HackForLab Weekly Threat Advisory · Jul 13-19 2026 · Weekly Intelligence Briefing · executive research report cover v4 · deep slate + electric blue + warm copper + ivory palette · 59,935 indicators · 116 clusters · 4 APT names · 20+ ransomware families · TOP INTELLIGENCE SIGNALS bar chart · PREDICTIVE INTELLIGENCE callout with 149.X.167.X (6 days), 194.46.X.X (3 days imminent), 45.X.X.0/24 (6 days) forecast weaponisation

Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)

● CTI SITREP 026·29 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-029 · July 13 – 19, 2026

Intelligence week. 59,935 unique IOCs across 116 adversary clusters. A novel command-and-control resolution pattern surfaced — Polygon-Based C2, 314 IOCs, resolving operator infrastructure through the Polygon blockchain rather than DNS. Blockchain-resolved C2 is now a recurring pattern rather than a one-off. Four Chinese-aligned APT clusters ran in parallel: APT-C-60 (121 IOCs, full 5-type spread), UAT-11795 (52 IOCs), APT-C-35 (41 IOCs), APT-Q-27 (15 IOCs). Twenty-plus named ransomware families generated fresh indicators. The TencShell C2 operator concentrated 16 IPs across four subnet blocks — the largest single-cluster subnet footprint of the year. If your CTI team was quiet this week, this briefing has your reading list.

Sectioned for the working analyst: cluster catalogue, deep-dives on the high-tempo names, ATT&CK technique mapping per adversary, subnet + port anchors, top 15 IOCs per indicator type, four production-ready Sigma rules, 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and adversary cluster pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

The catalogue produced 59,935 unique IOCs across 116 adversary clusters this cycle — a wide-tempo week. Framework-infrastructure entries dominate the topline volume (as usual), but the narrow-indicator layer (domain / hash / URL / email) contributed 3,382 unique records — approximately double the year-to-date baseline. Every major operator category is elevated: APT +4 named clusters, ransomware 20+ families concurrent, supply-chain double strike, macOS threats surging, and a novel blockchain-resolved C2 pattern surfacing at scale for the second time in a month.

// CTI SITREP 026·29 · July 13 – 19, 2026 · TA-2026-029
496,767
Records
59,935
Unique IOCs
6,687
High-severity
116
Clusters
4
Named APTs
20+
Ransomware families

Catalogued, ML-scored, ATT&CK-tagged. Every record carries adversary attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · Polygon-Based C2 — novel blockchain-resolved command channel

314 IOCs across DOMAIN + IP. Second observation this month of a malware family that resolves its command-and-control endpoints through a public blockchain rather than conventional DNS. Same operational category as the prior TONResolver cluster observed a fortnight ago. The operator publishes the current C2 address as an on-chain record; the implant queries the chain to retrieve the address; every rotation is a new on-chain transaction. Result: takedown-resistant infrastructure by design. DNS-based blocking cannot break the resolution chain because resolution never touches DNS. Detection has to move to the endpoint layer (process behavioural detection on the blockchain-RPC library calls) and the network layer (any outbound connection to public blockchain RPC endpoints from a non-engineering host).

Headline 02 · APT week — 4 Chinese-aligned clusters active in parallel

Four named Chinese-aligned APT clusters produced fresh indicators this cycle: APT-C-60 (121 IOCs across all 5 primary IOC types — the broadest single-cluster IOC-type spread of the week; subnet anchor at 213.111.158.0/24), UAT-11795 (52 IOCs with developer-and-cryptocurrency-targeting domain infrastructure), APT-C-35 (41 IOCs), and APT-Q-27 (15 IOCs). Combined APT-category footprint: 316 IOCs. Concurrent activity from four named clusters is a load-bearing signal about regional operational tempo.

Headline 03 · Ransomware surge — 20+ families concurrent, RAWorld + Trigona lead

The ransomware-as-a-service category produced 632 IOCs across 20+ named families this cycle. RAWorld led at 213 IOCs (with active leak-site publication observable in the OTHERS category). Trigona followed at 115. Qilin at 56. MedusaLocker at 26. Medusa at 25. Fog at 24. WORLDLEAKS at 15. Spirals at 12. Sorry at 17. Plus a dozen more with 5+ indicators each. Universal ATT&CK signature: the encrypt-plus-inhibit-recovery pair (T1486 → T1490) is present in every family. A single detector fired against volume-shadow-copy deletion catches all of them.

Headline 04 · Package-registry supply-chain double strike

Two concurrent supply-chain campaigns hit public package registries. The malicious game-cheat package campaign (39 IOCs) targeted a public package registry with typosquat packages advertising game-cheat functionality. The malicious Go module campaign (36 IOCs) hit a public Go module registry with similar typosquat-and-payload tradecraft. The coordination across two registries in the same cycle suggests either shared upstream tooling or an operator maturing their supply-chain capability across multiple ecosystems. CI build agents that pull from unrestricted registries are the exposed surface.

Headline 05 · macOS threat layer maturing

Three separate macOS-focused observations in a single cycle: AppleScript-based infostealer (36 IOCs across DOMAIN + HASH + URL), macOS-focused information stealer (11 IOCs across HASH + IP + URL), and Artlist ClickFix Campaign (18 IOCs including a macOS-specific variant). The pattern — multiple concurrent macOS-focused clusters — is new. Historically macOS has been an occasional target; this cycle it is a persistent one. macOS environments are typically under-instrumented for terminal-execution telemetry compared with Windows — this week is a strong prompt to invest in macOS endpoint telemetry parity.


03 · Indicator type, severity, and category mix

The IP indicator layer dominates the topline (94 percent) because the framework-infrastructure feed is running heavy this cycle. The intelligence density sits in the narrow layers: 1,585 unique domains, 1,333 unique hashes, 361 URLs, 103 emails, 61 OTHERS. The C&C category leads the category mix by a wide margin (89 percent) reflecting framework-infrastructure feed output. Ransomware-as-a-Service sits at 632 IOCs (1.1 percent share of records but the most operationally-actionable category).

By indicator type

Type Observations Share %
IPs 56,486
94.25%
Domains 1,585
2.64%
File hashes 1,333
2.22%
URLs 361
0.60%
Emails 103
0.17%
Other artefacts 61
0.10%
Process names 6
0.01%

By severity

Severity Observations Share %
High 6,687
10.70%
Medium 55,696
89.10%
Low 127
0.20%

By category

Category Observations Share %
C&C 53,138
80.54%
C&C Server 6,162
9.34%
Botnet 4,943
7.49%
Ransomware-as-a-service 632
0.96%
Malware-Activity 525
0.80%
APT 316
0.48%
Phishing 112
0.17%
Supply Chain 44
0.07%
RAT 30
0.05%
Framework 27
0.04%
Hacktivist Group 14
0.02%
Intrusion Campaign 13
0.02%
Spyware 10
0.02%
Vulnerability 8
0.01%

04 · Top adversary clusters

38 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. Polygon-Based C2 (314 IOCs) and APT-C-60 (121 IOCs full 5-type) are the standouts.

# Adversary cluster Relative footprint Unique IOCs Severity
01 Commodity C2 framework A (open-framework infrastructure)

C2 · DOMAIN, EMAIL, HASH, IP, URL
57,809 MEDIUM
02 Polygon-Based C2 (novel blockchain-resolved)

Malware · DOMAIN, IP
314 HIGH
03 RAWorld

Ransomware · HASH, IP, OTHERS
213 HIGH
04 Commodity C2 framework A (malware-tier)

Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
153 HIGH
05 APT-C-60

Threat Actor (APT) · DOMAIN, EMAIL, HASH, IP, URL
121 HIGH
06 Trigona

Ransomware · EMAIL, HASH
115 HIGH
07 Cloud-suite phishing operation

Phishing Campaign · DOMAIN, EMAIL, HASH, IP
68 LOW
08 PhantomEnigma

Malware Campaign · DOMAIN, HASH, IP, URL
59 HIGH
09 Qilin

Ransomware · HASH, OTHERS
56 HIGH
10 UAT-11795

Threat Actor (APT) · DOMAIN, HASH, IP, URL
52 HIGH
11 Open remote-management framework

C2 · IP
51 MEDIUM
12 The TTF Trap (font-exploit campaign)

Malware Campaign · DOMAIN, HASH, IP, URL
42 HIGH
13 APT-C-35

Threat Actor (APT) · DOMAIN, HASH, IP
41 HIGH
14 Malicious game-cheat package-registry campaign

Malware Campaign · DOMAIN, HASH, IP, URL
39 HIGH
15 AppleScript-based infostealer

Malware · DOMAIN, HASH, URL
36 HIGH
16 Malicious Go-module supply-chain campaign

Malware Campaign · DOMAIN, EMAIL, HASH, URL
36 HIGH
17 Fake-offers phishing campaign

Phishing Campaign · DOMAIN, URL
34 LOW
18 CrashStealer

Malware · DOMAIN, HASH, IP, URL
33 HIGH
19 TuxBot v3

Malware (Botnet) · DOMAIN, HASH, IP
32 HIGH
20 TelePuz

Malware · DOMAIN, HASH, IP
31 HIGH
21 Open exploitation framework

C2 · IP
29 MEDIUM
22 MedusaLocker

Ransomware · EMAIL, HASH, OTHERS
26 HIGH
23 OkoBot

Malware (Botnet) · DOMAIN, HASH, IP
25 HIGH
24 Medusa

Ransomware · EMAIL, HASH, OTHERS
25 HIGH
25 Fog

Ransomware · HASH
24 HIGH
26 Lucide Proxy

DDoS · HASH, IP, URL
23 MEDIUM
27 GoSerpent

Malware · HASH, IP
22 HIGH
28 TencShell C2 infrastructure

Malware Campaign · HASH, IP
22 HIGH
29 Artlist ClickFix Campaign

Malware Campaign · DOMAIN, HASH, IP
18 HIGH
30 Sorry

Ransomware · HASH, IP
17 HIGH
31 ACR Stealer

Malware · DOMAIN
16 HIGH
32 OTTERCOOKIE

Malware · DOMAIN, HASH, IP
16 HIGH
33 Kratos

Phishing Kit · DOMAIN, IP
16 MEDIUM
34 APT-Q-27

Threat Actor (APT) · DOMAIN, HASH, IP
15 HIGH
35 WORLDLEAKS

Ransomware · HASH
15 HIGH
36 ClickLock

Malware · DOMAIN, HASH, URL
13 HIGH
37 Spirals

Ransomware · HASH, IP, URL
12 HIGH
38 macOS-focused information stealer

Malware · HASH, IP, URL
11 HIGH

05 · Cluster deep-dives — the names to act on

05.1 · Polygon-Based C2 — blockchain-resolved command channel

314 IOCs across DOMAIN + IP. The malware family resolves its C2 endpoints through the Polygon public blockchain rather than DNS. Operator publishes the current C2 address as an on-chain smart-contract record; implant queries the blockchain to retrieve the address; every rotation is a new on-chain transaction (cheap for the operator, instant for the implant). The pattern is takedown-resistant by design because there is no domain registrar to notify and no DNS record to takedown.

Defensive actions: Push the 314 catalogued indicators to blocking. But recognise the strategic limit — the operator’s next rotation will not surface in DNS-based catalogues. Detection must move to (a) endpoint behavioural detection on the process’s blockchain-RPC library calls, or (b) network detection of any outbound connection to public Polygon RPC endpoints from a non-engineering host. Audit your outbound egress policy to explicitly deny blockchain-RPC traffic unless business use is documented.

05.2 · APT-C-60 — broadest 5-type IOC spread

121 IOCs across all 5 primary IOC types (DOMAIN + EMAIL + HASH + IP + URL) with a subnet anchor at 213.111.158.0/24. The 5-type spread is the broadest single-cluster IOC-type spread this week — indicating a full-ecosystem intrusion, not a single-lure campaign. Standard regional-APT tradecraft: adversary-acquired domains, spearphishing attachments, user-execution, command-interpreter, obfuscated payload, second-stage pull, web-protocol C2, exfil.

Defensive actions: All 121 catalogued indicators to blocking / watchlist by tier. Block the 213.111.158.0/24 subnet anchor. Hunt for outbound to the anchor across the last 90 days.

05.3 · UAT-11795 — developer-and-cryptocurrency-targeting

52 IOCs across DOMAIN + HASH + IP + URL. Adversary-acquired domain infrastructure with distinctive targeting: aipythondevs[.]com targets Python developers; alphabitcapital[.]info targets cryptocurrency-adjacent audiences. Combines two high-value victim populations in a single cluster. Standard APT tradecraft otherwise.

Defensive actions: Block the 52 catalogued indicators. Brief developer and cryptocurrency-using populations on the domain-adjacent targeting pattern.

05.4 · RAWorld ransomware — 213 IOCs with active leak-site publication

Largest ransomware footprint of the week. HASH + IP + OTHERS. The OTHERS category contains victim-slug patterns published on the operator’s data-leak site — watch this indicator class for early warning that your organisation appears on the site.

Defensive actions: Hash-block the catalogued binaries at endpoint scan. Push IPs to perimeter blocklist. Subscribe to leak-site infrastructure monitoring if your organisation is exposed to double-extortion operators.

05.5 · Trigona — 115 IOCs with operator ransom-negotiation email surface

EMAIL + HASH. The email indicators are ransom-negotiation contact channels the operator uses post-encryption. Detection value: if any email in your environment sent or received communication with a Trigona negotiation address, that is a strong signal of an in-progress or historical intrusion.

Defensive actions: Deploy the catalogued email indicators as SMTP-gateway blocklist AND as a retrospective hunt against the last 90 days of mailbox audit logs.

05.6 · TencShell C2 infrastructure — 4 subnet anchors, 16 IPs

22 IOCs across HASH + IP with the most concentrated subnet footprint of the week: 4 /24 blocks (134.122.200.0/24 with 6 IPs, 192.163.167.0/24 with 4 IPs, 45.64.52.0/24 with 3 IPs, 112.213.124.0/24 with 3 IPs). 16 IPs across 4 anchor blocks is the largest single-cluster hosting concentration observed this year. Rotation resilience is low from the defender’s perspective — new IPs are highly likely to fall in the same blocks.

Defensive actions: Block all four /24 anchors at the perimeter now. Cost: zero. Operational risk: bounded (~1,024 addresses across 4 blocks). Amortised leverage: every rotation inside any block hits the same wall.

05.7 · Malicious package-registry double strike (game-cheat + Go module)

Two concurrent supply-chain campaigns. Game-cheat campaign: 39 IOCs across all 4 IOC types. Typosquat packages advertising game-cheat functionality delivered obfuscated payloads at install time. Go module campaign: 36 IOCs across DOMAIN + EMAIL + HASH + URL. Compromised Go modules with post-install command execution. Together they suggest an operator maturing their supply-chain capability across multiple language ecosystems.

Defensive actions: Package allow-listing in CI build agents. Outbound-domain monitoring from build runners. Publisher-identity verification. Hunt for install-time process trees where a package installer spawns a shell that pulls from an unfamiliar domain.

05.8 · macOS threat layer maturing

Three concurrent macOS-focused clusters: AppleScript-based infostealer (36 IOCs), macOS-focused information stealer (11 IOCs), and Artlist ClickFix Campaign (18 IOCs including macOS variants). The concurrent activity is the signal — macOS has moved from occasional target to persistent one.

Defensive actions: Update user-awareness content for macOS users on the ClickFix technique. Block catalogued endpoints at DNS resolver. Deploy macOS endpoint content flagging AppleScript execution from unusual parents, and terminal execution of curl-piped-to-shell / bash-piped commands. Invest in macOS endpoint telemetry parity with Windows if you have not already.

05.9 · The TTF Trap — font-parsing exploit campaign

42 IOCs across all 4 IOC types. Drive-by compromise via malicious TrueType Font parsing. T1189 exploitation-for-client-execution is the initial-access technique — user visits a compromised or attacker-controlled page, browser/document viewer parses malicious font data, exploit triggers, second-stage pull follows.

Defensive actions: Block the 42 catalogued endpoints. Hunt for browser or document-viewer process crashes followed by unexpected process spawn within 30 seconds — the canonical drive-by kill-chain fingerprint.

06 · ATT&CK mapping per named cluster

Per-cluster technique mapping with operational narrative. Detection content that fires on these techniques catches the cluster even after IOC rotation.

Cluster ATT&CK techniques observed Operational narrative
Polygon-Based C2 (novel) T1102 · T1568 · T1071 · T1071.001 · T1027 · T1105 314 IOCs across DOMAIN + IP. Novel command-and-control pattern: the malware resolves C2 endpoints through the public Polygon blockchain rather than DNS. Same operational category as prior-week TONResolver — blockchain-resolved C2 is now a recurring pattern rather than a one-off. Traditional DNS-based blocking cannot break the resolution chain because resolution never touches conventional DNS. Detection must move to endpoint (process behaviour) and egress (any outbound to public blockchain RPC endpoints from non-engineering hosts).
APT-C-60 T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1027 · T1105 · T1071.001 · T1041 Regional APT cluster with the week’s broadest single-cluster IOC-type spread — 121 IOCs across all 5 primary types (DOMAIN + EMAIL + HASH + IP + URL). Subnet anchor at 213.111.158.0/24. Spearphishing attachment → user-execution → command interpreter → obfuscation → second-stage pull → web-protocol C2 → exfil.
UAT-11795 (APT) T1583.001 · T1566 · T1071.001 · T1105 · T1041 52 IOCs across DOMAIN + HASH + IP + URL. Adversary-acquired domain infrastructure (e.g. aipythondevs[.]com, alphabitcapital[.]info) targeting developer and cryptocurrency-adjacent audiences. Standard APT tradecraft — phishing + web-protocol C2 + exfil.
APT-C-35 T1583.001 · T1566 · T1105 · T1041 41 IOCs across DOMAIN + HASH + IP. Compact TTP profile — adversary-acquired infrastructure with phishing initial access, second-stage pull, exfil over C2.
APT-Q-27 T1566 · T1105 · T1071 · T1041 15 IOCs across DOMAIN + HASH + IP. Chinese-tracked cluster with compact standard-APT profile.
RAWorld (Ransomware) T1566.001 · T1190 · T1078 · T1133 · T1059.001 · T1105 · T1021.001 · T1021.002 · T1003.001 · T1486 · T1490 · T1489 · T1041 · T1567 · T1070.004 213 IOCs across HASH + IP + OTHERS. Full ransomware kill-chain plus operator-controlled leak-site publication (OTHERS category = victim-slug patterns). Double-extortion signature.
Trigona (Ransomware) T1566.001 · T1078 · T1059.001 · T1055 · T1105 · T1021.001 · T1486 · T1489 · T1490 115 IOCs across EMAIL + HASH. Email indicators are operator ransom-negotiation contact channels. Classic ransomware kill chain with focus on domain-controller reachability for maximal impact.
Qilin (Ransomware) T1190 · T1566.001 · T1078 · T1133 · T1110 · T1059.001 · T1105 · T1021.001 · T1486 · T1490 · T1489 · T1567 56 IOCs across HASH + OTHERS. Brute-force credential-access surface added compared to the standard ransomware chain — targeting exposed RDP / external services.
MedusaLocker / Medusa T1566.001 · T1190 · T1078 · T1059.001 · T1105 · T1486 · T1490 · T1041 · T1567 Two related ransomware brands active this cycle. Standard kill-chain with focus on inhibit-recovery and exfil-to-web-service for the double-extortion play.
PhantomEnigma T1566.002 · T1204.001 · T1059 · T1105 · T1027 · T1071 · T1041 59 IOCs across all 4 primary IOC types. Regional targeting pattern — some indicators surface as victim-adjacent government-hosted domains (defanged). Watch for phishing lures impersonating regional government services.
ClickFix + variants T1204.001 · T1204.002 · T1059.001 · T1059.003 · T1059.005 · T1059.007 · T1105 · T1566.002 · T1036 · T1140 Broad ClickFix family across multiple sub-campaigns (Artlist ClickFix 18 IOCs, ClickFix-campaign 11 IOCs, ClickLock 13 IOCs). Fake-instruction lure tricks the visitor into pasting attacker-controlled command into command interpreter. Universal signature: unfamiliar domain visit → command interpreter launch within 30 seconds.
Malicious game-cheat package registry T1195.001 · T1204.002 · T1059 · T1027 · T1041 39 IOCs across all 4 IOC types. Public package-registry compromise targeting gaming audiences. Install-time obfuscated payload + exfil over C2.
Malicious Go-module supply chain T1195.001 · T1059 · T1027 · T1132 · T1041 36 IOCs across DOMAIN + EMAIL + HASH + URL. Public Go module compromise. Coordinated with the game-cheat campaign this week — two supply-chain campaigns concurrent.
AppleScript-based infostealer + macOS stealer T1204 · T1059.004 · T1005 · T1555 · T1041 · T1071 36 + 11 = 47 IOCs combined. First-tier macOS threat surface. AppleScript execution + local data theft + password-store access + exfil over web-protocol C2. macOS environments have historically been under-instrumented — this week is a reminder to prioritise macOS endpoint telemetry parity with Windows.
The TTF Trap (font-exploit campaign) T1189 · T1204.001 · T1059 · T1105 · T1027 42 IOCs across all 4 IOC types. Drive-by compromise via malicious TrueType Font parsing. Exploitation-for-client-execution + command-interpreter + second-stage pull + obfuscated payload. Watch for browser or document viewer crashes followed by unexpected process spawn.
TencShell C2 infrastructure T1071.001 · T1105 · T1041 · T1571 22 IOCs with the largest subnet-anchor footprint this week — 4 concentrated subnet blocks holding 16 IPs. Web-protocol C2 with non-standard-port variants. Rotation-resilient because subnet concentration means new IPs likely fall in the same blocks.
Cloud-suite phishing operation T1566.002 · T1078.004 · T1539 · T1621 · T1213 68 IOCs across DOMAIN + EMAIL + HASH + IP. Adversary-in-the-middle style phishing operation targeting cloud-suite identity providers. Session-cookie theft + MFA-fatigue tradecraft. The IOCs are Low severity because most are catalogue-ingest observations rather than confirmed post-compromise indicators — but the operational pattern is worth flagging.

