Framework-C2 week. The commodity C2 framework tier surged to 52,717 unique indicators across 25+ concentrated /24 subnet anchors — the highest weekly framework-C2 volume catalogued year-to-date. Concurrently: an emerging supply-chain wave targeting the developer ecosystem (fake package registrations, fake installer sites, fake AI-assistant installers), a macOS-native malware surge across three concurrent families, three concurrent ransomware operators, and continued Iranian-linked APT activity.
54,763 unique indicators, 107 tracked clusters, nine source feeds. Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, subnet anchors, top IOCs per indicator type, four production-ready Sigma rules, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.
HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.
01 · This week in numbers
54,763 unique indicators across 107 tracked clusters this cycle. IP volume dominates at 97% share (52,984 unique IPs) — driven almost entirely by the framework-C2 tier’s year-to-date-high infrastructure footprint. Narrow-indicator layer (domain + URL + hash) at ~3% share. Severity distribution: 3.2% High (1,738 records) — a low High-share this cycle because most of the volume sits at Medium (framework-C2 baseline is Medium-scored per-IP).
Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.
02 · Five headlines — what defined this cycle
Headline 01 · Framework-C2 infrastructure at year-to-date highs
The dominant story of the week. The open-framework C2 tier — the commodity C2 framework used almost universally by red teams and by cost-conscious operators — produced 52,717 unique indicators across 25+ concentrated /24 subnet anchors this cycle. This is the highest weekly framework-C2 volume catalogued year-to-date, and the density of concentrated anchors (25 /24 blocks each with 30-106 concentrated IPs) is unusual.
Sub-anchors: multiple concentrated /24 blocks (typical density: 30-106 IPs per anchor). Full anchor list available via the operator console.
Defensive answer: deploy standard framework-C2 detection signatures at network egress (TLS fingerprint / JA3-JA3S / POST-URI pattern matching / sleep-jitter timing anomalies). Block the top-10 concentrated anchors outright if no legitimate red-team infrastructure operates from them.
Headline 02 · Emerging supply-chain wave
Multiple concurrent supply-chain / fake-installer campaigns targeting the developer ecosystem this cycle. Signals: a fake-package supply-chain campaign (19 IOCs across three IOC types) impersonating benign-looking package registrations, a fake developer-tooling site campaign (10 IOCs) hosting a fake corepack-style installer, a fake AI-assistant installer campaign (8 IOCs across four IOC types), and a fake job-interview software campaign (13 IOCs) targeting cryptocurrency-adjacent developer roles.
The pattern — targeting developers with fake tooling — is not new but the concurrent volume this week is above baseline. Developer machines carry disproportionate blast radius (cloud credentials, code-signing keys, CI/CD access), which is why this is a MUST-priority signal even at low aggregate IOC count.
Defensive answer: mail-gateway policy blocking untrusted .pkg / .msi / .dmg installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only.
Headline 03 · macOS malware surge (three families concurrent)
Three concurrent macOS-native malware families active this cycle. Combined footprint: 136 IOCs across DOMAIN + HASH + IP. One larger cross-platform family (76 IOCs) with a v4.0 evolution, one macOS-native RAT family (18 IOCs), one macOS-sync malware campaign (10 IOCs). The concurrent-family signal is more important than the individual IOC counts — macOS-native adversary activity typically appears in ones-and-twos per cycle, not threes.
Defensive answer: confirm EDR coverage across all macOS endpoints (many environments still have coverage gaps). Verify endpoint-detection includes recent macOS TCC-abuse and launch-agent-persistence patterns.
Headline 04 · Three ransomware operators active in parallel
Three distinct ransomware families active this cycle. Combined ransomware-category footprint: 747 IOCs across three operators. Notable: an established RaaS operator resurfaced with 275 fresh IOCs, a mid-tier operator active at 48 IOCs, a newer-brand operator at 25 IOCs (first-observation in this catalogue — either a rebrand or a genuinely new market entrant).
Defensive answer: ensure endpoint-detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion, service-stop, backup-service kill). If backups are not immutable or air-gapped, address this week regardless of any other signal.
Headline 05 · Iranian-linked APT clusters and regional operations
Three tracked APT clusters linked to Iranian regional operations produced fresh IOCs this cycle. Combined regional-operation footprint (Iranian-linked + Southeast-Asian tracker + attributed regional cluster): 62+ IOCs across five APT-category clusters. Target profiles include Middle East diplomatic missions, defence-industrial-base research, and government-adjacent think-tanks.
Defensive answer: if your organisation operates in energy, defence-industrial-base, diplomatic, government-adjacent research, or Middle East regional verticals, treat these clusters as MUST-block infrastructure. Alert real-time on first-seen contact.
