Intelligence week. 59,935 unique IOCs across 116 adversary clusters. A novel command-and-control resolution pattern surfaced — Polygon-Based C2, 314 IOCs, resolving operator infrastructure through the Polygon blockchain rather than DNS. Blockchain-resolved C2 is now a recurring pattern rather than a one-off. Four Chinese-aligned APT clusters ran in parallel: APT-C-60 (121 IOCs, full 5-type spread), UAT-11795 (52 IOCs), APT-C-35 (41 IOCs), APT-Q-27 (15 IOCs). Twenty-plus named ransomware families generated fresh indicators. The TencShell C2 operator concentrated 16 IPs across four subnet blocks — the largest single-cluster subnet footprint of the year. If your CTI team was quiet this week, this briefing has your reading list.
Sectioned for the working analyst: cluster catalogue, deep-dives on the high-tempo names, ATT&CK technique mapping per adversary, subnet + port anchors, top 15 IOCs per indicator type, four production-ready Sigma rules, 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
02 · Five headlines
03 · IOC / severity / category mix
04 · Top adversary clusters
05 · Cluster deep-dives
06 · ATT&CK per adversary
07 · Tactic-pressure roll-up
08 · Subnet anchors
08b · Predictive intelligence
09 · Top 15 IOCs per type
10 · Sigma detection rules
11 · Hunt queries
12 · Operationalise in 60 min
13 · FAQ
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and adversary cluster pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
The catalogue produced 59,935 unique IOCs across 116 adversary clusters this cycle — a wide-tempo week. Framework-infrastructure entries dominate the topline volume (as usual), but the narrow-indicator layer (domain / hash / URL / email) contributed 3,382 unique records — approximately double the year-to-date baseline. Every major operator category is elevated: APT +4 named clusters, ransomware 20+ families concurrent, supply-chain double strike, macOS threats surging, and a novel blockchain-resolved C2 pattern surfacing at scale for the second time in a month.
Catalogued, ML-scored, ATT&CK-tagged. Every record carries adversary attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · Polygon-Based C2 — novel blockchain-resolved command channel
314 IOCs across DOMAIN + IP. Second observation this month of a malware family that resolves its command-and-control endpoints through a public blockchain rather than conventional DNS. Same operational category as the prior TONResolver cluster observed a fortnight ago. The operator publishes the current C2 address as an on-chain record; the implant queries the chain to retrieve the address; every rotation is a new on-chain transaction. Result: takedown-resistant infrastructure by design. DNS-based blocking cannot break the resolution chain because resolution never touches DNS. Detection has to move to the endpoint layer (process behavioural detection on the blockchain-RPC library calls) and the network layer (any outbound connection to public blockchain RPC endpoints from a non-engineering host).
Headline 02 · APT week — 4 Chinese-aligned clusters active in parallel
Four named Chinese-aligned APT clusters produced fresh indicators this cycle: APT-C-60 (121 IOCs across all 5 primary IOC types — the broadest single-cluster IOC-type spread of the week; subnet anchor at 213.111.158.0/24), UAT-11795 (52 IOCs with developer-and-cryptocurrency-targeting domain infrastructure), APT-C-35 (41 IOCs), and APT-Q-27 (15 IOCs). Combined APT-category footprint: 316 IOCs. Concurrent activity from four named clusters is a load-bearing signal about regional operational tempo.
Headline 03 · Ransomware surge — 20+ families concurrent, RAWorld + Trigona lead
The ransomware-as-a-service category produced 632 IOCs across 20+ named families this cycle. RAWorld led at 213 IOCs (with active leak-site publication observable in the OTHERS category). Trigona followed at 115. Qilin at 56. MedusaLocker at 26. Medusa at 25. Fog at 24. WORLDLEAKS at 15. Spirals at 12. Sorry at 17. Plus a dozen more with 5+ indicators each. Universal ATT&CK signature: the encrypt-plus-inhibit-recovery pair (T1486 → T1490) is present in every family. A single detector fired against volume-shadow-copy deletion catches all of them.
Headline 04 · Package-registry supply-chain double strike
Two concurrent supply-chain campaigns hit public package registries. The malicious game-cheat package campaign (39 IOCs) targeted a public package registry with typosquat packages advertising game-cheat functionality. The malicious Go module campaign (36 IOCs) hit a public Go module registry with similar typosquat-and-payload tradecraft. The coordination across two registries in the same cycle suggests either shared upstream tooling or an operator maturing their supply-chain capability across multiple ecosystems. CI build agents that pull from unrestricted registries are the exposed surface.
Headline 05 · macOS threat layer maturing
Three separate macOS-focused observations in a single cycle: AppleScript-based infostealer (36 IOCs across DOMAIN + HASH + URL), macOS-focused information stealer (11 IOCs across HASH + IP + URL), and Artlist ClickFix Campaign (18 IOCs including a macOS-specific variant). The pattern — multiple concurrent macOS-focused clusters — is new. Historically macOS has been an occasional target; this cycle it is a persistent one. macOS environments are typically under-instrumented for terminal-execution telemetry compared with Windows — this week is a strong prompt to invest in macOS endpoint telemetry parity.
03 · Indicator type, severity, and category mix
The IP indicator layer dominates the topline (94 percent) because the framework-infrastructure feed is running heavy this cycle. The intelligence density sits in the narrow layers: 1,585 unique domains, 1,333 unique hashes, 361 URLs, 103 emails, 61 OTHERS. The C&C category leads the category mix by a wide margin (89 percent) reflecting framework-infrastructure feed output. Ransomware-as-a-Service sits at 632 IOCs (1.1 percent share of records but the most operationally-actionable category).