Detection-engineering takeaway. The universal ransomware pair (T1486 → T1490) is present in every ransomware cluster this cycle. The universal APT chain (T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers all four Chinese-aligned clusters. Two well-designed detectors catch the entire APT and ransomware surface with minimal per-family tuning.

07 · ATT&CK tactic-pressure roll-up

Tactic Top techniques observed What the pressure means IOC count
Command and Control T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 Web-protocol C2, ingress tool transfer, web-service and blockchain-based C2 resolution, dynamic resolution, asymmetric crypto, proxy 812
Initial Access T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195.001 Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply-chain via package registry 634
Execution T1059 · T1059.001 · T1059.003 · T1059.005 · T1059.007 · T1204 · T1189 Command interpreter (PowerShell / CMD / VB / JS / AppleScript), user-execution, drive-by (font-exploit) 587
Impact T1486 · T1489 · T1490 · T1567 Encryption for impact, service stop, inhibit recovery, exfil to leak-site (ransomware chain — 20+ families this cycle) 496
Discovery T1082 · T1057 · T1083 · T1087 · T1018 · T1135 · T1046 System info + process + file + account + system network configuration + share discovery 421
Credential Access T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1539 OS credential dumping (LSASS), password store theft, session-cookie theft, brute force 356
Defense Evasion T1027 · T1027.002 · T1036 · T1055 · T1070 · T1070.004 · T1140 · T1562 · T1112 Obfuscation, packing, masquerading, process injection, indicator removal (log deletion), disable security tools 429
Lateral Movement T1021 · T1021.001 · T1021.002 · T1570 · T1550 RDP, SMB/admin shares, lateral tool transfer, use of alternate authentication material 298
Exfiltration T1041 · T1567 Exfil over C2 channel, exfil to operator-controlled web service 512
Persistence T1547.001 · T1543.003 · T1053.005 · T1078 Registry-run keys, Windows service creation, scheduled tasks, valid-account persistence 267
Collection T1005 · T1119 · T1113 · T1056.001 · T1560 · T1560.001 Local + automated data collection, screen capture, keylogging, archive collected 219
Resource Development T1583.001 · T1584.001 Adversary-acquired domains, compromised infrastructure 178

08 · Subnet anchors — the shared-infrastructure signal

Subnet (/24) IPs Adversary cluster Operator observation
134.122.200.0/24 6 TencShell C2 infrastructure The week’s largest single-cluster subnet anchor. TencShell operator concentration.
192.163.167.0/24 4 TencShell C2 infrastructure Second TencShell anchor — hedged hosting tenants across the operator’s C2 stack
92.38.177.0/24 4 Lucide Proxy DDoS proxy-botnet concentration
45.64.52.0/24 3 TencShell C2 infrastructure Third TencShell anchor
112.213.124.0/24 3 TencShell C2 infrastructure Fourth TencShell anchor — 16 IPs across 4 blocks
213.111.158.0/24 3 APT-C-60 APT-C-60 infrastructure anchor
45.156.87.0/24 3 Sorry ransomware Sorry ransomware operator anchor
77.92.95.0/24 3 Open exploitation framework Framework listener farm

The asymmetric block. TencShell C2 operates across four distinct subnet anchors with 16 concentrated IPs — unusually large single-cluster hosting concentration. Blocking all four /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across four different hosting tenants simultaneously to defeat the block.

08b · Predictive intelligence — forecast weaponisation

Retrospective indicators tell you what has happened; predictive indicators tell you what is about to. This week’s catalogue-driven forecast layer surfaces three infrastructure blocks with a high forward-looking probability of adversary weaponisation. The forecast is derived from a mix of signals: passive-DNS drift, registration-velocity clustering, hosting-tenant reputation drift, and pattern-match against previously-catalogued operator behaviours. Each forecast carries a days-to-weaponisation estimate. Push these into your perimeter watchlist now — not because they are compromised today, but because they are the highest-probability rotation candidates for adversary use over the next week.

// PREDICTIVE INTELLIGENCE · FORECAST WEAPONISATION
Infrastructure signal Forecast window Confidence Signal profile
149.X.167.X 6 DAYS MEDIUM Broad-range hosting anchor with adjacent activity in prior weeks. Second-octet-fixed / fourth-octet-varying rotation candidate.
194.46.X.X 3 DAYS HIGH Imminent weaponisation forecast. Registration-velocity and passive-DNS drift patterns match multiple previously-catalogued operator anchors. /16 block treatment recommended.
45.114.106.0/24 6 DAYS HIGH Discrete /24 CIDR anchor. Hosting-tenant reputation and passive-DNS drift indicate an operator staging block. Full /24 block-candidate.

How the forecast is derived

The forward-looking signal combines four inputs. Passive-DNS drift — the rate at which the block’s resolutions are changing relative to its historical baseline. Registration-velocity clustering — comparison of adjacent-block domain-registration rates against operator-fingerprint baselines from previously-catalogued campaigns. Hosting-tenant reputation drift — whether the anchor block’s hosting tenant is trending toward or away from adversary-adjacent reputation classes. And pattern-match against catalogued operator behaviours — whether the block’s early observable signature (open ports, TLS fingerprints, self-signed cert patterns) resembles any known operator anchor from the last 90 days. When two or more inputs converge, the block enters the forecast layer with a days-to-weaponisation estimate.

Operational actions

  • Perimeter watchlist — add all three anchors to a watchlist lane (not automatic block) that alerts on any outbound contact.
  • Countdown-based escalation — the 3-day forecast (194.46.X.X) warrants tighter monitoring than the 6-day forecasts. Consider provisional blocking of 194.46.0.0/16 at the perimeter if your environment has no legitimate business use in that range.
  • CIDR-level block — for the discrete 45.114.106.0/24 anchor, a direct /24 block is the cheapest defensive control (256 addresses, no legitimate business use in most enterprises).
  • Retrospective hunt — run a 90-day historical lookback for any past contact with these anchor ranges. Any historical touch is a candidate compromise regardless of the forward-looking forecast.

What predictive intelligence actually gives you. The classical intelligence catalogue tells you what has been observed already; the predictive layer tells you what is about to be observed. In defensive terms, that shift buys the SOC a lead time it does not otherwise have — the difference between blocking an operator anchor after your first compromise vs. blocking it before the operator’s rotation reaches you. The forecast is probabilistic, not deterministic — treat the days-to-weaponisation estimates as watchlist priorities, not automated-blocking triggers.

09 · Top 15 IOCs per indicator type

All indicators defanged (re-fang on import: [.]. and hxxphttp).

Top 15 · IP addresses (High severity)

# Indicator Adversary Category Severity
01 101.36.104.87 GoSerpent Malware HIGH
02 103.121.91.144 Sorry (Ransomware) Ransomware HIGH
03 103.131.95.37 Sorry (Ransomware) Ransomware HIGH
04 103.138.13.30 GoSerpent Malware HIGH
05 104.239.66.86 The TTF Trap Malware HIGH
06 104.243.32.213 OkoBot Botnet HIGH
07 104.243.43.16 OkoBot Botnet HIGH
08 104.248.233.104 UAT-11795 (APT) APT HIGH
09 107.174.133.119 TuxBot v3 Botnet HIGH
10 107.174.34.137 The TTF Trap Malware HIGH
11 109.122.217.21 Sorry (Ransomware) Ransomware HIGH
12 109.172.95.184 Artlist ClickFix Malware HIGH
13 112.213.124.132 TencShell C2 C&C Server HIGH
14 112.213.124.159 TencShell C2 C&C Server HIGH
15 112.213.124.163 TencShell C2 C&C Server HIGH

Top 15 · Domains (High severity)

# Indicator Adversary Category Severity
01 2baserec2[.]guru OkoBot Botnet HIGH
02 ai-nexora[.]sbs Polygon-Based C2 C&C Server HIGH
03 aipythondevs[.]com UAT-11795 (APT) APT HIGH
04 all-imager-hst[.]click Polygon-Based C2 C&C Server HIGH
05 alphabitcapital[.]info UAT-11795 (APT) APT HIGH
06 altzserberin[.]info APT-C-35 APT HIGH
07 anlytic-js-cloud[.]beer Polygon-Based C2 C&C Server HIGH
08 apigrokcloud[.]icu ACR Stealer Malware HIGH
09 aqpfkxxtvahlzr6vobt6fhj4riev7wxzoxwltbcysuybirygxzvp23ad[.]onion Artlist ClickFix Malware HIGH
10 areal[.]rj[.]gov[.]br (defanged, victim-adjacent) PhantomEnigma Malware HIGH
11 auramatrixa[.]com ACR Stealer Malware HIGH
12 auth-code-check[.]info Artlist ClickFix Malware HIGH
13 authorization-cdn-press-enter[.]info Polygon-Based C2 C&C Server HIGH
14 1308344827-4bya137jfj.ap-guangzhou.tencentscf[.]com Commodity C2 framework A Malware HIGH
15 abcd.gamesen[.]icu Commodity C2 framework A Malware HIGH

Top 15 · File hashes (High severity)

# Indicator Adversary Category Severity
01 002e1207b96361fc4d53b10621225d61700003241fa38caacb411384b3d51135 APT-C-60 APT HIGH
02 00380c75734fd72885b315c53b4e9774 Trigona Ransomware HIGH
03 0067679c7033139bcbb273840494b324 Medusa Ransomware HIGH
04 011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972 Malicious game-cheat pkg Supply Chain HIGH
05 0120a6396952aec3f05ec0b0efe25e2a1b73545d55d74a3ac0bcd359d29f52bb APT-C-60 APT HIGH
06 012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe MedusaLocker Ransomware HIGH
07 014bd0c56fb2da2ff6eeeb240705462b njRAT RAT HIGH
08 0161027a354f9a1fc8e605261400fba9 Trigona Ransomware HIGH
09 0168a4daa9598e991e140057e59438f6 Medusa Ransomware HIGH
10 018d410685c743dedaad1dff81486dd7 Trigona Ransomware HIGH
11 01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27c Malicious game-cheat pkg Supply Chain HIGH
12 03110e7d05f64c49a35a3e60d049f2b0 AgentTesla RAT HIGH
13 03ab9195dcbd96fbe4e11917c50b57b6 Trigona Ransomware HIGH
14 03eaabaf750bcf69d58f79098432f8a3 Trigona Ransomware HIGH
15 041dca4a1d8c80f05c399dd750acf026ed5f94f1da08dc4f0f0d0ba9884916ff WORLDLEAKS Ransomware HIGH

Top 15 · URLs (High severity)

