URL) indicates either a Phishing-as-a-Service platform with many affiliates or a very well-resourced single operator. Either way, the operator has a stable automation pipeline — not a hand-run campaign.
737 malicious browser extensions from one campaign — how did marketplace moderation miss that?
Volume and speed. Marketplace moderation is designed to catch obvious policy violations (malicious code signatures, prohibited-content indicators). Well-crafted malicious extensions can hide policy-violating behaviour behind delayed activation, remote-loaded modules, or benign-looking initial functionality. At 737-extension scale from a single campaign, the operator is likely using automated extension-generation tooling that produces slight variations of each extension to defeat signature-based moderation.
Three DPRK-linked APT clusters concurrent — is that a new pattern?
Elevated. DPRK-associated APT activity is typically observed as one dominant cluster per cycle (Lazarus-tier). Three concurrent clusters with distinct target profiles (credential-focused + cryptocurrency-adjacent + government-research) suggests coordinated strategic tasking across multiple sub-teams rather than one operator running everything.
NFC-relay malware — what does that actually do?
NFC-relay malware intercepts communication between an NFC card and a reader (typically a contactless payment terminal), forwards it to a remote attacker system, and replays it. It effectively enables the attacker to make purchases or transactions using a victim’s card without physical possession of the card. Historically observed in mobile-device-attacker scenarios; observation on payment-terminal infrastructure at IOC scale is newer.
Healthcare edging past Government/Tech as the top-targeted sector — should we read anything into that?
Marginal signal at this point. Healthcare has been consistently in the top-5 for months; this is the first cycle it edges into the top slot. Could reflect one-off high-volume campaign attribution, or could be the start of a sustained shift. Watch the next 2-3 cycles for confirmation. Healthcare organisations should treat this as a “monitor closely” signal, not “sound the alarm.”
Where can I see this briefing’s intelligence operationally?
The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference. For hunt-program methodology, see the TaHiTI framework walkthrough and the investigation-abstract deep-dive.