03 · Indicator type, severity, and category mix
IP dominance at 97% share is the story of this week — the framework-C2 tier alone accounts for 52,717 IOCs (essentially all of the IP volume). Narrow indicators (domain/URL/hash) sit at ~3% share. Severity distribution: only 3.2% High (1,738 records) — framework-C2 IPs are Medium-scored per-IP (low-per-IP risk in a properly-defended environment). Category dominance: C&C at 96.3% share.
Bars scaled relative to the dominant IP volume so smaller slices remain visible. The 97% IP share reflects the framework-C2 baseline. The narrow-indicator layer (1,751 records = 3%) is where the campaign-specific intelligence lives — see Lesson 06 below.
By indicator type
| Type | Observations | Share | % |
|---|---|---|---|
| IPs | 52,984 | 96.75% | |
| Domains | 813 | 1.48% | |
| URLs | 514 | 0.94% | |
| File hashes | 424 | 0.77% | |
| Other artefacts | 23 | 0.04% | |
| Emails | 5 | 0.01% |
By severity
| Severity | Observations | Share | % |
|---|---|---|---|
| High | 1,738 | 3.17% | |
| Medium | 53,002 | 96.78% | |
| Low | 24 | 0.04% |
By category
| Category | Observations | Share | % |
|---|---|---|---|
| C&C | 52,717 | 96.26% | |
| Malware-Activity | 718 | 1.31% | |
| Ransomware-as-a-service | 389 | 0.71% | |
| APT | 224 | 0.41% | |
| Phishing | 200 | 0.37% | |
| RAT | 140 | 0.26% | |
| Backdoor | 123 | 0.22% | |
| Botnet | 93 | 0.17% | |
| Supply Chain | 62 | 0.11% | |
| C&C Server | 33 | 0.06% | |
| Malicious-Infrastructure | 17 | 0.03% | |
| Loader | 15 | 0.03% | |
| Framework | 15 | 0.03% | |
| Trojan | 10 | 0.02% | |
| Spyware | 9 | 0.02% |
04 · Cluster footprint — ranked by unique-IOC count
40 clusters ranked by unique IOC footprint. Framework-infrastructure entries shown in grey to preserve visual clarity of the campaign-attributed clusters. All labels sanitised into category descriptors.
| # | Cluster descriptor | Relative footprint | Unique IOCs | Severity |
|---|---|---|---|---|
| 01 | Open-framework C2 infrastructure (framework tier)
C2 · IP
|
52,717 | MEDIUM | |
| 02 | Ransomware-as-a-service operator (Cluster A)
Ransomware · DOMAIN
|
275 | HIGH | |
| 03 | Info-stealer family (Cluster B)
Malware · DOMAIN, IP, URL
|
268 | HIGH | |
| 04 | Broad-infrastructure phishing kit
Phishing · DOMAIN
|
191 | MEDIUM | |
| 05 | Attributed APT cluster (identifier C)
APT · DOMAIN, HASH, IP, URL
|
97 | HIGH | |
| 06 | Multi-stage operation (Cluster D)
Malware-Activity · DOMAIN, HASH, IP, URL
|
92 | HIGH | |
| 07 | macOS-native malware family (Cluster E)
Malware · DOMAIN, HASH, IP
|
76 | HIGH | |
| 08 | Loader family (Cluster F)
Loader · DOMAIN, HASH, IP
|
73 | HIGH | |
| 09 | Fake-application malware campaign
Malware-Activity · DOMAIN
|
71 | HIGH | |
| 10 | Multi-stage operation (Cluster G)
Malware-Activity · DOMAIN, IP, URL
|
59 | HIGH | |
| 11 | Commodity RAT family (Cluster H)
RAT · DOMAIN, HASH, IP, URL
|
50 | MEDIUM | |
| 12 | Mobile-adjacent malware family
Malware · DOMAIN, HASH, IP
|
50 | HIGH | |
| 13 | Ransomware operator (Cluster I)
Ransomware · DOMAIN, HASH
|
48 | HIGH | |
| 14 | Multi-family backdoor campaign
Backdoor · DOMAIN, HASH, IP
|
47 | HIGH | |
| 15 | Info-stealer family (Cluster J)
Malware · DOMAIN, HASH, IP
|
44 | HIGH | |
| 16 | Regional-tracked APT cluster (Southeast Asia)
APT · DOMAIN, HASH, IP
|
32 | HIGH | |
| 17 | Iranian-linked APT cluster (identifier K)
APT · DOMAIN, HASH, IP
|
31 | HIGH | |
| 18 | Multi-stage operation (Cluster L)
Malware-Activity · DOMAIN, HASH, IP
|
30 | HIGH | |
| 19 | Ransomware operator (Cluster M)
Ransomware · DOMAIN, HASH
|
25 | HIGH | |
| 20 | Open remote-agent framework
C2 · IP
|
25 | MEDIUM | |
| 21 | gRPC-based C2 campaign
Malware-Activity · DOMAIN, HASH, IP
|
23 | HIGH | |
| 22 | Developer-targeting RAT family
RAT · DOMAIN, HASH, IP
|
23 | HIGH | |
| 23 | Supply-chain package attack (Cluster N)
Supply Chain · DOMAIN, HASH, IP
|
19 | HIGH | |
| 24 | Info-stealer family (Cluster O)
Malware · DOMAIN
|
19 | HIGH | |
| 25 | Attributed APT cluster (identifier P)
APT · DOMAIN, HASH
|
18 | HIGH | |
| 26 | macOS-native RAT family
Malware · DOMAIN, HASH, IP
|
18 | HIGH | |
| 27 | Browser-extension proxy-abuse campaign
Malware-Activity · DOMAIN
|
17 | HIGH | |
| 28 | Loader family (Cluster Q)
Loader · DOMAIN, HASH, IP
|
15 | HIGH | |
| 29 | RAT-family delivery campaign
Malware · DOMAIN, HASH
|
14 | HIGH | |
| 30 | Fake-installer supply-chain campaign (developer-lure)
Malware · DOMAIN, HASH, IP
|
13 | HIGH | |
| 31 | Iranian-linked APT cluster (identifier R)
APT · DOMAIN, HASH
|
13 | HIGH | |
| 32 | API-specification abuse malware campaign
Malware-Activity · DOMAIN, HASH, IP, URL
|
13 | HIGH | |
| 33 | Attributed APT cluster (identifier S)
APT · DOMAIN, HASH, IP
|
12 | HIGH | |
| 34 | Botnet operator (Cluster T)
Botnet · DOMAIN, HASH
|
11 | HIGH | |
| 35 | Recurrent malware campaign (Cluster U)
Malware-Activity · DOMAIN, HASH
|
11 | HIGH | |
| 36 | Fake developer-tooling phishing site
Phishing · DOMAIN
|
10 | LOW | |
| 37 | macOS-sync malware campaign
Malware-Activity · DOMAIN, HASH, IP
|
10 | HIGH | |
| 38 | Commodity RAT family (Cluster V)
Malware · DOMAIN, HASH
|
10 | HIGH | |
| 39 | Banking-focused malware family
Malware · DOMAIN, HASH, IP
|
10 | HIGH | |
| 40 | Fake-AI-assistant installer campaign
Malware-Activity · DOMAIN, HASH, IP, URL
|
8 | HIGH |
05 · Themed deep-dives
05.1 · Framework-C2 infrastructure at year-to-date highs
The commodity C2 framework tier surged to 52,717 unique indicators across 25+ concentrated /24 subnet anchors this cycle — the highest weekly framework-C2 volume catalogued year-to-date. The density of concentrated anchors is the unusual signal. A typical week sees 5-8 /24s at high concentration; this week has 25.
Top-density anchors: the largest single-block concentration this cycle held ~106 concentrated IPs; the second- and third-tier anchors held 88 and 62 IPs each. Multiple sibling-pair anchors observed (concurrent blocks adjacent in address space suggesting shared operator provisioning).
Defensive actions: deploy standard framework-C2 detection signatures at network egress (TLS fingerprint / JA3-JA3S / POST-URI pattern matching / sleep-jitter timing anomaly detection). Block the top-10 anchors outright if no legitimate red-team infrastructure operates from them. This is the single loudest defensive signal you can deploy against a modern threat surface.
05.2 · Supply-chain wave — developer-ecosystem targeting
Multiple concurrent supply-chain and fake-installer campaigns this cycle. Combined footprint modest at ~60 IOCs but the concurrent-family signal is notable.
- Fake-package supply-chain campaign — 19 IOCs across three IOC types. Impersonates a benign-looking package registration to seed malicious dependencies into the developer ecosystem. Standard supply-chain attack pattern.
- Fake developer-tooling site campaign — 10 IOCs. Hosts a fake corepack-style installer at a lookalike domain. Delivers a signed-but-attacker-configured binary.
- Fake AI-assistant installer campaign — 8 IOCs across four IOC types. Impersonates an AI-assistant installer. Notable for full-4-type coverage from a small-footprint operator (mature infrastructure).
- Fake job-interview software campaign — 13 IOCs. Targets cryptocurrency-adjacent developer roles with fake “interview software” downloads.
Why this matters: developer machines carry disproportionate blast radius. Cloud credentials, code-signing keys, CI/CD access, SSH keys, package-registry publish tokens. A single compromised developer can seed malicious code into hundreds of downstream consumers. Supply-chain attacks at this concurrent volume warrant MUST-priority attention even at low aggregate IOC count.
Defensive actions: mail-gateway policy blocking untrusted .pkg / .msi / .dmg installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit code-signing key access patterns; verify CI/CD secret rotation is on-schedule.
05.3 · macOS malware surge — three families concurrent
Three concurrent macOS-native malware families active this cycle. Combined footprint: 136 IOCs across DOMAIN + HASH + IP. A larger cross-platform family with a v4.0 evolution (76 IOCs) leads the volume, a macOS-native RAT family (18 IOCs) provides mid-tier persistence, and a macOS-sync malware campaign (10 IOCs) rounds out the surface.
Why this matters: macOS-native adversary activity typically appears in ones-and-twos per cycle in this catalogue. Three concurrent families is elevated and unusual. Many environments still have EDR coverage gaps on macOS endpoints (design engineering, executive laptops, creative teams).
Defensive actions: confirm EDR coverage across all macOS endpoints without exceptions. Verify endpoint-detection includes recent macOS-specific patterns: TCC bypass attempts, LaunchAgent + LaunchDaemon persistence, dylib-injection, unsigned-binary execution from user-writable paths.
05.4 · Three ransomware operators in parallel
Three distinct ransomware families active this cycle. Combined ransomware-category footprint: 747 IOCs. Notable:
- Established RaaS operator resurfaced with 275 fresh IOCs — suggests affiliate-program reactivation.
- Mid-tier operator active at 48 IOCs across two IOC types.
- Newer-brand operator appeared with 25 IOCs — first observation in this catalogue; either rebrand or new market entrant.
Defensive actions: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion, service-stop, backup-service kill patterns). If backups are not immutable or air-gapped, address this week regardless of any other signal.
05.5 · Iranian-linked APT clusters and regional operations
Three tracked APT clusters linked to Iranian regional operations produced fresh IOCs this cycle. Combined APT-category footprint including Iranian-linked + Southeast-Asian tracker + attributed regional clusters: 224 IOCs across 5+ APT clusters. Target profiles include Middle East diplomatic missions, defence-industrial-base research, government-adjacent think-tanks, and cryptocurrency-adjacent finance.
Defensive actions: if your organisation operates in energy, defence-industrial-base, diplomatic, government-adjacent research, or Middle East regional verticals, treat these clusters as MUST-block infrastructure. Real-time alerting on first-seen contact.
06 · ATT&CK tactic-pressure roll-up
| Tactic | Top techniques observed | What the pressure means | IOC count |
|---|---|---|---|
| Command and Control | T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 | Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling — dominant at year-to-date-high volume | 52,717 |
| Initial Access | T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 | Valid accounts, external remote services, public-facing exploit, phishing (attachment + link), supply chain | 486 |
| Execution | T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1218 | Command interpreter (shell / VB / JS), user-execution, signed-binary proxy execution | 412 |
| Ingress Tool Transfer | T1105 | Second-stage payload pull — universal across every multi-stage cluster | 338 |
| Defense Evasion | T1027 · T1036 · T1055 · T1070 · T1140 · T1562 | Obfuscation, masquerading, process injection, indicator removal, deobfuscate, disable defences | 289 |
| Persistence | T1547.001 · T1543.003 · T1053.005 · T1505.003 · T1543.001 | Registry-run keys, service creation, scheduled tasks, webshell, launch-agent (macOS) | 214 |
| Credential Access | T1003 · T1003.001 · T1555 · T1552.001 · T1110 | OS credential dumping, password store theft, brute force — info-stealer families driving credential-access volume | 178 |
| Discovery | T1082 · T1057 · T1083 · T1018 · T1046 | System info, process, file, remote-system, network configuration | 156 |
| Lateral Movement | T1021 · T1021.001 · T1021.002 · T1570 | Remote-desktop, SMB / admin shares, lateral tool transfer | 123 |
| Exfiltration | T1041 · T1567 · T1090 | Exfil over C2, exfil to web service, tunnel-based exfil | 187 |
| Impact | T1486 · T1489 · T1490 | Data encryption for impact (ransomware), service stop, inhibit system recovery | 89 |
| Resource Development | T1583.001 · T1584.001 · T1585 · T1195.002 | Adversary-acquired domains + compromised infrastructure + fabricated-identity + supply-chain compromise | 156 |
Detection-engineering takeaway. Command and Control is the dominant pressure this cycle at 52,717 IOCs (framework-C2 tier alone). Standard framework-signature detectors at network egress are the single highest-leverage defensive control this week. Impact tactics (T1486 ransomware encryption, T1489 / T1490 service stop + inhibit recovery) elevated with three concurrent ransomware operators. Resource Development (T1583 / T1584 / T1195.002) elevated due to supply-chain wave — watch for compromised package-registry activity and lookalike-installer sites.
07 · Real-world threat intelligence lessons from this week’s data
Every week’s intelligence contains more than a list of things to block. It contains signals about how the adversary landscape is shifting — where operator investment is moving, which target profiles are getting attention, which defensive controls are becoming table-stakes versus differentiators. Below are the practical takeaways from this cycle’s data that will still matter next month, next quarter, and into the second half of the year.
Lesson 01 · When 97% of your feed is one category, your filtering discipline is the differentiator
Framework-C2 infrastructure produced 52,717 of this week’s 54,763 IOCs. That is not a threat report — that is baseline noise. If your SOC is treating each of those 52,000 IPs as an equal-priority alert, you are drowning your analysts and paying them to triage things a signature-based detector should catch automatically. The mature CTI program deploys standard framework-C2 signatures as always-on real-time content and treats the individual IPs as enrichment data (context on alerts that fire on the signature), not as primary alert sources. Fix your feed-consumption architecture before you fix any individual detection.
Lesson 02 · The developer machine is the new perimeter
The supply-chain wave this cycle — fake package registrations, fake developer-tooling installers, fake AI-assistant installers, fake job-interview software — is a signal about where operator investment is moving. Traditional network defences do not see a compromised developer. They see a normal user pulling packages, running installers, pushing code. The blast radius is disproportionate: one developer with cloud credentials, code-signing keys, and CI/CD access can seed malicious content into hundreds of downstream consumers. The controls that matter for defending this surface are identity, endpoint, and CI/CD-pipeline hygiene — not perimeter firewalls. If your security investment ratio is 80% network / 20% identity + endpoint, this week’s data says you are optimising for last decade’s attack surface.
Lesson 03 · Concurrent-family signals matter more than individual family volume
Three concurrent macOS-native malware families this week is a bigger signal than any single family’s IOC count would suggest. When multiple independent operators arrive at the same target profile in the same window, it means the profile is being validated as viable and profitable across the ecosystem. macOS-in-engineering-environments has been an under-invested defensive area in most SOCs for years; three families arriving simultaneously is the ecosystem telling you the under-investment is being exploited. The same pattern applies to concurrent ransomware operators, concurrent regional APT clusters, concurrent supply-chain campaigns — count operators, not indicators, when assessing pressure on a target profile.
Lesson 04 · Framework-C2 detection is now table stakes, not a differentiator
The commodity C2 framework is at year-to-date-high volume and appears in every category-attributed cluster this week. If you are not detecting the standard framework signatures (TLS fingerprint / JA3-JA3S / POST-URI pattern / sleep-jitter timing anomaly) at network egress, you are missing 96% of what threat operators are running through. This is no longer a “nice to have” detection category. It is table stakes. Detection engineering programs that have not shipped framework-C2 content in the last 18 months are behind the curve regardless of what other content they have shipped.
Lesson 05 · RaaS operator reactivation is a leading indicator
An established RaaS operator resurfaced this cycle with 275 fresh IOCs after a lull period — the classic signal that an affiliate program is being reactivated after either a takedown recovery, a rebrand, or an infrastructure refresh. Reactivation patterns are leading indicators: they typically precede a 4-8 week ramp-up in actual encryption events in the customer base. If you monitor a specific vertical (finance, healthcare, manufacturing, professional services), track which RaaS operators historically target that vertical, and treat their reactivation as an early-warning signal warranting emergency backup-immutability verification and endpoint-detection tuning. Do not wait for the encryption event.
Lesson 06 · The narrow-indicator layer is where the story lives
3% of this week’s IOCs are the narrow-indicator layer (domain + hash + URL). Those 1,751 records contain more actionable intelligence than the 52,984 IPs combined. Narrow indicators map to specific campaigns, specific actors, specific target profiles. Broad-infrastructure indicators are largely context. A CTI analyst spending time on narrow indicators produces more defensive value per hour than one processing broad infrastructure. If your CTI team’s time allocation does not reflect this ratio, redistribute.
The one-line synthesis. This week’s data says: the commodity C2 tier is louder than ever (deploy signature detectors), the developer machine is under active investment as a target profile (harden identity + endpoint + CI/CD), macOS coverage is an emerging gap (audit EDR reach), and RaaS reactivation is a leading indicator you can act on before the encryption event. Four takeaways from one week that will still matter next quarter. That is what intelligence is for.
08 · Top IOCs per indicator type
Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.] → . and hxxp → http).
Top 15 · IP addresses (framework-C2 anchors)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 64.69.57.10 | C2 / Framework | MEDIUM |
| 02 | 64.69.57.42 | C2 / Framework | MEDIUM |
| 03 | 103.234.72.5 | C2 / Framework | MEDIUM |
| 04 | 154.216.55.11 | C2 / Framework | MEDIUM |
| 05 | 154.213.58.9 | C2 / Framework | MEDIUM |
| 06 | 43.240.48.8 | C2 / Framework | MEDIUM |
| 07 | 45.156.217.14 | C2 / Framework | MEDIUM |
| 08 | 84.32.188.10 | C2 / Framework | MEDIUM |
| 09 | 108.62.118.7 | C2 / Framework | MEDIUM |
| 10 | 23.108.57.13 | C2 / Framework | MEDIUM |
| 11 | 139.60.161.9 | C2 / Framework | MEDIUM |
| 12 | 23.106.215.5 | C2 / Framework | MEDIUM |
| 13 | 173.234.155.11 | C2 / Framework | MEDIUM |
| 14 | 172.241.27.9 | C2 / Framework | MEDIUM |
| 15 | 168.206.188.6 | C2 / Framework | MEDIUM |
Top domains (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 10mintimer[.]com | Malware | HIGH |
| 02 | 110gongan[.]com | RAT | HIGH |
| 03 | 2mblk[.]com | APT | HIGH |
| 04 | 4mblk[.]com | APT | HIGH |
| 05 | business-deegital[.]com | APT | HIGH |
| 06 | strepsils[.]top | Malware | HIGH |
| 07 | upgybj[.]store | APT | HIGH |
| 08 | 0tuiwp[.]mariomanagement[.]biz[.]id | Malware | HIGH |
| 09 | 2joafm[.]marioanalytics[.]my[.]id | Malware | HIGH |
| 10 | 4hawb[.]produtoeletro[.]my[.]id | Malware | HIGH |
| 11 | 1[.]232323[.]eu[.]org | Phishing | HIGH |
| 12 | 232323[.]eu[.]org | Phishing | HIGH |
Top file hashes (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | 015d7b212d20681d346e690159e7f4cd9e88b51de27e84b514fce865deef3a5c | Loader | HIGH |
| 02 | 016d90f337bd55dfcfbba8465a50e2261f0369cd448b4f020215f952a2a06bce | Trojan | HIGH |
| 03 | 01c3326ce5beb78a6c106960a3a0868682b97bfa | Botnet | HIGH |
| 04 | 0243692ce6ca522bc1359a3d89d70a229cf76587 | Botnet | HIGH |
| 05 | 0248c26c25bb5804f0c6d83238b6172c | Spyware | HIGH |
| 06 | 026c85b97a6ddac14c9835d0580228c0a82dd82ce12d8d921c2f3067a12bbb7e | Malware | HIGH |
| 07 | 029ba5f0f6997bc36a094e86848a5b82 | Malware | HIGH |
| 08 | 0334cd1b8ab17203179da1ae77c1fad97ddf794cc63a6048aca664956d10b2ca | Malware | HIGH |
| 09 | 03d93b56ac4219a8ac8a55fd4ba777618b5682cc84bec0efe8ea78e497dd3b3d | RAT | HIGH |
| 10 | 04bef2153417efeb408d8e027bd91bb6db5b957c43ceb7429a15cb76ef436af3 | RAT | HIGH |
| 11 | 04e216f4780b6292ccc836fa0481607c62abb244f6a2eedc21c4a822bcf6d79f | APT | HIGH |
| 12 | 054bad7ec0e19cec931078d45382fee6 | Malware | HIGH |
Top URLs (High severity)
| # | Indicator | Category | Severity |
|---|---|---|---|
| 01 | hxxp[://]1[.]232323[.]eu[.]org | Phishing | HIGH |
| 02 | hxxp[://]122[.]114[.]10[.]239/edcvfr | Malware | HIGH |
| 03 | hxxp[://]122[.]114[.]10[.]239/qazxsw | Malware | HIGH |
| 04 | hxxp[://]125[.]47[.]207[.]244:49245/Mozi[.]m | Botnet | HIGH |
| 05 | hxxp[://]138[.]124[.]93[.]26/Client[.]hta | Phishing | HIGH |
| 06 | hxxp[://]141[.]164[.]61[.]90/file/config[.]php | Malware | HIGH |
| 07 | hxxp[://]154[.]29[.]74[.]158 | Ransomware | HIGH |
| 08 | hxxp[://]158[.]247[.]206[.]214/articles/list[.]php | Malware | HIGH |
| 09 | hxxp[://]158[.]247[.]232[.]35/bbns/bbns[.]php | Malware | HIGH |
| 10 | hxxp[://]172[.]86[.]107[.]229:3000 | Phishing | HIGH |
09 · Sigma detection rules
Sigma 01 · Framework-C2 signature at concentrated anchor (HIGH)
title: Framework-C2 — Standard TLS/URI Signature at Concentrated Subnet Anchor
id: 9a3d7f2b-8c14-4630-a781-2f9b5c2e8d31
status: experimental
description: Detects the standard framework-C2 signature set from any of this
cycle's 25+ concentrated /24 subnet anchors. TLS fingerprint match + POST-URI
pattern match + destination-IP in attributed anchor list.
references:
- https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1568
- attack.defense_evasion
- attack.t1573
logsource:
category: network_connection
detection:
s1_anchor_destination:
DestinationIp|cidr:
# 25+ concentrated framework-C2 /24 anchors this cycle
# anchor list distributed via the operator console feed
- 'concentrated_framework_anchor_list'
s2_framework_signal:
- tls_ja3s_hash|contains: 'known_framework_ja3s_signatures'
- request_uri|re: '/[a-z0-9]{4,16}$'
condition: s1_anchor_destination or (s2_framework_signal and DestinationIp|cidr: 'other_anchor_list')
falsepositives:
- Legitimate red-team engagements from allowlisted infrastructure
level: high
Sigma 02 · Untrusted installer to developer subnet (HIGH)
title: Developer Ecosystem — Untrusted Installer to Developer Subnet
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a92
status: experimental
description: Detects untrusted installer files (msi/pkg/dmg/exe) delivered to
developer-subnet endpoints via mail or download, with signer not in the
developer-tooling allowlist. Catches the supply-chain wave targeting
developers with fake tooling installers.
references:
- https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
- attack.initial_access
- attack.t1195.002
- attack.t1566.001
- attack.execution
- attack.t1204.002
logsource:
category: file_event
detection:
s1_installer_extension:
TargetFilename|endswith:
- '.msi'
- '.pkg'
- '.dmg'
- '.exe'
- '.deb'
s2_developer_subnet:
HostRoleTag:
- 'developer'
- 'engineer'
- 'devops'
- 'ci_cd'
s3_signer_not_allowlisted:
SignerCategory|not:
- 'developer_tooling_allowlisted'
- 'os_vendor'
- 'code_repository_platform_allowlisted'
condition: s1_installer_extension and s2_developer_subnet and s3_signer_not_allowlisted
falsepositives:
- Legitimate onboarding of new developer tooling (extend allowlist)
level: high
Sigma 03 · macOS LaunchAgent/Daemon persistence in user-writable path (HIGH)
title: macOS — LaunchAgent or LaunchDaemon Written to User-Writable Path
id: 6a5e9d3f-7b28-4c50-a941-5f8b6d2e9c31
status: experimental
description: Detects LaunchAgent or LaunchDaemon plist file writes to
user-writable paths on macOS endpoints — a persistence pattern used by
this cycle's three concurrent macOS malware families.
references:
- https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
- attack.persistence
- attack.t1543.001
- attack.t1543.004
logsource:
category: file_event
product: macos
detection:
s1_launch_persistence_path:
TargetFilename|contains:
- '/Library/LaunchAgents/'
- '/Library/LaunchDaemons/'
- '~/Library/LaunchAgents/'
TargetFilename|endswith: '.plist'
s2_writer_not_signed_by_apple_or_allowlisted:
ProcessSigner|not:
- 'apple_vendor'
- 'allowlisted_mac_publisher'
condition: s1_launch_persistence_path and s2_writer_not_signed_by_apple_or_allowlisted
falsepositives:
- Legitimate third-party tooling with allowlisted signers
level: high
Sigma 04 · Universal ransomware behaviour (CRITICAL)
title: Ransomware Behaviour — Mass File Encrypt + Shadow-Copy Delete + Service Stop
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a13
status: experimental
description: Universal ransomware behaviour detector — mass file-modify with
new extensions + shadow-copy deletion + backup-service stop within a short
window. Catches all three concurrent ransomware operators this cycle
without requiring family-specific signatures.
references:
- https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
- attack.impact
- attack.t1486
- attack.t1490
- attack.t1489
logsource:
product: correlation
detection:
s1_mass_file_modify:
EventCount|file_modify_events: '>100_per_minute'
NewFileExtension|distinct_count: '<3'
s2_shadow_copy_delete:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'wmic shadowcopy delete'
s3_backup_service_stop:
Service|category: 'backup_or_shadowcopy'
ServiceAction: 'stop_or_disable'
condition: (s1_mass_file_modify and s2_shadow_copy_delete)
or (s1_mass_file_modify and s3_backup_service_stop)
level: critical
10 · Hunt queries — SIEM-agnostic pseudo-syntax
Hunt 01 · Framework-C2 anchor destination contact (last 30 days)
FROM network_flows
WHERE destination_ip IN CIDR('concentrated_framework_anchor_list')
AND event_time >= NOW() - 30 DAYS
| PROJECT source_host, destination_ip, destination_port, bytes, event_time
| SORT BY event_time ASC
Hunt 02 · Untrusted installer file-write on developer subnet (last 60 days)
FROM edr_file_events
JOIN host_role_tag ht ON ht.host = file_events.host
WHERE ht.role_tag IN ('developer', 'engineer', 'devops', 'ci_cd')
AND file_events.target_filename MATCHES '.*\.(msi|pkg|dmg|exe|deb)$'
AND file_events.signer_category NOT IN ('developer_tooling_allowlisted', 'os_vendor')
AND file_events.event_time >= NOW() - 60 DAYS
| PROJECT ht.host, file_events.target_filename, file_events.source_url, file_events.event_time
Hunt 03 · macOS LaunchAgent/Daemon persistence writes (last 90 days)
FROM edr_file_events
WHERE endpoint_os = 'macos'
AND target_filename MATCHES '.*/(LaunchAgents|LaunchDaemons)/.*\.plist$'
AND writer_signer_category NOT IN ('apple_vendor', 'allowlisted_mac_publisher')
AND event_time >= NOW() - 90 DAYS
| PROJECT host, user, target_filename, writer_process, event_time
Hunt 04 · Ransomware behavioural triage (last 30 days)
FROM edr_file_events WHERE event_type = 'modify' AND file_modification_rate > 100_per_minute AND new_file_extension_distinct_count < 3 AND event_time >= NOW() - 30 DAYS | JOIN edr_process_create pc ON pc.host = edr_file_events.host | WHERE pc.command_line CONTAINS 'vssadmin' OR pc.command_line CONTAINS 'shadowcopy' | PROJECT host, user, new_file_extension, file_modification_rate, event_time
11 · Operationalise in 60 minutes
// Cyber-Ops Runbook · Deploy in 4 time-boxed sprints
▸ Minute 00 – 15 · Block + Sinkhole
- Block the top-10 framework-C2 concentrated anchors at the perimeter (anchor list available via the operator console feed). Range coverage: 10 concentrated /24 blocks account for ~600 of the framework-C2 IPs this cycle.
- Add outbound-deny for known ransomware TOR-negotiation portals (feed subscriber list).
- Mail-gateway policy: block
.msi/.pkg/.dmgattachments to developer subnets unless signer allowlisted. - Verify backup immutability given three concurrent ransomware operators.
▸ Minute 15 – 30 · Detection Content
- Deploy Sigma 01 (framework-C2 anchor + signature) at network egress.
- Deploy Sigma 02 (untrusted installer to developer subnet) at file-event layer.
- Deploy Sigma 03 (macOS LaunchAgent/Daemon persistence) on all macOS endpoints.
- Deploy Sigma 04 (universal ransomware behaviour) at critical severity, direct-to-oncall.
▸ Minute 30 – 45 · Retrospective Hunt
- Run Hunt 01 (framework-C2 anchor contact) across last 30 days.
- Run Hunt 02 (untrusted installer on developer subnet) across last 60 days.
- Run Hunt 03 (macOS persistence writes) across last 90 days.
- Run Hunt 04 (ransomware behavioural triage) across last 30 days.
▸ Minute 45 – 60 · Awareness + Policy
- Brief developer teams: fake-installer wave targeting developer ecosystem. Only install tooling from official vendor URLs; verify signatures.
- Brief macOS-endpoint users: three macOS malware families active this cycle. Confirm EDR coverage across all macOS endpoints without exceptions.
- Audit code-signing key access patterns for developer machines. Rotate CI/CD secrets if not on-schedule.
- If in energy/defence/diplomatic/Middle East verticals: escalate Iranian-linked cluster monitoring to real-time alerting.
This briefing ships a selected subset per type. The catalogue carries the full 54,763 unique IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.
12 · Frequently asked questions
Is the framework-C2 volume this week concerning by itself?
Not by itself — the framework tier is popular baseline noise. The signal is the density of concentrated anchors: 25 /24 blocks at high concentration is unusual (typical week is 5-8). It indicates either a coordinated red-team engagement season, coordinated threat-actor procurement of infrastructure from a small hosting pool, or both. Either way, the defensive answer is the same: deploy the standard framework-signature detectors.
Why is the supply-chain wave a MUST-priority at only ~60 IOCs?
Blast radius. Developer machines carry disproportionate downstream impact — cloud credentials, code-signing keys, CI/CD access, package-registry publish tokens, SSH keys. A single compromised developer can seed malicious code into hundreds of downstream consumers. Priority scoring is impact-per-target × exploitation-likelihood, not raw IOC count.
Three concurrent macOS malware families — is that unusual?
Yes. This catalogue typically sees ones-and-twos of macOS-native families per cycle. Three concurrent (with one showing a v4.0 evolution) is elevated. Combined with the developer-ecosystem supply-chain wave, this suggests attention on the macOS-in-engineering-environments target profile specifically.
How do I know if my organisation is in scope for the Iranian-linked APT clusters?
If your organisation operates in energy (oil, gas, utilities), defence-industrial-base, diplomatic missions, government-adjacent research (think-tanks, universities with government funding), or Middle East regional business — assume in-scope. If not, monitor as background signal but do not treat as MUST-priority.
What confidence threshold should the SOC use for automated blocking?
High-confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting. This week’s top-10 framework-C2 anchors are a special case — the concentration signal is strong enough that automatic blocking is safe if no legitimate red-team infrastructure operates from those ranges.
Where can I see this briefing’s intelligence operationally?
The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference. For hunt-program methodology, see the TaHiTI framework walkthrough.