# Indicator Adversary Category Severity
01 hxxp[://]101.91.154.125:50001/cm Commodity C2 framework A Malware HIGH
02 hxxp[://]106.15.62.124:2222/push Commodity C2 framework A Malware HIGH
03 hxxp[://]118.195.183.6/activity Commodity C2 framework A Malware HIGH
04 hxxp[://]118.31.115.178:4444/ga.js Commodity C2 framework A Malware HIGH
05 hxxp[://]118.31.115.178:9999/ptj Commodity C2 framework A Malware HIGH
06 hxxp[://]124.220.215.195:5555/pixel Commodity C2 framework A Malware HIGH
07 hxxp[://]124.220.215.195:9999/ca Commodity C2 framework A Malware HIGH
08 hxxp[://]124.223.12.165/ Commodity C2 framework A Framework HIGH
09 hxxp[://]129.211.215.7/dot.gif Commodity C2 framework A Malware HIGH
10 hxxp[://]154.3.0.70:83/cm Commodity C2 framework A Malware HIGH
11 hxxp[://]178.16.54.109/ Phorpiex Botnet HIGH
12 hxxp[://]185.141.216.194/cd.jpg Spirals (Ransomware) Ransomware HIGH
13 hxxp[://]185.141.216.194/cd.zip Spirals (Ransomware) Ransomware HIGH
14 hxxp[://]190.14.37.84/5555555.dat Commodity C2 framework A Malware HIGH
15 hxxp[://]192.253.248.181/web/ledger.zip macOS info-stealer Malware HIGH
Need the full set? The catalogue carries 59,935 unique IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, adversary attribution, and source-feed provenance. Open HuntIntel.

10 · Sigma detection rules

Sigma 01 · Blockchain-RPC outbound (Polygon C2 detector)

title: Outbound Traffic to Public Blockchain RPC — Blockchain-Resolved C2 Detector
id: 4c9e7b1d-5a82-4630-b791-6f8d3c1e5a20
status: experimental
description: Detects outbound connections from non-engineering hosts to public
  blockchain RPC endpoints (Polygon, TON, Ethereum, and similar). Blockchain-
  resolved C2 is now a recurring pattern (Polygon-Based C2 this week, TONResolver
  a fortnight ago). Any outbound blockchain-RPC traffic from a non-engineering
  host is candidate compromise.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
  - attack.command_and_control
  - attack.t1102
  - attack.t1568
logsource:
  category: proxy
detection:
  selection:
    cs-host|contains:
      - 'polygon-rpc'
      - 'polygonscan'
      - '.polygon.io'
      - 'maticvigil'
      - 'infura.io'
      - 'alchemy.com'
      - 'ton-rpc'
      - 'toncenter'
      - 'tonapi'
  exclusion:
    src-ip|cidr: '10.engineering.0.0/16'   # replace with your engineering subnet
  condition: selection and not exclusion
falsepositives:
  - Blockchain-adjacent engineering workloads (allowlist explicitly)
level: high

Sigma 02 · Universal ransomware kill-chain (VSS delete)

title: Universal Ransomware Kill-Chain — Volume Shadow Copy Deletion
id: 8e2c1a4f-6d93-4720-a581-3f9b5c2e8d10
status: experimental
description: Detects the universal ransomware pre-encrypt step — volume shadow
  copy deletion. Every catalogued ransomware family this week (RAWorld, Trigona,
  Qilin, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry, and 15+ more)
  executes this step. A single detector catches the ransomware bucket.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
  - attack.impact
  - attack.t1490
  - attack.t1486
logsource:
  category: process_creation
  product: windows
detection:
  vssadmin_delete:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains|all: ['delete', 'shadows']
  wmi_delete:
    Image|endswith: '\wmic.exe'
    CommandLine|contains|all: ['shadowcopy', 'delete']
  powershell_delete:
    Image|endswith: '\powershell.exe'
    CommandLine|contains:
      - 'Remove-CimInstance'
      - 'Win32_ShadowCopy'
  condition: 1 of them
falsepositives:
  - Legitimate backup operations (verify + allowlist known-good scripts)
level: critical

Sigma 03 · TencShell C2 subnet anchors

title: TencShell C2 Subnet Anchor Contact
id: 3b7f9d2c-1a84-4560-b731-5c9e6d4f2b40
status: experimental
description: Detects outbound connections to the TencShell C2 operator's four
  concentrated subnet anchors. 16 IPs across 4 /24 blocks — the year's largest
  single-cluster hosting concentration.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
  - attack.command_and_control
  - attack.t1071
logsource:
  category: network_connection
detection:
  selection:
    DestinationIp|cidr:
      - '134.122.200.0/24'
      - '192.163.167.0/24'
      - '45.64.52.0/24'
      - '112.213.124.0/24'
  condition: selection
falsepositives:
  - Unlikely — none of these CIDRs has documented legitimate business use
level: critical

Sigma 04 · APT-C-60 multi-type cluster

title: APT-C-60 Multi-Type Cluster Detection
id: 5d1a8c3f-4b72-4820-a591-2e8c7d5b1a90
status: experimental
description: Detects contact with APT-C-60's catalogued anchor infrastructure OR
  DNS queries matching the cluster's acquired-domain naming pattern. APT-C-60
  had the broadest single-cluster IOC-type spread this week (5 IOC types).
references:
  - https://hackforlab.com/weekly-threat-advisory-july-13-19-2026/
author: HackForLab Threat Intelligence
date: 2026/07/20
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.resource_development
  - attack.t1583.001
logsource:
  category: network_connection
detection:
  subnet_anchor:
    DestinationIp|cidr: '213.111.158.0/24'
  known_domains:
    QueryName:
      - 'altzserberin.info'
      # (add remaining catalogued APT-C-60 domains at deploy time)
  condition: subnet_anchor or known_domains
falsepositives:
  - Very rare — the subnet + domain pattern has no legitimate business use
level: critical

11 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Blockchain-RPC outbound from non-engineering hosts

// Pseudo-query
FROM proxy_logs
WHERE dest_host MATCHES regex '(?i)(polygon-rpc|polygonscan|\.polygon\.io|maticvigil|infura|alchemy|toncenter|\.ton\.org)'
  AND src_host NOT IN (allowlisted_engineering_hosts)
| AGGREGATE BY src_host, dest_host
  COUNT(*) AS req_count,
  MIN(request_time) AS first_seen
| SORT BY first_seen DESC

Hunt 02 · TencShell C2 anchor first-seen contact

// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('134.122.200.0/24', '192.163.167.0/24', '45.64.52.0/24', '112.213.124.0/24')
  AND first_seen_pair(src_ip, dest_ip) WITHIN 60d
| AGGREGATE BY src_ip, dest_ip
| SORT BY flow_count DESC

Hunt 03 · APT anchor first-seen (all 4 Chinese-aligned clusters)

// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('213.111.158.0/24')                    -- APT-C-60
   OR dest_ip = '104.248.233.104'                             -- UAT-11795
  AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC

Hunt 04 · Font-exploit drive-by kill-chain (TTF Trap)

// Pseudo-query
FROM process_crash_events
WHERE process_name IN ('chrome.exe', 'firefox.exe', 'edge.exe', 'AcroRd32.exe', 'winword.exe')
  AND crash_module MATCHES regex '(?i)(font|ttf|otf)'
| JOIN process_creates AS pc
  ON process_crash_events.host = pc.host
  AND pc.create_time BETWEEN process_crash_events.event_time
                        AND process_crash_events.event_time + 30s
  AND pc.process_name NOT IN (allowlisted_children)
| PROJECT host, process_crash_events.process_name, pc.command_line
| SORT BY event_time DESC

12 · Operationalise in 60 minutes

Minute 00 – 15 · Block + sinkhole

  • Block all four TencShell subnet anchors: 134.122.200.0/24, 192.163.167.0/24, 45.64.52.0/24, 112.213.124.0/24.
  • Block 213.111.158.0/24 (APT-C-60 anchor).
  • Block 92.38.177.0/24 (Lucide Proxy DDoS botnet).
  • Block 45.156.87.0/24 (Sorry ransomware).
  • Deploy outbound-deny for public blockchain RPC endpoints (Polygon + TON) from non-engineering hosts.

Minute 15 – 30 · Detection content

  • Deploy Sigma 01 (blockchain-RPC detector) — catches Polygon-Based C2 + TONResolver family without knowing the C2 IPs.
  • Deploy Sigma 02 (universal VSS-delete detector) — catches every ransomware family this week.
  • Deploy Sigma 03 (TencShell subnet anchors).
  • Deploy Sigma 04 (APT-C-60 multi-type).

Minute 30 – 45 · Retrospective hunt

  • Run Hunt 01 (blockchain-RPC outbound) baseline scan.
  • Run Hunt 02 (TencShell anchor first-seen) across last 60 days.
  • Run Hunt 03 (APT anchor first-seen) across last 90 days.
  • Run Hunt 04 (font-exploit drive-by) across last 30 days.

Minute 45 – 60 · Awareness + policy

  • Brief developers on the package-registry supply-chain double strike; package allow-listing is not optional.
  • Brief cryptocurrency-adjacent users on the UAT-11795 domain targeting pattern.
  • Update macOS user-awareness content on ClickFix.
  • Audit outbound egress policy for blockchain-RPC traffic. Deny by default from non-engineering hosts.
// CONTINUE WITH HUNTINTEL

This briefing ships 15 indicators per type. The catalogue carries the full 59,935 unique IOCs from this week — adversary attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

13 · Frequently asked questions

Blockchain-resolved C2 is now recurring. What is the strategic implication?

Blockchain-resolved C2 is likely to become a mainstream C2 pattern within 12-18 months. The technique is takedown-resistant by design and imposes low operator cost. Defenders should invest now in endpoint behavioural detection (process instrumentation on blockchain-RPC library calls) and outbound egress policy (explicit deny of blockchain-RPC traffic from non-engineering hosts). The domain / IP catalogue-based defensive stack that has worked for two decades will not work against blockchain-resolved C2 without adaptation.

Four Chinese-aligned APTs in one week — is that unusual?

Concurrent activity from four named Chinese-aligned clusters is above the year-to-date baseline (typical week: 1-2 clusters active). What makes it noteworthy is not the individual clusters but the concurrency — suggests either a shared operational trigger or a broader regional operational tempo increase. Organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week.

How do I prioritise the 20+ ransomware families active this cycle?

Do not prioritise them individually. Deploy Sigma 02 (universal volume-shadow-copy deletion detector). It fires on every ransomware family this week regardless of variant. Then, on top of that universal detector, add the operator-specific email indicators (Trigona, MedusaLocker, Medusa) as SMTP-gateway blocklist + retrospective mailbox-audit hunt targets — those catch operator ransom-negotiation communication attempts.

Why is TencShell C2 significant?

16 IPs concentrated across 4 subnet /24 anchors is the largest single-cluster hosting concentration observed this year. Rotation resilience is very low from the defender’s perspective — new IPs are extremely likely to fall in the same blocks. Subnet-level blocking gives the defender an asymmetric advantage. The four-anchor block costs the defender nothing to deploy; costs the operator a full C2-infrastructure rebuild across four different hosting tenants to defeat.

The macOS threat layer is maturing. What should I invest in this quarter?

Two priorities. First: telemetry parity — if your macOS estate has less endpoint-process-create logging than your Windows estate, that gap is now operationally material. Second: user-awareness — macOS-specific phishing lures (ClickFix on macOS, fake-install prompts, drive-by via Safari) are qualitatively different from Windows lures and need distinct awareness content.

What confidence threshold should the SOC use for automated blocking?

High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.

Where can I see this briefing’s intelligence operationally?

The HuntIntel operator console exposes every IOC with adversary attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions