HackForLab Weekly Threat Advisory · Jul 20-26 2026 · APT Storm cover · sanitised v2 · deep charcoal + crimson + gold palette · 77,118 indicators · 155 clusters · 25 attributed APT clusters · category-based footprint chart (C2 infrastructure, malware activity, APT, botnet, phishing) · this-week defining signals (15,000 loader hashes, 3 ICS/OT anchor blocks, SVG new-delivery vector)

Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)

● CTI SITREP 026·30 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-030 · July 20 – 26, 2026

APT storm week. 25 named APT clusters ran in parallel — the widest concurrent APT footprint observed in this catalogue year-to-date. GoldenEyeDog surged to 7,848 unique hashes in seven days — polymorphic-build-farm signal. Two DPRK-adjacent operations active (BlueNoroff impersonating collaboration-platform video URLs; Wagemole IT-worker infiltration). Three Russian-aligned clusters (Turla, APT28-linked router campaigns, LAUNDRY BEAR). Iran-Middle-East regional operations. The LARVA cluster group triple-active (LARVA-15, -17, -47). And a rare ICS/OT signal — PLC Exploitation across three concentrated subnet anchors targeting industrial control systems. If your CTI team was quiet this week, this briefing is your priority reading list.

Sectioned for the working analyst: cluster catalogue, deep-dives on the high-tempo names, ATT&CK technique mapping per adversary, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules, Predictive Intelligence weaponisation forecast, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and adversary cluster pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

The catalogue produced 77,118 unique IOCs across 155 adversary clusters this cycle. Framework-infrastructure entries dominate the topline volume (as usual), but the narrow-indicator layer is the intelligence story: 3,374 unique domains + 16,316 unique hashes + 503 URLs. The hash volume alone (16,316) is the second-highest weekly count observed in this catalogue this year — driven by two clusters (GoldenEyeDog at 7,848 and SmartLoader at 7,115) running at industrial-scale polymorphic-build volume. Every APT category is elevated: 25 named APT clusters concurrent is the widest APT footprint of the year.

// CTI SITREP 026·30 · July 20 – 26, 2026 · TA-2026-030
83,969
Records
77,118
Unique IOCs
20,804
High-severity
155
Clusters
25
Named APTs
60
Source feeds

Catalogued, ML-scored, ATT&CK-tagged. Every record carries adversary attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · APT Storm — 25 named clusters concurrent

Twenty-five named APT clusters produced fresh indicators this cycle — the widest concurrent APT footprint in the year-to-date window. The APT-category IOC total: 8,291 records across 25 named actors. Cluster diversity spans DPRK-adjacent (BlueNoroff, Wagemole), Russian-aligned (Turla, APT28-linked router campaigns, LAUNDRY BEAR), Iran-Middle-East regional operations, the LARVA cluster group (LARVA-15, -17, -47), UAT/UAC-tracked clusters, and the JadeProx / GoldenEyeDog / TAG-195 named clusters. Concurrent activity at this scale is a load-bearing intelligence signal.

Headline 02 · GoldenEyeDog — 7,848 unique hashes in 7 days

The single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators this cycle. Volume at that scale from a single named cluster suggests a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated. The operational implication: the hash-blocklist layer is fragile against this volume. Behavioural loader-detection is the durable defence layer. SmartLoader (7,115 hashes) shows the same industrial-scale build signal from a different family.

Headline 03 · ICS/OT threat surface — PLC Exploitation, 3 subnet anchors

A rare and operationally significant signal. The PLC Exploitation cluster produced 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4 IPs, 88.80.150.0/24 with 3 IPs — 15 IPs across 3 blocks). PLC = Programmable Logic Controller. The cluster targets industrial control systems, not enterprise IT. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. If your organisation operates any OT/ICS environment, this cluster warrants immediate attention.

Headline 04 · DPRK double-track — BlueNoroff + Wagemole

Two DPRK-adjacent operations active in parallel. BlueNoroff (83 IOCs) uses a distinctive domain-naming pattern impersonating collaboration-platform video URLs (02webus[.]zoom[.]02us[.]sbs, 05us[.]zoom[.]web05[.]sbs, etc.) with a subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. Separately, Wagemole (64 IOCs across all 4 primary IOC types) is the IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is a HR-workflow threat, not an endpoint threat — detection requires identity-verification and hiring-workflow controls, not detection content.

Headline 05 · Novel delivery vector — SVG malicious scripts

The SVG Malicious Scripts cluster produced 25 IOCs across DOMAIN + HASH. Delivery pattern: attackers embed JavaScript payloads inside SVG image files. When the SVG is rendered in a browser (as an inline image, email attachment preview, or website asset), the embedded script executes. Bypasses many email attachment scanners that do not treat SVG as executable-adjacent. Combined with the ClearFake drive-by cluster (143 IOCs), this cycle shows a broader shift toward browser-rendering-time payload delivery. Defensive answer: content-inspection of SVG files at the mail-gateway and web-proxy layers.


03 · Indicator type, severity, and category mix

The narrow-indicator layer is the intelligence story this week: 16,316 unique HASH indicators is the highest hash-share observed year-to-date at 21 percent (driven by GoldenEyeDog + SmartLoader polymorphic builds). Domain volume at 3,374 is also elevated. Severity distribution shows 27 percent HIGH (20,804 records) — well above the year-to-date baseline. APT category at 8,291 IOCs (11 percent share) is the highest APT concentration of the year.

By indicator type

TypeObservationsShare%
IPs56,860
73.73%
File hashes16,316
21.16%
Domains3,374
4.38%
URLs503
0.65%
Other artefacts42
0.05%
Emails17
0.02%
Process names6
0.01%

By severity

SeverityObservationsShare%
High20,804
26.41%
Medium57,837
73.41%
Low143
0.18%

By category

CategoryObservationsShare%
C&C53,149
64.37%
Malware-Activity8,570
10.38%
APT8,291
10.04%
C&C Server5,435
6.58%
Botnet5,000
6.06%
Phishing1,725
2.09%
RAT185
0.22%
Framework65
0.08%
Spyware44
0.05%
Ransomware-as-a-service38
0.05%
Hacktivist Group16
0.02%
Loader15
0.02%
Vulnerability13
0.02%
Intrusion Campaign13
0.02%
Supply Chain9
0.01%

04 · Top adversary clusters

36 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. GoldenEyeDog (7,848 hashes) and SmartLoader (7,115 hashes) are the polymorphic-build standouts. Lucid Phishing Kit (1,723 IOCs) is the broadest phishing infrastructure of the week.

#Adversary clusterRelative footprintUnique IOCsSeverity
01Commodity C2 framework A (open-framework infrastructure)

C2 · DOMAIN, EMAIL, HASH, IP, URL
57,830MEDIUM
02GoldenEyeDog

Threat Actor (APT) · HASH
7,848HIGH
03SmartLoader

Malware · HASH
7,115HIGH
04Lucid

Phishing Kit · DOMAIN, IP
1,723MEDIUM
05WebDAV Campaign

Malware Campaign · HASH, IP, URL
275HIGH
06Commodity C2 framework A (malware-tier)

Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
152HIGH
07KongTuke C2

C2 · DOMAIN, URL
151MEDIUM
08AsyncRAT

Malware (RAT) · DOMAIN, HASH, IP, URL
109MEDIUM
09ClearFake

Malware Campaign · DOMAIN, HASH
143HIGH
10SourTrade

Malware · DOMAIN, HASH
99HIGH
11BlueNoroff

Threat Actor (APT) · DOMAIN, HASH, IP
83HIGH
12Knife-Cutting-the-Edge

Malware Campaign · DOMAIN, HASH, IP, URL
76HIGH
13Wagemole

Threat Actor (APT) · DOMAIN, HASH, IP, URL
64HIGH
14Fake browser-extension phishing cluster

Phishing Campaign · DOMAIN, IP, OTHERS
64LOW
15Open remote-management framework

C2 · IP
63MEDIUM
16LARVA-47

Threat Actor · HASH, IP
59HIGH
17LONEPAGE

Malware · DOMAIN, EMAIL, HASH, IP, URL
54HIGH
18Starland RAT + WLDR Implant Campaign

Malware Campaign · DOMAIN, HASH, IP, URL
52HIGH
19LARVA-15

Threat Actor · HASH, IP, URL
50HIGH
20Brunhilda Project

Malware Campaign · HASH, IP, OTHERS
48HIGH
21Cruciferra

Malware · DOMAIN, HASH, IP, URL
44HIGH
22JadeProx

Threat Actor (APT) · DOMAIN, HASH, IP
41HIGH
23TAG-195

Malware Campaign · DOMAIN, HASH, IP
39HIGH
24Lampion malware campaign

Malware Campaign · DOMAIN, HASH, URL
34HIGH
25UAT-8837

Threat Actor (APT) · HASH, IP
34HIGH
26UAC-0145

Threat Actor (APT) · DOMAIN, HASH
34HIGH
27LARVA-17

Threat Actor · DOMAIN
34HIGH
28Kali365

Phishing Kit · DOMAIN
34MEDIUM
29Iran-Middle-East campaign

Malware Campaign · DOMAIN, HASH, OTHERS, URL
33HIGH
30StealC

Malware (Stealer) · DOMAIN, HASH, IP, URL
29HIGH
31Fake-games stealer campaign

Malware · DOMAIN, HASH, IP
29HIGH
32SectopRAT

Malware (RAT) · DOMAIN, HASH, IP
28HIGH
33BINDCLOAK C2

Malware Campaign · DOMAIN, HASH
28HIGH
34Collaboration-platform phishing operation

Phishing Campaign · DOMAIN, EMAIL, HASH, URL
26LOW
35PLC Exploitation (ICS/OT campaign)

Malware Campaign · DOMAIN, HASH, IP
26HIGH
36SVG Malicious Scripts

Malware Campaign · DOMAIN, HASH
25HIGH

05 · Cluster deep-dives — the names to act on

05.1 · GoldenEyeDog (APT) — 7,848 hashes, polymorphic build farm

The largest single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators in seven days. Volume at that scale from a single named cluster indicates a polymorphic build pipeline actively producing many binary variants per target. The operational implication is significant: hash-blocklist-based defence is fragile against this volume — the operator can generate new variants faster than any hash feed can catalogue them.

Defensive actions: Push the catalogued hashes to endpoint quarantine as a baseline. But the durable defence layer is behavioural loader detection — process-tree anomalies, parent-child spawn patterns, network-flow shapes after execution. Deploy Sigma rule 01 below (universal loader-behaviour detector) as the primary defence against this cluster.

05.2 · SmartLoader — 7,115 hashes, industrial-scale build

Same polymorphic-build signal as GoldenEyeDog from a different family. 7,115 unique HASH indicators across the cycle. SmartLoader is a loader family designed to fetch and execute second-stage payloads. Standard commodity-loader tradecraft, industrial-scale build tempo.

Defensive actions: Same as GoldenEyeDog — hash-block as baseline, behavioural loader detection as durable defence.

05.3 · BlueNoroff (DPRK APT) — collaboration-platform impersonation

83 IOCs across DOMAIN + HASH + IP with a distinctive domain-naming pattern: 02webus[.]zoom[.]02us[.]sbs, 02webus[.]zoom[.]web02[.]sbs, 05us[.]zoom[.]web05[.]sbs, 06usweb[.]zoom[.]us06[.]sbs. The pattern impersonates collaboration-platform video-call URLs to lure victims into clicking fake “join meeting” links. Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.

Defensive actions: Regex-block the naming pattern at the DNS resolver: ^\d{2}[a-z]+\.zoom\.[a-z0-9]+\.sbs$. Block the subnet anchor. Alert users in cryptocurrency-adjacent roles specifically.

05.4 · Wagemole (DPRK IT-worker infiltration)

64 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired, not by exploiting a technical vulnerability.

Defensive actions: HR-workflow controls: video-verify interviews (not chat-only), verify education and employment claims independently, cross-check identity documents against second-source records, flag applicants using VPN or unusual geolocation during interviews. Deploy the catalogued IOCs as watchlist targets for outbound corporate-network traffic after any suspected Wagemole-profile hire.

05.5 · PLC Exploitation — ICS/OT threat with 3 subnet anchors

The rare-and-significant signal. 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors:

  • 185.82.73.0/24 — 8 IPs concentrated
  • 175.110.121.0/24 — 4 IPs concentrated
  • 88.80.150.0/24 — 3 IPs concentrated

15 IPs across 3 blocks targeting industrial control systems. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. Utilities, manufacturing, energy, and critical-infrastructure operators are the primary victim profile.

Defensive actions: If your organisation operates any OT/ICS environment: block all three /24 anchors at the perimeter now. Verify no internet-accessible PLCs in your environment (Shodan-search-adjacent inventory). Alert on any modbus / EtherNet-IP / DNP3 / Profinet traffic from unfamiliar external sources.

05.6 · Russian-aligned APT triad (Turla + APT28-linked + LAUNDRY BEAR)

Three concurrent Russian-aligned clusters active. Turla APT at IP anchor 103.31.250.253. APT28-linked router campaigns at 104.194.159.150 — targets network-edge router firmware for long-persistence intrusion. LAUNDRY BEAR at 104.248.134.194 with 3 IPs concentrated in 216.252.238.0/24. Combined footprint suggests coordinated regional operational tempo.

Defensive actions: Block all catalogued anchor IPs. For router-focused activity, prioritise firmware integrity scans on network-edge appliances. Hunt for anomalous configuration changes on internet-facing routers.

05.7 · LARVA cluster group (LARVA-15, -17, -47)

Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus. LARVA-47 has a subnet anchor at 45.138.26.0/24 with 4 IPs and a second anchor at 188.227.106.0/24 with 3 IPs.

05.8 · ClearFake drive-by + SVG script delivery — browser-render-time payload delivery

Two clusters point at the same shift — adversaries increasingly delivering payloads via browser-render-time execution rather than direct file execution. ClearFake (143 IOCs combined) compromises legitimate websites to inject fake browser-update prompts. SVG Malicious Scripts (25 IOCs) embed JavaScript inside SVG image files that execute on browser render. Both defeat email-attachment-scanner defensive controls because the payload is not delivered as an attachment.

Defensive actions: Content inspection of SVG files at mail-gateway and web-proxy layers (treat SVG as executable-adjacent). For ClearFake, detect the fake-update-prompt pattern: user visits a legitimate-looking site, then downloads a browser-update from a non-corporate domain.

05.9 · Iran-Middle-East regional campaign

33 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile (T1566, T1190, T1078, T1059, T1105, T1071, T1021, T1003, T1041) indicates full-attack-lifecycle intrusion capability.

05.10 · WebDAV Campaign (275 IOCs) — alternative delivery transport

275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. WebDAV traffic frequently escapes conventional web-proxy content inspection because it is treated as file-sharing rather than web browsing.

Defensive actions: Alert on outbound WebDAV traffic from non-collaboration-tool hosts. If your environment has no legitimate WebDAV use case, block WebDAV outbound at the perimeter.

06 · ATT&CK mapping per named cluster

Per-cluster technique mapping with operational narrative. Detection content that fires on these techniques catches the cluster even after IOC rotation.

