Drive-by and ransomware week. A single drive-by fake-update campaign produced 371 attacker-registered domains — the largest single-campaign domain footprint of the cycle. Concurrently: twelve ransomware operators active in parallel, an info-stealer and credential-drainer surge spanning Windows and macOS, third consecutive week of macOS-native multi-family activity, and continued supply-chain wave targeting the developer ecosystem.
1,999 unique high-confidence indicators across 116 tracked clusters. 87% High-severity — the intelligence this cycle is concentrated on high-confidence signals rather than commodity noise. Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, top IOCs per indicator type, four production-ready Sigma rules, real-world hunting lessons, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
02 · Five headlines
03 · IOC / severity / category mix
04 · Cluster footprint
05 · Themed deep-dives
05B · Adversary analytics
06 · ATT&CK tactic pressure
07 · Real-world lessons
08 · Top IOCs per type
09 · Sigma detection rules
10 · Hunt queries
11 · Operationalise in 60 min
12 · FAQ
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
1,999 unique high-confidence indicators across 116 tracked clusters this cycle. Volume is deliberately narrow — the catalogue this cycle filtered to the weekly-classified feed tier, prioritising high-signal indicators over commodity noise. This is why 87% of indicators are High-severity (vs 3% in prior weeks that included framework-C2 background). Domain volume dominates at 40% of the feed — driven by the drive-by fake-update campaign registering 371 domains.
Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · Drive-by fake-update wave — 371 attacker-registered domains
The dominant story of the cycle. A single drive-by fake-update malware campaign produced 371 attacker-registered domains this week alone — the largest single-campaign domain footprint of the cycle by a wide margin. Every domain follows a similar structural pattern (random-string subdomain + compromised legitimate site, e.g. [a-z0-9]{8}.[compromised-site].[tld]), suggesting an automated infrastructure-provisioning pipeline. The campaign delivers browser-render-time payloads via legitimate-appearing site compromise + injected fake-update prompts.
Defensive answer: web-proxy content-inspection for the domain-pattern regex; block downloads of .exe, .msi, .dmg, .pkg when the download source is a newly-registered subdomain of a low-reputation parent domain; alert on any “update your browser” download-prompt patterns.
Headline 02 · Twelve concurrent ransomware operators active
Twelve distinct ransomware families produced fresh IOCs this cycle — the highest concurrent-ransomware-operator count catalogued in recent weeks. Combined ransomware-category footprint: 335+ IOCs across twelve operators. Signature patterns include one operator with 27 IOCs at High severity (established RaaS reactivation), a crypto-brand-themed ransomware operator (15 IOCs), and multiple mid-tier operators at 8-18 IOCs each. TOR-based negotiation-portal infrastructure is the common thread — standard RaaS operational pattern.
Defensive answer: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion via vssadmin, service-stop patterns, backup-service kill patterns). If backups are not immutable or air-gapped, address this week regardless of any other signal.
Headline 03 · Info-stealer + credential-drainer surge across platforms
Multiple info-stealer and credential-drainer families active concurrently. One dominant info-stealer family produced 181 IOCs with full 4-type IOC coverage (DOMAIN + HASH + IP + URL). A macOS-native info-stealer / credential-drainer pair produced 17 IOCs. A macOS crypto-drainer variant added another 7 IOCs. The pattern reflects operator investment in credential-monetisation — browser session cookies, password-store data, cryptocurrency wallets. Cross-platform coverage (Windows + macOS) is increasingly the norm, not the exception.
Defensive answer: harden browser credential-store access controls (require re-auth for sensitive credential retrieval); MFA on all cryptocurrency-adjacent accounts; endpoint EDR coverage on macOS not optional.
Headline 04 · macOS multi-family surge continues
Third consecutive week of macOS-native multi-family activity. Combined footprint: 118 IOCs across three macOS-native families. One larger cross-platform family with a v4 evolution (77 IOCs across all 4 IOC types), one macOS info-stealer / credential-drainer pair (17 IOCs), one macOS crypto-drainer (7 IOCs). The concurrent-family pattern across three consecutive weeks establishes macOS as a validated adversary-attention target — the ecosystem is telling defenders that under-investment in macOS EDR coverage is being actively exploited.
Defensive answer: confirm EDR coverage across all macOS endpoints without exceptions. Verify endpoint detection includes recent macOS TCC-bypass, LaunchAgent + LaunchDaemon persistence, dylib-injection, and unsigned-binary-from-user-writable-path patterns.
Headline 05 · Supply-chain wave continues — developer ecosystem targeting
The developer-ecosystem supply-chain wave carries into a second week. Fresh signals this cycle: a malicious-package registry campaign (19 IOCs across three IOC types) and a fake developer-marketplace extension campaign (10 IOCs). Combined with the prior week’s fake-installer + fake-AI-assistant campaigns, this establishes the pattern: developer-tooling supply-chain attacks are not a one-off — they are a sustained operator investment. Blast radius per compromised developer remains disproportionate.
Defensive answer: mail-gateway policy blocking untrusted installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit package-manager lock-files for unexpected new-source dependencies; audit code-signing key access patterns.
03 · Indicator type, severity, and category mix
Domain dominance at 40% share is unusual and signals infrastructure-heavy campaign activity — typical baseline is 5-10% domain share. URL share at 22% and Hash share at 14% are also elevated. Severity distribution: 87% High-severity because the weekly-tier feed prioritises high-confidence signals over commodity noise. Category dominance: Malware-Activity at 42.5% share, Ransomware-as-a-service at 10%.
Bars scaled relative to the dominant Domain volume. The 40% Domain share (734 domains) is unusually high vs baseline — driven by the single drive-by campaign registering 371 attacker-controlled domains. Narrow-indicator concentration this week is where the campaign-specific intelligence lives.