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| IPs | 56,486 | 94.25% | |
| Domains | 1,585 | 2.64% | |
| File hashes | 1,333 | 2.22% | |
| URLs | 361 | 0.60% | |
| Emails | 103 | 0.17% | |
| Other artefacts | 61 | 0.10% | |
| Process names | 6 | 0.01% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 6,687 | 10.70% | |
| Medium | 55,696 | 89.10% | |
| Low | 127 | 0.20% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| C&C | 53,138 | 80.54% | |
| C&C Server | 6,162 | 9.34% | |
| Botnet | 4,943 | 7.49% | |
| Ransomware-as-a-service | 632 | 0.96% | |
| Malware-Activity | 525 | 0.80% | |
| APT | 316 | 0.48% | |
| Phishing | 112 | 0.17% | |
| Supply Chain | 44 | 0.07% | |
| RAT | 30 | 0.05% | |
| Framework | 27 | 0.04% | |
| Hacktivist Group | 14 | 0.02% | |
| Intrusion Campaign | 13 | 0.02% | |
| Spyware | 10 | 0.02% | |
| Vulnerability | 8 | 0.01% |
04 · Top adversary clusters
38 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. Polygon-Based C2 (314 IOCs) and APT-C-60 (121 IOCs full 5-type) are the standouts.
| # | Adversary cluster | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Commodity C2 framework A (open-framework infrastructure)
C2 · DOMAIN, EMAIL, HASH, IP, URL
|
57,809 | MEDIUM | |
| 02 | Polygon-Based C2 (novel blockchain-resolved)
Malware · DOMAIN, IP
|
314 | HIGH | |
| 03 | RAWorld
Ransomware · HASH, IP, OTHERS
|
213 | HIGH | |
| 04 | Commodity C2 framework A (malware-tier)
Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
|
153 | HIGH | |
| 05 | APT-C-60
Threat Actor (APT) · DOMAIN, EMAIL, HASH, IP, URL
|
121 | HIGH | |
| 06 | Trigona
Ransomware · EMAIL, HASH
|
115 | HIGH | |
| 07 | Cloud-suite phishing operation
Phishing Campaign · DOMAIN, EMAIL, HASH, IP
|
68 | LOW | |
| 08 | PhantomEnigma
Malware Campaign · DOMAIN, HASH, IP, URL
|
59 | HIGH | |
| 09 | Qilin
Ransomware · HASH, OTHERS
|
56 | HIGH | |
| 10 | UAT-11795
Threat Actor (APT) · DOMAIN, HASH, IP, URL
|
52 | HIGH | |
| 11 | Open remote-management framework
C2 · IP
|
51 | MEDIUM | |
| 12 | The TTF Trap (font-exploit campaign)
Malware Campaign · DOMAIN, HASH, IP, URL
|
42 | HIGH | |
| 13 | APT-C-35
Threat Actor (APT) · DOMAIN, HASH, IP
|
41 | HIGH | |
| 14 | Malicious game-cheat package-registry campaign
Malware Campaign · DOMAIN, HASH, IP, URL
|
39 | HIGH | |
| 15 | AppleScript-based infostealer
Malware · DOMAIN, HASH, URL
|
36 | HIGH | |
| 16 | Malicious Go-module supply-chain campaign
Malware Campaign · DOMAIN, EMAIL, HASH, URL
|
36 | HIGH | |
| 17 | Fake-offers phishing campaign
Phishing Campaign · DOMAIN, URL
|
34 | LOW | |
| 18 | CrashStealer
Malware · DOMAIN, HASH, IP, URL
|
33 | HIGH | |
| 19 | TuxBot v3
Malware (Botnet) · DOMAIN, HASH, IP
|
32 | HIGH | |
| 20 | TelePuz
Malware · DOMAIN, HASH, IP
|
31 | HIGH | |
| 21 | Open exploitation framework
C2 · IP
|
29 | MEDIUM | |
| 22 | MedusaLocker
Ransomware · EMAIL, HASH, OTHERS
|
26 | HIGH | |
| 23 | OkoBot
Malware (Botnet) · DOMAIN, HASH, IP
|
25 | HIGH | |
| 24 | Medusa
Ransomware · EMAIL, HASH, OTHERS
|
25 | HIGH | |
| 25 | Fog
Ransomware · HASH
|
24 | HIGH | |
| 26 | Lucide Proxy
DDoS · HASH, IP, URL
|
23 | MEDIUM | |
| 27 | GoSerpent
Malware · HASH, IP
|
22 | HIGH | |
| 28 | TencShell C2 infrastructure
Malware Campaign · HASH, IP
|
22 | HIGH | |
| 29 | Artlist ClickFix Campaign
Malware Campaign · DOMAIN, HASH, IP
|
18 | HIGH | |
| 30 | Sorry
Ransomware · HASH, IP
|
17 | HIGH | |
| 31 | ACR Stealer
Malware · DOMAIN
|
16 | HIGH | |
| 32 | OTTERCOOKIE
Malware · DOMAIN, HASH, IP
|
16 | HIGH | |
| 33 | Kratos
Phishing Kit · DOMAIN, IP
|
16 | MEDIUM | |
| 34 | APT-Q-27
Threat Actor (APT) · DOMAIN, HASH, IP
|
15 | HIGH | |
| 35 | WORLDLEAKS
Ransomware · HASH
|
15 | HIGH | |
| 36 | ClickLock
Malware · DOMAIN, HASH, URL
|
13 | HIGH | |
| 37 | Spirals
Ransomware · HASH, IP, URL
|
12 | HIGH | |
| 38 | macOS-focused information stealer
Malware · HASH, IP, URL
|
11 | HIGH |
05 · Cluster deep-dives — the names to act on
05.1 · Polygon-Based C2 — blockchain-resolved command channel
314 IOCs across DOMAIN + IP. The malware family resolves its C2 endpoints through the Polygon public blockchain rather than DNS. Operator publishes the current C2 address as an on-chain smart-contract record; implant queries the blockchain to retrieve the address; every rotation is a new on-chain transaction (cheap for the operator, instant for the implant). The pattern is takedown-resistant by design because there is no domain registrar to notify and no DNS record to takedown.
Defensive actions: Push the 314 catalogued indicators to blocking. But recognise the strategic limit — the operator’s next rotation will not surface in DNS-based catalogues. Detection must move to (a) endpoint behavioural detection on the process’s blockchain-RPC library calls, or (b) network detection of any outbound connection to public Polygon RPC endpoints from a non-engineering host. Audit your outbound egress policy to explicitly deny blockchain-RPC traffic unless business use is documented.
05.2 · APT-C-60 — broadest 5-type IOC spread
121 IOCs across all 5 primary IOC types (DOMAIN + EMAIL + HASH + IP + URL) with a subnet anchor at 213.111.158.0/24. The 5-type spread is the broadest single-cluster IOC-type spread this week — indicating a full-ecosystem intrusion, not a single-lure campaign. Standard regional-APT tradecraft: adversary-acquired domains, spearphishing attachments, user-execution, command-interpreter, obfuscated payload, second-stage pull, web-protocol C2, exfil.
Defensive actions: All 121 catalogued indicators to blocking / watchlist by tier. Block the 213.111.158.0/24 subnet anchor. Hunt for outbound to the anchor across the last 90 days.
05.3 · UAT-11795 — developer-and-cryptocurrency-targeting
52 IOCs across DOMAIN + HASH + IP + URL. Adversary-acquired domain infrastructure with distinctive targeting: aipythondevs[.]com targets Python developers; alphabitcapital[.]info targets cryptocurrency-adjacent audiences. Combines two high-value victim populations in a single cluster. Standard APT tradecraft otherwise.
Defensive actions: Block the 52 catalogued indicators. Brief developer and cryptocurrency-using populations on the domain-adjacent targeting pattern.
05.4 · RAWorld ransomware — 213 IOCs with active leak-site publication
Largest ransomware footprint of the week. HASH + IP + OTHERS. The OTHERS category contains victim-slug patterns published on the operator’s data-leak site — watch this indicator class for early warning that your organisation appears on the site.
Defensive actions: Hash-block the catalogued binaries at endpoint scan. Push IPs to perimeter blocklist. Subscribe to leak-site infrastructure monitoring if your organisation is exposed to double-extortion operators.
05.5 · Trigona — 115 IOCs with operator ransom-negotiation email surface
EMAIL + HASH. The email indicators are ransom-negotiation contact channels the operator uses post-encryption. Detection value: if any email in your environment sent or received communication with a Trigona negotiation address, that is a strong signal of an in-progress or historical intrusion.
Defensive actions: Deploy the catalogued email indicators as SMTP-gateway blocklist AND as a retrospective hunt against the last 90 days of mailbox audit logs.
05.6 · TencShell C2 infrastructure — 4 subnet anchors, 16 IPs
22 IOCs across HASH + IP with the most concentrated subnet footprint of the week: 4 /24 blocks (134.122.200.0/24 with 6 IPs, 192.163.167.0/24 with 4 IPs, 45.64.52.0/24 with 3 IPs, 112.213.124.0/24 with 3 IPs). 16 IPs across 4 anchor blocks is the largest single-cluster hosting concentration observed this year. Rotation resilience is low from the defender’s perspective — new IPs are highly likely to fall in the same blocks.
Defensive actions: Block all four /24 anchors at the perimeter now. Cost: zero. Operational risk: bounded (~1,024 addresses across 4 blocks). Amortised leverage: every rotation inside any block hits the same wall.
05.7 · Malicious package-registry double strike (game-cheat + Go module)
Two concurrent supply-chain campaigns. Game-cheat campaign: 39 IOCs across all 4 IOC types. Typosquat packages advertising game-cheat functionality delivered obfuscated payloads at install time. Go module campaign: 36 IOCs across DOMAIN + EMAIL + HASH + URL. Compromised Go modules with post-install command execution. Together they suggest an operator maturing their supply-chain capability across multiple language ecosystems.
Defensive actions: Package allow-listing in CI build agents. Outbound-domain monitoring from build runners. Publisher-identity verification. Hunt for install-time process trees where a package installer spawns a shell that pulls from an unfamiliar domain.
05.8 · macOS threat layer maturing
Three concurrent macOS-focused clusters: AppleScript-based infostealer (36 IOCs), macOS-focused information stealer (11 IOCs), and Artlist ClickFix Campaign (18 IOCs including macOS variants). The concurrent activity is the signal — macOS has moved from occasional target to persistent one.
Defensive actions: Update user-awareness content for macOS users on the ClickFix technique. Block catalogued endpoints at DNS resolver. Deploy macOS endpoint content flagging AppleScript execution from unusual parents, and terminal execution of curl-piped-to-shell / bash-piped commands. Invest in macOS endpoint telemetry parity with Windows if you have not already.
05.9 · The TTF Trap — font-parsing exploit campaign
42 IOCs across all 4 IOC types. Drive-by compromise via malicious TrueType Font parsing. T1189 exploitation-for-client-execution is the initial-access technique — user visits a compromised or attacker-controlled page, browser/document viewer parses malicious font data, exploit triggers, second-stage pull follows.
Defensive actions: Block the 42 catalogued endpoints. Hunt for browser or document-viewer process crashes followed by unexpected process spawn within 30 seconds — the canonical drive-by kill-chain fingerprint.
