Weekly Threat Advisory: The Most Active Cyber Adversaries Sep 29 – Oct 05, 2025
⚠Weekly Threat Advisory – Critical Trends Shaping the Cybersecurity Landscape
Top Threat Actors: Nation-state groups and cybercriminal syndicates are intensifying attacks on critical infrastructure and financial sectors.
Malware Evolution: Stealthy loaders and polymorphic malware variants are bypassing traditional defenses with alarming success.
Ransomware Surge: Double extortion tactics and RaaS (Ransomware-as-a-Service) models continue to dominate global breach reports.
C2 Infrastructure: Threat actors are leveraging decentralized and fast-flux networks to evade detection and prolong campaign lifespans.
Active Campaigns: Spear-phishing and supply chain compromises remain the preferred vectors for initial access across industries.
| NAME_OF_ADVERSARY | ADVERSARY_TYPE | NUMBER_OF_IOC | IOC_TYPE_COUNT_SUMMARY |
| UAT-8099 | Threat Actor | 69 | IP–>4 | DOMAIN–>32 | HASH–>32 | URL–>1 |
| Lunar Spider group | Threat Actor | 68 | IP–>18 | DOMAIN–>17 | HASH–>30 | URL–>3 |
| Cavalry Werewolf | Threat Actor | 40 | IP–>11 | HASH–>29 |
| COLDRIVER | Threat Actor | 20 | DOMAIN–>4 | HASH–>3 | URL–>13 |
| Nimbus Manticore | Threat Actor | 8 | HASH–>8 |
| Phantom-taurus | Threat Actor | 4 | HASH–>4 |
| SideCopy | Threat Actor | 115 | IP–>6 | DOMAIN–>7 | HASH–>47 | URL–>55 |
| Silent Lynx | Threat Actor | 13 | HASH–>8 | URL–>5 |
| Gunra-ransomware | Ransomware | 21 | IP–>1 | DOMAIN–>6 | HASH–>8 | URL–>3 | EMAIL–>2 | OTHERS–>1 |
| RA Lord Ransomware | Ransomware | 17 | IP–>1 | DOMAIN–>13 | HASH–>1 | OTHERS–>2 |
| Rapid | Ransomware | 46 | IP–>43 | HASH–>3 |
| SVG Phishing | Phishing Campaign | 21 | IP–>1 | DOMAIN–>7 | HASH–>13 |
| Lumma Stealer | Malware_campaign | 10 | DOMAIN–>7 | HASH–>3 |
| faster_log and async_println | Malware_campaign | 3 | URL–>3 |
| Burpsuite | Malware | 111 | IP–>111 |
| CastleRAT | Malware | 14 | HASH–>14 |
| Datzbro | Malware | 7 | HASH–>4 | OTHERS–>3 |
| HeartCrypt | Malware | 8 | HASH–>5 | URL–>3 |
| Olymp Loader | Malware | 23 | HASH–>19 | URL–>4 |
| PhantomCard | Malware | 30 | IP–>3 | HASH–>26 | URL–>1 |
| PureHVNC RAT | Malware | 15 | IP–>1 | DOMAIN–>5 | HASH–>8 | URL–>1 |
| SORVEPOTEL | Malware | 23 | DOMAIN–>14 | HASH–>8 | URL–>1 |
| Strela Stealer | Malware | 9 | IP–>1 | DOMAIN–>8 |
| Postmark | Malware | 2 | DOMAIN–>1 | EMAIL–>1 |
| Mythic C2 | C2 | 115 | IP–>115 |
| NetBus | C2 | 16 | IP–>16 |
| NimPlant | C2 | 5 | IP–>5 |
| Pantegana C2 | C2 | 2 | IP–>2 |
| RedGuard | C2 | 19 | IP–>19 |
| Remcos RAT | C2 | 3 | IP–>3 |
| Viper C2 | C2 | 254 | IP–>254 |
| XMRig Monero Cryptominer | C2 | 38 | IP–>38 |
| Gh0st RAT | C2 | 9 | IP–>9 |
| Orcus RAT | C2 | 1 | IP–>1 |
| Oyster C2 | C2 | 5 | IP–>5 |
| Poseidon C2 | C2 | 1 | IP–>1 |
| Quasar RAT | C2 | 14 | IP–>14 |
| SpiceRAT | C2 | 4 | IP–>4 |
| Unam Web Panel | C2 | 19 | IP–>19 |
| Cobaltstrike C2 IP | C2 | 883 | IP–>883 |
| Metasploit C2 IP | C2 | 53 | IP–>53 |
| 7777 Botnet | C2 | 3 | IP–>3 |
| Ares RAT | C2 | 1 | IP–>1 |
| AsyncRat | C2 | 21 | IP–>21 |
| XiebroC2 | C2 | 4 | IP–>1 | HASH–>2 | URL–>1 |
| Brute Ratel C4 | C2 | 4 | IP–>4 |
| Caldera | C2 | 5 | IP–>5 |
| Cobalt Strike | C2 | 451 | IP–>451 |
| DarkComet Trojan | C2 | 16 | IP–>16 |
| DcRAT | C2 | 7 | IP–>7 |
| GoPhish | C2 | 224 | IP–>224 |
| Hak5 Cloud C2 | C2 | 133 | IP–>133 |
| Havoc C2 | C2 | 54 | IP–>54 |
| Metasploit Framework | C2 | 505 | IP–>505 |
| NanoCore RAT | C2 | 9 | IP–>9 |
| njRAT | C2 | 2 | IP–>2 |
| Mozi Botnet | C2 | 15 | IP–>15 |
| PANDA C2 | C2 | 151 | IP–>151 |
| Sectop RAT | C2 | 37 | IP–>37 |
| ShadowPad | C2 | 17 | IP–>17 |
| Sliver C2 | C2 | 423 | IP–>423 |
| Supershell C2 | C2 | 94 | IP–>94 |
| Villain C2 | C2 | 8 | IP–>8 |
| XtremeRAT | C2 | 11 | IP–>11 |
| Hookbot | C2 | 10 | IP–>10 |
Enclosed are the high-risk Indicators of Compromise (IOCs), each accompanied by a confidence score derived through advanced machine learning analysis.
| IOC | Confidence_Score |
| 106[.]52[.]208[.]143 | 132 |
| 115[.]159[.]92[.]22 | 132 |
| 43[.]246[.]208[.]241 | 132 |
| 114[.]55[.]250[.]233 | 132 |
| 47[.]239[.]188[.]48 | 132 |
| 196[.]196[.]19[.]54 | 132 |
| 43[.]134[.]9[.]57 | 132 |
| 221[.]132[.]29[.]137 | 132 |
| 192[.]144[.]232[.]209 | 132 |
| 39[.]107[.]85[.]83 | 132 |
| 166[.]108[.]200[.]194 | 132 |
| 181[.]174[.]164[.]116 | 132 |
| 8[.]216[.]84[.]159 | 132 |
| Prvqhm[.]shop | 160 |
| Annwt[.]xyz | 160 |
| Ungryo[.]shop | 160 |
| f6ac2ac7cb521c38a334e0696db86a370f8be52ae563080c27982197719b74cf | 170 |
| 4f3edcc4df7bc6b5b96d2a681602f35e1e1b8bbb103e21752ad94ddda28a1dc1 | 170 |
| d567a41f802a7b7c498c78aadd4dde07662cb97527a751ed698026aa9c2ef6d7 | 170 |
| 5a741df3e4a61b8632f62109a65afc0f297f4ed03cd7e208ffd2ea5e2badf318 | 170 |
| 642c2f73fff0e453c9e6ae4de976a7821c512cb6dc5ed0c4aaf5e4dbf2596edb | 170 |
| 7e0d097412ca8c3acdbaaa7c1f79c42cda3a4e50b52c0a8b34d6c75cc764ce42 | 170 |
| 66aac2857eee73b1f5f715214bb50a03c0dc052d4bb3e64d6b0b492f2c85f374 | 170 |
| a97ff41736299857a3cae7c1917456eef5e0fcc703d0a1e475d0b9cfe42452c7 | 170 |
| 7a682be245a2e51f473ee1c60d537e57423ab2c3d9ae990445cdb6e43aeb5c76 | 170 |
| ce6a7af556090b3ff762e27058be2327e6c5188d6ed54703d794089f577fd20c | 170 |
| b0b24ff78ab1c4322764bcb332254069504b168cb8aaca469bdf1d37f313d4d3 | 170 |
| c2054617b8dcb619749c0402dc31eeb473386b3829f17176bc27b1447a8b6d92 | 170 |
| 60125159523c356d711ffa1076211359906e6283e25f75f4cf0f9dc8da6bf7b0 | 170 |
| 1ff6ee23b4cd9ac90ee569067b9e649c76dafac234761706724ae0c1943e4a75 | 170 |
| d51f81ee026df39447143b67eaf16326c30e0c9477c0d50507f1fbfffe53abd6 | 170 |
| e6bcdf375649a7cbf092fcab65a24d832d8725d833e422e28dfa634498b00928 | 170 |
| f2ff4cbcd6d015af20e4e858b0f216c077ec6d146d3b2e0cbe68b56b3db7a0be | 170 |
| 3dd877835c04fde3f2d14ce96f23a1c00002fefa9d731e8c4ce3b656aac90063 | 170 |
| 5e730e5f05acf7653291f3a06924553da36b16c6205f850a9388edfedad264ed | 170 |
| 2a54b80e464c2000ae4c6c0e5bb6fbd205fb850d77ebbcb533c5a6c753606a37 | 170 |
| 9807c45356e82e876a02fc0157d0a4253c6967e34ce38ea62f9702b98893b990 | 170 |
| 48e435559476771b06ddfbe0a7fb00e34472cf736a81c9e42aac0a7f04804105 | 170 |
| 189705223aa714897ffa8c61ac1d2dd37b5428502c45dcdd94b69e13e6a53d97 | 170 |
| 258f044046b11803f85bf8d8095897bcd2775fb6152877a2f5054f625d019386 | 170 |
| ae42632969be3247a465361395b04fec80b14622b94d3269fa02c6e062335a79 | 170 |
| 337bbb68d29a7d7763f02b4e7b753ab1de142d8dac0d47ff00a5bc41a2ad3245 | 170 |
| a78ab0c38fc97406727e48f0eb5a803b1edb9da4a39e613f013b3c5b4736262f | 170 |
| 5cecb80222d418b9adb93b5000aca54db28cd276d1d4d6f4f3bfa0e0167c5f5e | 170 |
| 5769ae3cc93943dda4d1743f2febf6cec1282a0a6289da68cb55bb4724ec9332 | 170 |
| 7fca16e7aa358c9d57054564c51a86031ebdcbedfa24ae42c26a8de3fdf24d44 | 170 |
| 21c66fe505f2bcd7b29d413189920b3a85df48da0ecf4eb6962d6a504a7fdcd8 | 170 |
| 0fb7385e5880da21398918d0f85cf2515ec097e6be271d430f038ada1763fa9a | 170 |
| 1e760aa3505fd6539f4938da919fb2b6dc7aee014a83632d1ecb5425b01e55fc | 170 |
| cb10953f39723427d697d06550fae2a330d7fff8fc42e034821e4a4c55f5a667 | 170 |
| daa45607401f00113a47565cb36ead5f6232a1c79d52641c4189c74c828fef4d | 170 |
| 2d4d60254c4eb979eda144832020170338b0c18159bc597e5699709b7209e188 | 170 |
| 30c8a8f570485b451e685acfb8d89df6bf7f01912f5d6a4c4ee7f48b7b7880f9 | 170 |
| 61a6aa241c354cc5b696146b5a2f08794c0b8865f3073675e22e0fa0f8fe5918 | 170 |
| 446c7b9ff49c7c0b8ae02b720054e4f09ef60475c92a5d7f2e2b2bdb4ca5de23 | 170 |
| sorvetenopote[.]com | 170 |
| expansiveuser[.]com | 170 |
| 217[.]154[.]212[.]25 | 176 |
| 43[.]156[.]59[.]110 | 176 |
| 2bw7r32r5eshwk2h7uekj3lwzorxds2jyhyzqyilphid3r27x5hsf4yd[.]onion | 180 |
| apdk7hpbbquomgoxbhutegxco6btrz2ara3x2weqnx65tt45ba3sclyd[.]onion | 180 |
| gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion | 180 |
| 104[.]238[.]205[.]105 | 180 |
| 144[.]172[.]95[.]78 | 180 |
| 193[.]239[.]236[.]149 | 180 |
| 193[.]163[.]194[.]7 | 180 |
| 77[.]247[.]126[.]239 | 180 |
| 16a79e36d9b371d1557310cb28d412207827db2759d795f4d8e27d5f5afaf63f | 194 |
| 62ab5a28801d2d7d607e591b7b2a1e9ae0bfc83f9ceda8a998e5e397b58623a0 | 194 |
| 87138f63974a8ccbbf5840c31165f1a4bf92a954bacccfbf1e7e5525d750aa48 | 194 |
| southprovesolutions[.]com | 194 |
| captchanom[.]top | 194 |
| blintepeeste[.]org | 194 |
| preentootmist[.]org | 194 |
| 0e4ff052250ade1edaab87de194e87a9afeff903695799bcbc3571918b131100 | 194 |
| b405ae67c4ad4704c2ae33b2cf60f5b0ccdaff65c2ec44f5913664805d446c9b | 194 |
| bx[.]ggseocdn[.]com | 194 |
| meindi11[.]com | 194 |
| greqjfu[.]xyz | 240 |
| df01a50867227fae6fa652d4cbc99a39f695ee5932574ea5c8e669f4882b56a3 | 255 |
| ralordt7gywtkkkkq2suldao6mpibsb7cpjvdfezpzwgltyj2laiuuid[.]onion | 270 |
| ralordqe33mpufkpsr6zkdatktlu3t2uei4ught3sitxgtzfmqmbsuyd[.]onion | 270 |
| ralord3htj7v2dkavss2hjzviviwgsf4anfdnihn5qcjl6eb5if3cuqd[.]onion | 270 |
| be15f62d14d1cbe2aecce8396f4c6289 | 270 |
| 9a7c0adedc4c68760e49274700218507 | 270 |