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| Domains | 734 | 40.18% | |
| URLs | 405 | 22.17% | |
| IPs | 378 | 20.69% | |
| File hashes | 264 | 14.45% | |
| Other artefacts | 31 | 1.70% | |
| Emails | 15 | 0.82% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 1,741 | 87.47% | |
| Medium | 162 | 8.87% | |
| Low | 67 | 3.67% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| Malware-Activity | 776 | 42.45% | |
| Ransomware-as-a-service | 182 | 9.96% | |
| Spyware | 181 | 9.90% | |
| C&C Server | 135 | 7.39% | |
| APT | 131 | 7.17% | |
| Supply Chain | 103 | 5.63% | |
| RAT | 95 | 5.20% | |
| Malicious-Infrastructure | 69 | 3.77% | |
| Backdoor | 42 | 2.30% | |
| Loader | 35 | 1.91% | |
| Framework | 27 | 1.48% | |
| Phishing | 26 | 1.42% | |
| Botnet | 20 | 1.09% | |
| Vulnerability | 6 | 0.33% |
Fourteen additional attributed clusters were added to the feed between the initial cut and this refresh. Notable new signals worth immediate attention:
- fake-CAPTCHA / paste-to-execute phishing campaign (27 IOCs, three IOC types) — social-engineering pattern impersonating verify-you-are-human challenges to trick users into pasting attacker-supplied clipboard content into the run prompt. Consistent with the emerging “paste-to-execute” social-engineering trend.
- Device Code Phishing campaign (10 IOCs) — abuse of the OAuth 2.0 device-authorization flow for account takeover. Bypasses several MFA models by legitimising the attacker session through the victim’s own approval.
- Three additional attributed APT clusters — one Larva-tracked cluster (15 IOCs), one storm-tracked cluster (15 IOCs), one long-established cluster (7 IOCs).
- Three additional ransomware operators — total is now twelve concurrent ransomware families. Two are actor-brand emerging entrants, one is a re-brand of a prior operator.
- Fresh supply-chain signal — a dedicated package-registry stealer campaign (7 IOCs) reinforces the developer-ecosystem-targeting narrative from the prior week.
- New RAT campaign (12 IOCs) and brand-impersonation phishing operation (17 IOCs, five IOC types — the highest IOC-type coverage of any single cluster this cycle).
04 · Cluster footprint — ranked by unique-IOC count
56 clusters ranked by unique IOC footprint (14 newly-added since initial publish). Framework-infrastructure entries shown in grey to preserve visual clarity of the campaign-attributed clusters. All labels sanitised into category descriptors.
| # | Cluster descriptor | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Drive-by fake-update malware campaign (Cluster A)
Malware Campaign · DOMAIN
|
371 | HIGH | |
| 02 | Info-stealer family with 4-type IOC coverage
Info-stealer · DOMAIN, HASH, IP, URL
|
181 | HIGH | |
| 03 | Open remote-agent C2 framework
C2 · IP
|
105 | MEDIUM | |
| 04 | Supply-chain campaign (Cluster B)
Supply Chain · HASH, IP, URL
|
96 | HIGH | |
| 05 | Attributed APT cluster (identifier C)
APT · DOMAIN, IP
|
83 | HIGH | |
| 06 | macOS-native malware family (v4 evolution)
Malware · DOMAIN, HASH, IP, URL
|
77 | HIGH | |
| 07 | Attributed APT cluster (identifier D)
APT · DOMAIN, HASH
|
44 | HIGH | |
| 08 | Multi-stage dropper family
Malware · DOMAIN, HASH, IP
|
40 | HIGH | |
| 09 | Loader family (polymorphic, Cluster E)
Loader · DOMAIN, HASH, IP, URL
|
36 | HIGH | |
| 10 | Malware family (Cluster F)
Malware · DOMAIN, HASH, IP
|
35 | HIGH | |
| 11 | Backdoor family (Cluster G)
Backdoor · DOMAIN, HASH, IP
|
33 | HIGH | |
| 12 | Ransomware operator (Cluster H)
Ransomware · DOMAIN, HASH, IP
|
27 | HIGH | |
| 13 | Open-framework C2 infrastructure (framework tier)
C2 · DOMAIN, HASH, IP, URL
|
27 | MEDIUM | |
| 14 | Multi-stage operation (Cluster J)
Malware Campaign · DOMAIN, HASH, IP, URL
|
27 | HIGH | |
| 15 | Collaboration-platform AiTM phishing campaign
Phishing · DOMAIN, HASH, URL
|
26 | LOW | |
| 16 | Commodity RAT family (Cluster K)
RAT · DOMAIN, HASH, URL
|
26 | HIGH | |
| 17 | Low-severity phishing infrastructure
Phishing · DOMAIN, IP
|
25 | LOW | |
| 18 | Commodity RAT family (Cluster L)
RAT · HASH, IP
|
25 | HIGH | |
| 19 | Social-engineering-lure malware chain
Malware · HASH, IP
|
25 | HIGH | |
| 20 | Commodity RAT family (Cluster M)
RAT · DOMAIN, HASH, IP
|
25 | HIGH | |
| 21 | Malware family (Cluster N)
Malware · DOMAIN, HASH, IP, URL
|
21 | HIGH | |
| 22 | IoT botnet family
Botnet · DOMAIN, HASH
|
20 | HIGH | |
| 23 | Malicious package-registry campaign
Supply Chain · DOMAIN, HASH, IP
|
19 | HIGH | |
| 24 | Commodity RAT family (Cluster P)
RAT · DOMAIN
|
19 | HIGH | |
| 25 | Commodity RAT family (Cluster Q)
RAT · DOMAIN, HASH
|
18 | HIGH | |
| 26 | Open remote-shell framework
C2 · DOMAIN
|
18 | MEDIUM | |
| 27 | Ransomware operator (Cluster R)
Ransomware · DOMAIN
|
18 | HIGH | |
| 28 | macOS-native info-stealer / credential-drainer pair
Malware · DOMAIN
|
17 | HIGH | |
| 29 | WebDAV-transport delivery campaign
Malware Campaign · DOMAIN, HASH, IP
|
16 | HIGH | |
| 30 | Direct-to-IP malware delivery campaign
Malware Campaign · HASH, IP
|
15 | HIGH | |
| 31 | Ransomware operator (Cluster S) — crypto-brand-lure
Ransomware · DOMAIN, HASH, URL
|
15 | HIGH | |
| 32 | Ransomware operator (Cluster T)
Ransomware · DOMAIN, HASH, URL
|
15 | HIGH | |
| 33 | Gaming-platform-lure malware campaign
Malware · DOMAIN, HASH, IP
|
14 | HIGH | |
| 34 | Threat-actor collective (identifier U)
Threat Actor · DOMAIN, HASH, URL
|
13 | HIGH | |
| 35 | Threat-actor collective (identifier V)
Threat Actor · DOMAIN
|
13 | HIGH | |
| 36 | Ransomware operator (Cluster W)
Ransomware · DOMAIN, URL
|
12 | HIGH | |
| 37 | Ransomware operator (Cluster X) — actor-hybrid
Ransomware · DOMAIN, HASH, URL
|
11 | HIGH | |
| 38 | Fake developer-marketplace extension campaign
Phishing · DOMAIN, HASH
|
10 | LOW | |
| 39 | DPRK-associated malware campaign
Malware Campaign · DOMAIN, HASH, IP
|
10 | HIGH | |
| 40 | Ransomware operator (Cluster Y)
Ransomware · DOMAIN, HASH, URL
|
9 | HIGH | |
| 41 | Open-source C2 framework (emerging)
C2 · DOMAIN
|
9 | HIGH | |
| 42 | Ransomware operator (Cluster Z)
Ransomware · DOMAIN, HASH, URL
|
8 | HIGH | |
| 43 | macOS crypto-drainer malware
Malware · DOMAIN, HASH, IP
|
7 | HIGH | |
| 44 | Multi-stage supply-chain campaign
Supply Chain · DOMAIN, HASH, URL
|
7 | HIGH | |
| 44 | Fake-CAPTCHA phishing / paste-to-execute campaign
Phishing · DOMAIN, HASH, URL
|
27 | LOW | |
| 45 | Info-stealer family (Cluster AA)
Malware · DOMAIN, HASH, IP
|
32 | HIGH | |
| 46 | Attributed APT cluster (Larva-tracked identifier AB)
APT · DOMAIN, HASH, IP
|
15 | HIGH | |
| 47 | Attributed APT cluster (Storm-tracked identifier AC)
APT · DOMAIN, HASH
|
15 | HIGH | |
| 48 | Ransomware operator (Cluster AD)
Ransomware · DOMAIN, HASH
|
15 | HIGH | |
| 49 | Brand-impersonation phishing (5-type IOC coverage)
Phishing · DOMAIN, HASH, IP, URL, EMAIL
|
17 | LOW | |
| 50 | Commodity RAT family (Cluster AE)
RAT · DOMAIN, HASH
|
12 | HIGH | |
| 51 | Device-code OAuth-flow phishing campaign
Phishing · DOMAIN, URL
|
10 | LOW | |
| 52 | Multi-stage campaign (Cluster AF)
Malware Campaign · DOMAIN, HASH, IP
|
8 | HIGH | |
| 53 | Attributed APT cluster (long-established identifier AG)
APT · DOMAIN, HASH
|
7 | HIGH | |
| 54 | Dedicated package-registry stealer campaign
Supply Chain · DOMAIN, HASH, IP
|
7 | HIGH | |
| 55 | Ransomware operator (Cluster AH)
Ransomware · DOMAIN, HASH
|
6 | HIGH |
05 · Themed deep-dives
05.1 · The 371-domain drive-by fake-update campaign
The dominant signal of the cycle. A single drive-by fake-update malware campaign registered 371 attacker-controlled domains this week. Structural pattern: [a-z0-9]{8}.[compromised-site].[tld] — a random-string subdomain hosted on a compromised legitimate parent site. The delivery chain: user visits legitimate-looking site → injected script triggers fake browser-update prompt → user clicks “update” → payload downloads from the attacker-controlled subdomain → execution.
Why 371 domains? Automation. The campaign has an infrastructure-provisioning pipeline that generates + registers new lookalike subdomains at scale. Blocking any individual domain has zero durable defensive value — the operator provisions a replacement within hours. The defensive answer must operate on the pattern, not the individual domains.
Defensive actions:
- Web-proxy regex block on the subdomain-pattern signature: random-string of 6-10 characters preceding a compromised-site TLD.
- Alert on any download of
.exe,.msi,.dmg,.pkgfrom a subdomain younger than 30 days. - Browser-plane hardening: disable automatic download prompts; require user confirmation for any file-type download.
- User-awareness bulletin: legitimate browser updates come from the browser itself, not from a website prompting you to click.
05.2 · Twelve concurrent ransomware operators
Twelve ransomware families active in parallel this cycle. Combined footprint: 335+ IOCs across twelve operators. Composition:
- One established RaaS operator resurfaced at High severity (27 IOCs) — affiliate-program reactivation signal.
- Mid-tier operators active at 8-18 IOCs each (six operators in this band).
- One crypto-brand-themed operator (15 IOCs) — social-engineering pattern targeting cryptocurrency-adjacent audiences.
- One threat-actor / ransomware hybrid operator (11 IOCs) using both ransomware and other tooling.
Common infrastructure pattern: TOR-based negotiation portals. This is the standard RaaS pattern — the URL indicators are .onion addresses for victim negotiation.
Defensive actions: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion via vssadmin, service-stop patterns, backup-service kill patterns). Immutable and air-gapped backups are non-negotiable given twelve concurrent operators.
05.3 · Info-stealer + credential-drainer surge across platforms
Multiple concurrent info-stealer and credential-drainer families this cycle. Signals:
- One dominant info-stealer family with full 4-type IOC coverage (181 IOCs across DOMAIN + HASH + IP + URL) — the mature-infrastructure signal.
- A macOS-native info-stealer + credential-drainer pair (17 IOCs).
- A macOS crypto-drainer variant (7 IOCs).
- A cross-platform crypto-drainer family (7 IOCs across three IOC types).
The pattern reflects operator investment in credential-monetisation — browser session cookies, password-store data, cryptocurrency wallet keys. Cross-platform coverage (Windows + macOS) is increasingly the default.
Defensive actions: harden browser credential-store access (require re-auth for sensitive credential retrieval); MFA on all cryptocurrency-adjacent accounts; endpoint EDR coverage on macOS is not optional; consider FIDO2 hardware keys for privileged accounts.
05.4 · macOS multi-family surge — third consecutive week
Third consecutive week of macOS-native multi-family activity. Combined footprint this week: 118 IOCs across three macOS-native families. One larger cross-platform family with a v4 evolution, one macOS info-stealer / credential-drainer pair, one macOS crypto-drainer. When multiple independent operators concurrently target the same profile across three consecutive weeks, the ecosystem is telling defenders that under-investment in the profile is being validated as an exploitable gap.
Defensive actions: confirm EDR coverage across all macOS endpoints without exceptions (design, engineering, executive laptops, creative teams). Verify endpoint detection includes recent macOS-specific patterns: TCC-bypass attempts, LaunchAgent + LaunchDaemon persistence, dylib-injection, unsigned-binary execution from user-writable paths, crypto-wallet file access from unfamiliar processes.
05.5 · Supply-chain wave continues — developer ecosystem
The developer-ecosystem supply-chain wave carries into a second week. Fresh signals: a malicious-package registry campaign (19 IOCs across three IOC types), a fake developer-marketplace extension campaign (10 IOCs), and a multi-stage supply-chain campaign (7 IOCs). Combined with the prior week’s fake-installer and fake-AI-assistant campaigns, the pattern is established: developer-tooling supply-chain attacks are a sustained operator investment, not a one-off.
Defensive actions: mail-gateway policy blocking untrusted installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit package-manager lock-files for unexpected new-source dependencies (recent additions of packages from unfamiliar publishers deserve review); audit code-signing key access patterns; consider requiring MFA-gated approval for new package additions in critical repositories.
05B · Adversary analytics — technique, geography, sector
Beyond the specific IOCs and cluster footprints, three cross-cutting analytics tell the story of adversary intent this cycle: which techniques are most prevalent across all clusters, which countries the intelligence signals are most likely targeting, and which sectors carry the highest concurrent-target attention. All three are extracted from this cycle’s full catalogue (not just the weekly-filtered high-confidence tier).
05B.1 · Top techniques (ATT&CK)
The single most-used technique this cycle: T1105 · Ingress Tool Transfer at 998 hits — the universal second-stage-payload-pull technique that appears in almost every multi-stage cluster. When ~1 in 4 attributed IOCs maps to T1105, the defensive answer is content-inspection at the network egress + endpoint download layer, not per-family signatures.
T1105 · Ingress Tool TransferT1071.001 · Application Layer Protocol · Web ProtocolsT1059.001 · Command Interpreter · PowerShellT1204.002 · User Execution · Malicious FileT1041 · Exfiltration Over C2 ChannelT1027 · Obfuscated Files or InformationT1204.001 · User Execution · Malicious LinkT1566.002 · Phishing · Spearphishing LinkT1036 · MasqueradingT1189 · Drive-by CompromisePercentages relative to the top-20 technique volume this cycle. T1105 (Ingress Tool Transfer) leads — the second-stage-payload-pull technique used by almost every multi-stage cluster. T1071.001 (web-protocol C2) and T1059.001 (PowerShell) form the persistent commodity-execution triad. T1189 (drive-by compromise) at 371 hits reflects this cycle’s dominant drive-by campaign.
05B.2 · Most-common targeted countries
The most-targeted country this cycle: Germany (628 attributions), followed closely by the United States (760, combined representations), France (563), the United Kingdom (531), Canada (515), India (505), and Australia (484). The distribution is unusually even across the top-7 countries — a Five-Eyes + Western-Europe + India profile that suggests broad-audience campaigns (drive-by wave, info-stealer wave) rather than surgical geographic targeting.
United States figure combines the two representations found in the source data (“United States” + “United States of America”). The top-7 concentration inside a ~150-attribution band indicates broad-audience campaigns rather than surgical geographic targeting.
05B.3 · Most-common targeted sectors
The most-targeted sector this cycle: Technology (902 attributions), essentially tied with Manufacturing (880), Government (877), Healthcare (877), and Financial Services (873). Same broad-target signature as the country distribution — the top-5 sectors all sit inside a ~30-attribution band. This is consistent with commodity-tier campaign activity (drive-by, info-stealer, ransomware) that targets any sector with monetisable exposure. Retail, Telecommunications, and Education round out the top-8 with substantial volume.
Broad target signature across top-5 sectors (Technology, Manufacturing, Government, Healthcare, Financial Services all within a 30-attribution band). Critical Infrastructure and Defense enter the top-15 at lower but non-zero volume — monitor closely for any narrowing of concentration in later cycles.
Reading the three dimensions together. Top technique = Ingress Tool Transfer (universal second-stage). Top country = Germany (broad Western + India + Australia distribution). Top sector = Technology (essentially tied with 4 other sectors in the top-5). All three signals point to the same conclusion: this cycle’s adversary attention is broad, not narrow. High-volume commodity campaigns hitting the widest possible audience across industries and geographies. The defensive answer for a broad-target cycle is signature-level content and behavioural detectors that catch the pattern regardless of who runs it.
06 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Initial Access | T1189 · T1566 · T1195 · T1195.002 · T1078 · T1133 | Drive-by compromise (dominant this cycle), phishing, supply-chain compromise (npm + marketplace extensions), valid accounts, external remote services | 495 |
| Execution | T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1204.002 · T1218 | Command interpreter (shell / VB / JS), user-execution (drive-by chain), signed-binary proxy execution | 421 |
| Command and Control | T1071 · T1071.001 · T1105 · T1090 · T1573 · T1132.001 | Web-protocol C2, ingress tool transfer, proxy tunnelling (open remote-agent framework), TOR-based negotiation for RaaS operators | 386 |
| Credential Access | T1003 · T1003.001 · T1555 · T1552.001 · T1539 | OS credential dumping, password-store theft, credential-file discovery, browser session-cookie theft (info-stealer families driving) | 340 |
| Defense Evasion | T1027 · T1036 · T1055 · T1070 · T1140 · T1562 · T1218 | Obfuscation, masquerading, process injection, indicator removal, deobfuscate, disable defences, signed-binary proxy execution | 289 |
| Persistence | T1547.001 · T1543.003 · T1543.001 · T1053.005 · T1505.003 | Registry-run keys, service creation, launch-agent (macOS), scheduled tasks, webshell | 231 |
| Impact | T1486 · T1489 · T1490 · T1491 | Data encryption for impact (twelve concurrent ransomware operators), service stop, inhibit system recovery, defacement | 296 |
| Exfiltration | T1041 · T1567 · T1090 | Exfil over C2, exfil to web service, tunnel-based exfil (info-stealer families) | 245 |
| Discovery | T1082 · T1057 · T1083 · T1018 · T1046 | System info, process, file, remote-system, network configuration | 178 |
| Lateral Movement | T1021 · T1021.001 · T1021.002 · T1570 | Remote-desktop, SMB / admin shares, lateral tool transfer | 145 |
| Resource Development | T1583.001 · T1584.001 · T1585 · T1195.002 | Adversary-acquired domains (371 in a single campaign this cycle), compromised infrastructure, supply-chain compromise | 495 |
| Collection | T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 | Local + automated collection, screen capture, input capture, session-cookie theft | 156 |
Detection-engineering takeaway. Initial Access is the dominant pressure this cycle at 495 IOCs, driven overwhelmingly by drive-by compromise (T1189). This is the highest drive-by pressure catalogued in recent weeks. Impact tactics (T1486 ransomware encryption, T1489 / T1490 service stop + inhibit recovery) are elevated with twelve concurrent ransomware operators. Credential Access is elevated (340 IOCs) driven by the info-stealer surge — browser password-store theft is the dominant sub-technique. Resource Development (T1583.001 adversary-acquired domains) at 495 IOCs reflects the 371-domain drive-by campaign infrastructure footprint.
07 · Real-world threat intelligence lessons
Beyond the specific IOCs, this cycle’s data carries lessons that will still matter next month and next quarter. Below are the pragmatic takeaways for the working analyst.
Lesson 01 · When one campaign owns 40% of your feed, pattern detection beats individual-IOC blocking
The 371-domain drive-by campaign accounted for 40% of this week’s domain volume. Blocking any single one of those 371 domains has zero durable defensive value — the operator has an infrastructure-provisioning pipeline that generates replacements faster than any feed can catalogue them. The mature CTI program detects the pattern (subdomain-format regex, subdomain-age enrichment, parent-domain-reputation join) and treats individual IOCs as evidence-of-pattern, not as primary blocklist entries. Reallocate feed-consumption architecture accordingly.
Lesson 02 · Twelve concurrent ransomware operators means backups are the perimeter
When nine ransomware operators are simultaneously active, the probability that at least one gets past your prevention controls in any given quarter approaches certainty. The perimeter defence is not endpoint detection alone — it is the recovery capability if endpoint detection misses. Immutable backups. Air-gapped backups. Tested restore procedures. If your restore has not been tested against a full-domain-encrypted scenario in the last 90 days, it has not been tested.
Lesson 03 · Cross-platform info-stealers mean the browser is the credential vault attackers care about
The dominant info-stealer family this cycle has full 4-type IOC coverage. Multiple macOS-native stealers are active concurrently. The consistent target: browser credential stores, cookies, cryptocurrency wallet files. This is where operator monetisation happens. The defensive answer: harden browser credential retrieval (require re-auth), move privileged secrets out of browser storage (use dedicated password managers with hardware-token unlocking), enforce FIDO2 hardware keys on all high-value accounts.
Lesson 04 · The developer ecosystem is not a temporary target
Two consecutive weeks of supply-chain campaigns targeting developer tooling. This is not a one-off — it is a validated operator investment area. Developer machines carry disproportionate blast radius: cloud credentials, code-signing keys, CI/CD pipeline access, package-registry publish tokens. The defensive answer is not just endpoint-level content on developer machines — it is CI/CD-pipeline hygiene (secret rotation, dependency-provenance verification, package-lock audits) and identity-plane hardening (MFA on all developer accounts, session-lifetime restrictions, privileged-access review).
Lesson 05 · macOS coverage is a growing operational gap
Three consecutive weeks of macOS multi-family activity establishes the pattern: operators are validating macOS as an exploitable gap. Environments that still treat macOS EDR as optional or best-effort are the environments this pattern is designed to exploit. Confirm EDR coverage across all macOS endpoints. Confirm coverage includes recent macOS-specific persistence patterns. Confirm your SOC can triage macOS alerts (analyst training on macOS-specific artefacts is often the missing piece).
Lesson 06 · High-severity concentration signals mature intelligence, not more threat
87% High-severity this week is not because the threat landscape got 30x worse. It is because the weekly-tier feed prioritises high-confidence signals over commodity noise. A mature CTI program uses this signal: the weekly-tier feed is where you look for actionable intelligence; the higher-volume feeds are where you look for context and enrichment on specific alerts. Do not treat all feed tiers as equal — they serve different analytical purposes.
The one-line synthesis. This week says: pattern-detection beats individual-blocking for high-volume campaigns; backup recovery is now the last line of defence against ransomware; browser credential-store hardening is table stakes; developer-ecosystem targeting is not going away; macOS EDR coverage is an active gap; feed tiering is an analytical tool. Six takeaways from one week that will still be true next quarter.
08 · Top IOCs per indicator type
Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.] → . and hxxp → http).
Top 15 · IP addresses (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 101.36.123.12 | Backdoor | HIGH |
| 02 | 103.106.190.217 | Malware-Activity | HIGH |
| 03 | 103.214.146.46 | Botnet | HIGH |
| 04 | 103.22.137.227 | Loader | HIGH |
| 05 | 103.226.155.200 | Malware-Activity | HIGH |
| 06 | 103.226.155.201 | Malware-Activity | HIGH |
| 07 | 103.231.15.135 | Supply Chain | HIGH |
| 08 | 103.231.15.219 | Supply Chain | HIGH |
| 09 | 103.231.15.248 | Supply Chain | HIGH |
| 10 | 103.238.129.112 | Malware-Activity | HIGH |
| 11 | 103.245.236.146 | Malware-Activity | HIGH |
| 12 | 103.246.244.13 | Supply Chain | HIGH |
| 13 | 103.246.244.20 | Supply Chain | HIGH |
| 14 | 103.53.80.201 | Backdoor | HIGH |
| 15 | 103.97.128.67 | Malware-Activity | HIGH |
Top domains (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 022kgyq9[.]eachway-multiplier[.]com | Malware-Activity | HIGH |
| 02 | 1systemsevolve[.]digital | APT | HIGH |
| 03 | 1vqj02ep[.]myboutiqswitch[.]com | Malware-Activity | HIGH |
| 04 | 2dflte3h[.]grannygshemporium[.]com | Malware-Activity | HIGH |
| 05 | 45gradnord[.]de | Malware-Activity | HIGH |
| 06 | 602a5sud[.]foodpapajobs[.]com | Malware-Activity | HIGH |
| 07 | 7xa644hx[.]habbofutbol[.]com | Malware-Activity | HIGH |
| 08 | 9haaqrsv[.]ryanposocco[.]com | Malware-Activity | HIGH |
| 09 | 9tczi7ct[.]overtheitgirl[.]com | Malware-Activity | HIGH |
| 10 | 9vn1ctfe[.]partyboxlovely[.]com | Malware-Activity | HIGH |
| 11 | crestmarkhq[.]com | Malware-Activity | HIGH |
| 12 | igsx[.]closedfistllc[.]com | Malware-Activity | HIGH |
| 13 | aaraenergy[.]com | Malware-Activity | HIGH |
Top file hashes (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 00a1228648fffa7338076970037b89f679a166a08c4d9573f1f27973ec6ed497 | Backdoor | HIGH |
| 02 | 01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2 | Malware-Activity | HIGH |
| 03 | 01e4cb3c60fa50b2927daa11f25a3c412549680406fc121a3d1870a9a33f5d38 | Malware-Activity | HIGH |
| 04 | 03fd832b81dd54d2bf5f610a8ff27856 | Supply Chain | HIGH |
| 05 | 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58 | Malware-Activity | HIGH |
| 06 | 06f8fa00d40da2ad3293e75bb7b95dc9 | RAT | HIGH |
| 07 | 0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3 | Malware-Activity | HIGH |
| 08 | 09683b2cb19f16818d0a60264663cac2 | RAT | HIGH |
| 09 | 09ed9ad3ac886f5aaf8357127b6dd5926bd4af1e2cc687a6a4856bcaedee2667 | Backdoor | HIGH |
| 10 | 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a | Malware-Activity | HIGH |
| 11 | 0cbbe5da1a691368343d029dcc546710 | RAT | HIGH |
| 12 | 0fc30f82e1fa5e51a6c0c43f3ed7f13592ea731cb331e43a4d085df60a4db8b6 | Malware-Activity | HIGH |
| 13 | 1081ff69cba7a5a64aa40480dc5f693c | RAT | HIGH |
Top URLs (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | hxxp[://]159[.]100[.]18[.]98:80/fbbef44e-51f2-4f0c-be82-09a32ddbb320 | Malware-Activity | HIGH |
| 02 | hxxp[://]22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead[.]onion/ | Ransomware-as-a-service | HIGH |
| 03 | hxxp[://]2c7nd54guzi6xhjyqrj5kdkrq2ngm2u3e6oy4nfhn3wm3r54ul2utiqd[.]onion/ | Malicious-Infrastructure | HIGH |
| 04 | hxxp[://]2cyxmof76rxeqze5snxxooqmhzjtcploqswxoxmenfayphumdhrtrzqd[.]onion | Ransomware-as-a-service | HIGH |
| 05 | hxxp[://]2nyysjgsfhnwizvbhjeklagbdbjz2z27meao7asl73zcqpb5cr4n4eyd[.]onion | Ransomware-as-a-service | HIGH |
| 06 | hxxp[://]2yxf2ald2c67twt4663piypum2fu6yt4su453naxsdiilpd4m7pgu6qd[.]onion | Ransomware-as-a-service | HIGH |
| 07 | hxxp[://]33333333h45xwqlf3s3eu4bkd6y6bjswva75ys7j6satex5ctf4pyfad[.]onion | Ransomware-as-a-service | HIGH |
| 08 | hxxp[://]3lce6cov7sj7vovrr3cbanqoolhgfgqqcvjrtlzlqnex7esdz33mdoqd[.]onion/ | Malicious-Infrastructure | HIGH |
| 09 | hxxp[://]4mmc[.]space | Malicious-Infrastructure | HIGH |
| 10 | hxxp[://]4qyjonpyksc52bc3fsgfgedssqgo4a6vlfsjknqnkncbyl4layqkqjid[.]onion/ | Ransomware-as-a-service | HIGH |
09 · Sigma detection rules
Sigma 01 · Drive-by fake-update chain (HIGH)
title: Drive-By Fake-Update Chain — Random-Subdomain Download of Installer
id: 4f2a8d6c-7b53-4820-9a71-3f5c1e2d8a41
status: experimental
description: Detects the drive-by fake-update chain — user browsing session
leads to a download of an installer file (.exe, .msi, .dmg, .pkg) from a
random-string subdomain of a low-reputation parent domain. Ships from
HackForLab weekly threat advisory Aug 3-9, 2026.
references:
- https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
- attack.initial_access
- attack.t1189
- attack.execution
- attack.t1204.002
- attack.resource_development
- attack.t1583.001
logsource:
category: web_proxy
detection:
s1_random_subdomain:
destination_host|re: '^[a-z0-9]{6,10}\.[a-z0-9-]+\.[a-z]{2,10}$'
s2_installer_download:
request_uri|endswith:
- '.exe'
- '.msi'
- '.dmg'
- '.pkg'
- '.deb'
request_method: 'GET'
response_content_type|contains:
- 'application/octet-stream'
- 'application/x-msi'
- 'application/x-apple-diskimage'
s3_low_reputation_parent:
destination_parent_domain_age: '<30d'
OR destination_parent_domain_reputation: 'unknown'
condition: s1_random_subdomain and s2_installer_download and s3_low_reputation_parent
falsepositives:
- Legitimate software installers from allowlisted publishers (maintain publisher allowlist)
level: high
Sigma 02 · Universal ransomware behaviour (CRITICAL)
title: Universal Ransomware Behaviour — Mass Encrypt + Shadow-Copy Delete
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a15
status: experimental
description: Detects universal ransomware behaviour — mass file-modification
with new extensions + shadow-copy deletion + backup-service stop within a
short window. Catches all twelve concurrent ransomware operators this cycle
without requiring family-specific signatures.
references:
- https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
- attack.impact
- attack.t1486
- attack.t1490
- attack.t1489
logsource:
product: correlation
detection:
s1_mass_file_modify:
EventCount|file_modify_events: '>100_per_minute'
NewFileExtension|distinct_count: '<3'
s2_shadow_copy_delete:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'wmic shadowcopy delete'
- 'bcdedit /set recoveryenabled No'
s3_backup_service_stop:
Service|category: 'backup_or_shadowcopy'
ServiceAction: 'stop_or_disable'
condition: (s1_mass_file_modify and s2_shadow_copy_delete)
or (s1_mass_file_modify and s3_backup_service_stop)
level: critical
Sigma 03 · Info-stealer credential-store read + exfil (HIGH)
title: Info-Stealer Chain — Browser Credential-Store Read + Outbound POST
id: 6a5e9d3f-7b28-4c50-a941-5f8b6d2e9c32
status: experimental
description: Detects the info-stealer chain — read access to browser
credential-store paths by a non-browser process, followed within 5 minutes
by outbound POST to a non-corporate destination with payload larger than
50 KB. Catches this cycle's dominant info-stealer + credential-drainer
families across Windows and macOS.
references:
- https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
- attack.credential_access
- attack.t1003
- attack.t1555
- attack.t1539
- attack.exfiltration
- attack.t1041
logsource:
product: correlation
detection:
s1_credential_store_read:
EventType: 'file_read'
TargetPath|contains:
- '\User Data\Default\Login Data'
- '\User Data\Default\Cookies'
- '/Library/Application Support/Google/Chrome/Default/Login Data'
- '/Library/Application Support/Firefox/Profiles'
- '/Library/Keychains/'
ReaderProcess|not:
- 'browser_processes_allowlist'
s2_outbound_post:
RequestMethod: 'POST'
DestinationIp|expand: '%non_corporate_destinations%'
RequestBodySize: '>50000'
condition: s1_credential_store_read and s2_outbound_post within 5m
falsepositives:
- Legitimate password manager sync (allowlist by known-good sync destinations)
level: high
Sigma 04 · macOS LaunchAgent / Daemon persistence (HIGH)
title: macOS Persistence — LaunchAgent or LaunchDaemon plist Write by Non-Allowlisted Signer
id: 5d8e9c1f-3b47-4a52-a831-6f2b7c1d9a53
status: experimental
description: Detects LaunchAgent or LaunchDaemon plist file writes to
user-writable paths on macOS endpoints by a process whose signer is not
on the allowlist. Catches this cycle's macOS multi-family activity
(third consecutive week of the pattern).
references:
- https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
- attack.persistence
- attack.t1543.001
- attack.t1543.004
logsource:
category: file_event
product: macos
detection:
s1_launch_persistence_path:
TargetFilename|contains:
- '/Library/LaunchAgents/'
- '/Library/LaunchDaemons/'
- '~/Library/LaunchAgents/'
TargetFilename|endswith: '.plist'
s2_writer_not_allowlisted:
ProcessSigner|not:
- 'os_vendor'
- 'allowlisted_mac_publisher'
condition: s1_launch_persistence_path and s2_writer_not_allowlisted
falsepositives:
- Legitimate third-party tooling with allowlisted signers (maintain allowlist)
level: high
10 · Hunt queries — SIEM-agnostic pseudo-syntax
Hunt 01 · Drive-by installer downloads from random-subdomain patterns (last 30 days)
FROM web_proxy
WHERE destination_host REGEXP '^[a-z0-9]{6,10}\.[a-z0-9-]+\.[a-z]{2,10}$'
AND request_uri REGEXP '\.(exe|msi|dmg|pkg|deb)$'
AND destination_parent_domain_age < 30 DAYS
AND event_time >= NOW() - 30 DAYS
| PROJECT source_host, destination_host, request_uri, event_time
| SORT BY event_time DESC
Hunt 02 · Ransomware behavioural triage (last 30 days)
FROM edr_file_events WHERE event_type = 'modify' AND file_modification_rate > 100_per_minute AND new_file_extension_distinct_count < 3 AND event_time >= NOW() - 30 DAYS | JOIN edr_process_create pc ON pc.host = file_events.host | WHERE pc.command_line CONTAINS 'vssadmin' OR pc.command_line CONTAINS 'shadowcopy' | PROJECT host, user, new_file_extension, file_modification_rate, event_time
Hunt 03 · Non-browser process reading browser credential stores (last 60 days)
FROM edr_file_events
WHERE event_type = 'read'
AND target_path MATCHES '.*/(Login Data|Cookies|Keychains/.+)$'
AND reader_process NOT IN (browser_processes_allowlist)
AND event_time >= NOW() - 60 DAYS
| JOIN edr_network_events ne
ON ne.host = edr_file_events.host
AND ne.event_time BETWEEN edr_file_events.event_time
AND edr_file_events.event_time + INTERVAL 5 MINUTE
| WHERE ne.request_method = 'POST'
AND ne.request_body_size > 50000
| PROJECT host, user, reader_process, ne.destination_host, event_time
Hunt 04 · macOS LaunchAgent / Daemon plist writes by non-allowlisted signer (last 90 days)
FROM edr_file_events
WHERE endpoint_os = 'macos'
AND target_filename MATCHES '.*/(LaunchAgents|LaunchDaemons)/.*\.plist$'
AND writer_signer_category NOT IN ('os_vendor', 'allowlisted_mac_publisher')
AND event_time >= NOW() - 90 DAYS
| PROJECT host, user, target_filename, writer_process, event_time
11 · Operationalise in 60 minutes
// Cyber-Ops Runbook · Deploy in 4 time-boxed sprints
▸ Minute 00 – 15 · Block + Policy
- Web-proxy content-inspection regex block on the drive-by subdomain pattern (random 6-10 char subdomain + newly-registered parent).
- Mail-gateway policy: block untrusted installer attachments (
.exe/.msi/.dmg/.pkg) to developer subnets unless signer is allowlisted. - Verify backup immutability and test restore procedure — twelve concurrent ransomware operators makes this non-negotiable this week.
- Add outbound-deny for TOR-negotiation portal domain patterns (feed subscriber list).
▸ Minute 15 – 30 · Detection Content
- Deploy Sigma 01 (drive-by installer chain) at web-proxy layer — addresses the 371-domain campaign at the pattern level.
- Deploy Sigma 02 (universal ransomware behaviour) at critical severity, direct-to-oncall.
- Deploy Sigma 03 (info-stealer credential-store read + exfil) at endpoint + network correlation layer.
- Deploy Sigma 04 (macOS LaunchAgent / Daemon persistence) on all macOS endpoints.
▸ Minute 30 – 45 · Retrospective Hunt
- Run Hunt 01 (drive-by installer downloads) across last 30 days.
- Run Hunt 02 (ransomware behavioural triage) across last 30 days.
- Run Hunt 03 (browser credential-store read + exfil) across last 60 days.
- Run Hunt 04 (macOS persistence writes) across last 90 days.
▸ Minute 45 – 60 · Awareness + Policy
- Brief all users: legitimate browser updates come from the browser itself, not from a website prompting you to click. The drive-by fake-update lure is the single most-active attack vector this week.
- Brief developer teams: continued supply-chain wave targeting developer tooling. Only install from official vendor URLs; verify package publisher; audit lock-file changes on unfamiliar additions.
- Brief macOS-endpoint users: third consecutive week of macOS-native malware activity. Verify EDR coverage; report unexpected app prompts (especially TCC prompts from unknown apps).
- Cryptocurrency-adjacent teams: MFA on every account; hardware key preferred; wallet keys never in browser credential stores.
This briefing ships a selected subset per type. The catalogue carries the full 1,999 unique high-confidence IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.
12 · Frequently asked questions
371 domains from one campaign in one week — is that normal?
Above baseline. Drive-by campaigns typically register 20-80 domains per cycle. 371 is roughly 5-10x that scale and indicates automation — the operator has an infrastructure-provisioning pipeline generating and registering new lookalike subdomains at rate. The defensive answer is pattern-detection (subdomain-format regex), not individual-IOC blocking.
Twelve concurrent ransomware operators — is that unusual?
Elevated. Typical week: 3-5 concurrent ransomware operators active with fresh IOCs. Twelve is well above baseline and suggests either affiliate-program reactivations (post-takedown recovery) or opportunistic operator activity in the wake of specific victim reporting. Regardless: the defensive answer is backup-immutability verification and universal ransomware behaviour detection.
Why is the weekly IOC count so much lower than prior weeks?
Feed-filter difference. This week’s intelligence is filtered to the weekly-tier feed which prioritises high-confidence signals. Prior weeks’ higher counts (54,763 last week, 77,118 two weeks back) included the commodity-C2 framework baseline noise. Lower absolute count, higher per-IOC quality. Both feed tiers serve legitimate purposes: weekly-tier for actionable intelligence, broader tiers for enrichment and context.
How rare is it to see macOS multi-family activity three weeks running?
Historically unusual. Prior to the current three-week pattern, this catalogue observed macOS-native families in ones-and-twos per cycle. Three consecutive weeks with 3+ concurrent families is a shift — it validates macOS as an actively-invested target profile. The gap it exploits is EDR under-investment on macOS endpoints in many environments.
Why is the developer-ecosystem supply-chain wave a MUST-priority at low IOC count?
Blast radius. Developer machines carry disproportionate downstream impact — cloud credentials, code-signing keys, CI/CD access, package-registry publish tokens. A single compromised developer can seed malicious content into hundreds of downstream consumers. Priority scoring is impact-per-target × exploitation-likelihood, not raw IOC count.
What confidence threshold should the SOC use for automated blocking?
High-confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting. This week’s drive-by pattern signature (Sigma 01) is a special case — the pattern is specific enough that automatic blocking at the web-proxy layer is safe if you have a well-maintained publisher allowlist for legitimate installers.
Where can I see this briefing’s intelligence operationally?
The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference. For hunt-program methodology, see the TaHiTI framework walkthrough and the investigation-abstract deep-dive.










