Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)

● CTI SITREP 026·31 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-031 · July 27 – August 2, 2026

Framework-C2 week. The commodity C2 framework tier surged to 52,717 unique indicators across 25+ concentrated /24 subnet anchors — the highest weekly framework-C2 volume catalogued year-to-date. Concurrently: an emerging supply-chain wave targeting the developer ecosystem (fake package registrations, fake installer sites, fake AI-assistant installers), a macOS-native malware surge across three concurrent families, three concurrent ransomware operators, and continued Iranian-linked APT activity.

54,763 unique indicators, 107 tracked clusters, nine source feeds. Sectioned for the working analyst: aggregate volumes, cluster-category footprint, ATT&CK tactic-pressure roll-up, subnet anchors, top IOCs per indicator type, four production-ready Sigma rules, and a 60-minute operationalisation plan. Vendor-neutral. Operator-grade. Archive of prior advisories.

OPERATOR-GRADE INTELLIGENCE → ONE QUERY AWAY

HuntIntel ships every IOC behind this briefing with provenance, confidence score, ATT&CK technique, and category attribution pre-mapped — queryable in the operator console, exportable to your SIEM in seconds.

Open HuntIntel →

01 · This week in numbers

54,763 unique indicators across 107 tracked clusters this cycle. IP volume dominates at 97% share (52,984 unique IPs) — driven almost entirely by the framework-C2 tier’s year-to-date-high infrastructure footprint. Narrow-indicator layer (domain + URL + hash) at ~3% share. Severity distribution: 3.2% High (1,738 records) — a low High-share this cycle because most of the volume sits at Medium (framework-C2 baseline is Medium-scored per-IP).

// CTI SITREP 026·31 · July 27 – August 2, 2026 · TA-2026-031
55,956
Records
54,763
Unique IOCs
1,738
High-severity
107
Clusters
25+
Subnet anchors
9
Source feeds

Catalogued, ML-scored, ATT&CK-tagged. Every record carries category attribution, technique tag, severity, and confidence — refreshed continuously across open-source, sandbox, TLS, DNS, and honeynet plane sources.

02 · Five headlines — what defined this cycle

Headline 01 · Framework-C2 infrastructure at year-to-date highs

The dominant story of the week. The open-framework C2 tier — the commodity C2 framework used almost universally by red teams and by cost-conscious operators — produced 52,717 unique indicators across 25+ concentrated /24 subnet anchors this cycle. This is the highest weekly framework-C2 volume catalogued year-to-date, and the density of concentrated anchors (25 /24 blocks each with 30-106 concentrated IPs) is unusual.

Sub-anchors: multiple concentrated /24 blocks (typical density: 30-106 IPs per anchor). Full anchor list available via the operator console.

Defensive answer: deploy standard framework-C2 detection signatures at network egress (TLS fingerprint / JA3-JA3S / POST-URI pattern matching / sleep-jitter timing anomalies). Block the top-10 concentrated anchors outright if no legitimate red-team infrastructure operates from them.

Headline 02 · Emerging supply-chain wave

Multiple concurrent supply-chain / fake-installer campaigns targeting the developer ecosystem this cycle. Signals: a fake-package supply-chain campaign (19 IOCs across three IOC types) impersonating benign-looking package registrations, a fake developer-tooling site campaign (10 IOCs) hosting a fake corepack-style installer, a fake AI-assistant installer campaign (8 IOCs across four IOC types), and a fake job-interview software campaign (13 IOCs) targeting cryptocurrency-adjacent developer roles.

The pattern — targeting developers with fake tooling — is not new but the concurrent volume this week is above baseline. Developer machines carry disproportionate blast radius (cloud credentials, code-signing keys, CI/CD access), which is why this is a MUST-priority signal even at low aggregate IOC count.

Defensive answer: mail-gateway policy blocking untrusted .pkg / .msi / .dmg installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only.

Headline 03 · macOS malware surge (three families concurrent)

Three concurrent macOS-native malware families active this cycle. Combined footprint: 136 IOCs across DOMAIN + HASH + IP. One larger cross-platform family (76 IOCs) with a v4.0 evolution, one macOS-native RAT family (18 IOCs), one macOS-sync malware campaign (10 IOCs). The concurrent-family signal is more important than the individual IOC counts — macOS-native adversary activity typically appears in ones-and-twos per cycle, not threes.

Defensive answer: confirm EDR coverage across all macOS endpoints (many environments still have coverage gaps). Verify endpoint-detection includes recent macOS TCC-abuse and launch-agent-persistence patterns.

Headline 04 · Three ransomware operators active in parallel

Three distinct ransomware families active this cycle. Combined ransomware-category footprint: 747 IOCs across three operators. Notable: an established RaaS operator resurfaced with 275 fresh IOCs, a mid-tier operator active at 48 IOCs, a newer-brand operator at 25 IOCs (first-observation in this catalogue — either a rebrand or a genuinely new market entrant).

Defensive answer: ensure endpoint-detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion, service-stop, backup-service kill). If backups are not immutable or air-gapped, address this week regardless of any other signal.

Headline 05 · Iranian-linked APT clusters and regional operations

Three tracked APT clusters linked to Iranian regional operations produced fresh IOCs this cycle. Combined regional-operation footprint (Iranian-linked + Southeast-Asian tracker + attributed regional cluster): 62+ IOCs across five APT-category clusters. Target profiles include Middle East diplomatic missions, defence-industrial-base research, and government-adjacent think-tanks.

Defensive answer: if your organisation operates in energy, defence-industrial-base, diplomatic, government-adjacent research, or Middle East regional verticals, treat these clusters as MUST-block infrastructure. Alert real-time on first-seen contact.


03 · Indicator type, severity, and category mix

IP dominance at 97% share is the story of this week — the framework-C2 tier alone accounts for 52,717 IOCs (essentially all of the IP volume). Narrow indicators (domain/URL/hash) sit at ~3% share. Severity distribution: only 3.2% High (1,738 records) — framework-C2 IPs are Medium-scored per-IP (low-per-IP risk in a properly-defended environment). Category dominance: C&C at 96.3% share.

// FIG A · IOC type distribution · 97% IP dominance (framework-C2 baseline)
54,763 unique IOCs · by type
IP addresses

52,984
96.8%
Domains

813
1.5%
URLs

514
0.94%
File hashes

424
0.77%
Other artefacts

28
0.05%

Bars scaled relative to the dominant IP volume so smaller slices remain visible. The 97% IP share reflects the framework-C2 baseline. The narrow-indicator layer (1,751 records = 3%) is where the campaign-specific intelligence lives — see Lesson 06 below.

By indicator type

Type Observations Share %
IPs 52,984
96.75%
Domains 813
1.48%
URLs 514
0.94%
File hashes 424
0.77%
Other artefacts 23
0.04%
Emails 5
0.01%

By severity

Severity Observations Share %
High 1,738
3.17%
Medium 53,002
96.78%
Low 24
0.04%

By category

Category Observations Share %
C&C 52,717
96.26%
Malware-Activity 718
1.31%
Ransomware-as-a-service 389
0.71%
APT 224
0.41%
Phishing 200
0.37%
RAT 140
0.26%
Backdoor 123
0.22%
Botnet 93
0.17%
Supply Chain 62
0.11%
C&C Server 33
0.06%
Malicious-Infrastructure 17
0.03%
Loader 15
0.03%
Framework 15
0.03%
Trojan 10
0.02%
Spyware 9
0.02%

04 · Cluster footprint — ranked by unique-IOC count

40 clusters ranked by unique IOC footprint. Framework-infrastructure entries shown in grey to preserve visual clarity of the campaign-attributed clusters. All labels sanitised into category descriptors.

# Cluster descriptor Relative footprint Unique IOCs Severity
01 Open-framework C2 infrastructure (framework tier)

C2 · IP
52,717 MEDIUM
02 Ransomware-as-a-service operator (Cluster A)

Ransomware · DOMAIN
275 HIGH
03 Info-stealer family (Cluster B)

Malware · DOMAIN, IP, URL
268 HIGH
04 Broad-infrastructure phishing kit

Phishing · DOMAIN
191 MEDIUM
05 Attributed APT cluster (identifier C)

APT · DOMAIN, HASH, IP, URL
97 HIGH
06 Multi-stage operation (Cluster D)

Malware-Activity · DOMAIN, HASH, IP, URL
92 HIGH
07 macOS-native malware family (Cluster E)

Malware · DOMAIN, HASH, IP
76 HIGH
08 Loader family (Cluster F)

Loader · DOMAIN, HASH, IP
73 HIGH
09 Fake-application malware campaign

Malware-Activity · DOMAIN
71 HIGH
10 Multi-stage operation (Cluster G)

Malware-Activity · DOMAIN, IP, URL
59 HIGH
11 Commodity RAT family (Cluster H)

RAT · DOMAIN, HASH, IP, URL
50 MEDIUM
12 Mobile-adjacent malware family

Malware · DOMAIN, HASH, IP
50 HIGH
13 Ransomware operator (Cluster I)

Ransomware · DOMAIN, HASH
48 HIGH
14 Multi-family backdoor campaign

Backdoor · DOMAIN, HASH, IP
47 HIGH
15 Info-stealer family (Cluster J)

Malware · DOMAIN, HASH, IP
44 HIGH
16 Regional-tracked APT cluster (Southeast Asia)

APT · DOMAIN, HASH, IP
32 HIGH
17 Iranian-linked APT cluster (identifier K)

APT · DOMAIN, HASH, IP
31 HIGH
18 Multi-stage operation (Cluster L)

Malware-Activity · DOMAIN, HASH, IP
30 HIGH
19 Ransomware operator (Cluster M)

Ransomware · DOMAIN, HASH
25 HIGH
20 Open remote-agent framework

C2 · IP
25 MEDIUM
21 gRPC-based C2 campaign

Malware-Activity · DOMAIN, HASH, IP
23 HIGH
22 Developer-targeting RAT family

RAT · DOMAIN, HASH, IP
23 HIGH
23 Supply-chain package attack (Cluster N)

Supply Chain · DOMAIN, HASH, IP
19 HIGH
24 Info-stealer family (Cluster O)

Malware · DOMAIN
19 HIGH
25 Attributed APT cluster (identifier P)

APT · DOMAIN, HASH
18 HIGH
26 macOS-native RAT family

Malware · DOMAIN, HASH, IP
18 HIGH
27 Browser-extension proxy-abuse campaign

Malware-Activity · DOMAIN
17 HIGH
28 Loader family (Cluster Q)

Loader · DOMAIN, HASH, IP
15 HIGH
29 RAT-family delivery campaign

Malware · DOMAIN, HASH
14 HIGH
30 Fake-installer supply-chain campaign (developer-lure)

Malware · DOMAIN, HASH, IP
13 HIGH
31 Iranian-linked APT cluster (identifier R)

APT · DOMAIN, HASH
13 HIGH
32 API-specification abuse malware campaign

Malware-Activity · DOMAIN, HASH, IP, URL
13 HIGH
33 Attributed APT cluster (identifier S)

APT · DOMAIN, HASH, IP
12 HIGH
34 Botnet operator (Cluster T)

Botnet · DOMAIN, HASH
11 HIGH
35 Recurrent malware campaign (Cluster U)

Malware-Activity · DOMAIN, HASH
11 HIGH
36 Fake developer-tooling phishing site

Phishing · DOMAIN
10 LOW
37 macOS-sync malware campaign

Malware-Activity · DOMAIN, HASH, IP
10 HIGH
38 Commodity RAT family (Cluster V)

Malware · DOMAIN, HASH
10 HIGH
39 Banking-focused malware family

Malware · DOMAIN, HASH, IP
10 HIGH
40 Fake-AI-assistant installer campaign

Malware-Activity · DOMAIN, HASH, IP, URL
8 HIGH

05 · Themed deep-dives

05.1 · Framework-C2 infrastructure at year-to-date highs

The commodity C2 framework tier surged to 52,717 unique indicators across 25+ concentrated /24 subnet anchors this cycle — the highest weekly framework-C2 volume catalogued year-to-date. The density of concentrated anchors is the unusual signal. A typical week sees 5-8 /24s at high concentration; this week has 25.

Top-density anchors: the largest single-block concentration this cycle held ~106 concentrated IPs; the second- and third-tier anchors held 88 and 62 IPs each. Multiple sibling-pair anchors observed (concurrent blocks adjacent in address space suggesting shared operator provisioning).

Defensive actions: deploy standard framework-C2 detection signatures at network egress (TLS fingerprint / JA3-JA3S / POST-URI pattern matching / sleep-jitter timing anomaly detection). Block the top-10 anchors outright if no legitimate red-team infrastructure operates from them. This is the single loudest defensive signal you can deploy against a modern threat surface.

05.2 · Supply-chain wave — developer-ecosystem targeting

Multiple concurrent supply-chain and fake-installer campaigns this cycle. Combined footprint modest at ~60 IOCs but the concurrent-family signal is notable.

  • Fake-package supply-chain campaign — 19 IOCs across three IOC types. Impersonates a benign-looking package registration to seed malicious dependencies into the developer ecosystem. Standard supply-chain attack pattern.
  • Fake developer-tooling site campaign — 10 IOCs. Hosts a fake corepack-style installer at a lookalike domain. Delivers a signed-but-attacker-configured binary.
  • Fake AI-assistant installer campaign — 8 IOCs across four IOC types. Impersonates an AI-assistant installer. Notable for full-4-type coverage from a small-footprint operator (mature infrastructure).
  • Fake job-interview software campaign — 13 IOCs. Targets cryptocurrency-adjacent developer roles with fake “interview software” downloads.

Why this matters: developer machines carry disproportionate blast radius. Cloud credentials, code-signing keys, CI/CD access, SSH keys, package-registry publish tokens. A single compromised developer can seed malicious code into hundreds of downstream consumers. Supply-chain attacks at this concurrent volume warrant MUST-priority attention even at low aggregate IOC count.

Defensive actions: mail-gateway policy blocking untrusted .pkg / .msi / .dmg installer attachments to developer subnets; endpoint-detection allowlist for developer-tooling installer signers only; audit code-signing key access patterns; verify CI/CD secret rotation is on-schedule.

05.3 · macOS malware surge — three families concurrent

Three concurrent macOS-native malware families active this cycle. Combined footprint: 136 IOCs across DOMAIN + HASH + IP. A larger cross-platform family with a v4.0 evolution (76 IOCs) leads the volume, a macOS-native RAT family (18 IOCs) provides mid-tier persistence, and a macOS-sync malware campaign (10 IOCs) rounds out the surface.

Why this matters: macOS-native adversary activity typically appears in ones-and-twos per cycle in this catalogue. Three concurrent families is elevated and unusual. Many environments still have EDR coverage gaps on macOS endpoints (design engineering, executive laptops, creative teams).

Defensive actions: confirm EDR coverage across all macOS endpoints without exceptions. Verify endpoint-detection includes recent macOS-specific patterns: TCC bypass attempts, LaunchAgent + LaunchDaemon persistence, dylib-injection, unsigned-binary execution from user-writable paths.

05.4 · Three ransomware operators in parallel

Three distinct ransomware families active this cycle. Combined ransomware-category footprint: 747 IOCs. Notable:

  • Established RaaS operator resurfaced with 275 fresh IOCs — suggests affiliate-program reactivation.
  • Mid-tier operator active at 48 IOCs across two IOC types.
  • Newer-brand operator appeared with 25 IOCs — first observation in this catalogue; either rebrand or new market entrant.

Defensive actions: ensure endpoint detection includes recent ransomware-family signatures + universal behavioural detectors (mass file-encryption, shadow-copy deletion, service-stop, backup-service kill patterns). If backups are not immutable or air-gapped, address this week regardless of any other signal.

05.5 · Iranian-linked APT clusters and regional operations

Three tracked APT clusters linked to Iranian regional operations produced fresh IOCs this cycle. Combined APT-category footprint including Iranian-linked + Southeast-Asian tracker + attributed regional clusters: 224 IOCs across 5+ APT clusters. Target profiles include Middle East diplomatic missions, defence-industrial-base research, government-adjacent think-tanks, and cryptocurrency-adjacent finance.

Defensive actions: if your organisation operates in energy, defence-industrial-base, diplomatic, government-adjacent research, or Middle East regional verticals, treat these clusters as MUST-block infrastructure. Real-time alerting on first-seen contact.

06 · ATT&CK tactic-pressure roll-up

Tactic Top techniques observed What the pressure means IOC count
Command and Control T1071 · T1071.001 · T1105 · T1102 · T1568 · T1573 · T1090 Web-protocol C2, ingress tool transfer, web-service C2, dynamic resolution, asymmetric crypto, proxy tunnelling — dominant at year-to-date-high volume 52,717
Initial Access T1078 · T1133 · T1190 · T1566 · T1566.001 · T1566.002 · T1195 Valid accounts, external remote services, public-facing exploit, phishing (attachment + link), supply chain 486
Execution T1059 · T1059.001 · T1059.005 · T1059.007 · T1204 · T1218 Command interpreter (shell / VB / JS), user-execution, signed-binary proxy execution 412
Ingress Tool Transfer T1105 Second-stage payload pull — universal across every multi-stage cluster 338
Defense Evasion T1027 · T1036 · T1055 · T1070 · T1140 · T1562 Obfuscation, masquerading, process injection, indicator removal, deobfuscate, disable defences 289
Persistence T1547.001 · T1543.003 · T1053.005 · T1505.003 · T1543.001 Registry-run keys, service creation, scheduled tasks, webshell, launch-agent (macOS) 214
Credential Access T1003 · T1003.001 · T1555 · T1552.001 · T1110 OS credential dumping, password store theft, brute force — info-stealer families driving credential-access volume 178
Discovery T1082 · T1057 · T1083 · T1018 · T1046 System info, process, file, remote-system, network configuration 156
Lateral Movement T1021 · T1021.001 · T1021.002 · T1570 Remote-desktop, SMB / admin shares, lateral tool transfer 123
Exfiltration T1041 · T1567 · T1090 Exfil over C2, exfil to web service, tunnel-based exfil 187
Impact T1486 · T1489 · T1490 Data encryption for impact (ransomware), service stop, inhibit system recovery 89
Resource Development T1583.001 · T1584.001 · T1585 · T1195.002 Adversary-acquired domains + compromised infrastructure + fabricated-identity + supply-chain compromise 156

Detection-engineering takeaway. Command and Control is the dominant pressure this cycle at 52,717 IOCs (framework-C2 tier alone). Standard framework-signature detectors at network egress are the single highest-leverage defensive control this week. Impact tactics (T1486 ransomware encryption, T1489 / T1490 service stop + inhibit recovery) elevated with three concurrent ransomware operators. Resource Development (T1583 / T1584 / T1195.002) elevated due to supply-chain wave — watch for compromised package-registry activity and lookalike-installer sites.


07 · Real-world threat intelligence lessons from this week’s data

Every week’s intelligence contains more than a list of things to block. It contains signals about how the adversary landscape is shifting — where operator investment is moving, which target profiles are getting attention, which defensive controls are becoming table-stakes versus differentiators. Below are the practical takeaways from this cycle’s data that will still matter next month, next quarter, and into the second half of the year.

Lesson 01 · When 97% of your feed is one category, your filtering discipline is the differentiator

Framework-C2 infrastructure produced 52,717 of this week’s 54,763 IOCs. That is not a threat report — that is baseline noise. If your SOC is treating each of those 52,000 IPs as an equal-priority alert, you are drowning your analysts and paying them to triage things a signature-based detector should catch automatically. The mature CTI program deploys standard framework-C2 signatures as always-on real-time content and treats the individual IPs as enrichment data (context on alerts that fire on the signature), not as primary alert sources. Fix your feed-consumption architecture before you fix any individual detection.

Lesson 02 · The developer machine is the new perimeter

The supply-chain wave this cycle — fake package registrations, fake developer-tooling installers, fake AI-assistant installers, fake job-interview software — is a signal about where operator investment is moving. Traditional network defences do not see a compromised developer. They see a normal user pulling packages, running installers, pushing code. The blast radius is disproportionate: one developer with cloud credentials, code-signing keys, and CI/CD access can seed malicious content into hundreds of downstream consumers. The controls that matter for defending this surface are identity, endpoint, and CI/CD-pipeline hygiene — not perimeter firewalls. If your security investment ratio is 80% network / 20% identity + endpoint, this week’s data says you are optimising for last decade’s attack surface.

Lesson 03 · Concurrent-family signals matter more than individual family volume

Three concurrent macOS-native malware families this week is a bigger signal than any single family’s IOC count would suggest. When multiple independent operators arrive at the same target profile in the same window, it means the profile is being validated as viable and profitable across the ecosystem. macOS-in-engineering-environments has been an under-invested defensive area in most SOCs for years; three families arriving simultaneously is the ecosystem telling you the under-investment is being exploited. The same pattern applies to concurrent ransomware operators, concurrent regional APT clusters, concurrent supply-chain campaigns — count operators, not indicators, when assessing pressure on a target profile.

Lesson 04 · Framework-C2 detection is now table stakes, not a differentiator

The commodity C2 framework is at year-to-date-high volume and appears in every category-attributed cluster this week. If you are not detecting the standard framework signatures (TLS fingerprint / JA3-JA3S / POST-URI pattern / sleep-jitter timing anomaly) at network egress, you are missing 96% of what threat operators are running through. This is no longer a “nice to have” detection category. It is table stakes. Detection engineering programs that have not shipped framework-C2 content in the last 18 months are behind the curve regardless of what other content they have shipped.

Lesson 05 · RaaS operator reactivation is a leading indicator

An established RaaS operator resurfaced this cycle with 275 fresh IOCs after a lull period — the classic signal that an affiliate program is being reactivated after either a takedown recovery, a rebrand, or an infrastructure refresh. Reactivation patterns are leading indicators: they typically precede a 4-8 week ramp-up in actual encryption events in the customer base. If you monitor a specific vertical (finance, healthcare, manufacturing, professional services), track which RaaS operators historically target that vertical, and treat their reactivation as an early-warning signal warranting emergency backup-immutability verification and endpoint-detection tuning. Do not wait for the encryption event.

Lesson 06 · The narrow-indicator layer is where the story lives

3% of this week’s IOCs are the narrow-indicator layer (domain + hash + URL). Those 1,751 records contain more actionable intelligence than the 52,984 IPs combined. Narrow indicators map to specific campaigns, specific actors, specific target profiles. Broad-infrastructure indicators are largely context. A CTI analyst spending time on narrow indicators produces more defensive value per hour than one processing broad infrastructure. If your CTI team’s time allocation does not reflect this ratio, redistribute.

The one-line synthesis. This week’s data says: the commodity C2 tier is louder than ever (deploy signature detectors), the developer machine is under active investment as a target profile (harden identity + endpoint + CI/CD), macOS coverage is an emerging gap (audit EDR reach), and RaaS reactivation is a leading indicator you can act on before the encryption event. Four takeaways from one week that will still matter next quarter. That is what intelligence is for.

08 · Top IOCs per indicator type

Operator-grade extractions with category and severity attribution only. All indicators are defanged (re-fang on import: [.]. and hxxphttp).

Top 15 · IP addresses (framework-C2 anchors)

# Indicator Category Severity
01 64.69.57.10 C2 / Framework MEDIUM
02 64.69.57.42 C2 / Framework MEDIUM
03 103.234.72.5 C2 / Framework MEDIUM
04 154.216.55.11 C2 / Framework MEDIUM
05 154.213.58.9 C2 / Framework MEDIUM
06 43.240.48.8 C2 / Framework MEDIUM
07 45.156.217.14 C2 / Framework MEDIUM
08 84.32.188.10 C2 / Framework MEDIUM
09 108.62.118.7 C2 / Framework MEDIUM
10 23.108.57.13 C2 / Framework MEDIUM
11 139.60.161.9 C2 / Framework MEDIUM
12 23.106.215.5 C2 / Framework MEDIUM
13 173.234.155.11 C2 / Framework MEDIUM
14 172.241.27.9 C2 / Framework MEDIUM
15 168.206.188.6 C2 / Framework MEDIUM

Top domains (High severity)

# Indicator Category Severity
01 10mintimer[.]com Malware HIGH
02 110gongan[.]com RAT HIGH
03 2mblk[.]com APT HIGH
04 4mblk[.]com APT HIGH
05 business-deegital[.]com APT HIGH
06 strepsils[.]top Malware HIGH
07 upgybj[.]store APT HIGH
08 0tuiwp[.]mariomanagement[.]biz[.]id Malware HIGH
09 2joafm[.]marioanalytics[.]my[.]id Malware HIGH
10 4hawb[.]produtoeletro[.]my[.]id Malware HIGH
11 1[.]232323[.]eu[.]org Phishing HIGH
12 232323[.]eu[.]org Phishing HIGH

Top file hashes (High severity)

# Indicator Category Severity
01 015d7b212d20681d346e690159e7f4cd9e88b51de27e84b514fce865deef3a5c Loader HIGH
02 016d90f337bd55dfcfbba8465a50e2261f0369cd448b4f020215f952a2a06bce Trojan HIGH
03 01c3326ce5beb78a6c106960a3a0868682b97bfa Botnet HIGH
04 0243692ce6ca522bc1359a3d89d70a229cf76587 Botnet HIGH
05 0248c26c25bb5804f0c6d83238b6172c Spyware HIGH
06 026c85b97a6ddac14c9835d0580228c0a82dd82ce12d8d921c2f3067a12bbb7e Malware HIGH
07 029ba5f0f6997bc36a094e86848a5b82 Malware HIGH
08 0334cd1b8ab17203179da1ae77c1fad97ddf794cc63a6048aca664956d10b2ca Malware HIGH
09 03d93b56ac4219a8ac8a55fd4ba777618b5682cc84bec0efe8ea78e497dd3b3d RAT HIGH
10 04bef2153417efeb408d8e027bd91bb6db5b957c43ceb7429a15cb76ef436af3 RAT HIGH
11 04e216f4780b6292ccc836fa0481607c62abb244f6a2eedc21c4a822bcf6d79f APT HIGH
12 054bad7ec0e19cec931078d45382fee6 Malware HIGH

Top URLs (High severity)

# Indicator Category Severity
01 hxxp[://]1[.]232323[.]eu[.]org Phishing HIGH
02 hxxp[://]122[.]114[.]10[.]239/edcvfr Malware HIGH
03 hxxp[://]122[.]114[.]10[.]239/qazxsw Malware HIGH
04 hxxp[://]125[.]47[.]207[.]244:49245/Mozi[.]m Botnet HIGH
05 hxxp[://]138[.]124[.]93[.]26/Client[.]hta Phishing HIGH
06 hxxp[://]141[.]164[.]61[.]90/file/config[.]php Malware HIGH
07 hxxp[://]154[.]29[.]74[.]158 Ransomware HIGH
08 hxxp[://]158[.]247[.]206[.]214/articles/list[.]php Malware HIGH
09 hxxp[://]158[.]247[.]232[.]35/bbns/bbns[.]php Malware HIGH
10 hxxp[://]172[.]86[.]107[.]229:3000 Phishing HIGH
Need the full set? The catalogue carries 54,763 unique IOCs for this week. The operator console exposes every record with severity, confidence, ATT&CK technique, category attribution, and source-feed provenance. Open HuntIntel.

09 · Sigma detection rules

Sigma 01 · Framework-C2 signature at concentrated anchor (HIGH)

title: Framework-C2 — Standard TLS/URI Signature at Concentrated Subnet Anchor
id: 9a3d7f2b-8c14-4630-a781-2f9b5c2e8d31
status: experimental
description: Detects the standard framework-C2 signature set from any of this
  cycle's 25+ concentrated /24 subnet anchors. TLS fingerprint match + POST-URI
  pattern match + destination-IP in attributed anchor list.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1568
  - attack.defense_evasion
  - attack.t1573
logsource:
  category: network_connection
detection:
  s1_anchor_destination:
    DestinationIp|cidr:
      # 25+ concentrated framework-C2 /24 anchors this cycle
      # anchor list distributed via the operator console feed
      - 'concentrated_framework_anchor_list'
  s2_framework_signal:
    - tls_ja3s_hash|contains: 'known_framework_ja3s_signatures'
    - request_uri|re: '/[a-z0-9]{4,16}$'
  condition: s1_anchor_destination or (s2_framework_signal and DestinationIp|cidr: 'other_anchor_list')
falsepositives:
  - Legitimate red-team engagements from allowlisted infrastructure
level: high

Sigma 02 · Untrusted installer to developer subnet (HIGH)

title: Developer Ecosystem — Untrusted Installer to Developer Subnet
id: 4e8b7c1d-3a95-4620-b791-6d8f2c1e5a92
status: experimental
description: Detects untrusted installer files (msi/pkg/dmg/exe) delivered to
  developer-subnet endpoints via mail or download, with signer not in the
  developer-tooling allowlist. Catches the supply-chain wave targeting
  developers with fake tooling installers.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
  - attack.initial_access
  - attack.t1195.002
  - attack.t1566.001
  - attack.execution
  - attack.t1204.002
logsource:
  category: file_event
detection:
  s1_installer_extension:
    TargetFilename|endswith:
      - '.msi'
      - '.pkg'
      - '.dmg'
      - '.exe'
      - '.deb'
  s2_developer_subnet:
    HostRoleTag:
      - 'developer'
      - 'engineer'
      - 'devops'
      - 'ci_cd'
  s3_signer_not_allowlisted:
    SignerCategory|not:
      - 'developer_tooling_allowlisted'
      - 'os_vendor'
      - 'code_repository_platform_allowlisted'
  condition: s1_installer_extension and s2_developer_subnet and s3_signer_not_allowlisted
falsepositives:
  - Legitimate onboarding of new developer tooling (extend allowlist)
level: high

Sigma 03 · macOS LaunchAgent/Daemon persistence in user-writable path (HIGH)

title: macOS — LaunchAgent or LaunchDaemon Written to User-Writable Path
id: 6a5e9d3f-7b28-4c50-a941-5f8b6d2e9c31
status: experimental
description: Detects LaunchAgent or LaunchDaemon plist file writes to
  user-writable paths on macOS endpoints — a persistence pattern used by
  this cycle's three concurrent macOS malware families.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
  - attack.persistence
  - attack.t1543.001
  - attack.t1543.004
logsource:
  category: file_event
  product: macos
detection:
  s1_launch_persistence_path:
    TargetFilename|contains:
      - '/Library/LaunchAgents/'
      - '/Library/LaunchDaemons/'
      - '~/Library/LaunchAgents/'
    TargetFilename|endswith: '.plist'
  s2_writer_not_signed_by_apple_or_allowlisted:
    ProcessSigner|not:
      - 'apple_vendor'
      - 'allowlisted_mac_publisher'
  condition: s1_launch_persistence_path and s2_writer_not_signed_by_apple_or_allowlisted
falsepositives:
  - Legitimate third-party tooling with allowlisted signers
level: high

Sigma 04 · Universal ransomware behaviour (CRITICAL)

title: Ransomware Behaviour — Mass File Encrypt + Shadow-Copy Delete + Service Stop
id: 5c9e7b2d-1a83-4550-b721-3f9b6d4f2a13
status: experimental
description: Universal ransomware behaviour detector — mass file-modify with
  new extensions + shadow-copy deletion + backup-service stop within a short
  window. Catches all three concurrent ransomware operators this cycle
  without requiring family-specific signatures.
references:
  - https://hackforlab.com/weekly-threat-advisory-july-27-august-2-2026/
author: HackForLab Threat Intelligence
date: 2026/08/03
tags:
  - attack.impact
  - attack.t1486
  - attack.t1490
  - attack.t1489
logsource:
  product: correlation
detection:
  s1_mass_file_modify:
    EventCount|file_modify_events: '>100_per_minute'
    NewFileExtension|distinct_count: '<3'
  s2_shadow_copy_delete:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'wmic shadowcopy delete'
  s3_backup_service_stop:
    Service|category: 'backup_or_shadowcopy'
    ServiceAction: 'stop_or_disable'
  condition: (s1_mass_file_modify and s2_shadow_copy_delete)
          or (s1_mass_file_modify and s3_backup_service_stop)
level: critical

10 · Hunt queries — SIEM-agnostic pseudo-syntax

Hunt 01 · Framework-C2 anchor destination contact (last 30 days)

FROM network_flows
WHERE destination_ip IN CIDR('concentrated_framework_anchor_list')
  AND event_time >= NOW() - 30 DAYS
| PROJECT source_host, destination_ip, destination_port, bytes, event_time
| SORT BY event_time ASC

Hunt 02 · Untrusted installer file-write on developer subnet (last 60 days)

FROM edr_file_events
JOIN host_role_tag ht ON ht.host = file_events.host
WHERE ht.role_tag IN ('developer', 'engineer', 'devops', 'ci_cd')
  AND file_events.target_filename MATCHES '.*\.(msi|pkg|dmg|exe|deb)$'
  AND file_events.signer_category NOT IN ('developer_tooling_allowlisted', 'os_vendor')
  AND file_events.event_time >= NOW() - 60 DAYS
| PROJECT ht.host, file_events.target_filename, file_events.source_url, file_events.event_time

Hunt 03 · macOS LaunchAgent/Daemon persistence writes (last 90 days)

FROM edr_file_events
WHERE endpoint_os = 'macos'
  AND target_filename MATCHES '.*/(LaunchAgents|LaunchDaemons)/.*\.plist$'
  AND writer_signer_category NOT IN ('apple_vendor', 'allowlisted_mac_publisher')
  AND event_time >= NOW() - 90 DAYS
| PROJECT host, user, target_filename, writer_process, event_time

Hunt 04 · Ransomware behavioural triage (last 30 days)

FROM edr_file_events
WHERE event_type = 'modify'
  AND file_modification_rate > 100_per_minute
  AND new_file_extension_distinct_count < 3
  AND event_time >= NOW() - 30 DAYS
| JOIN edr_process_create pc ON pc.host = edr_file_events.host
| WHERE pc.command_line CONTAINS 'vssadmin' OR pc.command_line CONTAINS 'shadowcopy'
| PROJECT host, user, new_file_extension, file_modification_rate, event_time

11 · Operationalise in 60 minutes

// Cyber-Ops Runbook · Deploy in 4 time-boxed sprints

▸ Minute 00 – 15 · Block + Sinkhole

  • Block the top-10 framework-C2 concentrated anchors at the perimeter (anchor list available via the operator console feed). Range coverage: 10 concentrated /24 blocks account for ~600 of the framework-C2 IPs this cycle.
  • Add outbound-deny for known ransomware TOR-negotiation portals (feed subscriber list).
  • Mail-gateway policy: block .msi/.pkg/.dmg attachments to developer subnets unless signer allowlisted.
  • Verify backup immutability given three concurrent ransomware operators.

▸ Minute 15 – 30 · Detection Content

  • Deploy Sigma 01 (framework-C2 anchor + signature) at network egress.
  • Deploy Sigma 02 (untrusted installer to developer subnet) at file-event layer.
  • Deploy Sigma 03 (macOS LaunchAgent/Daemon persistence) on all macOS endpoints.
  • Deploy Sigma 04 (universal ransomware behaviour) at critical severity, direct-to-oncall.

▸ Minute 30 – 45 · Retrospective Hunt

  • Run Hunt 01 (framework-C2 anchor contact) across last 30 days.
  • Run Hunt 02 (untrusted installer on developer subnet) across last 60 days.
  • Run Hunt 03 (macOS persistence writes) across last 90 days.
  • Run Hunt 04 (ransomware behavioural triage) across last 30 days.

▸ Minute 45 – 60 · Awareness + Policy

  • Brief developer teams: fake-installer wave targeting developer ecosystem. Only install tooling from official vendor URLs; verify signatures.
  • Brief macOS-endpoint users: three macOS malware families active this cycle. Confirm EDR coverage across all macOS endpoints without exceptions.
  • Audit code-signing key access patterns for developer machines. Rotate CI/CD secrets if not on-schedule.
  • If in energy/defence/diplomatic/Middle East verticals: escalate Iranian-linked cluster monitoring to real-time alerting.
// CONTINUE WITH HUNTINTEL

This briefing ships a selected subset per type. The catalogue carries the full 54,763 unique IOCs from this week — category attribution, ATT&CK technique, confidence score, source provenance included.

Open HuntIntel →

12 · Frequently asked questions

Is the framework-C2 volume this week concerning by itself?

Not by itself — the framework tier is popular baseline noise. The signal is the density of concentrated anchors: 25 /24 blocks at high concentration is unusual (typical week is 5-8). It indicates either a coordinated red-team engagement season, coordinated threat-actor procurement of infrastructure from a small hosting pool, or both. Either way, the defensive answer is the same: deploy the standard framework-signature detectors.

Why is the supply-chain wave a MUST-priority at only ~60 IOCs?

Blast radius. Developer machines carry disproportionate downstream impact — cloud credentials, code-signing keys, CI/CD access, package-registry publish tokens, SSH keys. A single compromised developer can seed malicious code into hundreds of downstream consumers. Priority scoring is impact-per-target × exploitation-likelihood, not raw IOC count.

Three concurrent macOS malware families — is that unusual?

Yes. This catalogue typically sees ones-and-twos of macOS-native families per cycle. Three concurrent (with one showing a v4.0 evolution) is elevated. Combined with the developer-ecosystem supply-chain wave, this suggests attention on the macOS-in-engineering-environments target profile specifically.

How do I know if my organisation is in scope for the Iranian-linked APT clusters?

If your organisation operates in energy (oil, gas, utilities), defence-industrial-base, diplomatic missions, government-adjacent research (think-tanks, universities with government funding), or Middle East regional business — assume in-scope. If not, monitor as background signal but do not treat as MUST-priority.

What confidence threshold should the SOC use for automated blocking?

High-confidence only for automatic blocklist promotion. Medium and above for watchlist enrichment. Include Low for retrospective hunting. This week’s top-10 framework-C2 anchors are a special case — the concentration signal is strong enough that automatic blocking is safe if no legitimate red-team infrastructure operates from those ranges.

Where can I see this briefing’s intelligence operationally?

The HuntIntel operator console exposes every IOC with category attribution, ATT&CK technique, severity, confidence, and source provenance pre-joined. Open at huntintel.hackforlab.com/login.html. For the underlying frameworks reference, see Indicators of Compromise and Threat Intelligence: A Practitioner Reference. For hunt-program methodology, see the TaHiTI framework walkthrough.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter Captcha Here : *

Reload Image