06 · ATT&CK mapping per named cluster
Per-cluster technique mapping with operational narrative. Detection content that fires on these techniques catches the cluster even after IOC rotation.
| Cluster | ATT&CK techniques observed | Operational narrative |
|---|---|---|
| Polygon-Based C2 (novel) | T1102 · T1568 · T1071 · T1071.001 · T1027 · T1105 | 314 IOCs across DOMAIN + IP. Novel command-and-control pattern: the malware resolves C2 endpoints through the public Polygon blockchain rather than DNS. Same operational category as prior-week TONResolver — blockchain-resolved C2 is now a recurring pattern rather than a one-off. Traditional DNS-based blocking cannot break the resolution chain because resolution never touches conventional DNS. Detection must move to endpoint (process behaviour) and egress (any outbound to public blockchain RPC endpoints from non-engineering hosts). |
| APT-C-60 | T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1027 · T1105 · T1071.001 · T1041 | Regional APT cluster with the week’s broadest single-cluster IOC-type spread — 121 IOCs across all 5 primary types (DOMAIN + EMAIL + HASH + IP + URL). Subnet anchor at 213.111.158.0/24. Spearphishing attachment → user-execution → command interpreter → obfuscation → second-stage pull → web-protocol C2 → exfil. |
| UAT-11795 (APT) | T1583.001 · T1566 · T1071.001 · T1105 · T1041 | 52 IOCs across DOMAIN + HASH + IP + URL. Adversary-acquired domain infrastructure (e.g. aipythondevs[.]com, alphabitcapital[.]info) targeting developer and cryptocurrency-adjacent audiences. Standard APT tradecraft — phishing + web-protocol C2 + exfil. |
| APT-C-35 | T1583.001 · T1566 · T1105 · T1041 | 41 IOCs across DOMAIN + HASH + IP. Compact TTP profile — adversary-acquired infrastructure with phishing initial access, second-stage pull, exfil over C2. |
| APT-Q-27 | T1566 · T1105 · T1071 · T1041 | 15 IOCs across DOMAIN + HASH + IP. Chinese-tracked cluster with compact standard-APT profile. |
| RAWorld (Ransomware) | T1566.001 · T1190 · T1078 · T1133 · T1059.001 · T1105 · T1021.001 · T1021.002 · T1003.001 · T1486 · T1490 · T1489 · T1041 · T1567 · T1070.004 | 213 IOCs across HASH + IP + OTHERS. Full ransomware kill-chain plus operator-controlled leak-site publication (OTHERS category = victim-slug patterns). Double-extortion signature. |
| Trigona (Ransomware) | T1566.001 · T1078 · T1059.001 · T1055 · T1105 · T1021.001 · T1486 · T1489 · T1490 | 115 IOCs across EMAIL + HASH. Email indicators are operator ransom-negotiation contact channels. Classic ransomware kill chain with focus on domain-controller reachability for maximal impact. |
| Qilin (Ransomware) | T1190 · T1566.001 · T1078 · T1133 · T1110 · T1059.001 · T1105 · T1021.001 · T1486 · T1490 · T1489 · T1567 | 56 IOCs across HASH + OTHERS. Brute-force credential-access surface added compared to the standard ransomware chain — targeting exposed RDP / external services. |
| MedusaLocker / Medusa | T1566.001 · T1190 · T1078 · T1059.001 · T1105 · T1486 · T1490 · T1041 · T1567 | Two related ransomware brands active this cycle. Standard kill-chain with focus on inhibit-recovery and exfil-to-web-service for the double-extortion play. |
| PhantomEnigma | T1566.002 · T1204.001 · T1059 · T1105 · T1027 · T1071 · T1041 | 59 IOCs across all 4 primary IOC types. Regional targeting pattern — some indicators surface as victim-adjacent government-hosted domains (defanged). Watch for phishing lures impersonating regional government services. |
| ClickFix + variants | T1204.001 · T1204.002 · T1059.001 · T1059.003 · T1059.005 · T1059.007 · T1105 · T1566.002 · T1036 · T1140 | Broad ClickFix family across multiple sub-campaigns (Artlist ClickFix 18 IOCs, ClickFix-campaign 11 IOCs, ClickLock 13 IOCs). Fake-instruction lure tricks the visitor into pasting attacker-controlled command into command interpreter. Universal signature: unfamiliar domain visit → command interpreter launch within 30 seconds. |
| Malicious game-cheat package registry | T1195.001 · T1204.002 · T1059 · T1027 · T1041 | 39 IOCs across all 4 IOC types. Public package-registry compromise targeting gaming audiences. Install-time obfuscated payload + exfil over C2. |
| Malicious Go-module supply chain | T1195.001 · T1059 · T1027 · T1132 · T1041 | 36 IOCs across DOMAIN + EMAIL + HASH + URL. Public Go module compromise. Coordinated with the game-cheat campaign this week — two supply-chain campaigns concurrent. |
| AppleScript-based infostealer + macOS stealer | T1204 · T1059.004 · T1005 · T1555 · T1041 · T1071 | 36 + 11 = 47 IOCs combined. First-tier macOS threat surface. AppleScript execution + local data theft + password-store access + exfil over web-protocol C2. macOS environments have historically been under-instrumented — this week is a reminder to prioritise macOS endpoint telemetry parity with Windows. |
| The TTF Trap (font-exploit campaign) | T1189 · T1204.001 · T1059 · T1105 · T1027 | 42 IOCs across all 4 IOC types. Drive-by compromise via malicious TrueType Font parsing. Exploitation-for-client-execution + command-interpreter + second-stage pull + obfuscated payload. Watch for browser or document viewer crashes followed by unexpected process spawn. |
| TencShell C2 infrastructure | T1071.001 · T1105 · T1041 · T1571 | 22 IOCs with the largest subnet-anchor footprint this week — 4 concentrated subnet blocks holding 16 IPs. Web-protocol C2 with non-standard-port variants. Rotation-resilient because subnet concentration means new IPs likely fall in the same blocks. |
| Cloud-suite phishing operation | T1566.002 · T1078.004 · T1539 · T1621 · T1213 | 68 IOCs across DOMAIN + EMAIL + HASH + IP. Adversary-in-the-middle style phishing operation targeting cloud-suite identity providers. Session-cookie theft + MFA-fatigue tradecraft. The IOCs are Low severity because most are catalogue-ingest observations rather than confirmed post-compromise indicators — but the operational pattern is worth flagging. |
Detection-engineering takeaway. The universal ransomware pair (
T1486 → T1490) is present in every ransomware cluster this cycle. The universal APT chain (T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers all four Chinese-aligned clusters. Two well-designed detectors catch the entire APT and ransomware surface with minimal per-family tuning.