ClusterATT&CK techniques observedOperational narrative
GoldenEyeDog (APT)T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1027 · T1105 · T1071.001 · T10417,848 unique hashes — the largest single-cluster hash footprint observed in this catalogue year-to-date. Volume suggests a polymorphic build pipeline actively producing many binary variants per target. Standard APT delivery chain: acquired domains + spearphishing attachment + user-execution + obfuscation + second-stage pull + web-protocol C2 + exfil.
SmartLoaderT1204.002 · T1059.001 · T1105 · T1027 · T1071.0017,115 unique hashes — same polymorphic-build-farm signal. Loader family designed to fetch and execute second-stage payloads. Hash-block layer is fragile against this volume; behavioural loader-detection is the durable defence.
Lucid Phishing KitT1566.002 · T1583.001 · T1584.001 · T1056.007 · T1539 · T1071.0011,723 IOCs across DOMAIN + IP. Phishing-kit infrastructure with adversary-in-the-middle capability — session-cookie theft after credential capture. Broad phishing-domain footprint suggests operator running many concurrent campaigns.
BlueNoroff (DPRK APT)T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T104183 IOCs across DOMAIN + HASH + IP. Distinctive domain naming pattern: *.zoom.*.sbs impersonating collaboration-platform video URLs (02webus.zoom.02us.sbs, 05us.zoom.web05.sbs, etc.). Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.
Wagemole (DPRK)T1583.001 · T1566.002 · T1585.001 · T1585.002 · T1204 · T105964 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Detection requires HR-workflow controls, not endpoint content.
Turla APT (Russian-aligned)T1071 · T1105 · T1059 · T1041 · T1027 · T1095 · T1568IP anchor at 103.31.250.253. Web-protocol C2 + second-stage pull + command-interpreter + exfil + obfuscation + non-app-layer C2 fallback + dynamic resolution.
APT28-linked router campaigns (Russian)T1595 · T1190 · T1210 · T1105 · T1071Router-focused compromise cluster — IP 104.194.159.150 observed. Public-app scanning + exploitation of network infrastructure + inbound C2 from operator to compromised router. Detection focus: firmware integrity + configuration drift on network-edge devices.
LAUNDRY BEAR (APT)T1583.001 · T1566 · T1071.001 · T10413 IPs concentrated in 216.252.238.0/24. Standard APT tradecraft — adversary-acquired domains, phishing initial access, web-protocol C2, exfil.
UAT-8837 (APT)T1190 · T1078 · T1110.001 · T1505.003 · T1059.001 · T1105 · T1021.001 · T1003.001 · T1082 · T1041 · T1090 · T1543.003 · T1558.00334 IOCs across HASH + IP. Broad TTP profile — public-app exploit, valid-account credential access via password spraying, webshell persistence, credential dumping, Kerberoasting (T1558.003), proxy tunnelling. Full-attack-lifecycle cluster.
UAC-0145 (Ukrainian-tracked APT)T1583.001 · T1566 · T1105 · T1071 · T104134 IOCs across DOMAIN + HASH. Adversary-acquired domain infrastructure (365softupdate[.]com-style software-update lure naming).
JadeProx (APT)T1583.001 · T1090 · T1071 · T1105 · T104141 IOCs across DOMAIN + HASH + IP. Proxy-tunnelling APT cluster.
LARVA cluster group (LARVA-15, LARVA-17, LARVA-47)T1566.001 · T1566.002 · T1078 · T1059.001 · T1105 · T1071.001 · T1555 · T1552.001 · T1005 · T1041 · T1070.004Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain, with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus.
Iran-Middle-East campaignT1566.001 · T1566.002 · T1190 · T1078 · T1059.001 · T1105 · T1071.001 · T1021.001 · T1003.001 · T1005 · T1041 · T1070.00433 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile suggests full-attack-lifecycle intrusion capability.
PLC Exploitation (ICS/OT)T0819 · T0866 · T0836 · T088526 IOCs across DOMAIN + HASH + IP with 3 subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4, 88.80.150.0/24 with 3). ICS ATT&CK techniques: exploit of internet-accessible device, unauthorised command execution, modify parameter, commonly-used-port abuse. Rare in this catalogue when observed — targets industrial control systems, not IT enterprise. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile.
SVG Malicious ScriptsT1204.002 · T1059.007 · T1027 · T110525 IOCs across DOMAIN + HASH. Novel delivery pattern: SVG image files carrying embedded JavaScript that executes when the SVG is rendered in a browser. Bypasses many email attachment scanners which do not treat SVG as executable-adjacent.
ClearFake (drive-by + fake-update)T1189 · T1204.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T1566.002 · T1036 · T1027143 IOCs combined. Compromised legitimate websites inject a fake browser-update prompt; user clicks; malicious payload is delivered. Detection focus: unexpected browser-update download from a non-corporate domain immediately after a normal-looking web visit.
AsyncRATT1566.001 · T1204 · T1105 · T1071.001 · T1041 · T1547.001109 IOCs across all 4 primary IOC types. Standard commodity-RAT chain — spearphish → user-execute → second-stage → web-protocol C2 → exfil → registry persistence.
KongTuke C2 infrastructureT1071151 IOCs across DOMAIN + URL. C2-infrastructure surge with distinctive path patterns. Watch outbound traffic for the catalogued endpoints.
WebDAV CampaignT1105 · T1071.001 · T1204 · T1027275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. Detection focus: outbound WebDAV traffic from non-collaboration hosts.
BINDCLOAK C2T1071 · T1571 · T110528 IOCs across DOMAIN + HASH. Non-standard-port C2 with cloaking layer.
StealC (Stealer)T1555 · T1005 · T1041Full 4-type footprint. Password-store theft + local data collection + exfil over C2.
Brunhilda ProjectT1583.001 · T1584.001 · T1566.002 · T1204.001 · T1204.002 · T1105 · T1059.001 · T1071.00148 IOCs across HASH + IP + OTHERS. Largest single-cluster subnet anchor of the week (185.177.93.0/24 with 9 IPs). Distribution-focused campaign.

Detection-engineering takeaway. The universal APT chain (T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers most of the 25 named clusters this week. Two well-designed detectors — one on adversary-acquired-domain first-seen contact, one on the ingress-tool-transfer-plus-exfil sequence within 5 minutes — cover most of the APT surface with minimal per-cluster tuning. For the loader-heavy layer (GoldenEyeDog + SmartLoader), behavioural loader-detection is the durable defence layer (Sigma 01 below).

07 · ATT&CK tactic-pressure roll-up

TacticTop techniques observedWhat the pressure meansIOC count
Command and ControlT1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling1,147
Initial AccessT1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply chain892
ExecutionT1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1189Command interpreter (PowerShell / CMD / VB / JS), user-execution, drive-by (SVG script)785
Ingress Tool TransferT1105Second-stage payload pull — universal across every multi-stage cluster634
Defense EvasionT1027 · T1036 · T1055 · T1070 · T1070.004 · T1562 · T1140Obfuscation, masquerading, process injection, indicator removal, disable defences, deobfuscate512
Credential AccessT1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1110.001 · T1558.003OS credential dumping, password store theft, brute force + Kerberoasting428
DiscoveryT1082 · T1057 · T1083 · T1018 · T1046 · T1482System info, process, file, remote-system, network configuration, domain trust356
Lateral MovementT1021 · T1021.001 · T1021.002 · T1570Remote-desktop, SMB / admin shares, lateral tool transfer289
ExfiltrationT1041 · T1567 · T1090Exfil over C2, exfil to web service, tunnel-based exfil654
PersistenceT1547.001 · T1543.003 · T1053.005 · T1505.003Registry-run keys, Windows service creation, scheduled tasks, webshell245
Resource DevelopmentT1583.001 · T1584.001 · T1585Adversary-acquired domains + compromised infrastructure + fabricated identities (Wagemole)218
CollectionT1005 · T1119 · T1113 · T1056 · T1056.007 · T1539Local + automated collection, screen capture, input capture, session-cookie theft187
ICS-specificT0819 · T0866 · T0836 · T0885PLC Exploitation cluster: internet-accessible device exploit, unauthorised command, modify parameter, commonly-used-port abuse26

08 · Subnet anchors — the shared-infrastructure signal

Subnet (/24)IPsAdversary clusterOperator observation
185.177.93.0/249Brunhilda ProjectThe week’s largest single-cluster subnet anchor — 9 IPs concentrated.
185.82.73.0/248PLC ExploitationSecond-largest anchor + operationally rare — targets ICS/OT infrastructure.
23.224.4.0/245CRPXO C2C2 infrastructure concentration
91.92.43.0/244Tsundere botnetBotnet C2 (continues from prior weeks)
175.110.121.0/244PLC ExploitationSecond PLC Exploitation anchor
45.138.26.0/244LARVA-47LARVA cluster infrastructure
156.247.47.0/244DCRatCommodity RAT C2
88.80.150.0/243PLC ExploitationThird PLC Exploitation anchor — 3 blocks total, 15 IPs
45.61.163.0/243BlueNoroff (APT)DPRK-aligned APT infrastructure anchor
45.59.122.0/243SectopRATRAT operator anchor
216.252.238.0/243LAUNDRY BEAR (APT)APT-tier subnet anchor
188.227.106.0/243LARVA-47Second LARVA-47 anchor

The asymmetric block. PLC Exploitation operates across three distinct /24 anchors with 15 concentrated IPs — unusual for an ICS/OT-focused cluster. Blocking all three /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across three different hosting tenants simultaneously to defeat the block. Brunhilda Project (9 IPs in a single /24) and BlueNoroff (3 IPs concentrated) are the other high-leverage blocks.

08b · Predictive intelligence — forecast weaponisation

Retrospective indicators tell you what has happened; predictive indicators tell you what is about to. This week’s catalogue-driven forecast layer surfaces three infrastructure blocks with a high forward-looking probability of adversary weaponisation. Derived from passive-DNS drift, registration-velocity clustering, hosting-tenant reputation drift, and pattern-match against previously-catalogued operator behaviours. Push into your perimeter watchlist now — not because they are compromised today, but because they are the highest-probability rotation candidates for adversary use over the next week.

// PREDICTIVE INTELLIGENCE · FORECAST WEAPONISATION
Infrastructure signalForecast windowConfidenceSignal profile
185.82.73.0/243 DAYSHIGHImminent forecast. Already anchoring 8 PLC Exploitation IPs; velocity + rotation pattern indicates further hosts in the same block are candidate operator staging.
185.177.93.0/245 DAYSHIGHBrunhilda Project anchor with 9 concentrated IPs — the block’s remaining ~247 addresses are rotation candidates. CIDR block-candidate.
45.X.X.0/246 DAYSMEDIUMBroad-range staging block adjacent to LARVA-47 + BlueNoroff + SectopRAT anchors. Composite rotation signal across multiple operators.

How the forecast is derived

The forward-looking signal combines four inputs. Passive-DNS drift — how fast the block’s resolutions are changing relative to its historical baseline. Registration-velocity clustering — adjacent-block domain-registration rates compared against operator-fingerprint baselines. Hosting-tenant reputation drift — whether the anchor’s hosting tenant is trending toward adversary-adjacent reputation classes. And pattern-match against catalogued operator behaviours — whether the block’s early observable signature (open ports, TLS fingerprints, cert patterns) resembles any known operator anchor from the last 90 days. When two or more inputs converge, the block enters the forecast layer with a days-to-weaponisation estimate.

Operational actions

  • Perimeter watchlist — add all three anchors to a watchlist lane (not automatic block) that alerts on any outbound contact.
  • 3-day forecast (185.82.73.0/24) already-anchoring PLC Exploitation warrants provisional blocking of the /24 at the perimeter now if your environment has no legitimate business use in that range.
  • CIDR-level block for the discrete 185.177.93.0/24 anchor (Brunhilda Project).
  • Retrospective hunt — run a 90-day historical lookback for any past contact with these anchor ranges.

What predictive intelligence gives you. The classical intelligence catalogue tells you what has been observed already; the predictive layer tells you what is about to be observed. That shift buys the SOC a lead time it does not otherwise have — block an operator anchor before the operator’s rotation reaches you, not after your first compromise. The forecast is probabilistic, not deterministic — treat the days-to-weaponisation estimates as watchlist priorities, not automated-blocking triggers.

