Weekly Threat Advisory

Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)

● CTI SITREP 026·32 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-032 · August 3 – 9, 2026

Drive-by and ransomware week. A single drive-by fake-update campaign produced 371 attacker-registered domains — the largest single-campaign domain footprint of the cycle. Concurrently: twelve ransomware operators active in parallel, an info-stealer and credential-drainer surge spanning Windows and macOS, third consecutive week of macOS-native multi-family activity, and continued supply-chain wave targeting the developer ecosystem.

1,999 unique high-confidence indicators across 116 tracked clusters. 87% High-severity — the intelligence this cycle is concentrated on high-confidence signals rather than commodity noise. Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, top IOCs per indicator type, four production-ready Sigma rules, real-world hunting lessons, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

1,999 unique high-confidence indicators across 116 tracked clusters this cycle. Volume is deliberately narrow — the catalogue this cycle filtered to the weekly-classified feed tier, prioritising high-signal indicators over commodity noise. This is why 87% of indicators are High-severity (vs 3% in prior weeks that included framework-C2 background). Domain volume dominates at 40% of the feed — driven by the drive-by fake-update campaign registering 371 domains.

// CTI SITREP 026·32 · August 3 – 9, 2026 · TA-2026-032
843,587
Weekly records (all feeds)
1,999
Weekly-filtered IOCs
1,741
High-severity
116
Clusters
12
Ransomware operators
3
Source feeds (weekly tier)

Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · Drive-by fake-update wave — 371 attacker-registered domains

The dominant story of the cycle. A single drive-by fake-update malware campaign produced 371 attacker-registered domains this week alone — the largest single-campaign domain footprint of the cycle by a wide margin. Every domain follows a similar structural pattern (random-string subdomain + compromised legitimate site, e.g. [a-z0-9]{8}.[compromised-site].[tld]), suggesting an automated infrastructure-provisioning pipeline. The campaign delivers browser-render-time payloads via legitimate-appearing site compromise + injected fake-update prompts.

Defensive answer: web-proxy content-inspection for the domain-pattern regex; block downloads of .exe, .msi, .dmg, .pkg when the download source is a newly-registered subdomain of a low-reputation parent domain; alert on any “update your browser” download-prompt patterns.

Headline 02 · Twelve concurrent ransomware operators active

Twelve distinct ransomware families produced fresh IOCs this cycle — the highest concurrent-ransomware-operator count catalogued in recent weeks. Combined ransomware-category footprint: 335+ IOCs across twelve operators. Signature patterns include one operator with 27 IOCs at High severity (established RaaS reactivation), a crypto-brand-themed ransomware operator (15 IOCs), and multiple mid-tier operators at 8-18 IOCs each. TOR-based negotiation-portal infrastructure is the common thread — standard RaaS operational pattern.

Defensive answer: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion via vssadmin, service-stop patterns, backup-service kill patterns). If backups are not immutable or air-gapped, address this week regardless of any other signal.

Headline 03 · Info-stealer + credential-drainer surge across platforms

Multiple info-stealer and credential-drainer families active concurrently. One dominant info-stealer family produced 181 IOCs with full 4-type IOC coverage (DOMAIN + HASH + IP + URL). A macOS-native info-stealer / credential-drainer pair produced 17 IOCs. A macOS crypto-drainer variant added another 7 IOCs. The pattern reflects operator investment in credential-monetisation — browser session cookies, password-store data, cryptocurrency wallets. Cross-platform coverage (Windows + macOS) is increasingly the norm, not the exception.

Defensive answer: harden browser credential-store access controls (require re-auth for sensitive credential retrieval); MFA on all cryptocurrency-adjacent accounts; endpoint EDR coverage on macOS not optional.

Headline 04 · macOS multi-family surge continues

Third consecutive week of macOS-native multi-family activity. Combined footprint: 118 IOCs across three macOS-native families. One larger cross-platform family with a v4 evolution (77 IOCs across all 4 IOC types), one macOS info-stealer / credential-drainer pair (17 IOCs), one macOS crypto-drainer (7 IOCs). The concurrent-family pattern across three consecutive weeks establishes macOS as a validated adversary-attention target — the ecosystem is telling defenders that under-investment in macOS EDR coverage is being actively exploited.

Defensive answer: confirm EDR coverage across all macOS endpoints without exceptions. Verify endpoint detection includes recent macOS TCC-bypass, LaunchAgent + LaunchDaemon persistence, dylib-injection, and unsigned-binary-from-user-writable-path patterns.

Headline 05 · Supply-chain wave continues — developer ecosystem targeting

The developer-ecosystem supply-chain wave carries into a second week. Fresh signals this cycle: a malicious-package registry campaign (19 IOCs across three IOC types) and a fake developer-marketplace extension campaign (10 IOCs). Combined with the prior week’s fake-installer + fake-AI-assistant campaigns, this establishes the pattern: developer-tooling supply-chain attacks are not a one-off — they are a sustained operator investment. Blast radius per compromised developer remains disproportionate.

Defensive answer: mail-gateway policy blocking untrusted installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit package-manager lock-files for unexpected new-source dependencies; audit code-signing key access patterns.


03 · Indicator type, severity, and category mix

Domain dominance at 40% share is unusual and signals infrastructure-heavy campaign activity — typical baseline is 5-10% domain share. URL share at 22% and Hash share at 14% are also elevated. Severity distribution: 87% High-severity because the weekly-tier feed prioritises high-confidence signals over commodity noise. Category dominance: Malware-Activity at 42.5% share, Ransomware-as-a-service at 10%.

// FIG A · IOC type distribution · 40% domain dominance (drive-by campaign signal)
1,827 unique IOCs · by type
Domains

734
40.2%
URLs

405
22.2%
IP addresses

378
20.7%
File hashes

264
14.4%
Other artefacts

46
2.5%

Bars scaled relative to the dominant Domain volume. The 40% Domain share (734 domains) is unusually high vs baseline — driven by the single drive-by campaign registering 371 attacker-controlled domains. Narrow-indicator concentration this week is where the campaign-specific intelligence lives.

By indicator type

Type Observations Share %
Domains 734
40.18%
URLs 405
22.17%
IPs 378
20.69%
File hashes 264
14.45%
Other artefacts 31
1.70%
Emails 15
0.82%

By severity

Severity Observations Share %
High 1,741
87.47%
Medium 162
8.87%
Low 67
3.67%

By category

Category Observations Share %
Malware-Activity 776
42.45%
Ransomware-as-a-service 182
9.96%
Spyware 181
9.90%
C&C Server 135
7.39%
APT 131
7.17%
Supply Chain 103
5.63%
RAT 95
5.20%
Malicious-Infrastructure 69
3.77%
Backdoor 42
2.30%
Loader 35
1.91%
Framework 27
1.48%
Phishing 26
1.42%
Botnet 20
1.09%
Vulnerability 6
0.33%
// UPDATE · NEWLY-ADDED CLUSTERS SINCE INITIAL PUBLISH

Fourteen additional attributed clusters were added to the feed between the initial cut and this refresh. Notable new signals worth immediate attention:

  • fake-CAPTCHA / paste-to-execute phishing campaign (27 IOCs, three IOC types) — social-engineering pattern impersonating verify-you-are-human challenges to trick users into pasting attacker-supplied clipboard content into the run prompt. Consistent with the emerging “paste-to-execute” social-engineering trend.
  • Device Code Phishing campaign (10 IOCs) — abuse of the OAuth 2.0 device-authorization flow for account takeover. Bypasses several MFA models by legitimising the attacker session through the victim’s own approval.
  • Three additional attributed APT clusters — one Larva-tracked cluster (15 IOCs), one storm-tracked cluster (15 IOCs), one long-established cluster (7 IOCs).
  • Three additional ransomware operators — total is now twelve concurrent ransomware families. Two are actor-brand emerging entrants, one is a re-brand of a prior operator.
  • Fresh supply-chain signal — a dedicated package-registry stealer campaign (7 IOCs) reinforces the developer-ecosystem-targeting narrative from the prior week.
  • New RAT campaign (12 IOCs) and brand-impersonation phishing operation (17 IOCs, five IOC types — the highest IOC-type coverage of any single cluster this cycle).

04 · Cluster footprint — ranked by unique-IOC count

56 clusters ranked by unique IOC footprint (14 newly-added since initial publish). Framework-infrastructure entries shown in grey to preserve visual clarity of the campaign-attributed clusters. All labels sanitised into category descriptors.

# Cluster descriptor Relative footprint Unique IOCs Severity
01 Drive-by fake-update malware campaign (Cluster A)

Malware Campaign · DOMAIN
371 HIGH
02 Info-stealer family with 4-type IOC coverage

Info-stealer · DOMAIN, HASH, IP, URL
181 HIGH
03 Open remote-agent C2 framework

C2 · IP
105 MEDIUM
04 Supply-chain campaign (Cluster B)

Supply Chain · HASH, IP, URL
96 HIGH
05 Attributed APT cluster (identifier C)

APT · DOMAIN, IP
83 HIGH
06 macOS-native malware family (v4 evolution)

Malware · DOMAIN, HASH, IP, URL
77 HIGH
07 Attributed APT cluster (identifier D)

APT · DOMAIN, HASH
44 HIGH
08 Multi-stage dropper family

Malware · DOMAIN, HASH, IP
40 HIGH
09 Loader family (polymorphic, Cluster E)

Loader · DOMAIN, HASH, IP, URL
36 HIGH
10 Malware family (Cluster F)

Malware · DOMAIN, HASH, IP
35 HIGH
11 Backdoor family (Cluster G)

Backdoor · DOMAIN, HASH, IP
33 HIGH
12 Ransomware operator (Cluster H)

Ransomware · DOMAIN, HASH, IP
27 HIGH
13 Open-framework C2 infrastructure (framework tier)

C2 · DOMAIN, HASH, IP, URL
27 MEDIUM
14 Multi-stage operation (Cluster J)

Malware Campaign · DOMAIN, HASH, IP, URL
27 HIGH
15 Collaboration-platform AiTM phishing campaign

Phishing · DOMAIN, HASH, URL
26 LOW
16 Commodity RAT family (Cluster K)

RAT · DOMAIN, HASH, URL
26 HIGH
17 Low-severity phishing infrastructure

Phishing · DOMAIN, IP
25 LOW
18 Commodity RAT family (Cluster L)

RAT · HASH, IP
25 HIGH
19 Social-engineering-lure malware chain

Malware · HASH, IP
25 HIGH
20 Commodity RAT family (Cluster M)

RAT · DOMAIN, HASH, IP
25 HIGH
21 Malware family (Cluster N)

Malware · DOMAIN, HASH, IP, URL
21 HIGH
22 IoT botnet family

Botnet · DOMAIN, HASH
20 HIGH
23 Malicious package-registry campaign

Supply Chain · DOMAIN, HASH, IP
19 HIGH
24 Commodity RAT family (Cluster P)

RAT · DOMAIN
19 HIGH
25 Commodity RAT family (Cluster Q)

RAT · DOMAIN, HASH
18 HIGH
26 Open remote-shell framework

C2 · DOMAIN
18 MEDIUM
27 Ransomware operator (Cluster R)

Ransomware · DOMAIN
18 HIGH
28 macOS-native info-stealer / credential-drainer pair

Malware · DOMAIN
17 HIGH
29 WebDAV-transport delivery campaign

Malware Campaign · DOMAIN, HASH, IP
16 HIGH
30 Direct-to-IP malware delivery campaign

Malware Campaign · HASH, IP
15 HIGH
31 Ransomware operator (Cluster S) — crypto-brand-lure

Ransomware · DOMAIN, HASH, URL
15 HIGH
32 Ransomware operator (Cluster T)

Ransomware · DOMAIN, HASH, URL
15 HIGH
33 Gaming-platform-lure malware campaign

Malware · DOMAIN, HASH, IP
14 HIGH
34 Threat-actor collective (identifier U)

Threat Actor · DOMAIN, HASH, URL
13 HIGH
35 Threat-actor collective (identifier V)

Threat Actor · DOMAIN
13 HIGH
36 Ransomware operator (Cluster W)

Ransomware · DOMAIN, URL
12 HIGH
37 Ransomware operator (Cluster X) — actor-hybrid

Ransomware · DOMAIN, HASH, URL
11 HIGH
38 Fake developer-marketplace extension campaign

Phishing · DOMAIN, HASH
10 LOW
39 DPRK-associated malware campaign

Malware Campaign · DOMAIN, HASH, IP
10 HIGH
40 Ransomware operator (Cluster Y)

Ransomware · DOMAIN, HASH, URL
9 HIGH
41 Open-source C2 framework (emerging)

C2 · DOMAIN
9 HIGH
42 Ransomware operator (Cluster Z)

Ransomware · DOMAIN, HASH, URL
8 HIGH
43 macOS crypto-drainer malware

Malware · DOMAIN, HASH, IP
7 HIGH
44 Multi-stage supply-chain campaign

Supply Chain · DOMAIN, HASH, URL
7 HIGH
44 Fake-CAPTCHA phishing / paste-to-execute campaign

Phishing · DOMAIN, HASH, URL
27 LOW
45 Info-stealer family (Cluster AA)

Malware · DOMAIN, HASH, IP
32 HIGH
46 Attributed APT cluster (Larva-tracked identifier AB)

APT · DOMAIN, HASH, IP
15 HIGH
47 Attributed APT cluster (Storm-tracked identifier AC)

APT · DOMAIN, HASH
15 HIGH
48 Ransomware operator (Cluster AD)

Ransomware · DOMAIN, HASH
15 HIGH
49 Brand-impersonation phishing (5-type IOC coverage)

Phishing · DOMAIN, HASH, IP, URL, EMAIL
17 LOW
50 Commodity RAT family (Cluster AE)

RAT · DOMAIN, HASH
12 HIGH
51 Device-code OAuth-flow phishing campaign

Phishing · DOMAIN, URL
10 LOW
52 Multi-stage campaign (Cluster AF)

Malware Campaign · DOMAIN, HASH, IP
8 HIGH
53 Attributed APT cluster (long-established identifier AG)

APT · DOMAIN, HASH
7 HIGH
54 Dedicated package-registry stealer campaign

Supply Chain · DOMAIN, HASH, IP
7 HIGH
55 Ransomware operator (Cluster AH)

Ransomware · DOMAIN, HASH
6 HIGH

05 · Themed deep-dives

05.1 · The 371-domain drive-by fake-update campaign

The dominant signal of the cycle. A single drive-by fake-update malware campaign registered 371 attacker-controlled domains this week. Structural pattern: [a-z0-9]{8}.[compromised-site].[tld] — a random-string subdomain hosted on a compromised legitimate parent site. The delivery chain: user visits legitimate-looking site → injected script triggers fake browser-update prompt → user clicks “update” → payload downloads from the attacker-controlled subdomain → execution.

Why 371 domains? Automation. The campaign has an infrastructure-provisioning pipeline that generates + registers new lookalike subdomains at scale. Blocking any individual domain has zero durable defensive value — the operator provisions a replacement within hours. The defensive answer must operate on the pattern, not the individual domains.

Defensive actions:

  • Web-proxy regex block on the subdomain-pattern signature: random-string of 6-10 characters preceding a compromised-site TLD.
  • Alert on any download of .exe, .msi, .dmg, .pkg from a subdomain younger than 30 days.
  • Browser-plane hardening: disable automatic download prompts; require user confirmation for any file-type download.
  • User-awareness bulletin: legitimate browser updates come from the browser itself, not from a website prompting you to click.

05.2 · Twelve concurrent ransomware operators

Twelve ransomware families active in parallel this cycle. Combined footprint: 335+ IOCs across twelve operators. Composition:

  • One established RaaS operator resurfaced at High severity (27 IOCs) — affiliate-program reactivation signal.
  • Mid-tier operators active at 8-18 IOCs each (six operators in this band).
  • One crypto-brand-themed operator (15 IOCs) — social-engineering pattern targeting cryptocurrency-adjacent audiences.
  • One threat-actor / ransomware hybrid operator (11 IOCs) using both ransomware and other tooling.

Common infrastructure pattern: TOR-based negotiation portals. This is the standard RaaS pattern — the URL indicators are .onion addresses for victim negotiation.

Defensive actions: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion via vssadmin, service-stop patterns, backup-service kill patterns). Immutable and air-gapped backups are non-negotiable given twelve concurrent operators.

05.3 · Info-stealer + credential-drainer surge across platforms

Multiple concurrent info-stealer and credential-drainer families this cycle. Signals:

  • One dominant info-stealer family with full 4-type IOC coverage (181 IOCs across DOMAIN + HASH + IP + URL) — the mature-infrastructure signal.
  • A macOS-native info-stealer + credential-drainer pair (17 IOCs).
  • A macOS crypto-drainer variant (7 IOCs).
  • A cross-platform crypto-drainer family (7 IOCs across three IOC types).

The pattern reflects operator investment in credential-monetisation — browser session cookies, password-store data, cryptocurrency wallet keys. Cross-platform coverage (Windows + macOS) is increasingly the default.

Defensive actions: harden browser credential-store access (require re-auth for sensitive credential retrieval); MFA on all cryptocurrency-adjacent accounts; endpoint EDR coverage on macOS is not optional; consider FIDO2 hardware keys for privileged accounts.

05.4 · macOS multi-family surge — third consecutive week

Third consecutive week of macOS-native multi-family activity. Combined footprint this week: 118 IOCs across three macOS-native families. One larger cross-platform family with a v4 evolution, one macOS info-stealer / credential-drainer pair, one macOS crypto-drainer. When multiple independent operators concurrently target the same profile across three consecutive weeks, the ecosystem is telling defenders that under-investment in the profile is being validated as an exploitable gap.

Defensive actions: confirm EDR coverage across all macOS endpoints without exceptions (design, engineering, executive laptops, creative teams). Verify endpoint detection includes recent macOS-specific patterns: TCC-bypass attempts, LaunchAgent + LaunchDaemon persistence, dylib-injection, unsigned-binary execution from user-writable paths, crypto-wallet file access from unfamiliar processes.

05.5 · Supply-chain wave continues — developer ecosystem

The developer-ecosystem supply-chain wave carries into a second week. Fresh signals: a malicious-package registry campaign (19 IOCs across three IOC types), a fake developer-marketplace extension campaign (10 IOCs), and a multi-stage supply-chain campaign (7 IOCs). Combined with the prior week’s fake-installer and fake-AI-assistant campaigns, the pattern is established: developer-tooling supply-chain attacks are a sustained operator investment, not a one-off.

Defensive actions: mail-gateway policy blocking untrusted installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit package-manager lock-files for unexpected new-source dependencies (recent additions of packages from unfamiliar publishers deserve review); audit code-signing key access patterns; consider requiring MFA-gated approval for new package additions in critical repositories.

05B · Adversary analytics — technique, geography, sector

Beyond the specific IOCs and cluster footprints, three cross-cutting analytics tell the story of adversary intent this cycle: which techniques are most prevalent across all clusters, which countries the intelligence signals are most likely targeting, and which sectors carry the highest concurrent-target attention. All three are extracted from this cycle’s full catalogue (not just the weekly-filtered high-confidence tier).

05B.1 · Top techniques (ATT&CK)

The single most-used technique this cycle: T1105 · Ingress Tool Transfer at 998 hits — the universal second-stage-payload-pull technique that appears in almost every multi-stage cluster. When ~1 in 4 attributed IOCs maps to T1105, the defensive answer is content-inspection at the network egress + endpoint download layer, not per-family signatures.

// TOP 10 · ATT&CK techniques this cycle
T1105 · Ingress Tool Transfer

998
16.5%
T1071.001 · Application Layer Protocol · Web Protocols

851
14.0%
T1059.001 · Command Interpreter · PowerShell

795
13.1%
T1204.002 · User Execution · Malicious File

704
11.6%
T1041 · Exfiltration Over C2 Channel

552
9.1%
T1027 · Obfuscated Files or Information

552
9.1%
T1204.001 · User Execution · Malicious Link

421
6.9%
T1566.002 · Phishing · Spearphishing Link

421
6.9%
T1036 · Masquerading

396
6.5%
T1189 · Drive-by Compromise

371
6.1%

Percentages relative to the top-20 technique volume this cycle. T1105 (Ingress Tool Transfer) leads — the second-stage-payload-pull technique used by almost every multi-stage cluster. T1071.001 (web-protocol C2) and T1059.001 (PowerShell) form the persistent commodity-execution triad. T1189 (drive-by compromise) at 371 hits reflects this cycle’s dominant drive-by campaign.

05B.2 · Most-common targeted countries

The most-targeted country this cycle: Germany (628 attributions), followed closely by the United States (760, combined representations), France (563), the United Kingdom (531), Canada (515), India (505), and Australia (484). The distribution is unusually even across the top-7 countries — a Five-Eyes + Western-Europe + India profile that suggests broad-audience campaigns (drive-by wave, info-stealer wave) rather than surgical geographic targeting.

// TOP 10 · potential targeted geographies
United States

760
18.1%
Germany

628
14.9%
France

563
13.4%
United Kingdom

531
12.6%
Canada

515
12.2%
India

505
12.0%
Australia

484
11.5%
Brazil

83
2.0%
Japan

72
1.7%
Turkey

68
1.6%

United States figure combines the two representations found in the source data (“United States” + “United States of America”). The top-7 concentration inside a ~150-attribution band indicates broad-audience campaigns rather than surgical geographic targeting.

05B.3 · Most-common targeted sectors

The most-targeted sector this cycle: Technology (902 attributions), essentially tied with Manufacturing (880), Government (877), Healthcare (877), and Financial Services (873). Same broad-target signature as the country distribution — the top-5 sectors all sit inside a ~30-attribution band. This is consistent with commodity-tier campaign activity (drive-by, info-stealer, ransomware) that targets any sector with monetisable exposure. Retail, Telecommunications, and Education round out the top-8 with substantial volume.

// TOP 10 · targeted industry sectors
Technology

902
12.6%
Manufacturing

880
12.3%
Government

877
12.2%
Healthcare

877
12.2%
Financial Services

873
12.2%
Retail

794
11.1%
Telecommunications

793
11.1%
Education

611
8.5%
Individual Users

473
6.6%
Critical Infrastructure

86
1.2%

Broad target signature across top-5 sectors (Technology, Manufacturing, Government, Healthcare, Financial Services all within a 30-attribution band). Critical Infrastructure and Defense enter the top-15 at lower but non-zero volume — monitor closely for any narrowing of concentration in later cycles.

Reading the three dimensions together. Top technique = Ingress Tool Transfer (universal second-stage). Top country = Germany (broad Western + India + Australia distribution). Top sector = Technology (essentially tied with 4 other sectors in the top-5). All three signals point to the same conclusion: this cycle’s adversary attention is broad, not narrow. High-volume commodity campaigns hitting the widest possible audience across industries and geographies. The defensive answer for a broad-target cycle is signature-level content and behavioural detectors that catch the pattern regardless of who runs it.

06 · ATT&CK tactic-pressure roll-up

Tactic Top techniques observed What the pressure means IOC count
Initial Access T1189 · T1566 · T1195 · T1195.002 · T1078 · T1133 Drive-by compromise (dominant this cycle), phishing, supply-chain compromise (npm + marketplace extensions), valid accounts, external remote services 495
Execution T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1204.002 · T1218 Command interpreter (shell / VB / JS), user-execution (drive-by chain), signed-binary proxy execution 421
Command and Control T1071 · T1071.001 · T1105 · T1090 · T1573 · T1132.001 Web-protocol C2, ingress tool transfer, proxy tunnelling (open remote-agent framework), TOR-based negotiation for RaaS operators 386
Credential Access T1003 · T1003.001 · T1555 · T1552.001 · T1539 OS credential dumping, password-store theft, credential-file discovery, browser session-cookie theft (info-stealer families driving) 340
Defense Evasion T1027 · T1036 · T1055 · T1070 · T1140 · T1562 · T1218 Obfuscation, masquerading, process injection, indicator removal, deobfuscate, disable defences, signed-binary proxy execution 289
Persistence T1547.001 · T1543.003 · T1543.001 · T1053.005 · T1505.003 Registry-run keys, service creation, launch-agent (macOS), scheduled tasks, webshell 231
Impact T1486 · T1489 · T1490 · T1491 Data encryption for impact (twelve concurrent ransomware operators), service stop, inhibit system recovery, defacement 296
Exfiltration T1041 · T1567 · T1090 Exfil over C2, exfil to web service, tunnel-based exfil (info-stealer families) 245
Discovery T1082 · T1057 · T1083 · T1018 · T1046 System info, process, file, remote-system, network configuration 178
Lateral Movement T1021 · T1021.001 · T1021.002 · T1570 Remote-desktop, SMB / admin shares, lateral tool transfer 145
Resource Development T1583.001 · T1584.001 · T1585 · T1195.002 Adversary-acquired domains (371 in a single campaign this cycle), compromised infrastructure, supply-chain compromise 495
Collection T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 Local + automated collection, screen capture, input capture, session-cookie theft 156

Detection-engineering takeaway. Initial Access is the dominant pressure this cycle at 495 IOCs, driven overwhelmingly by drive-by compromise (T1189). This is the highest drive-by pressure catalogued in recent weeks. Impact tactics (T1486 ransomware encryption, T1489 / T1490 service stop + inhibit recovery) are elevated with twelve concurrent ransomware operators. Credential Access is elevated (340 IOCs) driven by the info-stealer surge — browser password-store theft is the dominant sub-technique. Resource Development (T1583.001 adversary-acquired domains) at 495 IOCs reflects the 371-domain drive-by campaign infrastructure footprint.


07 · Real-world threat intelligence lessons

Beyond the specific IOCs, this cycle’s data carries lessons that will still matter next month and next quarter. Below are the pragmatic takeaways for the working analyst.

Lesson 01 · When one campaign owns 40% of your feed, pattern detection beats individual-IOC blocking

The 371-domain drive-by campaign accounted for 40% of this week’s domain volume. Blocking any single one of those 371 domains has zero durable defensive value — the operator has an infrastructure-provisioning pipeline that generates replacements faster than any feed can catalogue them. The mature CTI program detects the pattern (subdomain-format regex, subdomain-age enrichment, parent-domain-reputation join) and treats individual IOCs as evidence-of-pattern, not as primary blocklist entries. Reallocate feed-consumption architecture accordingly.

Lesson 02 · Twelve concurrent ransomware operators means backups are the perimeter

When nine ransomware operators are simultaneously active, the probability that at least one gets past your prevention controls in any given quarter approaches certainty. The perimeter defence is not endpoint detection alone — it is the recovery capability if endpoint detection misses. Immutable backups. Air-gapped backups. Tested restore procedures. If your restore has not been tested against a full-domain-encrypted scenario in the last 90 days, it has not been tested.

Lesson 03 · Cross-platform info-stealers mean the browser is the credential vault attackers care about

The dominant info-stealer family this cycle has full 4-type IOC coverage. Multiple macOS-native stealers are active concurrently. The consistent target: browser credential stores, cookies, cryptocurrency wallet files. This is where operator monetisation happens. The defensive answer: harden browser credential retrieval (require re-auth), move privileged secrets out of browser storage (use dedicated password managers with hardware-token unlocking), enforce FIDO2 hardware keys on all high-value accounts.

Lesson 04 · The developer ecosystem is not a temporary target

Two consecutive weeks of supply-chain campaigns targeting developer tooling. This is not a one-off — it is a validated operator investment area. Developer machines carry disproportionate blast radius: cloud credentials, code-signing keys, CI/CD pipeline access, package-registry publish tokens. The defensive answer is not just endpoint-level content on developer machines — it is CI/CD-pipeline hygiene (secret rotation, dependency-provenance verification, package-lock audits) and identity-plane hardening (MFA on all developer accounts, session-lifetime restrictions, privileged-access review).

Lesson 05 · macOS coverage is a growing operational gap

Three consecutive weeks of macOS multi-family activity establishes the pattern: operators are validating macOS as an exploitable gap. Environments that still treat macOS EDR as optional or best-effort are the environments this pattern is designed to exploit. Confirm EDR coverage across all macOS endpoints. Confirm coverage includes recent macOS-specific persistence patterns. Confirm your SOC can triage macOS alerts (analyst training on macOS-specific artefacts is often the missing piece).

Lesson 06 · High-severity concentration signals mature intelligence, not more threat

87% High-severity this week is not because the threat landscape got 30x worse. It is because the weekly-tier feed prioritises high-confidence signals over commodity noise. A mature CTI program uses this signal: the weekly-tier feed is where you look for actionable intelligence; the higher-volume feeds are where you look for context and enrichment on specific alerts. Do not treat all feed tiers as equal — they serve different analytical purposes.

The one-line synthesis. This week says: pattern-detection beats individual-blocking for high-volume campaigns; backup recovery is now the last line of defence against ransomware; browser credential-store hardening is table stakes; developer-ecosystem targeting is not going away; macOS EDR coverage is an active gap; feed tiering is an analytical tool. Six takeaways from one week that will still be true next quarter.

08 · Top IOCs per indicator type

Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.]. and hxxphttp).

Top 15 · IP addresses (High severity)

# Indicator Category Severity
01 101.36.123.12 Backdoor HIGH
02 103.106.190.217 Malware-Activity HIGH
03 103.214.146.46 Botnet HIGH
04 103.22.137.227 Loader HIGH
05 103.226.155.200 Malware-Activity HIGH
06 103.226.155.201 Malware-Activity HIGH
07 103.231.15.135 Supply Chain HIGH
08 103.231.15.219 Supply Chain HIGH
09 103.231.15.248 Supply Chain HIGH
10 103.238.129.112 Malware-Activity HIGH
11 103.245.236.146 Malware-Activity HIGH
12 103.246.244.13 Supply Chain HIGH
13 103.246.244.20 Supply Chain HIGH
14 103.53.80.201 Backdoor HIGH
15 103.97.128.67 Malware-Activity HIGH

Top domains (High severity)

# Indicator Category Severity
01 022kgyq9[.]eachway-multiplier[.]com Malware-Activity HIGH
02 1systemsevolve[.]digital APT HIGH
03 1vqj02ep[.]myboutiqswitch[.]com Malware-Activity HIGH
04 2dflte3h[.]grannygshemporium[.]com Malware-Activity HIGH
05 45gradnord[.]de Malware-Activity HIGH
06 602a5sud[.]foodpapajobs[.]com Malware-Activity HIGH
07 7xa644hx[.]habbofutbol[.]com Malware-Activity HIGH
08 9haaqrsv[.]ryanposocco[.]com Malware-Activity HIGH
09 9tczi7ct[.]overtheitgirl[.]com Malware-Activity HIGH
10 9vn1ctfe[.]partyboxlovely[.]com Malware-Activity HIGH
11 crestmarkhq[.]com Malware-Activity HIGH
12 igsx[.]closedfistllc[.]com Malware-Activity HIGH
13 aaraenergy[.]com Malware-Activity HIGH

Top file hashes (High severity)

# Indicator Category Severity
01 00a1228648fffa7338076970037b89f679a166a08c4d9573f1f27973ec6ed497 Backdoor HIGH
02 01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2 Malware-Activity HIGH
03 01e4cb3c60fa50b2927daa11f25a3c412549680406fc121a3d1870a9a33f5d38 Malware-Activity HIGH
04 03fd832b81dd54d2bf5f610a8ff27856 Supply Chain HIGH
05 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58 Malware-Activity HIGH
06 06f8fa00d40da2ad3293e75bb7b95dc9 RAT HIGH
07 0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3 Malware-Activity HIGH
08 09683b2cb19f16818d0a60264663cac2 RAT HIGH
09 09ed9ad3ac886f5aaf8357127b6dd5926bd4af1e2cc687a6a4856bcaedee2667 Backdoor HIGH
10 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a Malware-Activity HIGH
11 0cbbe5da1a691368343d029dcc546710 RAT HIGH
12 0fc30f82e1fa5e51a6c0c43f3ed7f13592ea731cb331e43a4d085df60a4db8b6 Malware-Activity HIGH
13 1081ff69cba7a5a64aa40480dc5f693c RAT HIGH

Top URLs (High severity)

# Indicator Category Severity
01 hxxp[://]159[.]100[.]18[.]98:80/fbbef44e-51f2-4f0c-be82-09a32ddbb320 Malware-Activity HIGH
02 hxxp[://]22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead[.]onion/ Ransomware-as-a-service HIGH
03 hxxp[://]2c7nd54guzi6xhjyqrj5kdkrq2ngm2u3e6oy4nfhn3wm3r54ul2utiqd[.]onion/ Malicious-Infrastructure HIGH
04 hxxp[://]2cyxmof76rxeqze5snxxooqmhzjtcploqswxoxmenfayphumdhrtrzqd[.]onion Ransomware-as-a-service HIGH
05 hxxp[://]2nyysjgsfhnwizvbhjeklagbdbjz2z27meao7asl73zcqpb5cr4n4eyd[.]onion Ransomware-as-a-service HIGH
06 hxxp[://]2yxf2ald2c67twt4663piypum2fu6yt4su453naxsdiilpd4m7pgu6qd[.]onion Ransomware-as-a-service HIGH
07 hxxp[://]33333333h45xwqlf3s3eu4bkd6y6bjswva75ys7j6satex5ctf4pyfad[.]onion Ransomware-as-a-service HIGH
08 hxxp[://]3lce6cov7sj7vovrr3cbanqoolhgfgqqcvjrtlzlqnex7esdz33mdoqd[.]onion/ Malicious-Infrastructure HIGH
09 hxxp[://]4mmc[.]space Malicious-Infrastructure HIGH
10 hxxp[://]4qyjonpyksc52bc3fsgfgedssqgo4a6vlfsjknqnkncbyl4layqkqjid[.]onion/ Ransomware-as-a-service HIGH
Need the full set? The catalogue carries 1,999 unique high-confidence IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, category attribution, and source-feed provenance. Open HuntIntel.

09 · Sigma detection rules

Sigma 01 · Drive-by fake-update chain (HIGH)

title: Drive-By Fake-Update Chain — Random-Subdomain Download of Installer
id: 4f2a8d6c-7b53-4820-9a71-3f5c1e2d8a41
status: experimental
description: Detects the drive-by fake-update chain — user browsing session
  leads to a download of an installer file (.exe, .msi, .dmg, .pkg) from a
  random-string subdomain of a low-reputation parent domain. Ships from
  HackForLab weekly threat advisory Aug 3-9, 2026.
references:
  - https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
  - attack.initial_access
  - attack.t1189
  - attack.execution
  - attack.t1204.002
  - attack.resource_development
  - attack.t1583.001
logsource:
  category: web_proxy
detection:
  s1_random_subdomain:
    destination_host|re: '^[a-z0-9]{6,10}\.[a-z0-9-]+\.[a-z]{2,10}$'
  s2_installer_download:
    request_uri|endswith:
      - '.exe'
      - '.msi'
      - '.dmg'
      - '.pkg'
      - '.deb'
    request_method: 'GET'
    response_content_type|contains:
      - 'application/octet-stream'
      - 'application/x-msi'
      - 'application/x-apple-diskimage'
  s3_low_reputation_parent:
    destination_parent_domain_age: '<30d'
    OR destination_parent_domain_reputation: 'unknown'
  condition: s1_random_subdomain and s2_installer_download and s3_low_reputation_parent
falsepositives:
  - Legitimate software installers from allowlisted publishers (maintain publisher allowlist)
level: high

Sigma 02 · Universal ransomware behaviour (CRITICAL)

title: Universal Ransomware Behaviour — Mass Encrypt + Shadow-Copy Delete
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a15
status: experimental
description: Detects universal ransomware behaviour — mass file-modification
  with new extensions + shadow-copy deletion + backup-service stop within a
  short window. Catches all twelve concurrent ransomware operators this cycle
  without requiring family-specific signatures.
references:
  - https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
  - attack.impact
  - attack.t1486
  - attack.t1490
  - attack.t1489
logsource:
  product: correlation
detection:
  s1_mass_file_modify:
    EventCount|file_modify_events: '>100_per_minute'
    NewFileExtension|distinct_count: '<3'
  s2_shadow_copy_delete:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'wmic shadowcopy delete'
      - 'bcdedit /set recoveryenabled No'
  s3_backup_service_stop:
    Service|category: 'backup_or_shadowcopy'
    ServiceAction: 'stop_or_disable'
  condition: (s1_mass_file_modify and s2_shadow_copy_delete)
          or (s1_mass_file_modify and s3_backup_service_stop)
level: critical

Sigma 03 · Info-stealer credential-store read + exfil (HIGH)

title: Info-Stealer Chain — Browser Credential-Store Read + Outbound POST
id: 6a5e9d3f-7b28-4c50-a941-5f8b6d2e9c32
status: experimental
description: Detects the info-stealer chain — read access to browser
  credential-store paths by a non-browser process, followed within 5 minutes
  by outbound POST to a non-corporate destination with payload larger than
  50 KB. Catches this cycle's dominant info-stealer + credential-drainer
  families across Windows and macOS.
references:
  - https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
  - attack.credential_access
  - attack.t1003
  - attack.t1555
  - attack.t1539
  - attack.exfiltration
  - attack.t1041
logsource:
  product: correlation
detection:
  s1_credential_store_read:
    EventType: 'file_read'
    TargetPath|contains:
      - '\User Data\Default\Login Data'
      - '\User Data\Default\Cookies'
      - '/Library/Application Support/Google/Chrome/Default/Login Data'
      - '/Library/Application Support/Firefox/Profiles'
      - '/Library/Keychains/'
    ReaderProcess|not:
      - 'browser_processes_allowlist'
  s2_outbound_post:
    RequestMethod: 'POST'
    DestinationIp|expand: '%non_corporate_destinations%'
    RequestBodySize: '>50000'
  condition: s1_credential_store_read and s2_outbound_post within 5m
falsepositives:
  - Legitimate password manager sync (allowlist by known-good sync destinations)
level: high

Sigma 04 · macOS LaunchAgent / Daemon persistence (HIGH)

title: macOS Persistence — LaunchAgent or LaunchDaemon plist Write by Non-Allowlisted Signer
id: 5d8e9c1f-3b47-4a52-a831-6f2b7c1d9a53
status: experimental
description: Detects LaunchAgent or LaunchDaemon plist file writes to
  user-writable paths on macOS endpoints by a process whose signer is not
  on the allowlist. Catches this cycle's macOS multi-family activity
  (third consecutive week of the pattern).
references:
  - https://hackforlab.com/weekly-threat-advisory-august-3-9-2026/
author: HackForLab Threat Intelligence
date: 2026/08/10
tags:
  - attack.persistence
  - attack.t1543.001
  - attack.t1543.004
logsource:
  category: file_event
  product: macos
detection:
  s1_launch_persistence_path:
    TargetFilename|contains:
      - '/Library/LaunchAgents/'
      - '/Library/LaunchDaemons/'
      - '~/Library/LaunchAgents/'
    TargetFilename|endswith: '.plist'
  s2_writer_not_allowlisted:
    ProcessSigner|not:
      - 'os_vendor'
      - 'allowlisted_mac_publisher'
  condition: s1_launch_persistence_path and s2_writer_not_allowlisted
falsepositives:
  - Legitimate third-party tooling with allowlisted signers (maintain allowlist)
level: high

10 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Drive-by installer downloads from random-subdomain patterns (last 30 days)

FROM web_proxy
WHERE destination_host REGEXP '^[a-z0-9]{6,10}\.[a-z0-9-]+\.[a-z]{2,10}$'
  AND request_uri REGEXP '\.(exe|msi|dmg|pkg|deb)$'
  AND destination_parent_domain_age < 30 DAYS
  AND event_time >= NOW() - 30 DAYS
| PROJECT source_host, destination_host, request_uri, event_time
| SORT BY event_time DESC

Hunt 02 · Ransomware behavioural triage (last 30 days)

FROM edr_file_events
WHERE event_type = 'modify'
  AND file_modification_rate > 100_per_minute
  AND new_file_extension_distinct_count < 3
  AND event_time >= NOW() - 30 DAYS
| JOIN edr_process_create pc ON pc.host = file_events.host
| WHERE pc.command_line CONTAINS 'vssadmin' OR pc.command_line CONTAINS 'shadowcopy'
| PROJECT host, user, new_file_extension, file_modification_rate, event_time

Hunt 03 · Non-browser process reading browser credential stores (last 60 days)

FROM edr_file_events
WHERE event_type = 'read'
  AND target_path MATCHES '.*/(Login Data|Cookies|Keychains/.+)$'
  AND reader_process NOT IN (browser_processes_allowlist)
  AND event_time >= NOW() - 60 DAYS
| JOIN edr_network_events ne
  ON ne.host = edr_file_events.host
  AND ne.event_time BETWEEN edr_file_events.event_time
                        AND edr_file_events.event_time + INTERVAL 5 MINUTE
| WHERE ne.request_method = 'POST'
  AND ne.request_body_size > 50000
| PROJECT host, user, reader_process, ne.destination_host, event_time

Hunt 04 · macOS LaunchAgent / Daemon plist writes by non-allowlisted signer (last 90 days)

FROM edr_file_events
WHERE endpoint_os = 'macos'
  AND target_filename MATCHES '.*/(LaunchAgents|LaunchDaemons)/.*\.plist$'
  AND writer_signer_category NOT IN ('os_vendor', 'allowlisted_mac_publisher')
  AND event_time >= NOW() - 90 DAYS
| PROJECT host, user, target_filename, writer_process, event_time

11 · Operationalise in 60 minutes

// Cyber-Ops Runbook · Deploy in 4 time-boxed sprints

▸ Minute 00 – 15 · Block + Policy

  • Web-proxy content-inspection regex block on the drive-by subdomain pattern (random 6-10 char subdomain + newly-registered parent).
  • Mail-gateway policy: block untrusted installer attachments (.exe/.msi/.dmg/.pkg) to developer subnets unless signer is allowlisted.
  • Verify backup immutability and test restore procedure — twelve concurrent ransomware operators makes this non-negotiable this week.
  • Add outbound-deny for TOR-negotiation portal domain patterns (feed subscriber list).

▸ Minute 15 – 30 · Detection Content

  • Deploy Sigma 01 (drive-by installer chain) at web-proxy layer — addresses the 371-domain campaign at the pattern level.
  • Deploy Sigma 02 (universal ransomware behaviour) at critical severity, direct-to-oncall.
  • Deploy Sigma 03 (info-stealer credential-store read + exfil) at endpoint + network correlation layer.
  • Deploy Sigma 04 (macOS LaunchAgent / Daemon persistence) on all macOS endpoints.

▸ Minute 30 – 45 · Retrospective Hunt

  • Run Hunt 01 (drive-by installer downloads) across last 30 days.
  • Run Hunt 02 (ransomware behavioural triage) across last 30 days.
  • Run Hunt 03 (browser credential-store read + exfil) across last 60 days.
  • Run Hunt 04 (macOS persistence writes) across last 90 days.

▸ Minute 45 – 60 · Awareness + Policy

  • Brief all users: legitimate browser updates come from the browser itself, not from a website prompting you to click. The drive-by fake-update lure is the single most-active attack vector this week.
  • Brief developer teams: continued supply-chain wave targeting developer tooling. Only install from official vendor URLs; verify package publisher; audit lock-file changes on unfamiliar additions.
  • Brief macOS-endpoint users: third consecutive week of macOS-native malware activity. Verify EDR coverage; report unexpected app prompts (especially TCC prompts from unknown apps).
  • Cryptocurrency-adjacent teams: MFA on every account; hardware key preferred; wallet keys never in browser credential stores.
// CONTINUE WITH HUNTINTEL

This briefing ships a selected subset per type. The catalogue carries the full 1,999 unique high-confidence IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

12 · Frequently asked questions

371 domains from one campaign in one week — is that normal?

Above baseline. Drive-by campaigns typically register 20-80 domains per cycle. 371 is roughly 5-10x that scale and indicates automation — the operator has an infrastructure-provisioning pipeline generating and registering new lookalike subdomains at rate. The defensive answer is pattern-detection (subdomain-format regex), not individual-IOC blocking.

Twelve concurrent ransomware operators — is that unusual?

Elevated. Typical week: 3-5 concurrent ransomware operators active with fresh IOCs. Twelve is well above baseline and suggests either affiliate-program reactivations (post-takedown recovery) or opportunistic operator activity in the wake of specific victim reporting. Regardless: the defensive answer is backup-immutability verification and universal ransomware behaviour detection.

Why is the weekly IOC count so much lower than prior weeks?

Feed-filter difference. This week’s intelligence is filtered to the weekly-tier feed which prioritises high-confidence signals. Prior weeks’ higher counts (54,763 last week, 77,118 two weeks back) included the commodity-C2 framework baseline noise. Lower absolute count, higher per-IOC quality. Both feed tiers serve legitimate purposes: weekly-tier for actionable intelligence, broader tiers for enrichment and context.

How rare is it to see macOS multi-family activity three weeks running?

Historically unusual. Prior to the current three-week pattern, this catalogue observed macOS-native families in ones-and-twos per cycle. Three consecutive weeks with 3+ concurrent families is a shift — it validates macOS as an actively-invested target profile. The gap it exploits is EDR under-investment on macOS endpoints in many environments.

Why is the developer-ecosystem supply-chain wave a MUST-priority at low IOC count?

Blast radius. Developer machines carry disproportionate downstream impact — cloud credentials, code-signing keys, CI/CD access, package-registry publish tokens. A single compromised developer can seed malicious content into hundreds of downstream consumers. Priority scoring is impact-per-target × exploitation-likelihood, not raw IOC count.

What confidence threshold should the SOC use for automated blocking?

High-confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting. This week’s drive-by pattern signature (Sigma 01) is a special case — the pattern is specific enough that automatic blocking at the web-proxy layer is safe if you have a well-maintained publisher allowlist for legitimate installers.

Where can I see this briefing’s intelligence operationally?

The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference. For hunt-program methodology, see the TaHiTI framework walkthrough and the investigation-abstract deep-dive.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter Captcha Here : *

Reload Image