The Most Active Cyber Adversaries October 13 – October 19

Weekly Threat Advisory: The Most Active Cyber Adversaries October 13 – October 19, 2025

Weekly Threat Advisory: The Most Active Cyber Adversaries October 13 – October 19, 2025

⚠ Weekly Threat Advisory — Key Cybersecurity Trends You Should Know

Top Threat Actors:
State-sponsored hackers and organized cybercriminal groups are stepping up attacks, especially on financial institutions and critical infrastructure.

Malware Shifts:
New malware variants are becoming smarter and harder to detect, easily slipping past traditional security tools.

Ransomware Spike:
Ransomware gangs are using double-extortion tactics and RaaS platforms to spread faster and cause bigger business disruptions.

C2 Networks:
Hackers are now hiding behind decentralized and fast-changing command-and-control servers, making it difficult to track and shut them down.

Ongoing Campaigns:
Phishing emails and supply chain breaches remain the most common entry points, reinforcing the need for stronger vigilance and vendor security checks.

AdversaryAdversary_TypeIPDOMAINHASHURLTotal_IOCs
Italian banking AMLC226109
LummaMalware1041400424
PhantomVAIMalware0067067
GhostBatMalware00204161
AstarothMalware11191334
CLAYRATMalware04004
EvilAIMalware00303
PolarEdgeMalware00101
ProSpy and ToSpyMalware_campaign121236060
Multi-Stage Android MalwareMalware_campaign91721442
DPRK_Contagious_Interview_CampaignMalware_campaign700815
Operation Zero DiscoMalware_campaign00909
Trojanized_Ivanti_Pulse_SecureMalware_campaign14229
Operation Silk LureMalware_campaign20507
CLEARFAKEMalware_campaign04004
C2-SOCKPhishing Campaign43805799
Email_CampaignsPhishing Campaign1201016
MAC_Spoofer_Malicious_Chrome_ExtensionPhishing Campaign00617
AsyncRATPhishing Campaign00606
BeamgleaPhishing Campaign02013
AkiraRansomware50027
Cavalry_WerewolfThreat Actor11029040
BeaverTail and OtterCookieThreat Actor00131932
JewelbugThreat Actor1225028
TA585Threat Actor11012023
UNC5342Threat Actor00707
APT41Threat Actor50005
Flax_TyphoonThreat Actor10405

Weekly High-Risk Indicators of Compromise (IOCs) with ML-Derived Confidence Scores

ioc_valueConfidence Score
yrokistorii.ru85
orienderi.com85
physicianusepeptides.com85
precisionbiomeds.com85
utvp1.net85
vishneviyjazz.ru85
xurekodip.com85
wdxocrh.cn33
144.172.106.14048.5556
apothfya.qpon85
172.86.89.5185
brunsmmv.qpon85
http://tinyurl.com/jjmcw85
fruiunp.qpon85
https://shorturl.at/YDFSq85
lutraqdb.qpon85
mastwin.in85
mensfjb.qpon85
pattemqr.qpon85
upwanpdx.qpon85
woodvuqb.qpon85
pictuqyr.qpon85
196.251.92.4242.4286
7da82e14fb483a680a623b0ef69bcfbd9aaaedf3ec26f4c34922d6923159f52f97
8404f8294b14d61ff712b60e92b7310e50816c24b38a00fcc3da1371a336710397
8e6d7c44ab66f37bf24351323dc5e8d913173425b14750a50a2cbea6d9e439ba97
8e7fb9f6acfb9b08fb424ff5772c46011a92d80191e7736010380443a46e695c97
91.219.148.9397
94.198.52.20097
96.9.125.16897
a3ec2992e6416a3af54b3aca3417cf4a109866a07df7b5ec0ace7bd1bf73f3c697
a8ada7532ace3d72e98d1e3c3e02d1bd1538a4c5e78ce64b2fe1562047ba4e5297
185.173.37.6797
af3d740c5b09c9a6237d5d54d78b5227cdaf60be89f48284b3386a3aadeb028397
b13b83b515ce60a61c721afd0aeb7d5027e3671494d6944b34b83a5ab1e2d9f497
c26b62fa593d6e713f1f2ccd987ef09fe8a3e691c40eb1c3f19dd57f896d9f5997
c3df16cce916f1855476a2d1c4f0946fa62c2021d1016da1dc524f4389a3b6fa97
c9ffbe942a0b0182e0cd9178ac4fbf8334cae48607748d978abf47bd3510405197
cc84bfdb6e996b67d8bc812cf08674e8eca6906b53c98df195ed99ac5ec14a0697
cc9e5d8f0b30c0aaeb427b1511004e0e4e89416d8416478144d76aa1777d155497
dae3c08fa3df76f54b6bae837d5abdc309a24007e9e6132a940721045e65d2bb97
e15f1a6d24b833ab05128b4b34495ef1471bd616b9833815e2e98b8d3ae78ff297
ec80e96e3d15a215d59d1095134e7131114f669ebc406c6ea1a709003d3f6f1797
fa6cdd1873fba54764c52c64eadca49d52e5b79740364ef16e5d86d61538878d97
fbf1bae3c576a6fcfa86db7c36a06c2530423d487441ad2c684cfeda5cd1968597
04769b75d7fb42fbbce39d4c4b0e9f83b60cc330efa477927e68b9bdba279bb897
0e7b65930bc73636f2f99b05a3bb0af9aaf17d3790d0107eb06992d25e62f59d97
109.172.85.9597
148a42ccaa97c2e2352dbb207f07932141d5290d4c3b57f61a780f9168783eda97
185.231.155.11197
185.244.180.16997
188.127.225.19197
188.127.227.22697
1dfe65e8dc80c59000d92457ff7053c07f272571a8920dbe8fc5c2e7037a6c9897
ab0ad77a341b12cfc719d10e0fc45a6613f41b2b3f6ea963ee6572cf02b41f4d97
22ba8c24f1aefc864490f70f503f709d2d980b9bc18fece4187152a1d9ca5fab97
27a11c59072a6c2f57147724e04c7d6884b52921da2629fb0807e0bb93901cbc97
3cd7f621052919e937d9a2fdd4827fc7f82c0319379c46d4f9b9dd5861369ffc97
4f17a7f8d2cec5c2206c3cba92967b4b499f0d223748d3b34f9ec4981461d28897
62.113.114.20997
6b290953441b1c53f63f98863aae75bd8ea32996ab07976e498bad111d53525297
7084f06f2d8613dfe418b242c43060ae578e7166ce5aeed2904a8327cd98dbdf97
78.128.112.20997
155.138.150.1291
107.155.93.15490

Happy Threat Hunting

#threathunting #threatintelligence #cybersecurity #threatactor #malware #CVE #campaign #ransomware #phishing #threatadvisory #threatfeeds #APTGroups #InfosecIntel #CTI #IOC #CyberThreatIntel #TTPs #CyberThreatReport #OSINT #CyberDefense #weeklythreatbriefing #CyberResilience #RAT #C2 #confidencescore #ML #AI

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter Captcha Here : *

Reload Image