07 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Command and Control | T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 | Web-protocol C2, ingress tool transfer, web-service and blockchain-based C2 resolution, dynamic resolution, asymmetric crypto, proxy | 812 |
| Initial Access | T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195.001 | Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply-chain via package registry | 634 |
| Execution | T1059 · T1059.001 · T1059.003 · T1059.005 · T1059.007 · T1204 · T1189 | Command interpreter (PowerShell / CMD / VB / JS / AppleScript), user-execution, drive-by (font-exploit) | 587 |
| Impact | T1486 · T1489 · T1490 · T1567 | Encryption for impact, service stop, inhibit recovery, exfil to leak-site (ransomware chain — 20+ families this cycle) | 496 |
| Discovery | T1082 · T1057 · T1083 · T1087 · T1018 · T1135 · T1046 | System info + process + file + account + system network configuration + share discovery | 421 |
| Credential Access | T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1539 | OS credential dumping (LSASS), password store theft, session-cookie theft, brute force | 356 |
| Defense Evasion | T1027 · T1027.002 · T1036 · T1055 · T1070 · T1070.004 · T1140 · T1562 · T1112 | Obfuscation, packing, masquerading, process injection, indicator removal (log deletion), disable security tools | 429 |
| Lateral Movement | T1021 · T1021.001 · T1021.002 · T1570 · T1550 | RDP, SMB/admin shares, lateral tool transfer, use of alternate authentication material | 298 |
| Exfiltration | T1041 · T1567 | Exfil over C2 channel, exfil to operator-controlled web service | 512 |
| Persistence | T1547.001 · T1543.003 · T1053.005 · T1078 | Registry-run keys, Windows service creation, scheduled tasks, valid-account persistence | 267 |
| Collection | T1005 · T1119 · T1113 · T1056.001 · T1560 · T1560.001 | Local + automated data collection, screen capture, keylogging, archive collected | 219 |
| Resource Development | T1583.001 · T1584.001 | Adversary-acquired domains, compromised infrastructure | 178 |
08 · Subnet anchors — the shared-infrastructure signal
| Subnet (/24) | IPs | Adversary cluster | Operator observation |
|---|---|---|---|
| 134.122.200.0/24 | 6 | TencShell C2 infrastructure | The week’s largest single-cluster subnet anchor. TencShell operator concentration. |
| 192.163.167.0/24 | 4 | TencShell C2 infrastructure | Second TencShell anchor — hedged hosting tenants across the operator’s C2 stack |
| 92.38.177.0/24 | 4 | Lucide Proxy | DDoS proxy-botnet concentration |
| 45.64.52.0/24 | 3 | TencShell C2 infrastructure | Third TencShell anchor |
| 112.213.124.0/24 | 3 | TencShell C2 infrastructure | Fourth TencShell anchor — 16 IPs across 4 blocks |
| 213.111.158.0/24 | 3 | APT-C-60 | APT-C-60 infrastructure anchor |
| 45.156.87.0/24 | 3 | Sorry ransomware | Sorry ransomware operator anchor |
| 77.92.95.0/24 | 3 | Open exploitation framework | Framework listener farm |
The asymmetric block. TencShell C2 operates across four distinct subnet anchors with 16 concentrated IPs — unusually large single-cluster hosting concentration. Blocking all four /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across four different hosting tenants simultaneously to defeat the block.
08b · Predictive intelligence — forecast weaponisation
Retrospective indicators tell you what has happened; predictive indicators tell you what is about to. This week’s catalogue-driven forecast layer surfaces three infrastructure blocks with a high forward-looking probability of adversary weaponisation. The forecast is derived from a mix of signals: passive-DNS drift, registration-velocity clustering, hosting-tenant reputation drift, and pattern-match against previously-catalogued operator behaviours. Each forecast carries a days-to-weaponisation estimate. Push these into your perimeter watchlist now — not because they are compromised today, but because they are the highest-probability rotation candidates for adversary use over the next week.
| Infrastructure signal | Forecast window | Confidence | Signal profile |
|---|---|---|---|
| 149.X.167.X | 6 DAYS | MEDIUM | Broad-range hosting anchor with adjacent activity in prior weeks. Second-octet-fixed / fourth-octet-varying rotation candidate. |
| 194.46.X.X | 3 DAYS | HIGH | Imminent weaponisation forecast. Registration-velocity and passive-DNS drift patterns match multiple previously-catalogued operator anchors. /16 block treatment recommended. |
| 45.114.106.0/24 | 6 DAYS | HIGH | Discrete /24 CIDR anchor. Hosting-tenant reputation and passive-DNS drift indicate an operator staging block. Full /24 block-candidate. |
How the forecast is derived
The forward-looking signal combines four inputs. Passive-DNS drift — the rate at which the block’s resolutions are changing relative to its historical baseline. Registration-velocity clustering — comparison of adjacent-block domain-registration rates against operator-fingerprint baselines from previously-catalogued campaigns. Hosting-tenant reputation drift — whether the anchor block’s hosting tenant is trending toward or away from adversary-adjacent reputation classes. And pattern-match against catalogued operator behaviours — whether the block’s early observable signature (open ports, TLS fingerprints, self-signed cert patterns) resembles any known operator anchor from the last 90 days. When two or more inputs converge, the block enters the forecast layer with a days-to-weaponisation estimate.
Operational actions
- Perimeter watchlist — add all three anchors to a watchlist lane (not automatic block) that alerts on any outbound contact.
- Countdown-based escalation — the 3-day forecast (
194.46.X.X) warrants tighter monitoring than the 6-day forecasts. Consider provisional blocking of194.46.0.0/16at the perimeter if your environment has no legitimate business use in that range. - CIDR-level block — for the discrete
45.114.106.0/24anchor, a direct /24 block is the cheapest defensive control (256 addresses, no legitimate business use in most enterprises). - Retrospective hunt — run a 90-day historical lookback for any past contact with these anchor ranges. Any historical touch is a candidate compromise regardless of the forward-looking forecast.
What predictive intelligence actually gives you. The classical intelligence catalogue tells you what has been observed already; the predictive layer tells you what is about to be observed. In defensive terms, that shift buys the SOC a lead time it does not otherwise have — the difference between blocking an operator anchor after your first compromise vs. blocking it before the operator’s rotation reaches you. The forecast is probabilistic, not deterministic — treat the days-to-weaponisation estimates as watchlist priorities, not automated-blocking triggers.
09 · Top 15 IOCs per indicator type
All indicators defanged (re-fang on import: [.] → . and hxxp → http).
Top 15 · IP addresses (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 101.36.104.87 | GoSerpent | Malware | HIGH |
| 02 | 103.121.91.144 | Sorry (Ransomware) | Ransomware | HIGH |
| 03 | 103.131.95.37 | Sorry (Ransomware) | Ransomware | HIGH |
| 04 | 103.138.13.30 | GoSerpent | Malware | HIGH |
| 05 | 104.239.66.86 | The TTF Trap | Malware | HIGH |
| 06 | 104.243.32.213 | OkoBot | Botnet | HIGH |
| 07 | 104.243.43.16 | OkoBot | Botnet | HIGH |
| 08 | 104.248.233.104 | UAT-11795 (APT) | APT | HIGH |
| 09 | 107.174.133.119 | TuxBot v3 | Botnet | HIGH |
| 10 | 107.174.34.137 | The TTF Trap | Malware | HIGH |
| 11 | 109.122.217.21 | Sorry (Ransomware) | Ransomware | HIGH |
| 12 | 109.172.95.184 | Artlist ClickFix | Malware | HIGH |
| 13 | 112.213.124.132 | TencShell C2 | C&C Server | HIGH |
| 14 | 112.213.124.159 | TencShell C2 | C&C Server | HIGH |
| 15 | 112.213.124.163 | TencShell C2 | C&C Server | HIGH |
Top 15 · Domains (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 2baserec2[.]guru | OkoBot | Botnet | HIGH |
| 02 | ai-nexora[.]sbs | Polygon-Based C2 | C&C Server | HIGH |
| 03 | aipythondevs[.]com | UAT-11795 (APT) | APT | HIGH |
| 04 | all-imager-hst[.]click | Polygon-Based C2 | C&C Server | HIGH |
| 05 | alphabitcapital[.]info | UAT-11795 (APT) | APT | HIGH |
| 06 | altzserberin[.]info | APT-C-35 | APT | HIGH |
| 07 | anlytic-js-cloud[.]beer | Polygon-Based C2 | C&C Server | HIGH |
| 08 | apigrokcloud[.]icu | ACR Stealer | Malware | HIGH |
| 09 | aqpfkxxtvahlzr6vobt6fhj4riev7wxzoxwltbcysuybirygxzvp23ad[.]onion | Artlist ClickFix | Malware | HIGH |
| 10 | areal[.]rj[.]gov[.]br (defanged, victim-adjacent) | PhantomEnigma | Malware | HIGH |
| 11 | auramatrixa[.]com | ACR Stealer | Malware | HIGH |
| 12 | auth-code-check[.]info | Artlist ClickFix | Malware | HIGH |
| 13 | authorization-cdn-press-enter[.]info | Polygon-Based C2 | C&C Server | HIGH |
| 14 | 1308344827-4bya137jfj.ap-guangzhou.tencentscf[.]com | Commodity C2 framework A | Malware | HIGH |
| 15 | abcd.gamesen[.]icu | Commodity C2 framework A | Malware | HIGH |
Top 15 · File hashes (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 002e1207b96361fc4d53b10621225d61700003241fa38caacb411384b3d51135 | APT-C-60 | APT | HIGH |
| 02 | 00380c75734fd72885b315c53b4e9774 | Trigona | Ransomware | HIGH |
| 03 | 0067679c7033139bcbb273840494b324 | Medusa | Ransomware | HIGH |
| 04 | 011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972 | Malicious game-cheat pkg | Supply Chain | HIGH |
| 05 | 0120a6396952aec3f05ec0b0efe25e2a1b73545d55d74a3ac0bcd359d29f52bb | APT-C-60 | APT | HIGH |
| 06 | 012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe | MedusaLocker | Ransomware | HIGH |
| 07 | 014bd0c56fb2da2ff6eeeb240705462b | njRAT | RAT | HIGH |
| 08 | 0161027a354f9a1fc8e605261400fba9 | Trigona | Ransomware | HIGH |
| 09 | 0168a4daa9598e991e140057e59438f6 | Medusa | Ransomware | HIGH |
| 10 | 018d410685c743dedaad1dff81486dd7 | Trigona | Ransomware | HIGH |
| 11 | 01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27c | Malicious game-cheat pkg | Supply Chain | HIGH |
| 12 | 03110e7d05f64c49a35a3e60d049f2b0 | AgentTesla | RAT | HIGH |
| 13 | 03ab9195dcbd96fbe4e11917c50b57b6 | Trigona | Ransomware | HIGH |
| 14 | 03eaabaf750bcf69d58f79098432f8a3 | Trigona | Ransomware | HIGH |
| 15 | 041dca4a1d8c80f05c399dd750acf026ed5f94f1da08dc4f0f0d0ba9884916ff | WORLDLEAKS | Ransomware | HIGH |
Top 15 · URLs (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | hxxp[://]101.91.154.125:50001/cm | Commodity C2 framework A | Malware | HIGH |
| 02 | hxxp[://]106.15.62.124:2222/push | Commodity C2 framework A | Malware | HIGH |
| 03 | hxxp[://]118.195.183.6/activity | Commodity C2 framework A | Malware | HIGH |
| 04 | hxxp[://]118.31.115.178:4444/ga.js | Commodity C2 framework A | Malware | HIGH |
| 05 | hxxp[://]118.31.115.178:9999/ptj | Commodity C2 framework A | Malware | HIGH |
| 06 | hxxp[://]124.220.215.195:5555/pixel | Commodity C2 framework A | Malware | HIGH |
| 07 | hxxp[://]124.220.215.195:9999/ca | Commodity C2 framework A | Malware | HIGH |
| 08 | hxxp[://]124.223.12.165/ | Commodity C2 framework A | Framework | HIGH |
| 09 | hxxp[://]129.211.215.7/dot.gif | Commodity C2 framework A | Malware | HIGH |
| 10 | hxxp[://]154.3.0.70:83/cm | Commodity C2 framework A | Malware | HIGH |
| 11 | hxxp[://]178.16.54.109/ | Phorpiex | Botnet | HIGH |
| 12 | hxxp[://]185.141.216.194/cd.jpg | Spirals (Ransomware) | Ransomware | HIGH |
| 13 | hxxp[://]185.141.216.194/cd.zip | Spirals (Ransomware) | Ransomware | HIGH |
| 14 | hxxp[://]190.14.37.84/5555555.dat | Commodity C2 framework A | Malware | HIGH |
| 15 | hxxp[://]192.253.248.181/web/ledger.zip | macOS info-stealer | Malware | HIGH |
10 · Sigma detection rules
Sigma 01 · Blockchain-RPC outbound (Polygon C2 detector)
title: Outbound Traffic to Public Blockchain RPC — Blockchain-Resolved C2 Detector
id: 4c9e7b1d-5a82-4630-b791-6f8d3c1e5a20
status: experimental
description: Detects outbound connections from non-engineering hosts to public
blockchain RPC endpoints (Polygon, TON, Ethereum, and similar). Blockchain-
resolved C2 is now a recurring pattern (Polygon-Based C2 this week, TONResolver
a fortnight ago). Any outbound blockchain-RPC traffic from a non-engineering
host is candidate compromise.
references:
- https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
- attack.command_and_control
- attack.t1102
- attack.t1568
logsource:
category: proxy
detection:
selection:
cs-host|contains:
- 'polygon-rpc'
- 'polygonscan'
- '.polygon.io'
- 'maticvigil'
- 'infura.io'
- 'alchemy.com'
- 'ton-rpc'
- 'toncenter'
- 'tonapi'
exclusion:
src-ip|cidr: '10.engineering.0.0/16' # replace with your engineering subnet
condition: selection and not exclusion
falsepositives:
- Blockchain-adjacent engineering workloads (allowlist explicitly)
level: high
Sigma 02 · Universal ransomware kill-chain (VSS delete)
title: Universal Ransomware Kill-Chain — Volume Shadow Copy Deletion
id: 8e2c1a4f-6d93-4720-a581-3f9b5c2e8d10
status: experimental
description: Detects the universal ransomware pre-encrypt step — volume shadow
copy deletion. Every catalogued ransomware family this week (RAWorld, Trigona,
Qilin, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry, and 15+ more)
executes this step. A single detector catches the ransomware bucket.
references:
- https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
- attack.impact
- attack.t1490
- attack.t1486
logsource:
category: process_creation
product: windows
detection:
vssadmin_delete:
Image|endswith: '\vssadmin.exe'
CommandLine|contains|all: ['delete', 'shadows']
wmi_delete:
Image|endswith: '\wmic.exe'
CommandLine|contains|all: ['shadowcopy', 'delete']
powershell_delete:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- 'Remove-CimInstance'
- 'Win32_ShadowCopy'
condition: 1 of them
falsepositives:
- Legitimate backup operations (verify + allowlist known-good scripts)
level: critical
Sigma 03 · TencShell C2 subnet anchors
title: TencShell C2 Subnet Anchor Contact
id: 3b7f9d2c-1a84-4560-b731-5c9e6d4f2b40
status: experimental
description: Detects outbound connections to the TencShell C2 operator's four
concentrated subnet anchors. 16 IPs across 4 /24 blocks — the year's largest
single-cluster hosting concentration.
references:
- https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
- attack.command_and_control
- attack.t1071
logsource:
category: network_connection
detection:
selection:
DestinationIp|cidr:
- '134.122.200.0/24'
- '192.163.167.0/24'
- '45.64.52.0/24'
- '112.213.124.0/24'
condition: selection
falsepositives:
- Unlikely — none of these CIDRs has documented legitimate business use
level: critical
Sigma 04 · APT-C-60 multi-type cluster
title: APT-C-60 Multi-Type Cluster Detection
id: 5d1a8c3f-4b72-4820-a591-2e8c7d5b1a90
status: experimental
description: Detects contact with APT-C-60's catalogued anchor infrastructure OR
DNS queries matching the cluster's acquired-domain naming pattern. APT-C-60
had the broadest single-cluster IOC-type spread this week (5 IOC types).
references:
- https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
- attack.command_and_control
- attack.t1071.001
- attack.resource_development
- attack.t1583.001
logsource:
category: network_connection
detection:
subnet_anchor:
DestinationIp|cidr: '213.111.158.0/24'
known_domains:
QueryName:
- 'altzserberin.info'
# (add remaining catalogued APT-C-60 domains at deploy time)
condition: subnet_anchor or known_domains
falsepositives:
- Very rare — the subnet + domain pattern has no legitimate business use
level: critical
11 · Hunt queries — SIEM-agnostic pseudo-syntax
Hunt 01 · Blockchain-RPC outbound from non-engineering hosts
// Pseudo-query FROM proxy_logs WHERE dest_host MATCHES regex '(?i)(polygon-rpc|polygonscan|\.polygon\.io|maticvigil|infura|alchemy|toncenter|\.ton\.org)' AND src_host NOT IN (allowlisted_engineering_hosts) | AGGREGATE BY src_host, dest_host COUNT(*) AS req_count, MIN(request_time) AS first_seen | SORT BY first_seen DESC
Hunt 02 · TencShell C2 anchor first-seen contact
// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('134.122.200.0/24', '192.163.167.0/24', '45.64.52.0/24', '112.213.124.0/24')
AND first_seen_pair(src_ip, dest_ip) WITHIN 60d
| AGGREGATE BY src_ip, dest_ip
| SORT BY flow_count DESC
Hunt 03 · APT anchor first-seen (all 4 Chinese-aligned clusters)
// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('213.111.158.0/24') -- APT-C-60
OR dest_ip = '104.248.233.104' -- UAT-11795
AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC
Hunt 04 · Font-exploit drive-by kill-chain (TTF Trap)
// Pseudo-query
FROM process_crash_events
WHERE process_name IN ('chrome.exe', 'firefox.exe', 'edge.exe', 'AcroRd32.exe', 'winword.exe')
AND crash_module MATCHES regex '(?i)(font|ttf|otf)'
| JOIN process_creates AS pc
ON process_crash_events.host = pc.host
AND pc.create_time BETWEEN process_crash_events.event_time
AND process_crash_events.event_time + 30s
AND pc.process_name NOT IN (allowlisted_children)
| PROJECT host, process_crash_events.process_name, pc.command_line
| SORT BY event_time DESC
12 · Operationalise in 60 minutes
Minute 00 – 15 · Block + sinkhole
- Block all four TencShell subnet anchors: 134.122.200.0/24, 192.163.167.0/24, 45.64.52.0/24, 112.213.124.0/24.
- Block 213.111.158.0/24 (APT-C-60 anchor).
- Block 92.38.177.0/24 (Lucide Proxy DDoS botnet).
- Block 45.156.87.0/24 (Sorry ransomware).
- Deploy outbound-deny for public blockchain RPC endpoints (Polygon + TON) from non-engineering hosts.
Minute 15 – 30 · Detection content
- Deploy Sigma 01 (blockchain-RPC detector) — catches Polygon-Based C2 + TONResolver family without knowing the C2 IPs.
- Deploy Sigma 02 (universal VSS-delete detector) — catches every ransomware family this week.
- Deploy Sigma 03 (TencShell subnet anchors).
- Deploy Sigma 04 (APT-C-60 multi-type).
Minute 30 – 45 · Retrospective hunt
- Run Hunt 01 (blockchain-RPC outbound) baseline scan.
- Run Hunt 02 (TencShell anchor first-seen) across last 60 days.
- Run Hunt 03 (APT anchor first-seen) across last 90 days.
- Run Hunt 04 (font-exploit drive-by) across last 30 days.
Minute 45 – 60 · Awareness + policy
- Brief developers on the package-registry supply-chain double strike; package allow-listing is not optional.
- Brief cryptocurrency-adjacent users on the UAT-11795 domain targeting pattern.
- Update macOS user-awareness content on ClickFix.
- Audit outbound egress policy for blockchain-RPC traffic. Deny by default from non-engineering hosts.
This briefing ships 15 indicators per type. The catalogue carries the full 59,935 unique IOCs from this week — adversary attribution, ATT&CK technique, confidence score, source provenance included.
13 · Frequently asked questions
Blockchain-resolved C2 is now recurring. What is the strategic implication?
Blockchain-resolved C2 is likely to become a mainstream C2 pattern within 12-18 months. The technique is takedown-resistant by design and imposes low operator cost. Defenders should invest now in endpoint behavioural detection (process instrumentation on blockchain-RPC library calls) and outbound egress policy (explicit deny of blockchain-RPC traffic from non-engineering hosts). The domain / IP catalogue-based defensive stack that has worked for two decades will not work against blockchain-resolved C2 without adaptation.
Four Chinese-aligned APTs in one week — is that unusual?
Concurrent activity from four named Chinese-aligned clusters is above the year-to-date baseline (typical week: 1-2 clusters active). What makes it noteworthy is not the individual clusters but the concurrency — suggests either a shared operational trigger or a broader regional operational tempo increase. Organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week.
How do I prioritise the 20+ ransomware families active this cycle?
Do not prioritise them individually. Deploy Sigma 02 (universal volume-shadow-copy deletion detector). It fires on every ransomware family this week regardless of variant. Then, on top of that universal detector, add the operator-specific email indicators (Trigona, MedusaLocker, Medusa) as SMTP-gateway blocklist + retrospective mailbox-audit hunt targets — those catch operator ransom-negotiation communication attempts.
Why is TencShell C2 significant?
16 IPs concentrated across 4 subnet /24 anchors is the largest single-cluster hosting concentration observed this year. Rotation resilience is very low from the defender’s perspective — new IPs are extremely likely to fall in the same blocks. Subnet-level blocking gives the defender an asymmetric advantage. The four-anchor block costs the defender nothing to deploy; costs the operator a full C2-infrastructure rebuild across four different hosting tenants to defeat.
The macOS threat layer is maturing. What should I invest in this quarter?
Two priorities. First: telemetry parity — if your macOS estate has less endpoint-process-create logging than your Windows estate, that gap is now operationally material. Second: user-awareness — macOS-specific phishing lures (ClickFix on macOS, fake-install prompts, drive-by via Safari) are qualitatively different from Windows lures and need distinct awareness content.
What confidence threshold should the SOC use for automated blocking?
High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.
Where can I see this briefing’s intelligence operationally?
The HuntIntel operator console exposes every IOC with adversary attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.
Previous week (Jul 6-12) ·
Two weeks back (Jun 29 – Jul 5) ·
Practitioner Reference (IOC + TI) ·
Cloud Threat Hunting Library ·
15-Month Threat Hunter Roadmap ·
Threat Intelligence archive










