HackForLab Weekly Threat Advisory · Jul 20-26 2026 · APT Storm cover · sanitised v2 · deep charcoal + crimson + gold palette · 77,118 indicators · 155 clusters · 25 attributed APT clusters · category-based footprint chart (C2 infrastructure, malware activity, APT, botnet, phishing) · this-week defining signals (15,000 loader hashes, 3 ICS/OT anchor blocks, SVG new-delivery vector)

Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)

● CTI SITREP 026·30 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-030 · July 20 – 26, 2026

APT storm week. 25 attributed APT clusters ran in parallel — the widest concurrent APT footprint observed in this catalogue year-to-date. Two loader families produced ~15,000 unique hashes combined in seven days — a polymorphic-build-farm signal that defeats hash-based defence at industrial scale. DPRK-adjacent activity double-tracked (cryptocurrency-focused APT + IT-worker infiltration campaign). Russian-aligned clusters concurrent with Middle East / North Africa regional operations. A rare and consequential signal — an ICS/OT PLC-targeted exploitation campaign across three concentrated subnet anchors targeting industrial control systems. A novel delivery vector — SVG-embedded script payloads that bypass traditional attachment scanners. If your CTI team was quiet this week, this briefing is your priority reading list.

Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, subnet anchors, top IOCs per indicator type, four production-ready Sigma rules, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

The catalogue produced 77,118 unique IOCs across 155 clusters this cycle. Framework-infrastructure entries dominate the topline volume, but the narrow-indicator layer is the intelligence story: 3,374 unique domains + 16,316 unique hashes + 503 URLs. The hash volume alone (16,316) is the second-highest weekly count observed in this catalogue year-to-date — driven by two loader families running at industrial-scale polymorphic-build volume (~15,000 combined hashes). Every APT category is elevated: 25 attributed APT clusters concurrent is the widest APT footprint of the year.

// CTI SITREP 026·30 · July 20 – 26, 2026 · TA-2026-030
83,969
Records
77,118
Unique IOCs
20,804
High-severity
155
Clusters
25
APT clusters
60
Source feeds

Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · APT Storm — 25 attributed clusters concurrent

Twenty-five attributed APT clusters produced fresh indicators this cycle — the widest concurrent APT footprint in the year-to-date window. The APT-category IOC total: 8,291 records across 25 attributed clusters. Cluster diversity spans DPRK-adjacent activity, Russian-aligned operations, Middle East / North Africa regional operations, multiple tracked cluster groups, and proxy-focused intrusion sets. Concurrent APT activity at this scale is a load-bearing intelligence signal — organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week.

Headline 02 · Polymorphic loader surge — ~15,000 hashes in 7 days

Two loader families produced ~15,000 unique HASH indicators combined in seven days — the largest loader-tier hash footprint of the year. Volume at that scale from a small number of families indicates a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated. The operational implication: hash-blocking is fragile against this volume. Behavioural loader detection is the durable defence layer (Sigma 01 below).

Headline 03 · ICS/OT threat surface — PLC-targeted campaign with 3 subnet anchors

A rare and operationally significant signal. A PLC-targeted exploitation campaign produced 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4 IPs, 88.80.150.0/24 with 3 IPs — 15 IPs across 3 blocks). The cluster targets industrial control systems, not enterprise IT. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. If your organisation operates any OT/ICS environment, this cluster warrants immediate attention.

Headline 04 · DPRK-adjacent double-track — cryptocurrency-focus + IT-worker infiltration

Two DPRK-adjacent operations active in parallel. A cryptocurrency-focused APT cluster (83 IOCs across DOMAIN + HASH + IP) uses a distinctive collaboration-platform-impersonation domain-naming pattern with a subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. Separately, an IT-worker infiltration campaign (64 IOCs across all 4 primary IOC types) sees DPRK-linked operatives applying to remote-work positions using fabricated identities to gain insider access. This IT-worker campaign is a HR-workflow threat, not primarily an endpoint threat — detection requires identity-verification and hiring-workflow controls, not detection content.

Headline 05 · Novel delivery vector — SVG-embedded scripts

An SVG-embedded script delivery campaign produced 25 IOCs across DOMAIN + HASH. Delivery pattern: attackers embed JavaScript payloads inside SVG image files. When the SVG is rendered in a browser (as an inline image, email attachment preview, or website asset), the embedded script executes. Bypasses many email attachment scanners that do not treat SVG as executable-adjacent. Combined with a concurrent drive-by fake-update malware campaign (143 IOCs), this cycle shows a broader shift toward browser-rendering-time payload delivery. Defensive answer: content-inspection of SVG files at the mail-gateway and web-proxy layers.


03 · Indicator type, severity, and category mix

The narrow-indicator layer is the intelligence story this week: 16,316 unique HASH indicators is the highest hash-share observed year-to-date at 21 percent (driven by polymorphic loader builds). Domain volume at 3,374 is also elevated. Severity distribution shows 27 percent HIGH (20,804 records) — well above the year-to-date baseline. APT category at 8,291 IOCs (11 percent share) is the highest APT concentration of the year.

By indicator type

Type Observations Share %
IPs 56,860
73.73%
File hashes 16,316
21.16%
Domains 3,374
4.38%
URLs 503
0.65%
Other artefacts 42
0.05%
Emails 17
0.02%
Process names 6
0.01%

By severity

Severity Observations Share %
High 20,804
26.41%
Medium 57,837
73.41%
Low 143
0.18%

By category

Category Observations Share %
C&C 53,149
64.39%
Malware-Activity 8,570
10.38%
APT 8,291
10.04%
C&C Server 5,435
6.58%
Botnet 5,000
6.06%
Phishing 1,725
2.09%
RAT 185
0.22%
Framework 65
0.08%
Spyware 44
0.05%
Ransomware-as-a-service 38
0.05%
Loader 15
0.02%
Intrusion Campaign 13
0.02%
Supply Chain 9
0.01%

04 · Cluster footprint — ranked by unique-IOC count

36 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. All names generalised into category descriptors.

# Cluster descriptor Relative footprint Unique IOCs Severity
01 Open-framework C2 infrastructure (framework tier)

C2 · DOMAIN, EMAIL, HASH, IP, URL
57,830 MEDIUM
02 High-tempo APT cluster (Cluster A)

APT · HASH
7,848 HIGH
03 Loader family A (polymorphic build)

Malware · HASH
7,115 HIGH
04 Phishing kit (broad domain infrastructure)

Phishing kit · DOMAIN, IP
1,723 MEDIUM
05 WebDAV-transport delivery campaign

Malware Campaign · HASH, IP, URL
275 HIGH
06 Open-framework C2 infrastructure (malware tier)

Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
152 HIGH
07 C2 infrastructure campaign (Cluster B)

C2 · DOMAIN, URL
151 MEDIUM
08 Commodity RAT family (Cluster C)

RAT · DOMAIN, HASH, IP, URL
109 MEDIUM
09 Drive-by / fake-update malware campaign

Malware Campaign · DOMAIN, HASH
143 HIGH
10 Malware family (Cluster D)

Malware · DOMAIN, HASH
99 HIGH
11 DPRK-adjacent APT cluster (cryptocurrency focus)

APT · DOMAIN, HASH, IP
83 HIGH
12 Malware campaign (Cluster E)

Malware Campaign · DOMAIN, HASH, IP, URL
76 HIGH
13 DPRK-adjacent IT-worker infiltration campaign

APT · DOMAIN, HASH, IP, URL
64 HIGH
14 Fake browser-extension phishing cluster

Phishing Campaign · DOMAIN, IP, OTHERS
64 LOW
15 Open remote-management framework

C2 · IP
63 MEDIUM
16 Tracked cluster group – identifier F

APT · HASH, IP
59 HIGH
17 Malware family (Cluster G)

Malware · DOMAIN, EMAIL, HASH, IP, URL
54 HIGH
18 Multi-stage RAT + implant campaign

Malware Campaign · DOMAIN, HASH, IP, URL
52 HIGH
19 Tracked cluster group – identifier H

APT · HASH, IP, URL
50 HIGH
20 Malware campaign (Cluster J)

Malware Campaign · HASH, IP, OTHERS
48 HIGH
21 Malware family (Cluster K)

Malware · DOMAIN, HASH, IP, URL
44 HIGH
22 Proxy-focused APT cluster

APT · DOMAIN, HASH, IP
41 HIGH
23 Tracked APT cluster – identifier L

APT · DOMAIN, HASH, IP
39 HIGH
24 Banking-focused malware campaign

Malware Campaign · DOMAIN, HASH, URL
34 HIGH
25 Tracked APT cluster – identifier M

APT · HASH, IP
34 HIGH
26 Regional-tracked APT cluster – identifier N

APT · DOMAIN, HASH
34 HIGH
27 Tracked cluster group – identifier P

APT · DOMAIN
34 HIGH
28 Phishing kit (Cluster Q)

Phishing kit · DOMAIN
34 MEDIUM
29 Middle East / North Africa regional operations

APT · DOMAIN, HASH, OTHERS, URL
33 HIGH
30 Info-stealer family (Cluster R)

Malware · DOMAIN, HASH, IP, URL
29 HIGH
31 Gaming-lure stealer campaign

Malware · DOMAIN, HASH, IP
29 HIGH
32 Commodity RAT family (Cluster S)

RAT · DOMAIN, HASH, IP
28 HIGH
33 C2 infrastructure with cloaking layer

Malware Campaign · DOMAIN, HASH
28 HIGH
34 Collaboration-platform phishing operation

Phishing Campaign · DOMAIN, EMAIL, HASH, URL
26 LOW
35 ICS/OT — PLC-targeted exploitation campaign

Malware Campaign · DOMAIN, HASH, IP
26 HIGH
36 SVG-embedded script delivery campaign

Malware Campaign · DOMAIN, HASH
25 HIGH

05 · Themed deep-dives

05.1 · Polymorphic loader surge — ~15,000 hashes across two families

Two loader families dominated the weekly hash footprint. The larger of the two (7,848 unique HASH indicators) and its counterpart (7,115 unique HASH indicators) together produced ~15,000 unique binaries in seven days. Volume at that scale from a small number of families indicates a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated.

Defensive actions: Push the catalogued hashes to endpoint quarantine as a baseline. But the durable defence layer is behavioural loader detection — process-tree anomalies, parent-child spawn patterns, network-flow shapes after execution. Deploy Sigma rule 01 below (universal loader-behaviour detector) as the primary defence.

05.2 · DPRK-adjacent double-track

Cryptocurrency-focused APT cluster (83 IOCs) uses a distinctive domain-naming pattern impersonating collaboration-platform video-call URLs to lure victims into clicking fake “join meeting” links. Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.

IT-worker infiltration campaign (64 IOCs across all 4 primary IOC types) sees DPRK-linked operatives applying to remote-work positions using fabricated identities to gain insider access. This is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired, not by exploiting a technical vulnerability. Detection requires identity-verification and hiring-workflow controls, not detection content.

Defensive actions: Block the subnet anchor. Alert users in cryptocurrency-adjacent roles specifically. For hiring workflows: video-verify interviews (not chat-only), verify education and employment claims independently, cross-check identity documents against second-source records, flag applicants using VPN or unusual geolocation during interviews.

05.3 · ICS/OT PLC-targeted exploitation campaign — 3 subnet anchors

The rare-and-significant signal. 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors:

  • 185.82.73.0/24 — 8 IPs concentrated
  • 175.110.121.0/24 — 4 IPs concentrated
  • 88.80.150.0/24 — 3 IPs concentrated

15 IPs across 3 blocks targeting industrial control systems. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. Utilities, manufacturing, energy, and critical-infrastructure operators are the primary victim profile.

Defensive actions: If your organisation operates any OT/ICS environment: block all three /24 anchors at the perimeter now. Verify no internet-accessible PLCs in your environment. Alert on any modbus / EtherNet-IP / DNP3 / Profinet traffic from unfamiliar external sources.

05.4 · Browser-render-time delivery — SVG scripts + drive-by fake-update

Two campaigns point at the same shift — adversaries increasingly delivering payloads via browser-render-time execution rather than direct file execution. The drive-by fake-update campaign (143 IOCs combined) compromises legitimate websites to inject fake browser-update prompts. The SVG-embedded script delivery campaign (25 IOCs) embeds JavaScript inside SVG image files that execute on browser render. Both defeat email-attachment-scanner defensive controls because the payload is not delivered as an attachment.

Defensive actions: Content inspection of SVG files at mail-gateway and web-proxy layers (treat SVG as executable-adjacent). For drive-by fake-update: detect the pattern where a user visits a legitimate-looking site, then downloads a browser-update from a non-corporate domain.

05.5 · WebDAV-transport delivery campaign (275 IOCs)

275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. WebDAV traffic frequently escapes conventional web-proxy content inspection because it is treated as file-sharing rather than web browsing.

Defensive actions: Alert on outbound WebDAV traffic from non-collaboration-tool hosts. If your environment has no legitimate WebDAV use case, block WebDAV outbound at the perimeter.

05.6 · Regional and tracked-cluster activity summary

The remaining 20-plus APT clusters cover Russian-aligned, Middle East / North Africa regional, proxy-focused, credential-access-focused, and multiple tracked-cluster group activity. Combined they represent 8,291 APT-category IOCs. Standard multi-stage APT chain applies across most: adversary-acquired-domain infrastructure → phishing initial access → second-stage payload pull → web-protocol C2 → exfil-over-C2. Detection content that fires on that universal chain (Sigma 02 below) catches most of the APT surface without per-cluster tuning.

06 · ATT&CK tactic-pressure roll-up

Tactic Top techniques observed What the pressure means IOC count
Command and Control T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling 1,147
Initial Access T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply chain 892
Execution T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1189 Command interpreter (PowerShell / CMD / VB / JS), user-execution, drive-by (SVG script) 785
Ingress Tool Transfer T1105 Second-stage payload pull — universal across every multi-stage cluster 634
Defense Evasion T1027 · T1036 · T1055 · T1070 · T1070.004 · T1562 · T1140 Obfuscation, masquerading, process injection, indicator removal, disable defences, deobfuscate 512
Credential Access T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1110.001 · T1558.003 OS credential dumping, password store theft, brute force + Kerberoasting 428
Discovery T1082 · T1057 · T1083 · T1018 · T1046 · T1482 System info, process, file, remote-system, network configuration, domain trust 356
Lateral Movement T1021 · T1021.001 · T1021.002 · T1570 Remote-desktop, SMB / admin shares, lateral tool transfer 289
Exfiltration T1041 · T1567 · T1090 Exfil over C2, exfil to web service, tunnel-based exfil 654
Persistence T1547.001 · T1543.003 · T1053.005 · T1505.003 Registry-run keys, service creation, scheduled tasks, webshell 245
Resource Development T1583.001 · T1584.001 · T1585 Adversary-acquired domains + compromised infrastructure + fabricated-identity infiltration 218
Collection T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 Local + automated collection, screen capture, input capture, session-cookie theft 187
ICS-specific T0819 · T0866 · T0836 · T0885 PLC-targeted campaign: internet-accessible device exploit, unauthorised command, modify parameter, commonly-used-port abuse 26

Detection-engineering takeaway. The universal APT chain (T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers most of the 25 attributed clusters this week. Two well-designed detectors — one on adversary-acquired-domain first-seen contact, one on the ingress-tool-transfer-plus-exfil sequence within 5 minutes — cover most of the APT surface with minimal per-cluster tuning. For the loader-heavy layer, behavioural loader-detection is the durable defence layer (Sigma 01 below).


07 · Subnet anchors — the shared-infrastructure signal

Subnet (/24) IPs Operator observation
185.177.93.0/24 9 Largest single-cluster subnet anchor of the week — 9 IPs concentrated in one /24 block.
185.82.73.0/24 8 ICS/OT-attributed subnet anchor — targets industrial control system infrastructure.
23.224.4.0/24 5 C2 infrastructure concentration.
91.92.43.0/24 4 Botnet C2 infrastructure (continues from prior weeks).
175.110.121.0/24 4 Second ICS/OT-attributed anchor.
45.138.26.0/24 4 Tracked-cluster group infrastructure.
156.247.47.0/24 4 Commodity RAT C2 infrastructure.
88.80.150.0/24 3 Third ICS/OT-attributed anchor — 3 blocks total, 15 IPs concentrated.
45.61.163.0/24 3 DPRK-adjacent APT infrastructure anchor.
45.59.122.0/24 3 RAT operator anchor.
216.252.238.0/24 3 APT-tier subnet anchor.
188.227.106.0/24 3 Tracked-cluster secondary anchor.

The asymmetric block. The ICS/OT-attributed campaign operates across three distinct /24 anchors with 15 concentrated IPs — unusual for an ICS/OT-focused cluster. Blocking all three /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across three different hosting tenants simultaneously to defeat the block. The 9-IP-in-one-/24 anchor and the 3-IP DPRK-adjacent anchor are the other high-leverage blocks.

08 · Top IOCs per indicator type

Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.]. and hxxphttp). Domain list reduced this week to remove brand-referencing entries.

Top 15 · IP addresses (High severity)

# Indicator Category Severity
01 1.94.106.150 C2 / Botnet HIGH
02 101.96.224.108 C2 / Botnet HIGH
03 103.101.85.111 C2 / Botnet HIGH
04 103.149.93.150 C2 / Botnet HIGH
05 103.235.46.102 APT HIGH
06 103.27.109.233 C2 / Botnet HIGH
07 103.31.250.253 APT HIGH
08 103.97.0.57 Malware HIGH
09 104.168.22.209 C2 / Botnet HIGH
10 104.194.133.210 RAT HIGH
11 104.194.159.150 APT HIGH
12 104.238.34.209 Loader HIGH
13 104.243.35.63 Ransomware HIGH
14 104.248.134.194 APT HIGH
15 102.117.171.29 C2 / Botnet HIGH

Top domains (High severity)

# Indicator Category Severity
01 0059595390202402400202[.]sobul[.]net Malware HIGH
02 01058telecom[.]de Malware HIGH
03 0co7tx46[.]worldofmacarons[.]com Malware HIGH
04 0xvona[.]duckdns[.]org RAT HIGH
05 0zbqnac1t4dv2t2wuodv1m[.]com Malware HIGH
06 365softupdate[.]com APT HIGH
07 4mrkjecd[.]rsudtarutung[.]com Malware HIGH
08 57b0rv7c[.]sansekerta[.]org Malware HIGH
09 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com RAT HIGH
10 5teun337[.]yummiquickway[.]com Malware HIGH
11 abcd[.]gamesen[.]icu Malware HIGH

Top 15 · File hashes (High severity)

# Indicator Category Severity
01 0002a8d9b71895c616dd52e32eb08823c79ce423a238757fcd275c13806dcb66 Malware HIGH
02 000732e37ed2431c677cca56aafbd53f Ransomware HIGH
03 000a25edc1bd2e91d65851c5171edf6facc0ca3f APT HIGH
04 000f0de250917d2d7a90c70116f0422f APT HIGH
05 0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a APT HIGH
06 00113b357f18ba5f62c3e8856871f1902f019a1a16de2e3c8a29f84de2565065 Malware HIGH
07 001c16af3cfde47a3289e5c55d72533c5c0e4bc4 APT HIGH
08 001e1824fef043f26d235ccf7eec71cdebfb419a APT HIGH
09 001e9bf4488c5bca1a81d087d2e310b4cf42f123 APT HIGH
10 001f205103af843faa77bb811ef33bd791a184e9dc629363c3da509c16f5420c Malware HIGH
11 001faaf397dde12a044efeb98efd972bdec0229c APT HIGH
12 0022520838406bf985cc7ad13487288f8f4364e823fa3d41d44c4dbee9d659ee Malware HIGH
13 0024b6045416febb3b3c80569fbb7c4fe85e3ce8112e7dba6d80b3d601ffb523 Malware HIGH
14 00295a9ed4dbc4bb25b423ccd04af37e331d42a86f48edbeff5bd811fa97b899 Malware HIGH
15 003e4e3f3f4bb96ba4ddd10a43a7b5290cc237c1 APT HIGH

Top 15 · URLs (High severity)

# Indicator Category Severity
01 hxxp[://]0xvona[.]duckdns[.]org RAT HIGH
02 hxxp[://]103.31.250.253 APT HIGH
03 hxxp[://]110.92.64.17/moo.cgi Malware HIGH
04 hxxp[://]117.175.185.81:8003/ Malware HIGH
05 hxxp[://]118.195.183.6/activity Malware HIGH
06 hxxp[://]118.31.115.178:4444/ga.js Malware HIGH
07 hxxp[://]118.31.115.178:9999/ptj Malware HIGH
08 hxxp[://]124.220.215.195:5555/pixel Malware HIGH
09 hxxp[://]124.220.215.195:9999/ca Malware HIGH
10 hxxp[://]124.223.12.165/ Framework HIGH
11 hxxp[://]129.211.215.7/dot.gif Malware HIGH
12 hxxp[://]154.3.0.70:83/cm Malware HIGH
13 hxxp[://]157.254.223.141/25/ RAT HIGH
14 hxxp[://]101.91.154.125:50001/cm Malware HIGH
15 hxxp[://]106.15.62.124:2222/push Malware HIGH
Need the full set? The catalogue carries 77,118 unique IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, category attribution, and source-feed provenance. Open HuntIntel.

09 · Sigma detection rules

Sigma 01 · Universal loader behaviour (polymorphic-build durable defence)

title: Universal Loader Behaviour — Polymorphic Build Family Detector
id: 6a2c8e1f-5b74-4930-a681-3f9b5c2e8d10
status: experimental
description: Detects the universal loader behaviour signature — a downloaded
  binary spawns from a browser or document reader parent process, then triggers
  outbound network traffic to a non-corporate destination within 60 seconds.
  Catches polymorphic-build loader families where hash-blocking is defeated
  by build-farm volume.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.execution
  - attack.t1204
  - attack.command_and_control
  - attack.t1105
  - attack.t1071.001
logsource:
  product: correlation
detection:
  s1_downloaded_binary:
    EventID: 4688
    ParentImage|endswith:
      - '\chrome.exe'
      - '\firefox.exe'
      - '\edge.exe'
      - '\OUTLOOK.EXE'
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\AcroRd32.exe'
    Image|contains:
      - '\Downloads\'
      - '\Temp\'
      - '\AppData\Local\Temp\'
  s2_outbound_web:
    EventID: 5156
    DestinationPort: [80, 443, 8080, 8443]
    DestinationIp|expand: '%non_corporate_destinations%'
  condition: s1_downloaded_binary and s2_outbound_web within 60s
falsepositives:
  - Legitimate software installers from allowlisted domains
level: high

Sigma 02 · Universal APT chain (adversary-acquired domain first-seen)

title: Universal APT Chain — Adversary-Acquired Domain First-Seen Contact
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a90
status: experimental
description: Detects DNS or HTTP contact with a domain that (a) has been
  first-observed to your environment within the last 24 hours, (b) has a
  registration age under 30 days, and (c) is contacted from a workstation
  rather than a mail-gateway or web-proxy. Catches the universal APT
  first-stage-C2 pattern across most attributed clusters.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.resource_development
  - attack.t1583.001
logsource:
  category: dns_query
detection:
  selection:
    QueryName|first_seen_within: 24h
    QueryName|registration_age: <30d
    SourceHost|category: workstation
  condition: selection
falsepositives:
  - New corporate SaaS onboarding (allowlist by known-good tenant patterns)
level: high

Sigma 03 · PLC-targeted subnet + OT-protocol egress

title: PLC-Targeted Subnet Anchor Contact + OT-Protocol Egress (ICS/OT)
id: 8d1a4b6f-5c92-4670-a881-3f9c7d5b2a40
status: experimental
description: Detects any outbound connection to the PLC-targeted campaign's
  three concentrated subnet anchors. Also fires on OT-protocol traffic to any
  destination outside the internal OT segment. Critical signal for OT/ICS
  environments.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.command_and_control
  - attack.t1071
  - ics.t0819
  - ics.t0866
logsource:
  category: network_connection
detection:
  ot_subnet_anchors:
    DestinationIp|cidr:
      - '185.82.73.0/24'
      - '175.110.121.0/24'
      - '88.80.150.0/24'
  ot_protocol_egress:
    DestinationPort:
      - 502    # Modbus TCP
      - 44818  # EtherNet/IP
      - 20000  # DNP3
      - 34962  # Profinet
      - 34963  # Profinet
      - 34964  # Profinet
    DestinationIp|expand: '%external_destinations%'
  condition: ot_subnet_anchors or ot_protocol_egress
falsepositives:
  - Legitimate OT vendor remote-support (allowlist by known-good IPs)
level: critical

Sigma 04 · SVG file with embedded script content

title: SVG File Delivery with Embedded Script Content
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a10
status: experimental
description: Detects delivery of SVG files (inbound mail attachment or web
  download) that contain embedded JavaScript. Catches the SVG-embedded
  script delivery campaign and any future SVG-based delivery.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.execution
  - attack.t1204.002
  - attack.t1059.007
logsource:
  category: file_event
detection:
  svg_delivery:
    TargetFilename|endswith: '.svg'
    FileContent|contains:
      - '

10 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Loader chain — browser/document parent + outbound web within 60s

// Pseudo-query
FROM process_creates AS pc
JOIN network_flows AS nf
  ON pc.host = nf.src_host
  AND nf.flow_time BETWEEN pc.create_time AND pc.create_time + 60s
WHERE pc.parent_process IN ('chrome.exe', 'firefox.exe', 'edge.exe',
                             'OUTLOOK.EXE', 'winword.exe', 'excel.exe',
                             'powerpnt.exe', 'AcroRd32.exe')
  AND pc.image_path MATCHES regex '\\(Downloads|Temp)\\'
  AND nf.dest_ip NOT IN (allowlisted_ranges)
  AND nf.dest_port IN (80, 443, 8080, 8443)
| PROJECT pc.host, pc.image_path, nf.dest_ip, nf.dest_domain
| SORT BY pc.create_time DESC

Hunt 02 · APT subnet-anchor first-seen contact

// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24',
                       '45.61.163.0/24', '216.252.238.0/24', '185.177.93.0/24')
  AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC

Hunt 03 · ICS/OT subnet + OT protocol traffic

// Pseudo-query
FROM network_flows
WHERE (dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24'))
   OR (dest_port IN (502, 44818, 20000, 34962, 34963, 34964)
       AND dest_ip NOT IN (internal_ot_segment))
| AGGREGATE BY src_ip, dest_ip, dest_port
| SORT BY flow_count DESC

Hunt 04 · New-registration domain first-seen from workstations

// Pseudo-query
FROM dns_queries
WHERE first_seen_in_environment(query_name) WITHIN 24h
  AND domain_registration_age(query_name) < 30d
  AND src_host_category = 'workstation'
| PROJECT src_host, query_name, query_time
| SORT BY query_time DESC

11 · Operationalise in 60 minutes

Minute 00 – 15 · Block + sinkhole

  • Block all three ICS/OT-attributed subnet anchors: 185.82.73.0/24, 175.110.121.0/24, 88.80.150.0/24.
  • Block the largest single-cluster anchor 185.177.93.0/24 (9 concentrated IPs).
  • Block DPRK-adjacent anchor 45.61.163.0/24 + APT-tier anchor 216.252.238.0/24.
  • Add outbound-deny for WebDAV traffic from non-collaboration-tool hosts.

Minute 15 – 30 · Detection content

  • Deploy Sigma 01 (universal loader behaviour) — catches polymorphic-loader families without hash volatility.
  • Deploy Sigma 02 (universal APT chain — new-registration domain first-seen).
  • Deploy Sigma 03 (ICS/OT subnet + OT-protocol egress) — critical for OT/ICS environments.
  • Deploy Sigma 04 (SVG with embedded script).

Minute 30 – 45 · Retrospective hunt

  • Run Hunt 01 (loader chain) baseline scan across last 30 days.
  • Run Hunt 02 (APT subnet-anchor first-seen) across last 90 days.
  • Run Hunt 03 (ICS/OT subnet + OT-protocol egress) across last 60 days.
  • Run Hunt 04 (new-registration domain first-seen) across last 30 days.

Minute 45 – 60 · Awareness + policy

  • Brief cryptocurrency-adjacent users on collaboration-platform impersonation lures.
  • Brief HR on the IT-worker infiltration pattern — video-verify interviews, cross-check identities against second-source records, flag applicants using VPN or unusual geolocation.
  • For OT/ICS environments: emergency verification that no internet-accessible PLCs are exposed. Immediate external-attack-surface inventory recommended.
  • Update mail-gateway policy to inspect SVG file contents (treat as executable-adjacent).
// CONTINUE WITH HUNTINTEL

This briefing ships a selected subset per type. The catalogue carries the full 77,118 unique IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

12 · Frequently asked questions

25 attributed APT clusters in one week — is that unusual?

Yes. Twenty-five concurrent attributed APT clusters is the widest APT footprint in this catalogue year-to-date. The typical week sees 5-10 concurrent attributed clusters; this week's 25 is more than double baseline. Organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week. The APT-storm signal is a leading indicator of near-term intrusion activity.

Two loader families produced 15,000 hashes in one week. How does hash-blocking survive that?

It doesn't. Hash-blocking is fragile against polymorphic-build volume at that scale — the operator can generate new variants faster than any hash feed can catalogue them. The durable defence is behavioural loader detection (Sigma 01 above). Detect the pattern browser/document parent → downloaded binary → outbound web within 60s, and you catch the family regardless of hash variance.

Why is the PLC-targeted campaign flagged as critical when it's only 26 IOCs?

Because it targets industrial control systems, not enterprise IT. A single successful PLC compromise can shut down a power substation, contaminate a water treatment facility, or halt a manufacturing line. The impact-per-IOC is orders of magnitude higher than typical malware. For any organisation operating OT/ICS environments, this cluster belongs in the priority-block queue regardless of IOC count.

What is the IT-worker infiltration campaign and why is it different?

DPRK-linked operatives applying to legitimate remote-work positions using fabricated identities to gain insider access to target organisations. It is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired. Detection requires HR-workflow controls (video-verify interviews, independent identity verification, second-source employment/education checks) — not detection content.

Why is SVG script delivery worth its own detection rule?

Because most email-attachment scanners don't treat SVG as executable-adjacent. SVG files can contain embedded JavaScript that executes when the file is rendered in a browser — including via inline preview in mail clients. The delivery vector defeats attachment-scanning defensive controls that would catch a malicious .exe / .doc / .zip. Adding SVG content inspection at the mail gateway closes the gap.

What confidence threshold should the SOC use for automated blocking?

High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.

Where can I see this briefing's intelligence operationally?

The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions