APT storm week. 25 attributed APT clusters ran in parallel — the widest concurrent APT footprint observed in this catalogue year-to-date. Two loader families produced ~15,000 unique hashes combined in seven days — a polymorphic-build-farm signal that defeats hash-based defence at industrial scale. DPRK-adjacent activity double-tracked (cryptocurrency-focused APT + IT-worker infiltration campaign). Russian-aligned clusters concurrent with Middle East / North Africa regional operations. A rare and consequential signal — an ICS/OT PLC-targeted exploitation campaign across three concentrated subnet anchors targeting industrial control systems. A novel delivery vector — SVG-embedded script payloads that bypass traditional attachment scanners. If your CTI team was quiet this week, this briefing is your priority reading list.
Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, subnet anchors, top IOCs per indicator type, four production-ready Sigma rules, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
The catalogue produced 77,118 unique IOCs across 155 clusters this cycle. Framework-infrastructure entries dominate the topline volume, but the narrow-indicator layer is the intelligence story: 3,374 unique domains + 16,316 unique hashes + 503 URLs. The hash volume alone (16,316) is the second-highest weekly count observed in this catalogue year-to-date — driven by two loader families running at industrial-scale polymorphic-build volume (~15,000 combined hashes). Every APT category is elevated: 25 attributed APT clusters concurrent is the widest APT footprint of the year.
Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · APT Storm — 25 attributed clusters concurrent
Twenty-five attributed APT clusters produced fresh indicators this cycle — the widest concurrent APT footprint in the year-to-date window. The APT-category IOC total: 8,291 records across 25 attributed clusters. Cluster diversity spans DPRK-adjacent activity, Russian-aligned operations, Middle East / North Africa regional operations, multiple tracked cluster groups, and proxy-focused intrusion sets. Concurrent APT activity at this scale is a load-bearing intelligence signal — organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week.
Headline 02 · Polymorphic loader surge — ~15,000 hashes in 7 days
Two loader families produced ~15,000 unique HASH indicators combined in seven days — the largest loader-tier hash footprint of the year. Volume at that scale from a small number of families indicates a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated. The operational implication: hash-blocking is fragile against this volume. Behavioural loader detection is the durable defence layer (Sigma 01 below).
Headline 03 · ICS/OT threat surface — PLC-targeted campaign with 3 subnet anchors
A rare and operationally significant signal. A PLC-targeted exploitation campaign produced 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors (185.82.73.0/24 with 8 IPs, 175.110.121.0/24 with 4 IPs, 88.80.150.0/24 with 3 IPs — 15 IPs across 3 blocks). The cluster targets industrial control systems, not enterprise IT. Utilities, manufacturing, and critical-infrastructure operators are the primary victim profile. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. If your organisation operates any OT/ICS environment, this cluster warrants immediate attention.
Headline 04 · DPRK-adjacent double-track — cryptocurrency-focus + IT-worker infiltration
Two DPRK-adjacent operations active in parallel. A cryptocurrency-focused APT cluster (83 IOCs across DOMAIN + HASH + IP) uses a distinctive collaboration-platform-impersonation domain-naming pattern with a subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences. Separately, an IT-worker infiltration campaign (64 IOCs across all 4 primary IOC types) sees DPRK-linked operatives applying to remote-work positions using fabricated identities to gain insider access. This IT-worker campaign is a HR-workflow threat, not primarily an endpoint threat — detection requires identity-verification and hiring-workflow controls, not detection content.
Headline 05 · Novel delivery vector — SVG-embedded scripts
An SVG-embedded script delivery campaign produced 25 IOCs across DOMAIN + HASH. Delivery pattern: attackers embed JavaScript payloads inside SVG image files. When the SVG is rendered in a browser (as an inline image, email attachment preview, or website asset), the embedded script executes. Bypasses many email attachment scanners that do not treat SVG as executable-adjacent. Combined with a concurrent drive-by fake-update malware campaign (143 IOCs), this cycle shows a broader shift toward browser-rendering-time payload delivery. Defensive answer: content-inspection of SVG files at the mail-gateway and web-proxy layers.
03 · Indicator type, severity, and category mix
The narrow-indicator layer is the intelligence story this week: 16,316 unique HASH indicators is the highest hash-share observed year-to-date at 21 percent (driven by polymorphic loader builds). Domain volume at 3,374 is also elevated. Severity distribution shows 27 percent HIGH (20,804 records) — well above the year-to-date baseline. APT category at 8,291 IOCs (11 percent share) is the highest APT concentration of the year.
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| IPs | 56,860 | 73.73% | |
| File hashes | 16,316 | 21.16% | |
| Domains | 3,374 | 4.38% | |
| URLs | 503 | 0.65% | |
| Other artefacts | 42 | 0.05% | |
| Emails | 17 | 0.02% | |
| Process names | 6 | 0.01% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 20,804 | 26.41% | |
| Medium | 57,837 | 73.41% | |
| Low | 143 | 0.18% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| C&C | 53,149 | 64.39% | |
| Malware-Activity | 8,570 | 10.38% | |
| APT | 8,291 | 10.04% | |
| C&C Server | 5,435 | 6.58% | |
| Botnet | 5,000 | 6.06% | |
| Phishing | 1,725 | 2.09% | |
| RAT | 185 | 0.22% | |
| Framework | 65 | 0.08% | |
| Spyware | 44 | 0.05% | |
| Ransomware-as-a-service | 38 | 0.05% | |
| Loader | 15 | 0.02% | |
| Intrusion Campaign | 13 | 0.02% | |
| Supply Chain | 9 | 0.01% |
04 · Cluster footprint — ranked by unique-IOC count
36 clusters ranked by unique IOC footprint. Framework-infrastructure entries in grey to preserve visual clarity of the campaign-attributed clusters. All names generalised into category descriptors.
| # | Cluster descriptor | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Open-framework C2 infrastructure (framework tier)
C2 · DOMAIN, EMAIL, HASH, IP, URL
|
57,830 | MEDIUM | |
| 02 | High-tempo APT cluster (Cluster A)
APT · HASH
|
7,848 | HIGH | |
| 03 | Loader family A (polymorphic build)
Malware · HASH
|
7,115 | HIGH | |
| 04 | Phishing kit (broad domain infrastructure)
Phishing kit · DOMAIN, IP
|
1,723 | MEDIUM | |
| 05 | WebDAV-transport delivery campaign
Malware Campaign · HASH, IP, URL
|
275 | HIGH | |
| 06 | Open-framework C2 infrastructure (malware tier)
Malware · DOMAIN, HASH, IP, OTHERS, PROCESS, URL
|
152 | HIGH | |
| 07 | C2 infrastructure campaign (Cluster B)
C2 · DOMAIN, URL
|
151 | MEDIUM | |
| 08 | Commodity RAT family (Cluster C)
RAT · DOMAIN, HASH, IP, URL
|
109 | MEDIUM | |
| 09 | Drive-by / fake-update malware campaign
Malware Campaign · DOMAIN, HASH
|
143 | HIGH | |
| 10 | Malware family (Cluster D)
Malware · DOMAIN, HASH
|
99 | HIGH | |
| 11 | DPRK-adjacent APT cluster (cryptocurrency focus)
APT · DOMAIN, HASH, IP
|
83 | HIGH | |
| 12 | Malware campaign (Cluster E)
Malware Campaign · DOMAIN, HASH, IP, URL
|
76 | HIGH | |
| 13 | DPRK-adjacent IT-worker infiltration campaign
APT · DOMAIN, HASH, IP, URL
|
64 | HIGH | |
| 14 | Fake browser-extension phishing cluster
Phishing Campaign · DOMAIN, IP, OTHERS
|
64 | LOW | |
| 15 | Open remote-management framework
C2 · IP
|
63 | MEDIUM | |
| 16 | Tracked cluster group – identifier F
APT · HASH, IP
|
59 | HIGH | |
| 17 | Malware family (Cluster G)
Malware · DOMAIN, EMAIL, HASH, IP, URL
|
54 | HIGH | |
| 18 | Multi-stage RAT + implant campaign
Malware Campaign · DOMAIN, HASH, IP, URL
|
52 | HIGH | |
| 19 | Tracked cluster group – identifier H
APT · HASH, IP, URL
|
50 | HIGH | |
| 20 | Malware campaign (Cluster J)
Malware Campaign · HASH, IP, OTHERS
|
48 | HIGH | |
| 21 | Malware family (Cluster K)
Malware · DOMAIN, HASH, IP, URL
|
44 | HIGH | |
| 22 | Proxy-focused APT cluster
APT · DOMAIN, HASH, IP
|
41 | HIGH | |
| 23 | Tracked APT cluster – identifier L
APT · DOMAIN, HASH, IP
|
39 | HIGH | |
| 24 | Banking-focused malware campaign
Malware Campaign · DOMAIN, HASH, URL
|
34 | HIGH | |
| 25 | Tracked APT cluster – identifier M
APT · HASH, IP
|
34 | HIGH | |
| 26 | Regional-tracked APT cluster – identifier N
APT · DOMAIN, HASH
|
34 | HIGH | |
| 27 | Tracked cluster group – identifier P
APT · DOMAIN
|
34 | HIGH | |
| 28 | Phishing kit (Cluster Q)
Phishing kit · DOMAIN
|
34 | MEDIUM | |
| 29 | Middle East / North Africa regional operations
APT · DOMAIN, HASH, OTHERS, URL
|
33 | HIGH | |
| 30 | Info-stealer family (Cluster R)
Malware · DOMAIN, HASH, IP, URL
|
29 | HIGH | |
| 31 | Gaming-lure stealer campaign
Malware · DOMAIN, HASH, IP
|
29 | HIGH | |
| 32 | Commodity RAT family (Cluster S)
RAT · DOMAIN, HASH, IP
|
28 | HIGH | |
| 33 | C2 infrastructure with cloaking layer
Malware Campaign · DOMAIN, HASH
|
28 | HIGH | |
| 34 | Collaboration-platform phishing operation
Phishing Campaign · DOMAIN, EMAIL, HASH, URL
|
26 | LOW | |
| 35 | ICS/OT — PLC-targeted exploitation campaign
Malware Campaign · DOMAIN, HASH, IP
|
26 | HIGH | |
| 36 | SVG-embedded script delivery campaign
Malware Campaign · DOMAIN, HASH
|
25 | HIGH |
05 · Themed deep-dives
05.1 · Polymorphic loader surge — ~15,000 hashes across two families
Two loader families dominated the weekly hash footprint. The larger of the two (7,848 unique HASH indicators) and its counterpart (7,115 unique HASH indicators) together produced ~15,000 unique binaries in seven days. Volume at that scale from a small number of families indicates a polymorphic build pipeline actively producing many binary variants per target — a defensive-evasion strategy that defeats hash-based endpoint content as fast as it can be updated.
Defensive actions: Push the catalogued hashes to endpoint quarantine as a baseline. But the durable defence layer is behavioural loader detection — process-tree anomalies, parent-child spawn patterns, network-flow shapes after execution. Deploy Sigma rule 01 below (universal loader-behaviour detector) as the primary defence.
05.2 · DPRK-adjacent double-track
Cryptocurrency-focused APT cluster (83 IOCs) uses a distinctive domain-naming pattern impersonating collaboration-platform video-call URLs to lure victims into clicking fake “join meeting” links. Subnet anchor at 45.61.163.0/24. Targets cryptocurrency-adjacent audiences.
IT-worker infiltration campaign (64 IOCs across all 4 primary IOC types) sees DPRK-linked operatives applying to remote-work positions using fabricated identities to gain insider access. This is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired, not by exploiting a technical vulnerability. Detection requires identity-verification and hiring-workflow controls, not detection content.
Defensive actions: Block the subnet anchor. Alert users in cryptocurrency-adjacent roles specifically. For hiring workflows: video-verify interviews (not chat-only), verify education and employment claims independently, cross-check identity documents against second-source records, flag applicants using VPN or unusual geolocation during interviews.
05.3 · ICS/OT PLC-targeted exploitation campaign — 3 subnet anchors
The rare-and-significant signal. 26 IOCs across DOMAIN + HASH + IP with three concentrated subnet anchors:
185.82.73.0/24— 8 IPs concentrated175.110.121.0/24— 4 IPs concentrated88.80.150.0/24— 3 IPs concentrated
15 IPs across 3 blocks targeting industrial control systems. ICS ATT&CK techniques observed: T0819 exploit of internet-accessible device, T0866 unauthorised command execution, T0836 modify parameter, T0885 commonly-used-port abuse. Utilities, manufacturing, energy, and critical-infrastructure operators are the primary victim profile.
Defensive actions: If your organisation operates any OT/ICS environment: block all three /24 anchors at the perimeter now. Verify no internet-accessible PLCs in your environment. Alert on any modbus / EtherNet-IP / DNP3 / Profinet traffic from unfamiliar external sources.
05.4 · Browser-render-time delivery — SVG scripts + drive-by fake-update
Two campaigns point at the same shift — adversaries increasingly delivering payloads via browser-render-time execution rather than direct file execution. The drive-by fake-update campaign (143 IOCs combined) compromises legitimate websites to inject fake browser-update prompts. The SVG-embedded script delivery campaign (25 IOCs) embeds JavaScript inside SVG image files that execute on browser render. Both defeat email-attachment-scanner defensive controls because the payload is not delivered as an attachment.
Defensive actions: Content inspection of SVG files at mail-gateway and web-proxy layers (treat SVG as executable-adjacent). For drive-by fake-update: detect the pattern where a user visits a legitimate-looking site, then downloads a browser-update from a non-corporate domain.
05.5 · WebDAV-transport delivery campaign (275 IOCs)
275 IOCs across HASH + IP + URL. Uses WebDAV as the payload-delivery transport rather than HTTP/HTTPS. WebDAV traffic frequently escapes conventional web-proxy content inspection because it is treated as file-sharing rather than web browsing.
Defensive actions: Alert on outbound WebDAV traffic from non-collaboration-tool hosts. If your environment has no legitimate WebDAV use case, block WebDAV outbound at the perimeter.
05.6 · Regional and tracked-cluster activity summary
The remaining 20-plus APT clusters cover Russian-aligned, Middle East / North Africa regional, proxy-focused, credential-access-focused, and multiple tracked-cluster group activity. Combined they represent 8,291 APT-category IOCs. Standard multi-stage APT chain applies across most: adversary-acquired-domain infrastructure → phishing initial access → second-stage payload pull → web-protocol C2 → exfil-over-C2. Detection content that fires on that universal chain (Sigma 02 below) catches most of the APT surface without per-cluster tuning.
06 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Command and Control | T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 | Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling | 1,147 |
| Initial Access | T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 | Valid accounts, external remote services, public-app exploit, phishing (attachment + link), supply chain | 892 |
| Execution | T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1189 | Command interpreter (PowerShell / CMD / VB / JS), user-execution, drive-by (SVG script) | 785 |
| Ingress Tool Transfer | T1105 | Second-stage payload pull — universal across every multi-stage cluster | 634 |
| Defense Evasion | T1027 · T1036 · T1055 · T1070 · T1070.004 · T1562 · T1140 | Obfuscation, masquerading, process injection, indicator removal, disable defences, deobfuscate | 512 |
| Credential Access | T1003 · T1003.001 · T1555 · T1552.001 · T1110 · T1110.001 · T1558.003 | OS credential dumping, password store theft, brute force + Kerberoasting | 428 |
| Discovery | T1082 · T1057 · T1083 · T1018 · T1046 · T1482 | System info, process, file, remote-system, network configuration, domain trust | 356 |
| Lateral Movement | T1021 · T1021.001 · T1021.002 · T1570 | Remote-desktop, SMB / admin shares, lateral tool transfer | 289 |
| Exfiltration | T1041 · T1567 · T1090 | Exfil over C2, exfil to web service, tunnel-based exfil | 654 |
| Persistence | T1547.001 · T1543.003 · T1053.005 · T1505.003 | Registry-run keys, service creation, scheduled tasks, webshell | 245 |
| Resource Development | T1583.001 · T1584.001 · T1585 | Adversary-acquired domains + compromised infrastructure + fabricated-identity infiltration | 218 |
| Collection | T1005 · T1119 · T1113 · T1056 · T1056.007 · T1539 | Local + automated collection, screen capture, input capture, session-cookie theft | 187 |
| ICS-specific | T0819 · T0866 · T0836 · T0885 | PLC-targeted campaign: internet-accessible device exploit, unauthorised command, modify parameter, commonly-used-port abuse | 26 |
Detection-engineering takeaway. The universal APT chain (
T1583.001 → T1566 → T1105 → T1071.001 → T1041) covers most of the 25 attributed clusters this week. Two well-designed detectors — one on adversary-acquired-domain first-seen contact, one on the ingress-tool-transfer-plus-exfil sequence within 5 minutes — cover most of the APT surface with minimal per-cluster tuning. For the loader-heavy layer, behavioural loader-detection is the durable defence layer (Sigma 01 below).
07 · Subnet anchors — the shared-infrastructure signal
| Subnet (/24) | IPs | Operator observation |
|---|---|---|
| 185.177.93.0/24 | 9 | Largest single-cluster subnet anchor of the week — 9 IPs concentrated in one /24 block. |
| 185.82.73.0/24 | 8 | ICS/OT-attributed subnet anchor — targets industrial control system infrastructure. |
| 23.224.4.0/24 | 5 | C2 infrastructure concentration. |
| 91.92.43.0/24 | 4 | Botnet C2 infrastructure (continues from prior weeks). |
| 175.110.121.0/24 | 4 | Second ICS/OT-attributed anchor. |
| 45.138.26.0/24 | 4 | Tracked-cluster group infrastructure. |
| 156.247.47.0/24 | 4 | Commodity RAT C2 infrastructure. |
| 88.80.150.0/24 | 3 | Third ICS/OT-attributed anchor — 3 blocks total, 15 IPs concentrated. |
| 45.61.163.0/24 | 3 | DPRK-adjacent APT infrastructure anchor. |
| 45.59.122.0/24 | 3 | RAT operator anchor. |
| 216.252.238.0/24 | 3 | APT-tier subnet anchor. |
| 188.227.106.0/24 | 3 | Tracked-cluster secondary anchor. |
The asymmetric block. The ICS/OT-attributed campaign operates across three distinct /24 anchors with 15 concentrated IPs — unusual for an ICS/OT-focused cluster. Blocking all three /24s at the perimeter costs the defender nothing (no legitimate business use) and forces the operator to rebuild across three different hosting tenants simultaneously to defeat the block. The 9-IP-in-one-/24 anchor and the 3-IP DPRK-adjacent anchor are the other high-leverage blocks.
08 · Top IOCs per indicator type
Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.] → . and hxxp → http). Domain list reduced this week to remove brand-referencing entries.
Top 15 · IP addresses (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 1.94.106.150 | C2 / Botnet | HIGH |
| 02 | 101.96.224.108 | C2 / Botnet | HIGH |
| 03 | 103.101.85.111 | C2 / Botnet | HIGH |
| 04 | 103.149.93.150 | C2 / Botnet | HIGH |
| 05 | 103.235.46.102 | APT | HIGH |
| 06 | 103.27.109.233 | C2 / Botnet | HIGH |
| 07 | 103.31.250.253 | APT | HIGH |
| 08 | 103.97.0.57 | Malware | HIGH |
| 09 | 104.168.22.209 | C2 / Botnet | HIGH |
| 10 | 104.194.133.210 | RAT | HIGH |
| 11 | 104.194.159.150 | APT | HIGH |
| 12 | 104.238.34.209 | Loader | HIGH |
| 13 | 104.243.35.63 | Ransomware | HIGH |
| 14 | 104.248.134.194 | APT | HIGH |
| 15 | 102.117.171.29 | C2 / Botnet | HIGH |
Top domains (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 0059595390202402400202[.]sobul[.]net | Malware | HIGH |
| 02 | 01058telecom[.]de | Malware | HIGH |
| 03 | 0co7tx46[.]worldofmacarons[.]com | Malware | HIGH |
| 04 | 0xvona[.]duckdns[.]org | RAT | HIGH |
| 05 | 0zbqnac1t4dv2t2wuodv1m[.]com | Malware | HIGH |
| 06 | 365softupdate[.]com | APT | HIGH |
| 07 | 4mrkjecd[.]rsudtarutung[.]com | Malware | HIGH |
| 08 | 57b0rv7c[.]sansekerta[.]org | Malware | HIGH |
| 09 | 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com | RAT | HIGH |
| 10 | 5teun337[.]yummiquickway[.]com | Malware | HIGH |
| 11 | abcd[.]gamesen[.]icu | Malware | HIGH |
Top 15 · File hashes (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 0002a8d9b71895c616dd52e32eb08823c79ce423a238757fcd275c13806dcb66 | Malware | HIGH |
| 02 | 000732e37ed2431c677cca56aafbd53f | Ransomware | HIGH |
| 03 | 000a25edc1bd2e91d65851c5171edf6facc0ca3f | APT | HIGH |
| 04 | 000f0de250917d2d7a90c70116f0422f | APT | HIGH |
| 05 | 0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a | APT | HIGH |
| 06 | 00113b357f18ba5f62c3e8856871f1902f019a1a16de2e3c8a29f84de2565065 | Malware | HIGH |
| 07 | 001c16af3cfde47a3289e5c55d72533c5c0e4bc4 | APT | HIGH |
| 08 | 001e1824fef043f26d235ccf7eec71cdebfb419a | APT | HIGH |
| 09 | 001e9bf4488c5bca1a81d087d2e310b4cf42f123 | APT | HIGH |
| 10 | 001f205103af843faa77bb811ef33bd791a184e9dc629363c3da509c16f5420c | Malware | HIGH |
| 11 | 001faaf397dde12a044efeb98efd972bdec0229c | APT | HIGH |
| 12 | 0022520838406bf985cc7ad13487288f8f4364e823fa3d41d44c4dbee9d659ee | Malware | HIGH |
| 13 | 0024b6045416febb3b3c80569fbb7c4fe85e3ce8112e7dba6d80b3d601ffb523 | Malware | HIGH |
| 14 | 00295a9ed4dbc4bb25b423ccd04af37e331d42a86f48edbeff5bd811fa97b899 | Malware | HIGH |
| 15 | 003e4e3f3f4bb96ba4ddd10a43a7b5290cc237c1 | APT | HIGH |
Top 15 · URLs (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | hxxp[://]0xvona[.]duckdns[.]org | RAT | HIGH |
| 02 | hxxp[://]103.31.250.253 | APT | HIGH |
| 03 | hxxp[://]110.92.64.17/moo.cgi | Malware | HIGH |
| 04 | hxxp[://]117.175.185.81:8003/ | Malware | HIGH |
| 05 | hxxp[://]118.195.183.6/activity | Malware | HIGH |
| 06 | hxxp[://]118.31.115.178:4444/ga.js | Malware | HIGH |
| 07 | hxxp[://]118.31.115.178:9999/ptj | Malware | HIGH |
| 08 | hxxp[://]124.220.215.195:5555/pixel | Malware | HIGH |
| 09 | hxxp[://]124.220.215.195:9999/ca | Malware | HIGH |
| 10 | hxxp[://]124.223.12.165/ | Framework | HIGH |
| 11 | hxxp[://]129.211.215.7/dot.gif | Malware | HIGH |
| 12 | hxxp[://]154.3.0.70:83/cm | Malware | HIGH |
| 13 | hxxp[://]157.254.223.141/25/ | RAT | HIGH |
| 14 | hxxp[://]101.91.154.125:50001/cm | Malware | HIGH |
| 15 | hxxp[://]106.15.62.124:2222/push | Malware | HIGH |
09 · Sigma detection rules
Sigma 01 · Universal loader behaviour (polymorphic-build durable defence)
title: Universal Loader Behaviour — Polymorphic Build Family Detector
id: 6a2c8e1f-5b74-4930-a681-3f9b5c2e8d10
status: experimental
description: Detects the universal loader behaviour signature — a downloaded
binary spawns from a browser or document reader parent process, then triggers
outbound network traffic to a non-corporate destination within 60 seconds.
Catches polymorphic-build loader families where hash-blocking is defeated
by build-farm volume.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.execution
- attack.t1204
- attack.command_and_control
- attack.t1105
- attack.t1071.001
logsource:
product: correlation
detection:
s1_downloaded_binary:
EventID: 4688
ParentImage|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\edge.exe'
- '\OUTLOOK.EXE'
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\AcroRd32.exe'
Image|contains:
- '\Downloads\'
- '\Temp\'
- '\AppData\Local\Temp\'
s2_outbound_web:
EventID: 5156
DestinationPort: [80, 443, 8080, 8443]
DestinationIp|expand: '%non_corporate_destinations%'
condition: s1_downloaded_binary and s2_outbound_web within 60s
falsepositives:
- Legitimate software installers from allowlisted domains
level: high
Sigma 02 · Universal APT chain (adversary-acquired domain first-seen)
title: Universal APT Chain — Adversary-Acquired Domain First-Seen Contact
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a90
status: experimental
description: Detects DNS or HTTP contact with a domain that (a) has been
first-observed to your environment within the last 24 hours, (b) has a
registration age under 30 days, and (c) is contacted from a workstation
rather than a mail-gateway or web-proxy. Catches the universal APT
first-stage-C2 pattern across most attributed clusters.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.command_and_control
- attack.t1071.001
- attack.resource_development
- attack.t1583.001
logsource:
category: dns_query
detection:
selection:
QueryName|first_seen_within: 24h
QueryName|registration_age: <30d
SourceHost|category: workstation
condition: selection
falsepositives:
- New corporate SaaS onboarding (allowlist by known-good tenant patterns)
level: high
Sigma 03 · PLC-targeted subnet + OT-protocol egress
title: PLC-Targeted Subnet Anchor Contact + OT-Protocol Egress (ICS/OT)
id: 8d1a4b6f-5c92-4670-a881-3f9c7d5b2a40
status: experimental
description: Detects any outbound connection to the PLC-targeted campaign's
three concentrated subnet anchors. Also fires on OT-protocol traffic to any
destination outside the internal OT segment. Critical signal for OT/ICS
environments.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.command_and_control
- attack.t1071
- ics.t0819
- ics.t0866
logsource:
category: network_connection
detection:
ot_subnet_anchors:
DestinationIp|cidr:
- '185.82.73.0/24'
- '175.110.121.0/24'
- '88.80.150.0/24'
ot_protocol_egress:
DestinationPort:
- 502 # Modbus TCP
- 44818 # EtherNet/IP
- 20000 # DNP3
- 34962 # Profinet
- 34963 # Profinet
- 34964 # Profinet
DestinationIp|expand: '%external_destinations%'
condition: ot_subnet_anchors or ot_protocol_egress
falsepositives:
- Legitimate OT vendor remote-support (allowlist by known-good IPs)
level: critical
Sigma 04 · SVG file with embedded script content
title: SVG File Delivery with Embedded Script Content
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a10
status: experimental
description: Detects delivery of SVG files (inbound mail attachment or web
download) that contain embedded JavaScript. Catches the SVG-embedded
script delivery campaign and any future SVG-based delivery.
references:
- https://hackforlab.com/weekly-threat-advisory-july-20-26-2026/
author: HackForLab Threat Intelligence
date: 2026/07/27
tags:
- attack.initial_access
- attack.t1566.001
- attack.execution
- attack.t1204.002
- attack.t1059.007
logsource:
category: file_event
detection:
svg_delivery:
TargetFilename|endswith: '.svg'
FileContent|contains:
- '
10 · Hunt queries — SIEM-agnostic pseudo-syntax
Hunt 01 · Loader chain — browser/document parent + outbound web within 60s
// Pseudo-query
FROM process_creates AS pc
JOIN network_flows AS nf
ON pc.host = nf.src_host
AND nf.flow_time BETWEEN pc.create_time AND pc.create_time + 60s
WHERE pc.parent_process IN ('chrome.exe', 'firefox.exe', 'edge.exe',
'OUTLOOK.EXE', 'winword.exe', 'excel.exe',
'powerpnt.exe', 'AcroRd32.exe')
AND pc.image_path MATCHES regex '\\(Downloads|Temp)\\'
AND nf.dest_ip NOT IN (allowlisted_ranges)
AND nf.dest_port IN (80, 443, 8080, 8443)
| PROJECT pc.host, pc.image_path, nf.dest_ip, nf.dest_domain
| SORT BY pc.create_time DESC
Hunt 02 · APT subnet-anchor first-seen contact
// Pseudo-query
FROM network_flows
WHERE dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24',
'45.61.163.0/24', '216.252.238.0/24', '185.177.93.0/24')
AND first_seen_pair(src_ip, dest_ip) WITHIN 90d
| PROJECT src_ip, dest_ip, first_seen
| SORT BY first_seen DESC
Hunt 03 · ICS/OT subnet + OT protocol traffic
// Pseudo-query
FROM network_flows
WHERE (dest_ip IN CIDR('185.82.73.0/24', '175.110.121.0/24', '88.80.150.0/24'))
OR (dest_port IN (502, 44818, 20000, 34962, 34963, 34964)
AND dest_ip NOT IN (internal_ot_segment))
| AGGREGATE BY src_ip, dest_ip, dest_port
| SORT BY flow_count DESC
Hunt 04 · New-registration domain first-seen from workstations
// Pseudo-query FROM dns_queries WHERE first_seen_in_environment(query_name) WITHIN 24h AND domain_registration_age(query_name) < 30d AND src_host_category = 'workstation' | PROJECT src_host, query_name, query_time | SORT BY query_time DESC
11 · Operationalise in 60 minutes
Minute 00 – 15 · Block + sinkhole
- Block all three ICS/OT-attributed subnet anchors: 185.82.73.0/24, 175.110.121.0/24, 88.80.150.0/24.
- Block the largest single-cluster anchor 185.177.93.0/24 (9 concentrated IPs).
- Block DPRK-adjacent anchor 45.61.163.0/24 + APT-tier anchor 216.252.238.0/24.
- Add outbound-deny for WebDAV traffic from non-collaboration-tool hosts.
Minute 15 – 30 · Detection content
- Deploy Sigma 01 (universal loader behaviour) — catches polymorphic-loader families without hash volatility.
- Deploy Sigma 02 (universal APT chain — new-registration domain first-seen).
- Deploy Sigma 03 (ICS/OT subnet + OT-protocol egress) — critical for OT/ICS environments.
- Deploy Sigma 04 (SVG with embedded script).
Minute 30 – 45 · Retrospective hunt
- Run Hunt 01 (loader chain) baseline scan across last 30 days.
- Run Hunt 02 (APT subnet-anchor first-seen) across last 90 days.
- Run Hunt 03 (ICS/OT subnet + OT-protocol egress) across last 60 days.
- Run Hunt 04 (new-registration domain first-seen) across last 30 days.
Minute 45 – 60 · Awareness + policy
- Brief cryptocurrency-adjacent users on collaboration-platform impersonation lures.
- Brief HR on the IT-worker infiltration pattern — video-verify interviews, cross-check identities against second-source records, flag applicants using VPN or unusual geolocation.
- For OT/ICS environments: emergency verification that no internet-accessible PLCs are exposed. Immediate external-attack-surface inventory recommended.
- Update mail-gateway policy to inspect SVG file contents (treat as executable-adjacent).
This briefing ships a selected subset per type. The catalogue carries the full 77,118 unique IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.
12 · Frequently asked questions
25 attributed APT clusters in one week — is that unusual?
Yes. Twenty-five concurrent attributed APT clusters is the widest APT footprint in this catalogue year-to-date. The typical week sees 5-10 concurrent attributed clusters; this week's 25 is more than double baseline. Organisations in strategic-vertical environments (research, government-adjacent, critical infrastructure, cryptocurrency-adjacent) should prioritise indicator ingestion this week. The APT-storm signal is a leading indicator of near-term intrusion activity.
Two loader families produced 15,000 hashes in one week. How does hash-blocking survive that?
It doesn't. Hash-blocking is fragile against polymorphic-build volume at that scale — the operator can generate new variants faster than any hash feed can catalogue them. The durable defence is behavioural loader detection (Sigma 01 above). Detect the pattern browser/document parent → downloaded binary → outbound web within 60s, and you catch the family regardless of hash variance.
Why is the PLC-targeted campaign flagged as critical when it's only 26 IOCs?
Because it targets industrial control systems, not enterprise IT. A single successful PLC compromise can shut down a power substation, contaminate a water treatment facility, or halt a manufacturing line. The impact-per-IOC is orders of magnitude higher than typical malware. For any organisation operating OT/ICS environments, this cluster belongs in the priority-block queue regardless of IOC count.
What is the IT-worker infiltration campaign and why is it different?
DPRK-linked operatives applying to legitimate remote-work positions using fabricated identities to gain insider access to target organisations. It is not primarily an endpoint threat; it is a HR-workflow threat. The operator wins by getting hired. Detection requires HR-workflow controls (video-verify interviews, independent identity verification, second-source employment/education checks) — not detection content.
Why is SVG script delivery worth its own detection rule?
Because most email-attachment scanners don't treat SVG as executable-adjacent. SVG files can contain embedded JavaScript that executes when the file is rendered in a browser — including via inline preview in mail clients. The delivery vector defeats attachment-scanning defensive controls that would catch a malicious .exe / .doc / .zip. Adding SVG content inspection at the mail gateway closes the gap.
What confidence threshold should the SOC use for automated blocking?
High confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting.
Where can I see this briefing's intelligence operationally?
The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference.










