Indicators of Compromise (IOCs)

This table lists regularly updated Indicators of Compromise (IOCs), including malicious file hashes, domains, and IP addresses, to support threat detection and response.

IOCs

DateArticalCategoryIOCs
January 1, 2026Mustang Panda Uses Signed Kernel Mode Rootkit to Load TONESHELL BackdoorDomainavocadomechanism[.]com
January 1, 2026Mustang Panda Uses Signed Kernel Mode Rootkit to Load TONESHELL BackdoorDomainpotherbreference[.]com
January 1, 2026Trust Wallet Chrome Extension Breach Leads to 7 Million Dollar Crypto Loss via Malicious CodeDomainapi.metrics-trustwallet[.]com
January 1, 2026Trust Wallet Chrome Extension Breach Leads to 7 Million Dollar Crypto Loss via Malicious CodeDomainmetrics-trustwallet[.]com
January 1, 2026Trust Wallet Chrome Extension Breach Leads to 7 Million Dollar Crypto Loss via Malicious CodeDomaintrustwallet-support.freshdesk[.]com
January 1, 2026Trust Wallet Chrome Extension Breach Leads to 7 Million Dollar Crypto Loss via Malicious CodeDomaintrustwallet-support.freshdesk[.]com
January 1, 2026China Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot MalwareDomainp2p.hd.sohu.com.cn
January 1, 2026China Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot MalwareDomaindictionary.com
December 26, 2025New MacSync macOS Stealer Uses Signed App to Bypass Apple GatekeeperDomainzkcall[.]net
December 26, 2025SEC Files Charges Over $14 Million Crypto Scam Using Fake AI Themed Investment TipsDomainh5.morocoin[.]top
December 26, 2025SEC Files Charges Over $14 Million Crypto Scam Using Fake AI Themed Investment TipsDomainwww.bergev[.]org
December 24, 2025U.S. DoJ Seizes Fraud Domain Linked to 14.6 Million Dollar Bank Account Takeover SchemeDomainweb3adspanels[.]org
December 19, 2025WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN VulnerabilityIP199.247.7[.]82
December 18, 2025Kimsuky Spreads DocSwap Android Malware Through QR Phishing Posing as Delivery AppIP27.102.137[.]181
December 16, 2025New ForumTroll Phishing Attacks Target Russian Scholars via Fake eLibrary EmailsDomaine-library[.]wiki
December 16, 2025Malicious NuGet Package Posing as Tracer Fody Steals Cryptocurrency Wallet DataIP176.113.82[.]163
December 15, 2025Unpatched Gogs Zero Day Actively Exploited Across More Than 700 InstancesIP119.45.176[.]196
December 15, 2025Active Attacks Abuse Gladinet Hard Coded Keys to Gain Unauthorized Access and Execute CodeIP147.124.216[.]205
December 15, 2025React2Shell Exploitation Spreads Crypto Miners and New Malware Across Multiple SectorsIP185.247.224[.]41
December 12, 2025Storm 0249 Amplifies Ransomware Attacks Using ClickFix, Fileless PowerShell, and DLL SideloadingDomainsgcipl[.]com
December 8, 2025MuddyWater Uses UDPGangster Backdoor in Targeted Campaign Across Turkey, Israel, and AzerbaijanIP157.20.182[.]75
December 8, 2025Sneeit WordPress RCE Exploited in the Wild, and ICTBroadcast Bug Powering Frost Botnet AttacksIP185.125.50[.]59
December 8, 2025Sneeit WordPress RCE Exploited in the Wild, and ICTBroadcast Bug Powering Frost Botnet AttacksIP182.8.226[.]51
December 8, 2025Sneeit WordPress RCE Exploited in the Wild, and ICTBroadcast Bug Powering Frost Botnet AttacksIP89.187.175[.]80
December 3, 2025Brazil Faces Banking Trojan Spread Through WhatsApp Worm and RelayNFC Relay FraudDomainmanoelimoveiscaioba[.]com
December 3, 2025Brazil Faces Banking Trojan Spread Through WhatsApp Worm and RelayNFC Relay FraudDomainserverseistemasatu[.]com
December 3, 2025Brazil Faces Banking Trojan Spread Through WhatsApp Worm and RelayNFC Relay FraudDomainmaisseguraca[.]site
December 3, 2025Brazil Faces Banking Trojan Spread Through WhatsApp Worm and RelayNFC Relay FraudDomaintest.ikotech[.]online
December 2, 2025ShadyPanda Converts Popular Browser Extensions With 4.3 M of Installs Into SpywareDomaintrovi[.]com
December 2, 2025ShadyPanda Converts Popular Browser Extensions With 4.3 M of Installs Into SpywareDomainapi.extensionplay[.]com
November 29, 2025CISA adds actively exploited XSS flaw CVE-2021-26829 in OpenPLC ScadaBR to KEV listDomaini-sh.detectors-testing[.]com
November 29, 2025Legacy Python bootstrap scripts create domain takeover risk in several PyPI packagesDomainpython-distribute[.]org
November 29, 2025North Korean hackers use 197 npm packages to spread updated OtterCookie malwareDomaintetrismic.vercel[.]app
November 27, 2025Gainsight adds more affected customers after Salesforce security alertIP3.239.45[.]43
November 24, 2025ShadowPad Malware Exploits a WSUS Vulnerability to Gain Full System AccessIP149.28.78[.]189
November 22, 2025CISA Alerts on a Critical Oracle Identity Manager Zero Day Vulnerability That Is Being Actively ExploitedIP89.238.132[.]76
November 22, 2025CISA Alerts on a Critical Oracle Identity Manager Zero Day Vulnerability That Is Being Actively ExploitedIP185.245.82[.]81
November 22, 2025CISA Alerts on a Critical Oracle Identity Manager Zero Day Vulnerability That Is Being Actively ExploitedIP138.199.29[.]153
November 20, 2025Sneaky 2FA Phishing Kit Adds BitB Style Pop ups That Closely Imitate the Browser Address BarDomainpreviewdoc[.]us
November 19, 2025EdgeStepper Implant Redirects DNS Queries to Deliver Malware Through Compromised Software UpdatesDomaintest.dsc.wcsset[.]com
November 11, 2025Konni Hackers Turn Google Find Hub into Remote Data Wiping ToolIP116.202.99[.]218
November 8, 2025China’s Hackers Repurpose Legacy Flaws, from Log4j to IIS, into Global Espionage ToolsDomainmimosa.gleeze[.]com
November 8, 2025Vibe-Coded Malicious VS Code Extension Found Containing Built-In Ransomware FunctionalityDomainbullethost[.]cloud
November 7, 2025Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on UkraineDomainesetsmart[.]com
November 7, 2025Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on UkraineDomainesetscanner[.]com
November 7, 2025Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on UkraineDomainesetremover[.]com
November 7, 2025Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Rising Iran–Israel TensionsDomainthebesthomehealth[.]com
November 4, 2025SleepyDuck VSX Extension Uses Ethereum to Sustain Its Command ServerDomainsleepyduck[.]xyz
November 3, 2025HttpTroy Backdoor Poses as VPN Invoice to Infiltrate South Korean TargetsDomainload.auraria[.]org
November 3, 2025HttpTroy Backdoor Poses as VPN Invoice to Infiltrate South Korean TargetsDomaintronracing[.]com
October 30, 2025PhantomRaven Malware Hidden in 126 npm Packages Stealing GitHub Tokens from DevelopersDomainpackages.storeartifact[.]com
October 29, 202510 Malicious npm Packages Steal Developer Credentials Across Windows, macOS, and LinuxIP195.133.79[.]43
October 28, 2025SideWinder APT Uses ClickOnce Based Attack Chain to Target South Asian DiplomatsDomainmod.gov.bd.pk-mail[.]org
October 28, 2025SideWinder APT Uses ClickOnce Based Attack Chain to Target South Asian DiplomatsDomainmofa-gov-bd.filenest[.]live
October 25, 2025APT36 Targets Indian Government Using Golang-Based DeskRAT MalwareDomainmodgovindia[.]com
October 25, 2025APT36 Targets Indian Government Using Golang-Based DeskRAT MalwareDomainmodgovindia[.]space
October 24, 2025Self-Spreading GlassWorm Infects VS Code Extensions, Triggers Widespread Supply-Chain AttackIP217.69.3[.]218
October 24, 2025Self-Spreading GlassWorm Infects VS Code Extensions, Triggers Widespread Supply-Chain AttackIP199.247.10[.]166
October 24, 2025Self-Spreading GlassWorm Infects VS Code Extensions, Triggers Widespread Supply-Chain AttackIP140.82.52[.]31:80
October 24, 2025Hackers Exploit New Adobe Commerce Flaw to Breach Over 250 Magento Stores OvernightIP34.227.25[.]4
October 24, 2025Hackers Exploit New Adobe Commerce Flaw to Breach Over 250 Magento Stores OvernightIP44.212.43[.]34
October 24, 2025Hackers Exploit New Adobe Commerce Flaw to Breach Over 250 Magento Stores OvernightIP54.205.171[.]35
October 24, 2025Hackers Exploit New Adobe Commerce Flaw to Breach Over 250 Magento Stores OvernightIP155.117.84[.]134
October 24, 2025Hackers Exploit New Adobe Commerce Flaw to Breach Over 250 Magento Stores OvernightIP159.89.12[.]166
October 24, 2025Homoglyph Attack in Fake Nethereum NuGet Package Steals Crypto Wallet KeysDomainsolananetworkinstance[.]info
October 23, 2025Ukraine Aid Organizations Targeted via Fake Zoom Meetings and Malicious PDF FilesDomainbsnowcommunications[.]com
October 23, 2025Iran-Linked MuddyWater Targets Over 100 Organizations in Global Espionage CampaignIP159.198.36[.]115
October 22, 2025Cavalry Werewolf APT Targets Multiple Industries Using FoalShell and StallionRAT MalwareIP188.127.225[.]191
October 22, 2025Cavalry Werewolf APT Targets Multiple Industries Using FoalShell and StallionRAT MalwareIP109.172.85[.]63
October 22, 2025Cavalry Werewolf APT Targets Multiple Industries Using FoalShell and StallionRAT MalwareIP62.113.114[.]209
October 22, 2025Hackers Exploit Citrix Flaw and Deploy Snappybee Malware to Breach European Telecom NetworkDomainaar.gandhibludtric[.]com
October 19, 2025New .NET CAPI Backdoor Targets Russian Automotive and E-Commerce Firms via Phishing ZIPsIP91.223.75[.]96
October 19, 2025New .NET CAPI Backdoor Targets Russian Automotive and E-Commerce Firms via Phishing ZIPsDomaincarprlce[.]ru
October 17, 2025Microsoft Revokes 200 Fake Certificates Abused in Rhysida Ransomware AttacksDomainteams-download[.]buzz
October 17, 2025Microsoft Revokes 200 Fake Certificates Abused in Rhysida Ransomware AttacksDomainteams-install[.]run
October 17, 2025Microsoft Revokes 200 Fake Certificates Abused in Rhysida Ransomware AttacksDomainteams-download[.]top
October 15, 2025100+ VS Code Extensions Found Exposing Developers to Hidden Supply Chain ThreatsDomainab498.pythonanywhere[.]com
October 15, 2025Attackers Exploit ICTBroadcast Cookie Flaw to Obtain Remote Shell AccessIP143.47.53[.]106
October 15, 2025Attackers Exploit ICTBroadcast Cookie Flaw to Obtain Remote Shell AccessDomainlocalto[.]net
October 15, 2025Chinese Hackers Employ Geo Mapping Tool to Maintain Year Long PersistenceIP172.86.117[.]230
October 15, 2025Chinese Hackers Employ Geo Mapping Tool to Maintain Year Long PersistenceFile hash of bridge.exe4f9d9a6cba88832fcb7cfb845472b63ff15cb9b417f4f02cb8086552c19ceffc
October 15, 2025Chinese Hackers Employ Geo Mapping Tool to Maintain Year Long PersistenceFile hash of hamcore.se2
84959fe39d655a9426b58b4d8c5ec1e038af932461ca85916d7adeed299de1b3
October 15, 2025Researchers Reveal TA585’s MonsterV2 Malware Capabilities, Full Attack ChainDomainintlspring[.]com
October 15, 2025Researchers Reveal TA585’s MonsterV2 Malware Capabilities, Full Attack ChainDomainapi.ipify[.]org
October 11, 2025Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Divert Employee SalariesDomainhunt[.]io
October 10, 2025From HealthKick to GOVERSHELL: Tracking the Evolution of UTA0388 Espionage MalwareDomainonedrive[.]live[.]com
October 10, 2025Critical Flaw in WordPress Service Finder Theme Allows Authentication Bypass by AttackersIP192.121.16.196
October 10, 2025Critical Flaw in WordPress Service Finder Theme Allows Authentication Bypass by AttackersIP194.68.32.71
October 10, 2025Critical Flaw in WordPress Service Finder Theme Allows Authentication Bypass by AttackersIP178.125.204.198
October 10, 2025AI Emerges as Russia’s Latest Cyber Weapon in Its War on UkraineDomainonedrive[.]live[.]com
October 10, 2025AI Emerges as Russia’s Latest Cyber Weapon in Its War on UkraineDomainipfs[.]io
October 9, 2025Hackers Compromise WordPress Sites to Fuel Next-Generation ClickFix Phishing CampaignsDomainbrazilc[.]com
October 9, 2025Hackers Compromise WordPress Sites to Fuel Next-Generation ClickFix Phishing CampaignsDomainporsasystem[.]com
October 7, 2025BatShadow Group Deploys Go-Based ‘Vampire Bot’ Malware Targeting Job SeekersIP103.124.95[.]161
October 7, 2025BatShadow Group Deploys Go-Based ‘Vampire Bot’ Malware Targeting Job SeekersDomainapi3.samsungcareers[.]work
October 7, 2025BatShadow Group Deploys Go-Based ‘Vampire Bot’ Malware Targeting Job SeekersDomainsamsung-work[.]com
October 7, 2025BatShadow Group Deploys Go-Based ‘Vampire Bot’ Malware Targeting Job SeekersDomainsamsungcareers[.]work
October 7, 2025XWorm 6.0 Resurfaces with Over 35 Plugins, Upgraded Data Theft FeaturesIP94.159.113[.]64
October 3, 2025Detour Dog Exposed for Operating DNS-Based Malware Factory Linked to Strela StealerDomainwebdmonitor[.]io
October 3, 2025Detour Dog Exposed for Operating DNS-Based Malware Factory Linked to Strela StealerDomainaeroarrows[.]io
October 3, 2025Researchers Alert on SORVEPOTEL, a Self-Spreading Malware Targeting WhatsApp UsersDomainsorvetenopoate[.]com
October 2, 2025Android Spyware Masquerades as Signal Encryption Plugin and ToTok Pro, Users at RiskDomainsignal[.]org
October 2, 2025Hackers Exploit Milesight Routers to Send Phishing SMS to Users in EuropeDomainjnsi[.]xyz
September 28, 2025New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused CyberattacksDomaincaptchanom[.]top
September 28, 2025New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused CyberattacksDomainsouthprovesolutions[.]com
September 28, 2025Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud NetworkDomainomnatuor[.]com
September 28, 2025Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud NetworkDomainpropeller-tracking[.]com
September 27, 2025Fortra GoAnywhere CVSS 10 Vulnerability Exploited as Zero-Day Before DisclosureIP155.2.190[.]197
September 27, 2025Malicious Rust Crates Steal Solana and Ethereum Wallet Keys with 8,424 Downloads ConfirmedDomainmainnet.solana-rpc-pool.workers[.]dev
September 27, 2025Malicious Rust Crates Steal Solana and Ethereum Wallet Keys with 8,424 Downloads ConfirmedDomainapi.mainnet-beta.solana[.]com
September 19, 2025SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 ServersIP104.250.164[.]214
September 19, 2025SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 ServersDomainVN5Socks[.]com
September 19, 202517,500 Phishing Domains Target 316 Brands Across 74 Countries Amid Global PhaaS SurgeDomaineset.ydns[.]eu
September 19, 202517,500 Phishing Domains Target 316 Brands Across 74 Countries Amid Global PhaaS SurgeIP91.231.182[.]187
September 19, 2025Russian Hackers Gamaredon And Turla Join Forces To Deploy Kazuar Backdoor In UkraineDomaintelegraph[.]com (C2 mentioned via Telegraph API)
September 19, 2025Russian Hackers Gamaredon And Turla Join Forces To Deploy Kazuar Backdoor In UkraineDomaineset.ydns[.]eu
September 19, 2025Russian Hackers Gamaredon And Turla Join Forces To Deploy Kazuar Backdoor In UkraineIP91.231.182[.]187
September 19, 2025Russian Hackers Gamaredon And Turla Join Forces To Deploy Kazuar Backdoor In UkraineIP91.231.182[.]187
September 19, 2025SilentSync RAT distributed through two malicious PyPI packages targeting Python developersDomainpastebin[.]com
September 19, 2025SilentSync RAT distributed through two malicious PyPI packages targeting Python developersDomainpypi[.]org
September 19, 2025SilentSync RAT distributed through two malicious PyPI packages targeting Python developersIP200.58.107[.]25
September 18, 2025Chinese TA415 leverages VS Code remote tunnels to spy on U.S. economic policy expertsDomainzohomail[.]com
September 18, 2025Chinese TA415 leverages VS Code remote tunnels to spy on U.S. economic policy expertsDomainrequestrepo[.]com
September 18, 2025Chinese TA415 leverages VS Code remote tunnels to spy on U.S. economic policy expertsDomainpastebin[.]com
September 18, 2025SlopAds fraud ring exploits 224 Android apps to push 2.3 billion ad bids every dayDomainad2[.]cc
September 18, 2025New FileFix variant spreads StealC malware via multilingual phishing siteDomainwl.google-587262[.]com
September 18, 2025Over 180 npm packages targeted by self-replicating worm to steal credentials in recent supply chain attackDomainwebhook[.]site
September 18, 2025Over 180 npm packages targeted by self-replicating worm to steal credentials in recent supply chain attackDomainrustfoundation[.]dev
September 18, 2025Over 180 npm packages targeted by self-replicating worm to steal credentials in recent supply chain attackDomaingithub.rustfoundation[.]dev
September 18, 2025AI-powered Villager penetration testing tool surpasses 11,000 PyPI downloads amid abuse concernsDomaincyberspike[.]top
September 18, 2025CISA warns of active exploitation of critical CVE-2025-5086 in DELMIA AprisoIP156.244.33[.]162
September 9, 2025GPUGate Malware Leverages Google Ads and Fake GitHub Commits to Target IT CompaniesDomaingitpage[.]app
September 4, 2025Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise NetworksIP address85.203.4[.]232
September 4, 2025Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise NetworksDomainshttp[:]//attacker.com/shell[.]sh
September 4, 2025MystRodX Exploits DNS and ICMP Channels to Steal Data From Compromised SystemsIP address139.84.156.79
September 4, 2025Phishing Campaign Hid for 3 Years on Google Cloud and Cloudflare ServicesDomainIOCs
September 3, 2025Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS AttackIP Address104.194.9[.]127
September 3, 2025Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS AttackDomainiranistrash[.]libre
September 3, 2025Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS AttackDomainpool.rentcheapcars[.]sbs
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address185.156.72[.]0/24
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address45.143.201[.]0/24
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address185.193.89[.]0/24
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address88.210.63[.]0/24
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address92.63.197[.]0/24
September 2, 2025Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP DevicesIP Address185.156.73[.]0/24
August 29, 2025Sogou Zhuyin Update Server Hijacked in Taiwan Espionage CampaignDomainsogouzhuyin[.]com
August 29, 2025Sogou Zhuyin Update Server Hijacked in Taiwan Espionage CampaignDomaindl[.]sogouzhuyin[.]com
August 29, 2025Sogou Zhuyin Update Server Hijacked in Taiwan Espionage CampaignDomainsrv-pc.sogouzhuyin[.]com
August 29, 2025Amazon Disrupts APT29 Watering Hole Using Microsoft AuthenticationDomaincloudflare.redirectpartners[.]com
August 29, 2025Amazon Disrupts APT29 Watering Hole Using Microsoft AuthenticationDomainfindcloudflare[.]com