APT storm week. 25 named APT clusters ran in parallel — the widest concurrent APT footprint observed in this catalogue year-to-date. GoldenEyeDog surged to 7,848 unique hashes in seven days — polymorphic-build-farm signal. Two DPRK-adjacent operations active (BlueNoroff impersonating collaboration-platform video URLs; Wagemole IT-worker infiltration). Three Russian-aligned clusters (Turla, APT28-linked router campaigns, LAUNDRY BEAR). Iran-Middle-East regional operations. The LARVA cluster group triple-active (LARVA-15, -17, -47). And a rare ICS/OT signal — PLC Exploitation across three concentrated subnet anchors targeting industrial control systems. If your CTI team was quiet this week, this briefing is your priority reading list.
Sectioned for the working analyst: cluster catalogue, deep-dives on the high-tempo names, ATT&CK technique mapping per adversary, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules, Predictive Intelligence weaponisation forecast, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
02 · Five headlines
03 · IOC / severity / category mix
04 · Top adversary clusters
05 · Cluster deep-dives
06 · ATT&CK per adversary
07 · Tactic-pressure roll-up
08 · Subnet anchors
08b · Predictive intelligence
09 · Top 15 IOCs per type
10 · Sigma detection rules
11 · Hunt queries
12 · Operationalise in 60 min
13 · FAQ
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and adversary cluster pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
The catalogue produced 77,118 unique IOCs across 155 adversary clusters this cycle. Framework-infrastructure entries dominate the topline volume (as usual), but the narrow-indicator layer is the intelligence story: 3,374 unique domains + 16,316 unique hashes + 503 URLs. The hash volume alone (16,316) is the second-highest weekly count observed in this catalogue this year — driven by two clusters (GoldenEyeDog at 7,848 and SmartLoader at 7,115) running at industrial-scale polymorphic-build volume. Every APT category is elevated: 25 named APT clusters concurrent is the widest APT footprint of the year.
Catalogued, ML-scored, ATT&CK-tagged. Every record carries adversary attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · APT Storm — 25 named clusters concurrent
Twenty-five named APT clusters produced fresh indicators this cycle — the widest concurrent APT footprint in the year-to-date window. The APT-category IOC total: 8,291 records across 25 named actors. Cluster diversity spans DPRK-adjacent (BlueNoroff, Wagemole), Russian-aligned (Turla, APT28-linked router campaigns, LAUNDRY BEAR), Iran-Middle-East regional operations, the LARVA cluster group (LARVA-15, -17, -47), UAT/UAC-tracked clusters, and the JadeProx / GoldenEyeDog / TAG-195 named clusters. Concurrent activity at this scale is a load-bearing intelligence signal.
Headline 02 · GoldenEyeDog — 7,848 unique hashes in 7 days
The single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators this cycle. Volume at that scale from a single named cluster suggests a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated. The operational implication: the hash-blocklist layer is fragile against this volume. Behavioural loader-detection is the durable defence layer. SmartLoader (7,115 hashes) shows the same industrial-scale build signal from a different family.
Headline 03 · ICS/OT threat surface — PLC Exploitation, 3 subnet anchors
A rare and operationally significant signal. The PLC Exploitation cluster produced 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4 IPs, 88.80.150.0/24 with 3 IPs — 15 IPs across 3 blocks). PLC = Programmable Logic Controller. The cluster targets industrial control systems, not enterprise IT. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. If your organisation operates any OT/ICS environment, this cluster warrants immediate attention.
Headline 04 · DPRK double-track — BlueNoroff + Wagemole
Two DPRK-adjacent operations active in parallel. BlueNoroff (83 IOCs) uses a distinctive domain-naming pattern impersonating collaboration-platform video URLs (02webus[.]zoom[.]02us[.]sbs, 05us[.]zoom[.]web05[.]sbs, etc.) with a subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. Separately, Wagemole (64 IOCs across all 4 primary IOC types) is the IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is a HR-workflow threat, not an endpoint threat — detection requires identity-verification and hiring-workflow controls, not detection content.
Headline 05 · Novel delivery vector — SVG malicious scripts
The SVG Malicious Scripts cluster produced 25 IOCs across DOMAIN + HASH. Delivery pattern: attackers embed JavaScript payloads inside SVG image files. When the SVG is rendered in a browser (as an inline image, email attachment preview, or website asset), the embedded script executes. Bypasses many email attachment scanners that do not treat SVG as executable-adjacent. Combined with the ClearFake drive-by cluster (143 IOCs), this cycle shows a broader shift toward browser-rendering-time payload delivery. Defensive answer: content-inspection of SVG files at the mail-gateway and web-proxy layers.
03 · Indicator type, severity, and category mix
The narrow-indicator layer is the intelligence story this week: 16,316 unique HASH indicators is the highest hash-share observed year-to-date at 21 percent (driven by GoldenEyeDog + SmartLoader polymorphic builds). Domain volume at 3,374 is also elevated. Severity distribution shows 27 percent HIGH (20,804 records) — well above the year-to-date baseline. APT category at 8,291 IOCs (11 percent share) is the highest APT concentration of the year.
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| IPs | 56,860 | 73.73% | |
| File hashes | 16,316 | 21.16% | |
| Domains | 3,374 | 4.38% | |
| URLs | 503 | 0.65% | |
| Other artefacts | 42 | 0.05% | |
| Emails | 17 | 0.02% | |
| Process names | 6 | 0.01% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 20,804 | 26.41% | |
| Medium | 57,837 | 73.41% | |
| Low | 143 | 0.18% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| C&C | 53,149 | 64.37% | |
| Malware-Activity | 8,570 | 10.38% | |
| APT | 8,291 | 10.04% | |
| C&C Server | 5,435 | 6.58% | |
| Botnet | 5,000 | 6.06% | |
| Phishing | 1,725 | 2.09% | |
| RAT | 185 | 0.22% | |
| Framework | 65 | 0.08% | |
| Spyware | 44 | 0.05% | |
| Ransomware-as-a-service | 38 | 0.05% | |
| Hacktivist Group | 16 | 0.02% | |
| Loader | 15 | 0.02% | |
| Vulnerability | 13 | 0.02% | |
| Intrusion Campaign | 13 | 0.02% | |
| Supply Chain | 9 | 0.01% |
04 · Top adversary clusters
36 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. GoldenEyeDog (7,848 hashes) and SmartLoader (7,115 hashes) are the polymorphic-build standouts. Lucid Phishing Kit (1,723 IOCs) is the broadest phishing infrastructure of the week.
| # | Adversary cluster | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Commodity C2 framework A (open-framework infrastructure)
C2 · DOMAIN, EMAIL, HASH, IP, URL
|
57,830 | MEDIUM | |
| 02 | GoldenEyeDog
Threat Actor (APT) · HASH
|
7,848 | HIGH | |
| 03 | SmartLoader
Malware · HASH
|
7,115 | HIGH | |
| 04 | Lucid
Phishing Kit · DOMAIN, IP
|
1,723 | MEDIUM | |
| 05 | WebDAV Campaign
Malware Campaign · HASH, IP, URL
|
275 | HIGH | |
| 06 | Commodity C2 framework A (malware-tier)
Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
|
152 | HIGH | |
| 07 | KongTuke C2
C2 · DOMAIN, URL
|
151 | MEDIUM | |
| 08 | AsyncRAT
Malware (RAT) · DOMAIN, HASH, IP, URL
|
109 | MEDIUM | |
| 09 | ClearFake
Malware Campaign · DOMAIN, HASH
|
143 | HIGH | |
| 10 | SourTrade
Malware · DOMAIN, HASH
|
99 | HIGH | |
| 11 | BlueNoroff
Threat Actor (APT) · DOMAIN, HASH, IP
|
83 | HIGH | |
| 12 | Knife-Cutting-the-Edge
Malware Campaign · DOMAIN, HASH, IP, URL
|
76 | HIGH | |
| 13 | Wagemole
Threat Actor (APT) · DOMAIN, HASH, IP, URL
|
64 | HIGH | |
| 14 | Fake browser-extension phishing cluster
Phishing Campaign · DOMAIN, IP, OTHERS
|
64 | LOW | |
| 15 | Open remote-management framework
C2 · IP
|
63 | MEDIUM | |
| 16 | LARVA-47
Threat Actor · HASH, IP
|
59 | HIGH | |
| 17 | LONEPAGE
Malware · DOMAIN, EMAIL, HASH, IP, URL
|
54 | HIGH | |
| 18 | Starland RAT + WLDR Implant Campaign
Malware Campaign · DOMAIN, HASH, IP, URL
|
52 | HIGH | |
| 19 | LARVA-15
Threat Actor · HASH, IP, URL
|
50 | HIGH | |
| 20 | Brunhilda Project
Malware Campaign · HASH, IP, OTHERS
|
48 | HIGH | |
| 21 | Cruciferra
Malware · DOMAIN, HASH, IP, URL
|
44 | HIGH | |
| 22 | JadeProx
Threat Actor (APT) · DOMAIN, HASH, IP
|
41 | HIGH | |
| 23 | TAG-195
Malware Campaign · DOMAIN, HASH, IP
|
39 | HIGH | |
| 24 | Lampion malware campaign
Malware Campaign · DOMAIN, HASH, URL
|
34 | HIGH | |
| 25 | UAT-8837
Threat Actor (APT) · HASH, IP
|
34 | HIGH | |
| 26 | UAC-0145
Threat Actor (APT) · DOMAIN, HASH
|
34 | HIGH | |
| 27 | LARVA-17
Threat Actor · DOMAIN
|
34 | HIGH | |
| 28 | Kali365
Phishing Kit · DOMAIN
|
34 | MEDIUM | |
| 29 | Iran-Middle-East campaign
Malware Campaign · DOMAIN, HASH, OTHERS, URL
|
33 | HIGH | |
| 30 | StealC
Malware (Stealer) · DOMAIN, HASH, IP, URL
|
29 | HIGH | |
| 31 | Fake-games stealer campaign
Malware · DOMAIN, HASH, IP
|
29 | HIGH | |
| 32 | SectopRAT
Malware (RAT) · DOMAIN, HASH, IP
|
28 | HIGH | |
| 33 | BINDCLOAK C2
Malware Campaign · DOMAIN, HASH
|
28 | HIGH | |
| 34 | Collaboration-platform phishing operation
Phishing Campaign · DOMAIN, EMAIL, HASH, URL
|
26 | LOW | |
| 35 | PLC Exploitation (ICS/OT campaign)
Malware Campaign · DOMAIN, HASH, IP
|
26 | HIGH | |
| 36 | SVG Malicious Scripts
Malware Campaign · DOMAIN, HASH
|
25 | HIGH |
05 · Cluster deep-dives — the names to act on
05.1 · GoldenEyeDog (APT) — 7,848 hashes, polymorphic build farm
The largest single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators in seven days. Volume at that scale from a single named cluster indicates a polymorphic build pipeline actively producing many binary variants per target. The operational implication is significant: hash-blocklist-based defence is fragile against this volume — the operator can generate new variants faster than any hash feed can catalogue them.
Defensive actions: Push the catalogued hashes to endpoint quarantine as a baseline. But the durable defence layer is behavioural loader detection — process-tree anomalies, parent-child spawn patterns, network-flow shapes after execution. Deploy Sigma rule 01 below (universal loader-behaviour detector) as the primary defence against this cluster.
05.2 · SmartLoader — 7,115 hashes, industrial-scale build
Same polymorphic-build signal as GoldenEyeDog from a different family. 7,115 unique HASH indicators across the cycle. SmartLoader is a loader family designed to fetch and execute second-stage payloads. Standard commodity-loader tradecraft, industrial-scale build tempo.
Defensive actions: Same as GoldenEyeDog — hash-block as baseline, behavioural loader detection as durable defence.
05.3 · BlueNoroff (DPRK APT) — collaboration-platform impersonation
83 IOCs across DOMAIN + HASH + IP with a distinctive domain-naming pattern: 02webus[.]zoom[.]02us[.]sbs, 02webus[.]zoom[.]web02[.]sbs, 05us[.]zoom[.]web05[.]sbs, 06usweb[.]zoom[.]us06[.]sbs. The pattern impersonates collaboration-platform video-call URLs to lure victims into clicking fake “join meeting” links. Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.
Defensive actions: Regex-block the naming pattern at the DNS resolver: ^\d{2}[a-z]+\.zoom\.[a-z0-9]+\.sbs$. Block the subnet anchor. Alert users in cryptocurrency-adjacent roles specifically.
05.4 · Wagemole (DPRK IT-worker infiltration)
64 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired, not by exploiting a technical vulnerability.
Defensive actions: HR-workflow controls: video-verify interviews (not chat-only), verify education and employment claims independently, cross-check identity documents against second-source records, flag applicants using VPN or unusual geolocation during interviews. Deploy the catalogued IOCs as watchlist targets for outbound corporate-network traffic after any suspected Wagemole-profile hire.
05.5 · PLC Exploitation — ICS/OT threat with 3 subnet anchors
The rare-and-significant signal. 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors:
185.82.73.0/24— 8 IPs concentrated175.110.121.0/24— 4 IPs concentrated88.80.150.0/24— 3 IPs concentrated
15 IPs across 3 blocks targeting industrial control systems. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. Utilities, manufacturing, energy, and critical-infrastructure operators are the primary victim profile.
Defensive actions: If your organisation operates any OT/ICS environment: block all three /24 anchors at the perimeter now. Verify no internet-accessible PLCs in your environment (Shodan-search-adjacent inventory). Alert on any modbus / EtherNet-IP / DNP3 / Profinet traffic from unfamiliar external sources.
05.6 · Russian-aligned APT triad (Turla + APT28-linked + LAUNDRY BEAR)
Three concurrent Russian-aligned clusters active. Turla APT at IP anchor 103.31.250.253. APT28-linked router campaigns at 104.194.159.150 — targets network-edge router firmware for long-persistence intrusion. LAUNDRY BEAR at 104.248.134.194 with 3 IPs concentrated in 216.252.238.0/24. Combined footprint suggests coordinated regional operational tempo.
Defensive actions: Block all catalogued anchor IPs. For router-focused activity, prioritise firmware integrity scans on network-edge appliances. Hunt for anomalous configuration changes on internet-facing routers.
05.7 · LARVA cluster group (LARVA-15, -17, -47)
Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus. LARVA-47 has a subnet anchor at 45.138.26.0/24 with 4 IPs and a second anchor at 188.227.106.0/24 with 3 IPs.
05.8 · ClearFake drive-by + SVG script delivery — browser-render-time payload delivery
Two clusters point at the same shift — adversaries increasingly delivering payloads via browser-render-time execution rather than direct file execution. ClearFake (143 IOCs combined) compromises legitimate websites to inject fake browser-update prompts. SVG Malicious Scripts (25 IOCs) embed JavaScript inside SVG image files that execute on browser render. Both defeat email-attachment-scanner defensive controls because the payload is not delivered as an attachment.
Defensive actions: Content inspection of SVG files at mail-gateway and web-proxy layers (treat SVG as executable-adjacent). For ClearFake, detect the fake-update-prompt pattern: user visits a legitimate-looking site, then downloads a browser-update from a non-corporate domain.
05.9 · Iran-Middle-East regional campaign
33 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile (T1566, T1190, T1078, T1059, T1105, T1071, T1021, T1003, T1041) indicates full-attack-lifecycle intrusion capability.
05.10 · WebDAV Campaign (275 IOCs) — alternative delivery transport
275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. WebDAV traffic frequently escapes conventional web-proxy content inspection because it is treated as file-sharing rather than web browsing.
Defensive actions: Alert on outbound WebDAV traffic from non-collaboration-tool hosts. If your environment has no legitimate WebDAV use case, block WebDAV outbound at the perimeter.
06 · ATT&CK mapping per named cluster
Per-cluster technique mapping with operational narrative. Detection content that fires on these techniques catches the cluster even after IOC rotation.
| Cluster | ATT&CK techniques observed | Operational narrative |
|---|---|---|
| GoldenEyeDog (APT) | T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1027 · T1105 · T1071.001 · T1041 | 7,848 unique hashes — the largest single-cluster hash footprint observed in this catalogue year-to-date. Volume suggests a polymorphic build pipeline actively producing many binary variants per target. Standard APT delivery chain: acquired domains + spearphishing attachment + user-execution + obfuscation + second-stage pull + web-protocol C2 + exfil. |
| SmartLoader | T1204.002 · T1059.001 · T1105 · T1027 · T1071.001 | 7,115 unique hashes — same polymorphic-build-farm signal. Loader family designed to fetch and execute second-stage payloads. Hash-block layer is fragile against this volume; behavioural loader-detection is the durable defence. |
| Lucid Phishing Kit | T1566.002 · T1583.001 · T1584.001 · T1056.007 · T1539 · T1071.001 | 1,723 IOCs across DOMAIN + IP. Phishing-kit infrastructure with adversary-in-the-middle capability — session-cookie theft after credential capture. Broad phishing-domain footprint suggests operator running many concurrent campaigns. |
| BlueNoroff (DPRK APT) | T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T1041 | 83 IOCs across DOMAIN + HASH + IP. Distinctive domain naming pattern: *.zoom.*.sbs impersonating collaboration-platform video URLs (02webus.zoom.02us.sbs, 05us.zoom.web05.sbs, etc.). Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. |
| Wagemole (DPRK) | T1583.001 · T1566.002 · T1585.001 · T1585.002 · T1204 · T1059 | 64 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Detection requires HR-workflow controls, not endpoint content. |
| Turla APT (Russian-aligned) | T1071 · T1105 · T1059 · T1041 · T1027 · T1095 · T1568 | IP anchor at 103.31.250.253. Web-protocol C2 + second-stage pull + command-interpreter + exfil + obfuscation + non-app-layer C2 fallback + dynamic resolution. |
| APT28-linked router campaigns (Russian) | T1595 · T1190 · T1210 · T1105 · T1071 | Router-focused compromise cluster — IP 104.194.159.150 observed. Public-app scanning + exploitation of network infrastructure + inbound C2 from operator to compromised router. Detection focus: firmware integrity + configuration drift on network-edge devices. |
| LAUNDRY BEAR (APT) | T1583.001 · T1566 · T1071.001 · T1041 | 3 IPs concentrated in 216.252.238.0/24. Standard APT tradecraft — adversary-acquired domains, phishing initial access, web-protocol C2, exfil. |
| UAT-8837 (APT) | T1190 · T1078 · T1110.001 · T1505.003 · T1059.001 · T1105 · T1021.001 · T1003.001 · T1082 · T1041 · T1090 · T1543.003 · T1558.003 | 34 IOCs across HASH + IP. Broad TTP profile — public-app exploit, valid-account credential access via password spraying, webshell persistence, credential dumping, Kerberoasting (T1558.003), proxy tunnelling. Full-attack-lifecycle cluster. |
| UAC-0145 (Ukrainian-tracked APT) | T1583.001 · T1566 · T1105 · T1071 · T1041 | 34 IOCs across DOMAIN + HASH. Adversary-acquired domain infrastructure (365softupdate[.]com-style software-update lure naming). |
| JadeProx (APT) | T1583.001 · T1090 · T1071 · T1105 · T1041 | 41 IOCs across DOMAIN + HASH + IP. Proxy-tunnelling APT cluster. |
| LARVA cluster group (LARVA-15, LARVA-17, LARVA-47) | T1566.001 · T1566.002 · T1078 · T1059.001 · T1105 · T1071.001 · T1555 · T1552.001 · T1005 · T1041 · T1070.004 | Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain, with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus. |
| Iran-Middle-East campaign | T1566.001 · T1566.002 · T1190 · T1078 · T1059.001 · T1105 · T1071.001 · T1021.001 · T1003.001 · T1005 · T1041 · T1070.004 | 33 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile suggests full-attack-lifecycle intrusion capability. |
| PLC Exploitation (ICS/OT) | T0819 · T0866 · T0836 · T0885 | 26 IOCs across DOMAIN + HASH + IP with 3 subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4, 88.80.150.0/24 with 3). ICS ATT&CK techniques: exploit of internet-accessible device, unauthorised command execution, modify parameter, commonly-used-port abuse. Rare in this catalogue when observed — targets industrial control systems, not IT enterprise. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. |
| SVG Malicious Scripts | T1204.002 · T1059.007 · T1027 · T1105 | 25 IOCs across DOMAIN + HASH. Novel delivery pattern: SVG image files carrying embedded JavaScript that executes when the SVG is rendered in a browser. Bypasses many email attachment scanners which do not treat SVG as executable-adjacent. |
| ClearFake (drive-by + fake-update) | T1189 · T1204.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T1566.002 · T1036 · T1027 | 143 IOCs combined. Compromised legitimate websites inject a fake browser-update prompt; user clicks; malicious payload is delivered. Detection focus: unexpected browser-update download from a non-corporate domain immediately after a normal-looking web visit. |
| AsyncRAT | T1566.001 · T1204 · T1105 · T1071.001 · T1041 · T1547.001 | 109 IOCs across all 4 primary IOC types. Standard commodity-RAT chain — spearphish → user-execute → second-stage → web-protocol C2 → exfil → registry persistence. |
| KongTuke C2 infrastructure | T1071 | 151 IOCs across DOMAIN + URL. C2-infrastructure surge with distinctive path patterns. Watch outbound traffic for the catalogued endpoints. |
| WebDAV Campaign | T1105 · T1071.001 · T1204 · T1027 | 275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. Detection focus: outbound WebDAV traffic from non-collaboration hosts. |
| BINDCLOAK C2 | T1071 · T1571 · T1105 | 28 IOCs across DOMAIN + HASH. Non-standard-port C2 with cloaking layer. |
| StealC (Stealer) | T1555 · T1005 · T1041 | Full 4-type footprint. Password-store theft + local data collection + exfil over C2. |
| Brunhilda Project | T1583.001 · T1584.001 · T1566.002 · T1204.001 · T1204.002 · T1105 · T1059.001 · T1071.001 | 48 IOCs across HASH + IP + OTHERS. Largest single-cluster subnet anchor of the week (185.177.93.0/24 with 9 IPs). Distribution-focused campaign. |
Detection-engineering takeaway. The universal APT chain (
T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers most of the 25 named clusters this week. Two well-designed detectors — one on adversary-acquired-domain first-seen contact, one on the ingress-tool-transfer-plus-exfil sequence within 5 minutes — cover most of the APT surface with minimal per-cluster tuning. For the loader-heavy layer (GoldenEyeDog + SmartLoader), behavioural loader-detection is the durable defence layer (Sigma 01 below).
07 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Command and Control | T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 | Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling | 1,147 |
| Initial Access | T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 | Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply chain | 892 |
| Execution | T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1189 | Command interpreter (PowerShell / CMD / VB / JS), user-execution, drive-by (SVG script) | 785 |
| Ingress Tool Transfer | T1105 | Second-stage payload pull — universal across every multi-stage cluster | 634 |
| Defense Evasion | T1027 · T1036 · T1055 · T1070 · T1070.004 · T1562 · T1140 | Obfuscation, masquerading, process injection, indicator removal, disable defences, deobfuscate | 512 |
| Credential Access | T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1110.001 · T1558.003 | OS credential dumping, password store theft, brute force + Kerberoasting | 428 |
| Discovery | T1082 · T1057 · T1083 · T1018 · T1046 · T1482 | System info, process, file, remote-system, network configuration, domain trust | 356 |
| Lateral Movement | T1021 · T1021.001 · T1021.002 · T1570 | Remote-desktop, SMB / admin shares, lateral tool transfer | 289 |
| Exfiltration | T1041 · T1567 · T1090 | Exfil over C2, exfil to web service, tunnel-based exfil | 654 |
| Persistence | T1547.001 · T1543.003 · T1053.005 · T1505.003 | Registry-run keys, Windows service creation, scheduled tasks, webshell | 245 |
| Resource Development | T1583.001 · T1584.001 · T1585 | Adversary-acquired domains + compromised infrastructure + fabricated identities (Wagemole) | 218 |
| Collection | T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 | Local + automated collection, screen capture, input capture, session-cookie theft | 187 |
| ICS-specific | T0819 · T0866 · T0836 · T0885 | PLC Exploitation cluster: internet-accessible device exploit, unauthorised command, modify parameter, commonly-used-port abuse | 26 |
08 · Subnet anchors — the shared-infrastructure signal
| Subnet (/24) | IPs | Adversary cluster | Operator observation |
|---|---|---|---|
| 185.177.93.0/24 | 9 | Brunhilda Project | The week’s largest single-cluster subnet anchor — 9 IPs concentrated. |
| 185.82.73.0/24 | 8 | PLC Exploitation | Second-largest anchor + operationally rare — targets ICS/OT infrastructure. |
| 23.224.4.0/24 | 5 | CRPXO C2 | C2 infrastructure concentration |
| 91.92.43.0/24 | 4 | Tsundere botnet | Botnet C2 (continues from prior weeks) |
| 175.110.121.0/24 | 4 | PLC Exploitation | Second PLC Exploitation anchor |
| 45.138.26.0/24 | 4 | LARVA-47 | LARVA cluster infrastructure |
| 156.247.47.0/24 | 4 | DCRat | Commodity RAT C2 |
| 88.80.150.0/24 | 3 | PLC Exploitation | Third PLC Exploitation anchor — 3 blocks total, 15 IPs |
| 45.61.163.0/24 | 3 | BlueNoroff (APT) | DPRK-aligned APT infrastructure anchor |
| 45.59.122.0/24 | 3 | SectopRAT | RAT operator anchor |
| 216.252.238.0/24 | 3 | LAUNDRY BEAR (APT) | APT-tier subnet anchor |
| 188.227.106.0/24 | 3 | LARVA-47 | Second LARVA-47 anchor |
The asymmetric block. PLC Exploitation operates across three distinct /24 anchors with 15 concentrated IPs — unusual for an ICS/OT-focused cluster. Blocking all three /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across three different hosting tenants simultaneously to defeat the block. Brunhilda Project (9 IPs in a single /24) and BlueNoroff (3 IPs concentrated) are the other high-leverage blocks.
08b · Predictive intelligence — forecast weaponisation
Retrospective indicators tell you what has happened; predictive indicators tell you what is about to. This week’s catalogue-driven forecast layer surfaces three infrastructure blocks with a high forward-looking probability of adversary weaponisation. Derived from passive-DNS drift, registration-velocity clustering, hosting-tenant reputation drift, and pattern-match against previously-catalogued operator behaviours. Push into your perimeter watchlist now — not because they are compromised today, but because they are the highest-probability rotation candidates for adversary use over the next week.
| Infrastructure signal | Forecast window | Confidence | Signal profile |
|---|---|---|---|
| 185.82.73.0/24 | 3 DAYS | HIGH | Imminent forecast. Already anchoring 8 PLC Exploitation IPs; velocity + rotation pattern indicates further hosts in the same block are candidate operator staging. |
| 185.177.93.0/24 | 5 DAYS | HIGH | Brunhilda Project anchor with 9 concentrated IPs — the block’s remaining ~247 addresses are rotation candidates. CIDR block-candidate. |
| 45.X.X.0/24 | 6 DAYS | MEDIUM | Broad-range staging block adjacent to LARVA-47 + BlueNoroff + SectopRAT anchors. Composite rotation signal across multiple operators. |
How the forecast is derived
The forward-looking signal combines four inputs. Passive-DNS drift — how fast the block’s resolutions are changing relative to its historical baseline. Registration-velocity clustering — adjacent-block domain-registration rates compared against operator-fingerprint baselines. Hosting-tenant reputation drift — whether the anchor’s hosting tenant is trending toward adversary-adjacent reputation classes. And pattern-match against catalogued operator behaviours — whether the block’s early observable signature (open ports, TLS fingerprints, cert patterns) resembles any known operator anchor from the last 90 days. When two or more inputs converge, the block enters the forecast layer with a days-to-weaponisation estimate.
Operational actions
- Perimeter watchlist — add all three anchors to a watchlist lane (not automatic block) that alerts on any outbound contact.
- 3-day forecast (185.82.73.0/24) already-anchoring PLC Exploitation warrants provisional blocking of the /24 at the perimeter now if your environment has no legitimate business use in that range.
- CIDR-level block for the discrete
185.177.93.0/24anchor (Brunhilda Project). - Retrospective hunt — run a 90-day historical lookback for any past contact with these anchor ranges.
What predictive intelligence gives you. The classical intelligence catalogue tells you what has been observed already; the predictive layer tells you what is about to be observed. That shift buys the SOC a lead time it does not otherwise have — block an operator anchor before the operator’s rotation reaches you, not after your first compromise. The forecast is probabilistic, not deterministic — treat the days-to-weaponisation estimates as watchlist priorities, not automated-blocking triggers.
09 · Top 15 IOCs per indicator type
Operator-grade extractions. All indicators are defanged (re-fang on import: [.] → . and hxxp → http).
Top 15 · IP addresses (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 1.94.106.150 | VShell (C2) | Botnet | HIGH |
| 02 | 101.96.224.108 | VShell (C2) | Botnet | HIGH |
| 03 | 103.101.85.111 | Quasar RAT | Botnet | HIGH |
| 04 | 103.149.93.150 | VShell (C2) | Botnet | HIGH |
| 05 | 103.235.46.102 | UAT-8837 (APT) | APT | HIGH |
| 06 | 103.27.109.233 | Quasar RAT | Botnet | HIGH |
| 07 | 103.31.250.253 | Turla APT | APT | HIGH |
| 08 | 103.97.0.57 | Hermes AI Agent | Malware | HIGH |
| 09 | 104.168.22.209 | VShell (C2) | Botnet | HIGH |
| 10 | 104.194.133.210 | SectopRAT | RAT | HIGH |
| 11 | 104.194.159.150 | APT28-linked router | APT | HIGH |
| 12 | 104.238.34.209 | Ragnar Loader | Loader | HIGH |
| 13 | 104.243.35.63 | Cl0p ransomware | Ransomware | HIGH |
| 14 | 104.248.134.194 | LAUNDRY BEAR (APT) | APT | HIGH |
| 15 | 102.117.171.29 | Unknown malware C2 | Botnet | HIGH |
Top 15 · Domains (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 0059595390202402400202[.]sobul[.]net | LARVA-17 | Malware | HIGH |
| 02 | 01058telecom[.]de | SVG Malicious Scripts | Malware | HIGH |
| 03 | 02webus[.]zoom[.]02us[.]sbs | BlueNoroff (APT) | APT | HIGH |
| 04 | 02webus[.]zoom[.]web02[.]sbs | BlueNoroff (APT) | APT | HIGH |
| 05 | 05us[.]zoom[.]web05[.]sbs | BlueNoroff (APT) | APT | HIGH |
| 06 | 06usweb[.]zoom[.]us06[.]sbs | BlueNoroff (APT) | APT | HIGH |
| 07 | 0co7tx46[.]worldofmacarons[.]com | ClearFake | Malware | HIGH |
| 08 | 0xvona[.]duckdns[.]org | Chalubo RAT | RAT | HIGH |
| 09 | 0zbqnac1t4dv2t2wuodv1m[.]com | Cruciferra | Malware | HIGH |
| 10 | 365softupdate[.]com | UAC-0145 (APT) | APT | HIGH |
| 11 | 4mrkjecd[.]rsudtarutung[.]com | ClearFake | Malware | HIGH |
| 12 | 57b0rv7c[.]sansekerta[.]org | ClearFake | Malware | HIGH |
| 13 | 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com | SectopRAT | RAT | HIGH |
| 14 | 5teun337[.]yummiquickway[.]com | ClearFake | Malware | HIGH |
| 15 | abcd[.]gamesen[.]icu | Commodity C2 framework A | Malware | HIGH |
Top 15 · File hashes (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | 0002a8d9b71895c616dd52e32eb08823c79ce423a238757fcd275c13806dcb66 | SmartLoader | Malware | HIGH |
| 02 | 000732e37ed2431c677cca56aafbd53f | FadeSEC Ransomware | Ransomware | HIGH |
| 03 | 000a25edc1bd2e91d65851c5171edf6facc0ca3f | GoldenEyeDog (APT) | APT | HIGH |
| 04 | 000f0de250917d2d7a90c70116f0422f | GoldenEyeDog (APT) | APT | HIGH |
| 05 | 0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a | GoldenEyeDog (APT) | APT | HIGH |
| 06 | 00113b357f18ba5f62c3e8856871f1902f019a1a16de2e3c8a29f84de2565065 | SmartLoader | Malware | HIGH |
| 07 | 001c16af3cfde47a3289e5c55d72533c5c0e4bc4 | GoldenEyeDog (APT) | APT | HIGH |
| 08 | 001e1824fef043f26d235ccf7eec71cdebfb419a | GoldenEyeDog (APT) | APT | HIGH |
| 09 | 001e9bf4488c5bca1a81d087d2e310b4cf42f123 | GoldenEyeDog (APT) | APT | HIGH |
| 10 | 001f205103af843faa77bb811ef33bd791a184e9dc629363c3da509c16f5420c | SmartLoader | Malware | HIGH |
| 11 | 001faaf397dde12a044efeb98efd972bdec0229c | GoldenEyeDog (APT) | APT | HIGH |
| 12 | 0022520838406bf985cc7ad13487288f8f4364e823fa3d41d44c4dbee9d659ee | SmartLoader | Malware | HIGH |
| 13 | 0024b6045416febb3b3c80569fbb7c4fe85e3ce8112e7dba6d80b3d601ffb523 | SmartLoader | Malware | HIGH |
| 14 | 00295a9ed4dbc4bb25b423ccd04af37e331d42a86f48edbeff5bd811fa97b899 | SmartLoader | Malware | HIGH |
| 15 | 003e4e3f3f4bb96ba4ddd10a43a7b5290cc237c1 | GoldenEyeDog (APT) | APT | HIGH |
Top 15 · URLs (High severity)
| # | Indicator | Adversary | Category | Severity |
|---|---|---|---|---|
| 01 | hxxp[://]0xvona[.]duckdns[.]org | Chalubo RAT | RAT | HIGH |
| 02 | hxxp[://]103.31.250.253 | Turla APT | APT | HIGH |
| 03 | hxxp[://]110.92.64.17/moo.cgi | Knife-Cutting-the-Edge | Malware | HIGH |
| 04 | hxxp[://]117.175.185.81:8003/ | Knife-Cutting-the-Edge | Malware | HIGH |
| 05 | hxxp[://]118.195.183.6/activity | Commodity C2 framework A | Malware | HIGH |
| 06 | hxxp[://]118.31.115.178:4444/ga.js | Commodity C2 framework A | Malware | HIGH |
| 07 | hxxp[://]118.31.115.178:9999/ptj | Commodity C2 framework A | Malware | HIGH |
| 08 | hxxp[://]124.220.215.195:5555/pixel | Commodity C2 framework A | Malware | HIGH |
| 09 | hxxp[://]124.220.215.195:9999/ca | Commodity C2 framework A | Malware | HIGH |
| 10 | hxxp[://]124.223.12.165/ | Commodity C2 framework A | Framework | HIGH |
| 11 | hxxp[://]129.211.215.7/dot.gif | Commodity C2 framework A | Malware | HIGH |
| 12 | hxxp[://]154.3.0.70:83/cm | Commodity C2 framework A | Malware | HIGH |
| 13 | hxxp[://]157.254.223.141/25/ | Remcos | RAT | HIGH |
| 14 | hxxp[://]101.91.154.125:50001/cm | Commodity C2 framework A | Malware | HIGH |
| 15 | hxxp[://]106.15.62.124:2222/push | Commodity C2 framework A | Malware | HIGH |
10 · Sigma detection rules
Sigma 01 · Universal loader behaviour (GoldenEyeDog + SmartLoader durable defence)
title: Universal Loader Behaviour — Polymorphic Build Family Detector
id: 6a2c8e1f-5b74-4930-a681-3f9b5c2e8d10
status: experimental
description: Detects the universal loader behaviour signature — a downloaded
binary spawns from a browser or document reader parent process, then triggers
outbound network traffic to a non-corporate destination within 60 seconds.
Catches polymorphic-build families (GoldenEyeDog, SmartLoader, and similar)
where hash-blocking is defeated by build-farm volume.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.execution
- attack.t1204
- attack.command_and_control
- attack.t1105
- attack.t1071.001
logsource:
product: correlation
detection:
s1_downloaded_binary:
EventID: 4688
ParentImage|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\edge.exe'
- '\OUTLOOK.EXE'
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\AcroRd32.exe'
Image|contains:
- '\Downloads\'
- '\Temp\'
- '\AppData\Local\Temp\'
s2_outbound_web:
EventID: 5156
DestinationPort: [80, 443, 8080, 8443]
DestinationIp|expand: '%non_corporate_destinations%'
condition: s1_downloaded_binary and s2_outbound_web within 60s
falsepositives:
- Legitimate software installers from allowlisted domains
level: high
Sigma 02 · BlueNoroff collaboration-platform impersonation
title: BlueNoroff Collaboration-Platform Impersonation Domain Pattern
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a90
status: experimental
description: Detects DNS queries matching the BlueNoroff APT domain-naming
pattern impersonating collaboration-platform video-call URLs. Regex-tight
enough to avoid false positives against legitimate platform domains.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.initial_access
- attack.t1566
- attack.resource_development
- attack.t1583.001
logsource:
category: dns_query
detection:
selection:
QueryName|re:
- '^[0-9]{2}[a-z]+web?\.zoom\.[a-z0-9]+\.sbs$'
- '^[0-9]{2}[a-z]+\.zoom\.web[0-9]{2}\.sbs$'
condition: selection
falsepositives:
- None — the .sbs TLD + this naming pattern has no legitimate collaboration-platform use
level: critical
Sigma 03 · PLC Exploitation subnet + OT-protocol egress
title: PLC Exploitation Subnet Anchor Contact (ICS/OT)
id: 8d1a4b6f-5c92-4670-a881-3f9c7d5b2a40
status: experimental
description: Detects any outbound connection to the PLC Exploitation cluster's
three concentrated subnet anchors. 15 IPs across 3 /24 blocks — critical
signal for OT/ICS environments. Also fires on OT-protocol traffic to any
destination outside the internal OT segment.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.command_and_control
- attack.t1071
- ics.t0819
- ics.t0866
logsource:
category: network_connection
detection:
ot_subnet_anchors:
DestinationIp|cidr:
- '185.82.73.0/24'
- '175.110.121.0/24'
- '88.80.150.0/24'
ot_protocol_egress:
DestinationPort:
- 502 # Modbus TCP
- 44818 # EtherNet/IP
- 20000 # DNP3
- 34962 # Profinet
- 34963 # Profinet
- 34964 # Profinet
DestinationIp|expand: '%external_destinations%'
condition: ot_subnet_anchors or ot_protocol_egress
falsepositives:
- Legitimate OT vendor remote-support (allowlist by known-good IPs)
level: critical
Sigma 04 · SVG file with embedded script content
title: SVG File Delivery with Embedded Script Content
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a10
status: experimental
description: Detects delivery of SVG files (inbound mail attachment or web
download) that contain embedded JavaScript. Catches the SVG Malicious Scripts
cluster and any future SVG-based delivery.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.initial_access
- attack.t1566.001
- attack.execution
- attack.t1204.002
- attack.t1059.007
logsource:
category: file_event
detection:
svg_delivery:
TargetFilename|endswith: '.svg'
FileContent|contains:
- '