09 · Top 15 IOCs per indicator type

Operator-grade extractions. All indicators are defanged (re-fang on import: [.]. and hxxphttp).

Top 15 · IP addresses (High severity)

#IndicatorAdversaryCategorySeverity
011.94.106.150VShell (C2)BotnetHIGH
02101.96.224.108VShell (C2)BotnetHIGH
03103.101.85.111Quasar RATBotnetHIGH
04103.149.93.150VShell (C2)BotnetHIGH
05103.235.46.102UAT-8837 (APT)APTHIGH
06103.27.109.233Quasar RATBotnetHIGH
07103.31.250.253Turla APTAPTHIGH
08103.97.0.57Hermes AI AgentMalwareHIGH
09104.168.22.209VShell (C2)BotnetHIGH
10104.194.133.210SectopRATRATHIGH
11104.194.159.150APT28-linked routerAPTHIGH
12104.238.34.209Ragnar LoaderLoaderHIGH
13104.243.35.63Cl0p ransomwareRansomwareHIGH
14104.248.134.194LAUNDRY BEAR (APT)APTHIGH
15102.117.171.29Unknown malware C2BotnetHIGH

Top 15 · Domains (High severity)

#IndicatorAdversaryCategorySeverity
010059595390202402400202[.]sobul[.]netLARVA-17MalwareHIGH
0201058telecom[.]deSVG Malicious ScriptsMalwareHIGH
0302webus[.]zoom[.]02us[.]sbsBlueNoroff (APT)APTHIGH
0402webus[.]zoom[.]web02[.]sbsBlueNoroff (APT)APTHIGH
0505us[.]zoom[.]web05[.]sbsBlueNoroff (APT)APTHIGH
0606usweb[.]zoom[.]us06[.]sbsBlueNoroff (APT)APTHIGH
070co7tx46[.]worldofmacarons[.]comClearFakeMalwareHIGH
080xvona[.]duckdns[.]orgChalubo RATRATHIGH
090zbqnac1t4dv2t2wuodv1m[.]comCruciferraMalwareHIGH
10365softupdate[.]comUAC-0145 (APT)APTHIGH
114mrkjecd[.]rsudtarutung[.]comClearFakeMalwareHIGH
1257b0rv7c[.]sansekerta[.]orgClearFakeMalwareHIGH
135ca8758c-02d0-4a72-89c8-d468b66dda41[.]comSectopRATRATHIGH
145teun337[.]yummiquickway[.]comClearFakeMalwareHIGH
15abcd[.]gamesen[.]icuCommodity C2 framework AMalwareHIGH

Top 15 · File hashes (High severity)

#IndicatorAdversaryCategorySeverity
010002a8d9b71895c616dd52e32eb08823c79ce423a238757fcd275c13806dcb66SmartLoaderMalwareHIGH
02000732e37ed2431c677cca56aafbd53fFadeSEC RansomwareRansomwareHIGH
03000a25edc1bd2e91d65851c5171edf6facc0ca3fGoldenEyeDog (APT)APTHIGH
04000f0de250917d2d7a90c70116f0422fGoldenEyeDog (APT)APTHIGH
050010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8aGoldenEyeDog (APT)APTHIGH
0600113b357f18ba5f62c3e8856871f1902f019a1a16de2e3c8a29f84de2565065SmartLoaderMalwareHIGH
07001c16af3cfde47a3289e5c55d72533c5c0e4bc4GoldenEyeDog (APT)APTHIGH
08001e1824fef043f26d235ccf7eec71cdebfb419aGoldenEyeDog (APT)APTHIGH
09001e9bf4488c5bca1a81d087d2e310b4cf42f123GoldenEyeDog (APT)APTHIGH
10001f205103af843faa77bb811ef33bd791a184e9dc629363c3da509c16f5420cSmartLoaderMalwareHIGH
11001faaf397dde12a044efeb98efd972bdec0229cGoldenEyeDog (APT)APTHIGH
120022520838406bf985cc7ad13487288f8f4364e823fa3d41d44c4dbee9d659eeSmartLoaderMalwareHIGH
130024b6045416febb3b3c80569fbb7c4fe85e3ce8112e7dba6d80b3d601ffb523SmartLoaderMalwareHIGH
1400295a9ed4dbc4bb25b423ccd04af37e331d42a86f48edbeff5bd811fa97b899SmartLoaderMalwareHIGH
15003e4e3f3f4bb96ba4ddd10a43a7b5290cc237c1GoldenEyeDog (APT)APTHIGH

Top 15 · URLs (High severity)

#IndicatorAdversaryCategorySeverity
01hxxp[://]0xvona[.]duckdns[.]orgChalubo RATRATHIGH
02hxxp[://]103.31.250.253Turla APTAPTHIGH
03hxxp[://]110.92.64.17/moo.cgiKnife-Cutting-the-EdgeMalwareHIGH
04hxxp[://]117.175.185.81:8003/Knife-Cutting-the-EdgeMalwareHIGH
05hxxp[://]118.195.183.6/activityCommodity C2 framework AMalwareHIGH
06hxxp[://]118.31.115.178:4444/ga.jsCommodity C2 framework AMalwareHIGH
07hxxp[://]118.31.115.178:9999/ptjCommodity C2 framework AMalwareHIGH
08hxxp[://]124.220.215.195:5555/pixelCommodity C2 framework AMalwareHIGH
09hxxp[://]124.220.215.195:9999/caCommodity C2 framework AMalwareHIGH
10hxxp[://]124.223.12.165/Commodity C2 framework AFrameworkHIGH
11hxxp[://]129.211.215.7/dot.gifCommodity C2 framework AMalwareHIGH
12hxxp[://]154.3.0.70:83/cmCommodity C2 framework AMalwareHIGH
13hxxp[://]157.254.223.141/25/RemcosRATHIGH
14hxxp[://]101.91.154.125:50001/cmCommodity C2 framework AMalwareHIGH
15hxxp[://]106.15.62.124:2222/pushCommodity C2 framework AMalwareHIGH
Need the full set? The catalogue carries 77,118 unique IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, adversary attribution, and source-feed provenance. Open HuntIntel.

10 · Sigma detection rules

Sigma 01 · Universal loader behaviour (GoldenEyeDog + SmartLoader durable defence)

title: Universal Loader Behaviour — Polymorphic Build Family Detector
id: 6a2c8e1f-5b74-4930-a681-3f9b5c2e8d10
status: experimental
description: Detects the universal loader behaviour signature — a downloaded
  binary spawns from a browser or document reader parent process, then triggers
  outbound network traffic to a non-corporate destination within 60 seconds.
  Catches polymorphic-build families (GoldenEyeDog, SmartLoader, and similar)
  where hash-blocking is defeated by build-farm volume.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.execution
  - attack.t1204
  - attack.command_and_control
  - attack.t1105
  - attack.t1071.001
logsource:
  product: correlation
detection:
  s1_downloaded_binary:
    EventID: 4688
    ParentImage|endswith:
      - '\chrome.exe'
      - '\firefox.exe'
      - '\edge.exe'
      - '\OUTLOOK.EXE'
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\AcroRd32.exe'
    Image|contains:
      - '\Downloads\'
      - '\Temp\'
      - '\AppData\Local\Temp\'
  s2_outbound_web:
    EventID: 5156
    DestinationPort: [80, 443, 8080, 8443]
    DestinationIp|expand: '%non_corporate_destinations%'
  condition: s1_downloaded_binary and s2_outbound_web within 60s
falsepositives:
  - Legitimate software installers from allowlisted domains
level: high

Sigma 02 · BlueNoroff collaboration-platform impersonation

title: BlueNoroff Collaboration-Platform Impersonation Domain Pattern
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a90
status: experimental
description: Detects DNS queries matching the BlueNoroff APT domain-naming
  pattern impersonating collaboration-platform video-call URLs. Regex-tight
  enough to avoid false positives against legitimate platform domains.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.initial_access
  - attack.t1566
  - attack.resource_development
  - attack.t1583.001
logsource:
  category: dns_query
detection:
  selection:
    QueryName|re:
      - '^[0-9]{2}[a-z]+web?\.zoom\.[a-z0-9]+\.sbs$'
      - '^[0-9]{2}[a-z]+\.zoom\.web[0-9]{2}\.sbs$'
  condition: selection
falsepositives:
  - None — the .sbs TLD + this naming pattern has no legitimate collaboration-platform use
level: critical

Sigma 03 · PLC Exploitation subnet + OT-protocol egress

title: PLC Exploitation Subnet Anchor Contact (ICS/OT)
id: 8d1a4b6f-5c92-4670-a881-3f9c7d5b2a40
status: experimental
description: Detects any outbound connection to the PLC Exploitation cluster's
  three concentrated subnet anchors. 15 IPs across 3 /24 blocks — critical
  signal for OT/ICS environments. Also fires on OT-protocol traffic to any
  destination outside the internal OT segment.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.command_and_control
  - attack.t1071
  - ics.t0819
  - ics.t0866
logsource:
  category: network_connection
detection:
  ot_subnet_anchors:
    DestinationIp|cidr:
      - '185.82.73.0/24'
      - '175.110.121.0/24'
      - '88.80.150.0/24'
  ot_protocol_egress:
    DestinationPort:
      - 502    # Modbus TCP
      - 44818  # EtherNet/IP
      - 20000  # DNP3
      - 34962  # Profinet
      - 34963  # Profinet
      - 34964  # Profinet
    DestinationIp|expand: '%external_destinations%'
  condition: ot_subnet_anchors or ot_protocol_egress
falsepositives:
  - Legitimate OT vendor remote-support (allowlist by known-good IPs)
level: critical

Sigma 04 · SVG file with embedded script content

title: SVG File Delivery with Embedded Script Content
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a10
status: experimental
description: Detects delivery of SVG files (inbound mail attachment or web
  download) that contain embedded JavaScript. Catches the SVG Malicious Scripts
  cluster and any future SVG-based delivery.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.execution
  - attack.t1204.002
  - attack.t1059.007
logsource:
  category: file_event
detection:
  svg_delivery:
    TargetFilename|endswith: '.svg'
    FileContent|contains:
      - '

11 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Loader chain — browser/document parent + outbound web within 60s

// Pseudo-query
FROM process_creates AS pc
JOIN network_flows AS nf
  ON pc.host = nf.src_host
  AND nf.flow_time BETWEEN pc.create_time AND pc.create_time + 60s
WHERE pc.parent_process IN ('chrome.exe', 'firefox.exe', 'edge.exe',
                             'OUTLOOK.EXE', 'winword.exe', 'excel.exe',
                             'powerpnt.exe', 'AcroRd32.exe')
  AND pc.image_path MATCHES regex '\\(Downloads|Temp)\\'
  AND nf.dest_ip NOT IN (allowlisted_ranges)
  AND nf.dest_port IN (80, 443, 8080, 8443)
| PROJECT pc.host, pc.image_path, nf.dest_ip, nf.dest_domain
| SORT BY pc.create_time DESC

Hunt 02 · APT anchor first-seen (top clusters)

// Pseudo-query
FROM network_flows
WHERE dest_ip IN (
  '103.235.46.102',    -- UAT-8837
  '103.31.250.253',    -- Turla
  '104.194.159.150',   -- APT28-linked
  '104.248.134.194',   -- LAUNDRY BEAR
  '103.97.0.57'         -- Hermes AI Agent
)
  AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC

Hunt 03 · PLC Exploitation subnet + OT protocol traffic

// Pseudo-query
FROM network_flows
WHERE (dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24'))
   OR (dest_port IN (502, 44818, 20000, 34962, 34963, 34964)
       AND dest_ip NOT IN (internal_ot_segment))
| AGGREGATE BY src_ip, dest_ip, dest_port
| SORT BY flow_count DESC

Hunt 04 · BlueNoroff DNS pattern

// Pseudo-query
FROM dns_queries
WHERE query_name MATCHES regex '(?i)^[0-9]{2}[a-z]+web?\.zoom\.[a-z0-9]+\.sbs$'
   OR query_name MATCHES regex '(?i)^[0-9]{2}[a-z]+\.zoom\.web[0-9]{2}\.sbs$'
| PROJECT src_host, query_name, query_time
| SORT BY query_time DESC

12 · Operationalise in 60 minutes

Minute 00 – 15 · Block + sinkhole

  • Block all three PLC Exploitation subnet anchors: 185.82.73.0/24, 175.110.121.0/24, 88.80.150.0/24.
  • Block Brunhilda Project anchor 185.177.93.0/24 (9 concentrated IPs).
  • Block BlueNoroff anchor 45.61.163.0/24 + LAUNDRY BEAR 216.252.238.0/24.
  • Block 103.31.250.253 (Turla) + 104.194.159.150 (APT28-linked router).
  • Add outbound-deny for WebDAV traffic from non-collaboration-tool hosts.

Minute 15 – 30 · Detection content

  • Deploy Sigma 01 (universal loader behaviour) — catches GoldenEyeDog + SmartLoader without hash volatility.
  • Deploy Sigma 02 (BlueNoroff collaboration-platform DNS pattern).
  • Deploy Sigma 03 (PLC Exploitation subnet + OT-protocol egress) — critical for OT/ICS environments.
  • Deploy Sigma 04 (SVG with embedded script).

Minute 30 – 45 · Retrospective hunt

  • Run Hunt 01 (loader chain) baseline scan across last 30 days.
  • Run Hunt 02 (APT anchor first-seen) across last 90 days.
  • Run Hunt 03 (PLC Exploitation + OT-protocol egress) across last 60 days.
  • Run Hunt 04 (BlueNoroff DNS pattern) across last 30 days.

Minute 45 – 60 · Awareness + policy

  • Brief cryptocurrency-adjacent users on BlueNoroff collaboration-platform impersonation.
  • Brief HR on the Wagemole IT-worker infiltration pattern — video-verify interviews, cross-check identities.
  • For OT/ICS environments: emergency verification that no internet-accessible PLCs are exposed. Immediate Shodan-adjacent inventory recommended.
  • Update mail-gateway policy to inspect SVG file contents (treat as executable-adjacent).
// CONTINUE WITH HUNTINTEL

This briefing ships 15 indicators per type. The catalogue carries the full 77,118 unique IOCs from this week — adversary attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

13 · Frequently asked questions

25 named APTs in one week — is that unusual?

Yes. Twenty-five concurrent named APT clusters is the widest APT footprint in this catalogue year-to-date. The typical week sees 5-10 concurrent named clusters; this week's 25 is more than double baseline. What matters operationally: organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week. The APT-storm signal is a leading indicator of near-term intrusion activity.

GoldenEyeDog produced 7,848 hashes in one week. How does hash-blocking survive that?

It doesn't. Hash-blocking is fragile against polymorphic-build volume at that scale — the operator can generate new variants faster than any hash feed can catalogue them. The durable defence is behavioural loader detection (Sigma 01 above). Detect the pattern browser/document parent → downloaded binary → outbound web within 60s, and you catch the family regardless of hash variance.

Why is PLC Exploitation flagged as critical when it's only 26 IOCs?

Because it targets industrial control systems, not enterprise IT. A single successful PLC compromise can shut down a power substation, contaminate a water treatment facility, or halt a manufacturing line. The impact-per-IOC is orders of magnitude higher than typical malware. For any organisation operating OT/ICS environments, PLC Exploitation belongs in the priority-block queue regardless of IOC count.

What is Wagemole and why is it different?

Wagemole is the DPRK IT-worker infiltration operation — DPRK operatives applying to legitimate remote-work positions using fabricated identities to gain insider access to target organisations. It is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired. Detection requires HR-workflow controls (video-verify interviews, independent identity verification, second-source employment/education checks) — not detection content.

Why is SVG script delivery worth its own detection rule?

Because most email-attachment scanners don't treat SVG as executable-adjacent. SVG files can contain embedded JavaScript that executes when the file is rendered in a browser — including via inline preview in mail clients. The delivery vector defeats attachment-scanning defensive controls that would catch a malicious .exe / .doc / .zip. Adding SVG content inspection at the mail gateway closes the gap.

What confidence threshold should the SOC use for automated blocking?

High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.

Where can I see this briefing's intelligence operationally?

The HuntIntel operator console exposes every IOC with adversary attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions