HackForLab Weekly Threat Advisory · Jul 20-26 2026 · APT Storm cover · sanitised v2 · deep charcoal + crimson + gold palette · 77,118 indicators · 155 clusters · 25 attributed APT clusters · category-based footprint chart (C2 infrastructure, malware activity, APT, botnet, phishing) · this-week defining signals (15,000 loader hashes, 3 ICS/OT anchor blocks, SVG new-delivery vector)

Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)

● CTI SITREP 026·30 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-030 · July 20 – 26, 2026

APT storm week. 25 named APT clusters ran in parallel — the widest concurrent APT footprint observed in this catalogue year-to-date. GoldenEyeDog surged to 7,848 unique hashes in seven days — polymorphic-build-farm signal. Two DPRK-adjacent operations active (BlueNoroff impersonating collaboration-platform video URLs; Wagemole IT-worker infiltration). Three Russian-aligned clusters (Turla, APT28-linked router campaigns, LAUNDRY BEAR). Iran-Middle-East regional operations. The LARVA cluster group triple-active (LARVA-15, -17, -47). And a rare ICS/OT signal — PLC Exploitation across three concentrated subnet anchors targeting industrial control systems. If your CTI team was quiet this week, this briefing is your priority reading list.

Sectioned for the working analyst: cluster catalogue, deep-dives on the high-tempo names, ATT&CK technique mapping per adversary, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules, Predictive Intelligence weaponisation forecast, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and adversary cluster pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

The catalogue produced 77,118 unique IOCs across 155 adversary clusters this cycle. Framework-infrastructure entries dominate the topline volume (as usual), but the narrow-indicator layer is the intelligence story: 3,374 unique domains + 16,316 unique hashes + 503 URLs. The hash volume alone (16,316) is the second-highest weekly count observed in this catalogue this year — driven by two clusters (GoldenEyeDog at 7,848 and SmartLoader at 7,115) running at industrial-scale polymorphic-build volume. Every APT category is elevated: 25 named APT clusters concurrent is the widest APT footprint of the year.

// CTI SITREP 026·30 · July 20 – 26, 2026 · TA-2026-030
83,969
Records
77,118
Unique IOCs
20,804
High-severity
155
Clusters
25
Named APTs
60
Source feeds

Catalogued, ML-scored, ATT&CK-tagged. Every record carries adversary attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · APT Storm — 25 named clusters concurrent

Twenty-five named APT clusters produced fresh indicators this cycle — the widest concurrent APT footprint in the year-to-date window. The APT-category IOC total: 8,291 records across 25 named actors. Cluster diversity spans DPRK-adjacent (BlueNoroff, Wagemole), Russian-aligned (Turla, APT28-linked router campaigns, LAUNDRY BEAR), Iran-Middle-East regional operations, the LARVA cluster group (LARVA-15, -17, -47), UAT/UAC-tracked clusters, and the JadeProx / GoldenEyeDog / TAG-195 named clusters. Concurrent activity at this scale is a load-bearing intelligence signal.

Headline 02 · GoldenEyeDog — 7,848 unique hashes in 7 days

The single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators this cycle. Volume at that scale from a single named cluster suggests a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated. The operational implication: the hash-blocklist layer is fragile against this volume. Behavioural loader-detection is the durable defence layer. SmartLoader (7,115 hashes) shows the same industrial-scale build signal from a different family.

Headline 03 · ICS/OT threat surface — PLC Exploitation, 3 subnet anchors

A rare and operationally significant signal. The PLC Exploitation cluster produced 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4 IPs, 88.80.150.0/24 with 3 IPs — 15 IPs across 3 blocks). PLC = Programmable Logic Controller. The cluster targets industrial control systems, not enterprise IT. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. If your organisation operates any OT/ICS environment, this cluster warrants immediate attention.

Headline 04 · DPRK double-track — BlueNoroff + Wagemole

Two DPRK-adjacent operations active in parallel. BlueNoroff (83 IOCs) uses a distinctive domain-naming pattern impersonating collaboration-platform video URLs (02webus[.]zoom[.]02us[.]sbs, 05us[.]zoom[.]web05[.]sbs, etc.) with a subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. Separately, Wagemole (64 IOCs across all 4 primary IOC types) is the IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is a HR-workflow threat, not an endpoint threat — detection requires identity-verification and hiring-workflow controls, not detection content.

Headline 05 · Novel delivery vector — SVG malicious scripts

The SVG Malicious Scripts cluster produced 25 IOCs across DOMAIN + HASH. Delivery pattern: attackers embed JavaScript payloads inside SVG image files. When the SVG is rendered in a browser (as an inline image, email attachment preview, or website asset), the embedded script executes. Bypasses many email attachment scanners that do not treat SVG as executable-adjacent. Combined with the ClearFake drive-by cluster (143 IOCs), this cycle shows a broader shift toward browser-rendering-time payload delivery. Defensive answer: content-inspection of SVG files at the mail-gateway and web-proxy layers.


03 · Indicator type, severity, and category mix

The narrow-indicator layer is the intelligence story this week: 16,316 unique HASH indicators is the highest hash-share observed year-to-date at 21 percent (driven by GoldenEyeDog + SmartLoader polymorphic builds). Domain volume at 3,374 is also elevated. Severity distribution shows 27 percent HIGH (20,804 records) — well above the year-to-date baseline. APT category at 8,291 IOCs (11 percent share) is the highest APT concentration of the year.

By indicator type

Type Observations Share %
IPs 56,860
73.73%
File hashes 16,316
21.16%
Domains 3,374
4.38%
URLs 503
0.65%
Other artefacts 42
0.05%
Emails 17
0.02%
Process names 6
0.01%

By severity

Severity Observations Share %
High 20,804
26.41%
Medium 57,837
73.41%
Low 143
0.18%

By category

Category Observations Share %
C&C 53,149
64.37%
Malware-Activity 8,570
10.38%
APT 8,291
10.04%
C&C Server 5,435
6.58%
Botnet 5,000
6.06%
Phishing 1,725
2.09%
RAT 185
0.22%
Framework 65
0.08%
Spyware 44
0.05%
Ransomware-as-a-service 38
0.05%
Hacktivist Group 16
0.02%
Loader 15
0.02%
Vulnerability 13
0.02%
Intrusion Campaign 13
0.02%
Supply Chain 9
0.01%

04 · Top adversary clusters

36 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. GoldenEyeDog (7,848 hashes) and SmartLoader (7,115 hashes) are the polymorphic-build standouts. Lucid Phishing Kit (1,723 IOCs) is the broadest phishing infrastructure of the week.

# Adversary cluster Relative footprint Unique IOCs Severity
01 Commodity C2 framework A (open-framework infrastructure)

C2 · DOMAIN, EMAIL, HASH, IP, URL
57,830 MEDIUM
02 GoldenEyeDog

Threat Actor (APT) · HASH
7,848 HIGH
03 SmartLoader

Malware · HASH
7,115 HIGH
04 Lucid

Phishing Kit · DOMAIN, IP
1,723 MEDIUM
05 WebDAV Campaign

Malware Campaign · HASH, IP, URL
275 HIGH
06 Commodity C2 framework A (malware-tier)

Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
152 HIGH
07 KongTuke C2

C2 · DOMAIN, URL
151 MEDIUM
08 AsyncRAT

Malware (RAT) · DOMAIN, HASH, IP, URL
109 MEDIUM
09 ClearFake

Malware Campaign · DOMAIN, HASH
143 HIGH
10 SourTrade

Malware · DOMAIN, HASH
99 HIGH
11 BlueNoroff

Threat Actor (APT) · DOMAIN, HASH, IP
83 HIGH
12 Knife-Cutting-the-Edge

Malware Campaign · DOMAIN, HASH, IP, URL
76 HIGH
13 Wagemole

Threat Actor (APT) · DOMAIN, HASH, IP, URL
64 HIGH
14 Fake browser-extension phishing cluster

Phishing Campaign · DOMAIN, IP, OTHERS
64 LOW
15 Open remote-management framework

C2 · IP
63 MEDIUM
16 LARVA-47

Threat Actor · HASH, IP
59 HIGH
17 LONEPAGE

Malware · DOMAIN, EMAIL, HASH, IP, URL
54 HIGH
18 Starland RAT + WLDR Implant Campaign

Malware Campaign · DOMAIN, HASH, IP, URL
52 HIGH
19 LARVA-15

Threat Actor · HASH, IP, URL
50 HIGH
20 Brunhilda Project

Malware Campaign · HASH, IP, OTHERS
48 HIGH
21 Cruciferra

Malware · DOMAIN, HASH, IP, URL
44 HIGH
22 JadeProx

Threat Actor (APT) · DOMAIN, HASH, IP
41 HIGH
23 TAG-195

Malware Campaign · DOMAIN, HASH, IP
39 HIGH
24 Lampion malware campaign

Malware Campaign · DOMAIN, HASH, URL
34 HIGH
25 UAT-8837

Threat Actor (APT) · HASH, IP
34 HIGH
26 UAC-0145

Threat Actor (APT) · DOMAIN, HASH
34 HIGH
27 LARVA-17

Threat Actor · DOMAIN
34 HIGH
28 Kali365

Phishing Kit · DOMAIN
34 MEDIUM
29 Iran-Middle-East campaign

Malware Campaign · DOMAIN, HASH, OTHERS, URL
33 HIGH
30 StealC

Malware (Stealer) · DOMAIN, HASH, IP, URL
29 HIGH
31 Fake-games stealer campaign

Malware · DOMAIN, HASH, IP
29 HIGH
32 SectopRAT

Malware (RAT) · DOMAIN, HASH, IP
28 HIGH
33 BINDCLOAK C2

Malware Campaign · DOMAIN, HASH
28 HIGH
34 Collaboration-platform phishing operation

Phishing Campaign · DOMAIN, EMAIL, HASH, URL
26 LOW
35 PLC Exploitation (ICS/OT campaign)

Malware Campaign · DOMAIN, HASH, IP
26 HIGH
36 SVG Malicious Scripts

Malware Campaign · DOMAIN, HASH
25 HIGH

05 · Cluster deep-dives — the names to act on

05.1 · GoldenEyeDog (APT) — 7,848 hashes, polymorphic build farm

The largest single-cluster hash footprint of the year. GoldenEyeDog generated 7,848 unique HASH indicators in seven days. Volume at that scale from a single named cluster indicates a polymorphic build pipeline actively producing many binary variants per target. The operational implication is significant: hash-blocklist-based defence is fragile against this volume — the operator can generate new variants faster than any hash feed can catalogue them.

Defensive actions: Push the catalogued hashes to endpoint quarantine as a baseline. But the durable defence layer is behavioural loader detection — process-tree anomalies, parent-child spawn patterns, network-flow shapes after execution. Deploy Sigma rule 01 below (universal loader-behaviour detector) as the primary defence against this cluster.

05.2 · SmartLoader — 7,115 hashes, industrial-scale build

Same polymorphic-build signal as GoldenEyeDog from a different family. 7,115 unique HASH indicators across the cycle. SmartLoader is a loader family designed to fetch and execute second-stage payloads. Standard commodity-loader tradecraft, industrial-scale build tempo.

Defensive actions: Same as GoldenEyeDog — hash-block as baseline, behavioural loader detection as durable defence.

05.3 · BlueNoroff (DPRK APT) — collaboration-platform impersonation

83 IOCs across DOMAIN + HASH + IP with a distinctive domain-naming pattern: 02webus[.]zoom[.]02us[.]sbs, 02webus[.]zoom[.]web02[.]sbs, 05us[.]zoom[.]web05[.]sbs, 06usweb[.]zoom[.]us06[.]sbs. The pattern impersonates collaboration-platform video-call URLs to lure victims into clicking fake “join meeting” links. Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.

Defensive actions: Regex-block the naming pattern at the DNS resolver: ^\d{2}[a-z]+\.zoom\.[a-z0-9]+\.sbs$. Block the subnet anchor. Alert users in cryptocurrency-adjacent roles specifically.

05.4 · Wagemole (DPRK IT-worker infiltration)

64 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Wagemole is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired, not by exploiting a technical vulnerability.

Defensive actions: HR-workflow controls: video-verify interviews (not chat-only), verify education and employment claims independently, cross-check identity documents against second-source records, flag applicants using VPN or unusual geolocation during interviews. Deploy the catalogued IOCs as watchlist targets for outbound corporate-network traffic after any suspected Wagemole-profile hire.

05.5 · PLC Exploitation — ICS/OT threat with 3 subnet anchors

The rare-and-significant signal. 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors:

  • 185.82.73.0/24 — 8 IPs concentrated
  • 175.110.121.0/24 — 4 IPs concentrated
  • 88.80.150.0/24 — 3 IPs concentrated

15 IPs across 3 blocks targeting industrial control systems. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. Utilities, manufacturing, energy, and critical-infrastructure operators are the primary victim profile.

Defensive actions: If your organisation operates any OT/ICS environment: block all three /24 anchors at the perimeter now. Verify no internet-accessible PLCs in your environment (Shodan-search-adjacent inventory). Alert on any modbus / EtherNet-IP / DNP3 / Profinet traffic from unfamiliar external sources.

05.6 · Russian-aligned APT triad (Turla + APT28-linked + LAUNDRY BEAR)

Three concurrent Russian-aligned clusters active. Turla APT at IP anchor 103.31.250.253. APT28-linked router campaigns at 104.194.159.150 — targets network-edge router firmware for long-persistence intrusion. LAUNDRY BEAR at 104.248.134.194 with 3 IPs concentrated in 216.252.238.0/24. Combined footprint suggests coordinated regional operational tempo.

Defensive actions: Block all catalogued anchor IPs. For router-focused activity, prioritise firmware integrity scans on network-edge appliances. Hunt for anomalous configuration changes on internet-facing routers.

05.7 · LARVA cluster group (LARVA-15, -17, -47)

Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus. LARVA-47 has a subnet anchor at 45.138.26.0/24 with 4 IPs and a second anchor at 188.227.106.0/24 with 3 IPs.

05.8 · ClearFake drive-by + SVG script delivery — browser-render-time payload delivery

Two clusters point at the same shift — adversaries increasingly delivering payloads via browser-render-time execution rather than direct file execution. ClearFake (143 IOCs combined) compromises legitimate websites to inject fake browser-update prompts. SVG Malicious Scripts (25 IOCs) embed JavaScript inside SVG image files that execute on browser render. Both defeat email-attachment-scanner defensive controls because the payload is not delivered as an attachment.

Defensive actions: Content inspection of SVG files at mail-gateway and web-proxy layers (treat SVG as executable-adjacent). For ClearFake, detect the fake-update-prompt pattern: user visits a legitimate-looking site, then downloads a browser-update from a non-corporate domain.

05.9 · Iran-Middle-East regional campaign

33 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile (T1566, T1190, T1078, T1059, T1105, T1071, T1021, T1003, T1041) indicates full-attack-lifecycle intrusion capability.

05.10 · WebDAV Campaign (275 IOCs) — alternative delivery transport

275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. WebDAV traffic frequently escapes conventional web-proxy content inspection because it is treated as file-sharing rather than web browsing.

Defensive actions: Alert on outbound WebDAV traffic from non-collaboration-tool hosts. If your environment has no legitimate WebDAV use case, block WebDAV outbound at the perimeter.

06 · ATT&CK mapping per named cluster

Per-cluster technique mapping with operational narrative. Detection content that fires on these techniques catches the cluster even after IOC rotation.

Cluster ATT&CK techniques observed Operational narrative
GoldenEyeDog (APT) T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1027 · T1105 · T1071.001 · T1041 7,848 unique hashes — the largest single-cluster hash footprint observed in this catalogue year-to-date. Volume suggests a polymorphic build pipeline actively producing many binary variants per target. Standard APT delivery chain: acquired domains + spearphishing attachment + user-execution + obfuscation + second-stage pull + web-protocol C2 + exfil.
SmartLoader T1204.002 · T1059.001 · T1105 · T1027 · T1071.001 7,115 unique hashes — same polymorphic-build-farm signal. Loader family designed to fetch and execute second-stage payloads. Hash-block layer is fragile against this volume; behavioural loader-detection is the durable defence.
Lucid Phishing Kit T1566.002 · T1583.001 · T1584.001 · T1056.007 · T1539 · T1071.001 1,723 IOCs across DOMAIN + IP. Phishing-kit infrastructure with adversary-in-the-middle capability — session-cookie theft after credential capture. Broad phishing-domain footprint suggests operator running many concurrent campaigns.
BlueNoroff (DPRK APT) T1583.001 · T1566.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T1041 83 IOCs across DOMAIN + HASH + IP. Distinctive domain naming pattern: *.zoom.*.sbs impersonating collaboration-platform video URLs (02webus.zoom.02us.sbs, 05us.zoom.web05.sbs, etc.). Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.
Wagemole (DPRK) T1583.001 · T1566.002 · T1585.001 · T1585.002 · T1204 · T1059 64 IOCs across DOMAIN + HASH + IP + URL. The IT-worker infiltration operation — DPRK operatives applying to remote-work positions using fabricated identities to gain insider access. Detection requires HR-workflow controls, not endpoint content.
Turla APT (Russian-aligned) T1071 · T1105 · T1059 · T1041 · T1027 · T1095 · T1568 IP anchor at 103.31.250.253. Web-protocol C2 + second-stage pull + command-interpreter + exfil + obfuscation + non-app-layer C2 fallback + dynamic resolution.
APT28-linked router campaigns (Russian) T1595 · T1190 · T1210 · T1105 · T1071 Router-focused compromise cluster — IP 104.194.159.150 observed. Public-app scanning + exploitation of network infrastructure + inbound C2 from operator to compromised router. Detection focus: firmware integrity + configuration drift on network-edge devices.
LAUNDRY BEAR (APT) T1583.001 · T1566 · T1071.001 · T1041 3 IPs concentrated in 216.252.238.0/24. Standard APT tradecraft — adversary-acquired domains, phishing initial access, web-protocol C2, exfil.
UAT-8837 (APT) T1190 · T1078 · T1110.001 · T1505.003 · T1059.001 · T1105 · T1021.001 · T1003.001 · T1082 · T1041 · T1090 · T1543.003 · T1558.003 34 IOCs across HASH + IP. Broad TTP profile — public-app exploit, valid-account credential access via password spraying, webshell persistence, credential dumping, Kerberoasting (T1558.003), proxy tunnelling. Full-attack-lifecycle cluster.
UAC-0145 (Ukrainian-tracked APT) T1583.001 · T1566 · T1105 · T1071 · T1041 34 IOCs across DOMAIN + HASH. Adversary-acquired domain infrastructure (365softupdate[.]com-style software-update lure naming).
JadeProx (APT) T1583.001 · T1090 · T1071 · T1105 · T1041 41 IOCs across DOMAIN + HASH + IP. Proxy-tunnelling APT cluster.
LARVA cluster group (LARVA-15, LARVA-17, LARVA-47) T1566.001 · T1566.002 · T1078 · T1059.001 · T1105 · T1071.001 · T1555 · T1552.001 · T1005 · T1041 · T1070.004 Three related tracked clusters totalling 143 IOCs. Standard APT credential-access + collection + exfil chain, with distinctive password-store theft (T1555) and unsecured-credentials (T1552.001) focus.
Iran-Middle-East campaign T1566.001 · T1566.002 · T1190 · T1078 · T1059.001 · T1105 · T1071.001 · T1021.001 · T1003.001 · T1005 · T1041 · T1070.004 33 IOCs across DOMAIN + HASH + OTHERS + URL. Nation-state-adjacent campaign targeting Middle East / North Africa regional interests. Broad TTP profile suggests full-attack-lifecycle intrusion capability.
PLC Exploitation (ICS/OT) T0819 · T0866 · T0836 · T0885 26 IOCs across DOMAIN + HASH + IP with 3 subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4, 88.80.150.0/24 with 3). ICS ATT&CK techniques: exploit of internet-accessible device, unauthorised command execution, modify parameter, commonly-used-port abuse. Rare in this catalogue when observed — targets industrial control systems, not IT enterprise. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile.
SVG Malicious Scripts T1204.002 · T1059.007 · T1027 · T1105 25 IOCs across DOMAIN + HASH. Novel delivery pattern: SVG image files carrying embedded JavaScript that executes when the SVG is rendered in a browser. Bypasses many email attachment scanners which do not treat SVG as executable-adjacent.
ClearFake (drive-by + fake-update) T1189 · T1204.001 · T1204.002 · T1059.001 · T1105 · T1071.001 · T1566.002 · T1036 · T1027 143 IOCs combined. Compromised legitimate websites inject a fake browser-update prompt; user clicks; malicious payload is delivered. Detection focus: unexpected browser-update download from a non-corporate domain immediately after a normal-looking web visit.
AsyncRAT T1566.001 · T1204 · T1105 · T1071.001 · T1041 · T1547.001 109 IOCs across all 4 primary IOC types. Standard commodity-RAT chain — spearphish → user-execute → second-stage → web-protocol C2 → exfil → registry persistence.
KongTuke C2 infrastructure T1071 151 IOCs across DOMAIN + URL. C2-infrastructure surge with distinctive path patterns. Watch outbound traffic for the catalogued endpoints.
WebDAV Campaign T1105 · T1071.001 · T1204 · T1027 275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. Detection focus: outbound WebDAV traffic from non-collaboration hosts.
BINDCLOAK C2 T1071 · T1571 · T1105 28 IOCs across DOMAIN + HASH. Non-standard-port C2 with cloaking layer.
StealC (Stealer) T1555 · T1005 · T1041 Full 4-type footprint. Password-store theft + local data collection + exfil over C2.
Brunhilda Project T1583.001 · T1584.001 · T1566.002 · T1204.001 · T1204.002 · T1105 · T1059.001 · T1071.001 48 IOCs across HASH + IP + OTHERS. Largest single-cluster subnet anchor of the week (185.177.93.0/24 with 9 IPs). Distribution-focused campaign.

Detection-engineering takeaway. The universal APT chain (T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers most of the 25 named clusters this week. Two well-designed detectors — one on adversary-acquired-domain first-seen contact, one on the ingress-tool-transfer-plus-exfil sequence within 5 minutes — cover most of the APT surface with minimal per-cluster tuning. For the loader-heavy layer (GoldenEyeDog + SmartLoader), behavioural loader-detection is the durable defence layer (Sigma 01 below).

07 · ATT&CK tactic-pressure roll-up

Tactic Top techniques observed What the pressure means IOC count
Command and Control T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling 1,147
Initial Access T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply chain 892
Execution T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1189 Command interpreter (PowerShell / CMD / VB / JS), user-execution, drive-by (SVG script) 785
Ingress Tool Transfer T1105 Second-stage payload pull — universal across every multi-stage cluster 634
Defense Evasion T1027 · T1036 · T1055 · T1070 · T1070.004 · T1562 · T1140 Obfuscation, masquerading, process injection, indicator removal, disable defences, deobfuscate 512
Credential Access T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1110.001 · T1558.003 OS credential dumping, password store theft, brute force + Kerberoasting 428
Discovery T1082 · T1057 · T1083 · T1018 · T1046 · T1482 System info, process, file, remote-system, network configuration, domain trust 356
Lateral Movement T1021 · T1021.001 · T1021.002 · T1570 Remote-desktop, SMB / admin shares, lateral tool transfer 289
Exfiltration T1041 · T1567 · T1090 Exfil over C2, exfil to web service, tunnel-based exfil 654
Persistence T1547.001 · T1543.003 · T1053.005 · T1505.003 Registry-run keys, Windows service creation, scheduled tasks, webshell 245
Resource Development T1583.001 · T1584.001 · T1585 Adversary-acquired domains + compromised infrastructure + fabricated identities (Wagemole) 218
Collection T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 Local + automated collection, screen capture, input capture, session-cookie theft 187
ICS-specific T0819 · T0866 · T0836 · T0885 PLC Exploitation cluster: internet-accessible device exploit, unauthorised command, modify parameter, commonly-used-port abuse 26

08 · Subnet anchors — the shared-infrastructure signal

Subnet (/24) IPs Adversary cluster Operator observation
185.177.93.0/24 9 Brunhilda Project The week’s largest single-cluster subnet anchor — 9 IPs concentrated.
185.82.73.0/24 8 PLC Exploitation Second-largest anchor + operationally rare — targets ICS/OT infrastructure.
23.224.4.0/24 5 CRPXO C2 C2 infrastructure concentration
91.92.43.0/24 4 Tsundere botnet Botnet C2 (continues from prior weeks)
175.110.121.0/24 4 PLC Exploitation Second PLC Exploitation anchor
45.138.26.0/24 4 LARVA-47 LARVA cluster infrastructure
156.247.47.0/24 4 DCRat Commodity RAT C2
88.80.150.0/24 3 PLC Exploitation Third PLC Exploitation anchor — 3 blocks total, 15 IPs
45.61.163.0/24 3 BlueNoroff (APT) DPRK-aligned APT infrastructure anchor
45.59.122.0/24 3 SectopRAT RAT operator anchor
216.252.238.0/24 3 LAUNDRY BEAR (APT) APT-tier subnet anchor
188.227.106.0/24 3 LARVA-47 Second LARVA-47 anchor

The asymmetric block. PLC Exploitation operates across three distinct /24 anchors with 15 concentrated IPs — unusual for an ICS/OT-focused cluster. Blocking all three /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across three different hosting tenants simultaneously to defeat the block. Brunhilda Project (9 IPs in a single /24) and BlueNoroff (3 IPs concentrated) are the other high-leverage blocks.

08b · Predictive intelligence — forecast weaponisation

Retrospective indicators tell you what has happened; predictive indicators tell you what is about to. This week’s catalogue-driven forecast layer surfaces three infrastructure blocks with a high forward-looking probability of adversary weaponisation. Derived from passive-DNS drift, registration-velocity clustering, hosting-tenant reputation drift, and pattern-match against previously-catalogued operator behaviours. Push into your perimeter watchlist now — not because they are compromised today, but because they are the highest-probability rotation candidates for adversary use over the next week.

// PREDICTIVE INTELLIGENCE · FORECAST WEAPONISATION
Infrastructure signal Forecast window Confidence Signal profile
185.82.73.0/24 3 DAYS HIGH Imminent forecast. Already anchoring 8 PLC Exploitation IPs; velocity + rotation pattern indicates further hosts in the same block are candidate operator staging.
185.177.93.0/24 5 DAYS HIGH Brunhilda Project anchor with 9 concentrated IPs — the block’s remaining ~247 addresses are rotation candidates. CIDR block-candidate.
45.X.X.0/24 6 DAYS MEDIUM Broad-range staging block adjacent to LARVA-47 + BlueNoroff + SectopRAT anchors. Composite rotation signal across multiple operators.

How the forecast is derived

The forward-looking signal combines four inputs. Passive-DNS drift — how fast the block’s resolutions are changing relative to its historical baseline. Registration-velocity clustering — adjacent-block domain-registration rates compared against operator-fingerprint baselines. Hosting-tenant reputation drift — whether the anchor’s hosting tenant is trending toward adversary-adjacent reputation classes. And pattern-match against catalogued operator behaviours — whether the block’s early observable signature (open ports, TLS fingerprints, cert patterns) resembles any known operator anchor from the last 90 days. When two or more inputs converge, the block enters the forecast layer with a days-to-weaponisation estimate.

Operational actions

  • Perimeter watchlist — add all three anchors to a watchlist lane (not automatic block) that alerts on any outbound contact.
  • 3-day forecast (185.82.73.0/24) already-anchoring PLC Exploitation warrants provisional blocking of the /24 at the perimeter now if your environment has no legitimate business use in that range.
  • CIDR-level block for the discrete 185.177.93.0/24 anchor (Brunhilda Project).
  • Retrospective hunt — run a 90-day historical lookback for any past contact with these anchor ranges.

What predictive intelligence gives you. The classical intelligence catalogue tells you what has been observed already; the predictive layer tells you what is about to be observed. That shift buys the SOC a lead time it does not otherwise have — block an operator anchor before the operator’s rotation reaches you, not after your first compromise. The forecast is probabilistic, not deterministic — treat the days-to-weaponisation estimates as watchlist priorities, not automated-blocking triggers.

09 · Top 15 IOCs per indicator type

Operator-grade extractions. All indicators are defanged (re-fang on import: [.]. and hxxphttp).

Top 15 · IP addresses (High severity)

# Indicator Adversary Category Severity
01 1.94.106.150 VShell (C2) Botnet HIGH
02 101.96.224.108 VShell (C2) Botnet HIGH
03 103.101.85.111 Quasar RAT Botnet HIGH
04 103.149.93.150 VShell (C2) Botnet HIGH
05 103.235.46.102 UAT-8837 (APT) APT HIGH
06 103.27.109.233 Quasar RAT Botnet HIGH
07 103.31.250.253 Turla APT APT HIGH
08 103.97.0.57 Hermes AI Agent Malware HIGH
09 104.168.22.209 VShell (C2) Botnet HIGH
10 104.194.133.210 SectopRAT RAT HIGH
11 104.194.159.150 APT28-linked router APT HIGH
12 104.238.34.209 Ragnar Loader Loader HIGH
13 104.243.35.63 Cl0p ransomware Ransomware HIGH
14 104.248.134.194 LAUNDRY BEAR (APT) APT HIGH
15 102.117.171.29 Unknown malware C2 Botnet HIGH

Top 15 · Domains (High severity)

# Indicator Adversary Category Severity
01 0059595390202402400202[.]sobul[.]net LARVA-17 Malware HIGH
02 01058telecom[.]de SVG Malicious Scripts Malware HIGH
03 02webus[.]zoom[.]02us[.]sbs BlueNoroff (APT) APT HIGH
04 02webus[.]zoom[.]web02[.]sbs BlueNoroff (APT) APT HIGH
05 05us[.]zoom[.]web05[.]sbs BlueNoroff (APT) APT HIGH
06 06usweb[.]zoom[.]us06[.]sbs BlueNoroff (APT) APT HIGH
07 0co7tx46[.]worldofmacarons[.]com ClearFake Malware HIGH
08 0xvona[.]duckdns[.]org Chalubo RAT RAT HIGH
09 0zbqnac1t4dv2t2wuodv1m[.]com Cruciferra Malware HIGH
10 365softupdate[.]com UAC-0145 (APT) APT HIGH
11 4mrkjecd[.]rsudtarutung[.]com ClearFake Malware HIGH
12 57b0rv7c[.]sansekerta[.]org ClearFake Malware HIGH
13 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com SectopRAT RAT HIGH
14 5teun337[.]yummiquickway[.]com ClearFake Malware HIGH
15 abcd[.]gamesen[.]icu Commodity C2 framework A Malware HIGH

Top 15 · File hashes (High severity)

# Indicator Adversary Category Severity
01 0002a8d9b71895c616dd52e32eb08823c79ce423a238757fcd275c13806dcb66 SmartLoader Malware HIGH
02 000732e37ed2431c677cca56aafbd53f FadeSEC Ransomware Ransomware HIGH
03 000a25edc1bd2e91d65851c5171edf6facc0ca3f GoldenEyeDog (APT) APT HIGH
04 000f0de250917d2d7a90c70116f0422f GoldenEyeDog (APT) APT HIGH
05 0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a GoldenEyeDog (APT) APT HIGH
06 00113b357f18ba5f62c3e8856871f1902f019a1a16de2e3c8a29f84de2565065 SmartLoader Malware HIGH
07 001c16af3cfde47a3289e5c55d72533c5c0e4bc4 GoldenEyeDog (APT) APT HIGH
08 001e1824fef043f26d235ccf7eec71cdebfb419a GoldenEyeDog (APT) APT HIGH
09 001e9bf4488c5bca1a81d087d2e310b4cf42f123 GoldenEyeDog (APT) APT HIGH
10 001f205103af843faa77bb811ef33bd791a184e9dc629363c3da509c16f5420c SmartLoader Malware HIGH
11 001faaf397dde12a044efeb98efd972bdec0229c GoldenEyeDog (APT) APT HIGH
12 0022520838406bf985cc7ad13487288f8f4364e823fa3d41d44c4dbee9d659ee SmartLoader Malware HIGH
13 0024b6045416febb3b3c80569fbb7c4fe85e3ce8112e7dba6d80b3d601ffb523 SmartLoader Malware HIGH
14 00295a9ed4dbc4bb25b423ccd04af37e331d42a86f48edbeff5bd811fa97b899 SmartLoader Malware HIGH
15 003e4e3f3f4bb96ba4ddd10a43a7b5290cc237c1 GoldenEyeDog (APT) APT HIGH

Top 15 · URLs (High severity)

# Indicator Adversary Category Severity
01 hxxp[://]0xvona[.]duckdns[.]org Chalubo RAT RAT HIGH
02 hxxp[://]103.31.250.253 Turla APT APT HIGH
03 hxxp[://]110.92.64.17/moo.cgi Knife-Cutting-the-Edge Malware HIGH
04 hxxp[://]117.175.185.81:8003/ Knife-Cutting-the-Edge Malware HIGH
05 hxxp[://]118.195.183.6/activity Commodity C2 framework A Malware HIGH
06 hxxp[://]118.31.115.178:4444/ga.js Commodity C2 framework A Malware HIGH
07 hxxp[://]118.31.115.178:9999/ptj Commodity C2 framework A Malware HIGH
08 hxxp[://]124.220.215.195:5555/pixel Commodity C2 framework A Malware HIGH
09 hxxp[://]124.220.215.195:9999/ca Commodity C2 framework A Malware HIGH
10 hxxp[://]124.223.12.165/ Commodity C2 framework A Framework HIGH
11 hxxp[://]129.211.215.7/dot.gif Commodity C2 framework A Malware HIGH
12 hxxp[://]154.3.0.70:83/cm Commodity C2 framework A Malware HIGH
13 hxxp[://]157.254.223.141/25/ Remcos RAT HIGH
14 hxxp[://]101.91.154.125:50001/cm Commodity C2 framework A Malware HIGH
15 hxxp[://]106.15.62.124:2222/push Commodity C2 framework A Malware HIGH
Need the full set? The catalogue carries 77,118 unique IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, adversary attribution, and source-feed provenance. Open HuntIntel.

10 · Sigma detection rules

Sigma 01 · Universal loader behaviour (GoldenEyeDog + SmartLoader durable defence)

title: Universal Loader Behaviour — Polymorphic Build Family Detector
id: 6a2c8e1f-5b74-4930-a681-3f9b5c2e8d10
status: experimental
description: Detects the universal loader behaviour signature — a downloaded
  binary spawns from a browser or document reader parent process, then triggers
  outbound network traffic to a non-corporate destination within 60 seconds.
  Catches polymorphic-build families (GoldenEyeDog, SmartLoader, and similar)
  where hash-blocking is defeated by build-farm volume.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.execution
  - attack.t1204
  - attack.command_and_control
  - attack.t1105
  - attack.t1071.001
logsource:
  product: correlation
detection:
  s1_downloaded_binary:
    EventID: 4688
    ParentImage|endswith:
      - '\chrome.exe'
      - '\firefox.exe'
      - '\edge.exe'
      - '\OUTLOOK.EXE'
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\AcroRd32.exe'
    Image|contains:
      - '\Downloads\'
      - '\Temp\'
      - '\AppData\Local\Temp\'
  s2_outbound_web:
    EventID: 5156
    DestinationPort: [80, 443, 8080, 8443]
    DestinationIp|expand: '%non_corporate_destinations%'
  condition: s1_downloaded_binary and s2_outbound_web within 60s
falsepositives:
  - Legitimate software installers from allowlisted domains
level: high

Sigma 02 · BlueNoroff collaboration-platform impersonation

title: BlueNoroff Collaboration-Platform Impersonation Domain Pattern
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a90
status: experimental
description: Detects DNS queries matching the BlueNoroff APT domain-naming
  pattern impersonating collaboration-platform video-call URLs. Regex-tight
  enough to avoid false positives against legitimate platform domains.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.initial_access
  - attack.t1566
  - attack.resource_development
  - attack.t1583.001
logsource:
  category: dns_query
detection:
  selection:
    QueryName|re:
      - '^[0-9]{2}[a-z]+web?\.zoom\.[a-z0-9]+\.sbs$'
      - '^[0-9]{2}[a-z]+\.zoom\.web[0-9]{2}\.sbs$'
  condition: selection
falsepositives:
  - None — the .sbs TLD + this naming pattern has no legitimate collaboration-platform use
level: critical

Sigma 03 · PLC Exploitation subnet + OT-protocol egress

title: PLC Exploitation Subnet Anchor Contact (ICS/OT)
id: 8d1a4b6f-5c92-4670-a881-3f9c7d5b2a40
status: experimental
description: Detects any outbound connection to the PLC Exploitation cluster's
  three concentrated subnet anchors. 15 IPs across 3 /24 blocks — critical
  signal for OT/ICS environments. Also fires on OT-protocol traffic to any
  destination outside the internal OT segment.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.command_and_control
  - attack.t1071
  - ics.t0819
  - ics.t0866
logsource:
  category: network_connection
detection:
  ot_subnet_anchors:
    DestinationIp|cidr:
      - '185.82.73.0/24'
      - '175.110.121.0/24'
      - '88.80.150.0/24'
  ot_protocol_egress:
    DestinationPort:
      - 502    # Modbus TCP
      - 44818  # EtherNet/IP
      - 20000  # DNP3
      - 34962  # Profinet
      - 34963  # Profinet
      - 34964  # Profinet
    DestinationIp|expand: '%external_destinations%'
  condition: ot_subnet_anchors or ot_protocol_egress
falsepositives:
  - Legitimate OT vendor remote-support (allowlist by known-good IPs)
level: critical

Sigma 04 · SVG file with embedded script content

title: SVG File Delivery with Embedded Script Content
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a10
status: experimental
description: Detects delivery of SVG files (inbound mail attachment or web
  download) that contain embedded JavaScript. Catches the SVG Malicious Scripts
  cluster and any future SVG-based delivery.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.execution
  - attack.t1204.002
  - attack.t1059.007
logsource:
  category: file_event
detection:
  svg_delivery:
    TargetFilename|endswith: '.svg'
    FileContent|contains:
      - '

11 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Loader chain — browser/document parent + outbound web within 60s

// Pseudo-query
FROM process_creates AS pc
JOIN network_flows AS nf
  ON pc.host = nf.src_host
  AND nf.flow_time BETWEEN pc.create_time AND pc.create_time + 60s
WHERE pc.parent_process IN ('chrome.exe', 'firefox.exe', 'edge.exe',
                             'OUTLOOK.EXE', 'winword.exe', 'excel.exe',
                             'powerpnt.exe', 'AcroRd32.exe')
  AND pc.image_path MATCHES regex '\\(Downloads|Temp)\\'
  AND nf.dest_ip NOT IN (allowlisted_ranges)
  AND nf.dest_port IN (80, 443, 8080, 8443)
| PROJECT pc.host, pc.image_path, nf.dest_ip, nf.dest_domain
| SORT BY pc.create_time DESC

Hunt 02 · APT anchor first-seen (top clusters)

// Pseudo-query
FROM network_flows
WHERE dest_ip IN (
  '103.235.46.102',    -- UAT-8837
  '103.31.250.253',    -- Turla
  '104.194.159.150',   -- APT28-linked
  '104.248.134.194',   -- LAUNDRY BEAR
  '103.97.0.57'         -- Hermes AI Agent
)
  AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC

Hunt 03 · PLC Exploitation subnet + OT protocol traffic

// Pseudo-query
FROM network_flows
WHERE (dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24'))
   OR (dest_port IN (502, 44818, 20000, 34962, 34963, 34964)
       AND dest_ip NOT IN (internal_ot_segment))
| AGGREGATE BY src_ip, dest_ip, dest_port
| SORT BY flow_count DESC

Hunt 04 · BlueNoroff DNS pattern

// Pseudo-query
FROM dns_queries
WHERE query_name MATCHES regex '(?i)^[0-9]{2}[a-z]+web?\.zoom\.[a-z0-9]+\.sbs$'
   OR query_name MATCHES regex '(?i)^[0-9]{2}[a-z]+\.zoom\.web[0-9]{2}\.sbs$'
| PROJECT src_host, query_name, query_time
| SORT BY query_time DESC

12 · Operationalise in 60 minutes

Minute 00 – 15 · Block + sinkhole

  • Block all three PLC Exploitation subnet anchors: 185.82.73.0/24, 175.110.121.0/24, 88.80.150.0/24.
  • Block Brunhilda Project anchor 185.177.93.0/24 (9 concentrated IPs).
  • Block BlueNoroff anchor 45.61.163.0/24 + LAUNDRY BEAR 216.252.238.0/24.
  • Block 103.31.250.253 (Turla) + 104.194.159.150 (APT28-linked router).
  • Add outbound-deny for WebDAV traffic from non-collaboration-tool hosts.

Minute 15 – 30 · Detection content

  • Deploy Sigma 01 (universal loader behaviour) — catches GoldenEyeDog + SmartLoader without hash volatility.
  • Deploy Sigma 02 (BlueNoroff collaboration-platform DNS pattern).
  • Deploy Sigma 03 (PLC Exploitation subnet + OT-protocol egress) — critical for OT/ICS environments.
  • Deploy Sigma 04 (SVG with embedded script).

Minute 30 – 45 · Retrospective hunt

  • Run Hunt 01 (loader chain) baseline scan across last 30 days.
  • Run Hunt 02 (APT anchor first-seen) across last 90 days.
  • Run Hunt 03 (PLC Exploitation + OT-protocol egress) across last 60 days.
  • Run Hunt 04 (BlueNoroff DNS pattern) across last 30 days.

Minute 45 – 60 · Awareness + policy

  • Brief cryptocurrency-adjacent users on BlueNoroff collaboration-platform impersonation.
  • Brief HR on the Wagemole IT-worker infiltration pattern — video-verify interviews, cross-check identities.
  • For OT/ICS environments: emergency verification that no internet-accessible PLCs are exposed. Immediate Shodan-adjacent inventory recommended.
  • Update mail-gateway policy to inspect SVG file contents (treat as executable-adjacent).
// CONTINUE WITH HUNTINTEL

This briefing ships 15 indicators per type. The catalogue carries the full 77,118 unique IOCs from this week — adversary attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

13 · Frequently asked questions

25 named APTs in one week — is that unusual?

Yes. Twenty-five concurrent named APT clusters is the widest APT footprint in this catalogue year-to-date. The typical week sees 5-10 concurrent named clusters; this week's 25 is more than double baseline. What matters operationally: organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week. The APT-storm signal is a leading indicator of near-term intrusion activity.

GoldenEyeDog produced 7,848 hashes in one week. How does hash-blocking survive that?

It doesn't. Hash-blocking is fragile against polymorphic-build volume at that scale — the operator can generate new variants faster than any hash feed can catalogue them. The durable defence is behavioural loader detection (Sigma 01 above). Detect the pattern browser/document parent → downloaded binary → outbound web within 60s, and you catch the family regardless of hash variance.

Why is PLC Exploitation flagged as critical when it's only 26 IOCs?

Because it targets industrial control systems, not enterprise IT. A single successful PLC compromise can shut down a power substation, contaminate a water treatment facility, or halt a manufacturing line. The impact-per-IOC is orders of magnitude higher than typical malware. For any organisation operating OT/ICS environments, PLC Exploitation belongs in the priority-block queue regardless of IOC count.

What is Wagemole and why is it different?

Wagemole is the DPRK IT-worker infiltration operation — DPRK operatives applying to legitimate remote-work positions using fabricated identities to gain insider access to target organisations. It is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired. Detection requires HR-workflow controls (video-verify interviews, independent identity verification, second-source employment/education checks) — not detection content.

Why is SVG script delivery worth its own detection rule?

Because most email-attachment scanners don't treat SVG as executable-adjacent. SVG files can contain embedded JavaScript that executes when the file is rendered in a browser — including via inline preview in mail clients. The delivery vector defeats attachment-scanning defensive controls that would catch a malicious .exe / .doc / .zip. Adding SVG content inspection at the mail gateway closes the gap.

What confidence threshold should the SOC use for automated blocking?

High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.

Where can I see this briefing's intelligence operationally?

The HuntIntel operator console exposes every IOC with adversary attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions