{
  "feed": "threatcluster-public-iocs",
  "version": 1,
  "generated_at": "2026-07-19T03:53:42Z",
  "filters": {
    "confidence": "high",
    "window_days": 30,
    "types": [
      "ipv4",
      "ipv6",
      "domain"
    ]
  },
  "count": 63,
  "iocs": [
    {
      "type": "ipv4",
      "value": "216.126.225.129",
      "confidence": "high",
      "reason": "C2 server used for exfiltration of secrets",
      "first_seen": "2026-07-19T02:29:27.278845+00:00",
      "last_seen": "2026-07-19T02:29:27.278845+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "safedep.io",
          "url": "https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/",
          "pub_date": "2026-07-19T02:29:27.278845+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "evil.com",
      "confidence": "high",
      "reason": "Used as an exfiltration vector in the context of an attack.",
      "first_seen": "2026-07-17T18:47:17.820605+00:00",
      "last_seen": "2026-07-17T18:47:17.820605+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "simonwillison.net",
          "url": "https://simonwillison.net/tags/lethal-trifecta/",
          "pub_date": "2026-07-17T18:47:17.820605+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "my-salesforce-cms.com",
      "confidence": "high",
      "reason": "Registered by researchers to demonstrate data leak, indicating attacker-controlled infrastructure.",
      "first_seen": "2026-07-17T18:47:17.820605+00:00",
      "last_seen": "2026-07-17T18:47:17.820605+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "simonwillison.net",
          "url": "https://simonwillison.net/tags/lethal-trifecta/",
          "pub_date": "2026-07-17T18:47:17.820605+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "webhook.site",
      "confidence": "high",
      "reason": "Identified as an exfiltration vector used by attackers.",
      "first_seen": "2026-07-17T18:47:17.820605+00:00",
      "last_seen": "2026-07-17T18:47:17.820605+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "simonwillison.net",
          "url": "https://simonwillison.net/tags/lethal-trifecta/",
          "pub_date": "2026-07-17T18:47:17.820605+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "ghiseul.ro",
      "confidence": "high",
      "reason": "Phishing campaign using a clone of the government portal, indicating attacker-controlled infrastructure",
      "first_seen": "2026-07-17T08:44:08+00:00",
      "last_seen": "2026-07-17T08:44:08+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Romania-Insider",
          "url": "https://www.romania-insider.com/online-public-services-romania-cyberattacks-july-2026",
          "pub_date": "2026-07-17T08:44:08+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "usa.com",
      "confidence": "high",
      "reason": "Mentioned as a non-government sender domain used in phishing scheme",
      "first_seen": "2026-07-16T18:55:20+00:00",
      "last_seen": "2026-07-16T18:55:20+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Rock929Rocks",
          "url": "https://rock929rocks.com/2026/07/16/phishing-scheme-targets-massachusetts-homeowners-with-fake-zoning-fee-demands/",
          "pub_date": "2026-07-16T18:55:20+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "3.147.61.167",
      "confidence": "high",
      "reason": "Explicitly identified as the endpoint for malicious activity.",
      "first_seen": "2026-07-15T04:05:19.630553+00:00",
      "last_seen": "2026-07-15T04:05:19.630553+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "hackindex.io",
          "url": "https://hackindex.io/research/modheader-malware-chrome-spyware",
          "pub_date": "2026-07-15T04:05:19.630553+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "20.118.27.127",
      "confidence": "high",
      "reason": "Listed as VPS used for phishing operations",
      "first_seen": "2026-07-14T14:48:49.027128+00:00",
      "last_seen": "2026-07-14T14:48:49.027128+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "blog.lexfo.fr",
          "url": "https://blog.lexfo.fr/opendir-to-phishing-operator.html",
          "pub_date": "2026-07-14T14:48:49.027128+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "83.136.211.85",
      "confidence": "high",
      "reason": "Mentioned as part of malware delivery chain",
      "first_seen": "2026-07-14T14:48:49.027128+00:00",
      "last_seen": "2026-07-14T14:48:49.027128+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "blog.lexfo.fr",
          "url": "https://blog.lexfo.fr/opendir-to-phishing-operator.html",
          "pub_date": "2026-07-14T14:48:49.027128+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "pool.supportxmr.com",
      "confidence": "high",
      "reason": "Identified as a cryptocurrency wallet used for receiving funds",
      "first_seen": "2026-07-08T16:45:54+00:00",
      "last_seen": "2026-07-08T16:45:54+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Darkreading",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/vidar-infostealer-smb-malvertising-campaign",
          "pub_date": "2026-07-08T16:45:54+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "vniir-avia.space",
      "confidence": "high",
      "reason": "Freshly registered spoof domain used for phishing, identified as attacker-controlled",
      "first_seen": "2026-07-07T11:06:29+00:00",
      "last_seen": "2026-07-07T12:30:50+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Gbhackers",
          "url": "https://gbhackers.com/smtp-in-aerospace-phishing-campaign/amp/",
          "pub_date": "2026-07-07T12:30:50+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "api.jt2x.com",
      "confidence": "high",
      "reason": "Used for C2 operations, configuration downloads, and data exfiltration.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "dealctr.com",
      "confidence": "high",
      "reason": "Documented as a C2 domain in the GhostPoster investigation.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "jt2x.com",
      "confidence": "high",
      "reason": "Part of the cluster used for C2 operations and data exfiltration.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "liveupdt.com",
      "confidence": "high",
      "reason": "Documented as a C2 domain in the GhostPoster investigation.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "muo.cc",
      "confidence": "high",
      "reason": "Part of the cluster used for C2 operations and data exfiltration.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "zhuayuya.com",
      "confidence": "high",
      "reason": "Part of the cluster used for C2 operations and data exfiltration.",
      "first_seen": "2026-07-04T11:37:25.401151+00:00",
      "last_seen": "2026-07-04T11:37:26.678813+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "web.archive.org",
          "url": "https://web.archive.org/web/20260101202600/https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:26.678813+00:00"
        },
        {
          "source": "www.koi.ai",
          "url": "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
          "pub_date": "2026-07-04T11:37:25.401151+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "62.60.190.141",
      "confidence": "high",
      "reason": "Listed as C2 server used for remote control and data exfiltration",
      "first_seen": "2026-07-02T12:14:09+00:00",
      "last_seen": "2026-07-02T12:14:09+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Gbhackers",
          "url": "https://gbhackers.com/phishing-campaign-uses-fake-invoice-pdf/amp/",
          "pub_date": "2026-07-02T12:14:09+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "cloaked.gg",
      "confidence": "high",
      "reason": "Identified as a service for avoiding security scanners, associated with a phishing kit.",
      "first_seen": "2026-06-25T21:18:08+00:00",
      "last_seen": "2026-07-01T07:02:22+00:00",
      "source_count": 3,
      "sources": [
        {
          "source": "News.Risky.Biz",
          "url": "https://news.risky.biz/risky-bulletin-researcher-drops-giant-cache-of-zero-day-exploits/",
          "pub_date": "2026-07-01T07:02:22+00:00"
        },
        {
          "source": "abnormal.ai",
          "url": "https://abnormal.ai/blog/blacksite-aitm-phishing-kit-cloaked-gg",
          "pub_date": "2026-06-25T22:31:01.441438+00:00"
        },
        {
          "source": "Feeds.Feedburner",
          "url": "https://www.scworld.com/news/new-blacksite-phishing-kit-bundles-aitm-with-scanner-evasion",
          "pub_date": "2026-06-25T21:18:08+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "de-fra.i3storage.com",
      "confidence": "high",
      "reason": "Identified as primary exfiltration destination",
      "first_seen": "2026-06-30T19:16:50.055525+00:00",
      "last_seen": "2026-06-30T19:16:50.055525+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.welivesecurity.com",
          "url": "https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/",
          "pub_date": "2026-06-30T19:16:50.055525+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "188.208.141.177",
      "confidence": "high",
      "reason": "Identified as IP address communicating with attacker-controlled domain",
      "first_seen": "2026-06-29T17:15:29+00:00",
      "last_seen": "2026-06-29T17:15:29+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Acronis",
          "url": "https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/",
          "pub_date": "2026-06-29T17:15:29+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "188.208.141.196",
      "confidence": "high",
      "reason": "Previously identified as C2 server associated with Mustang Panda",
      "first_seen": "2026-06-29T17:15:29+00:00",
      "last_seen": "2026-06-29T17:15:29+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Acronis",
          "url": "https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/",
          "pub_date": "2026-06-29T17:15:29+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "160.30.209.77",
      "confidence": "high",
      "reason": "Explicitly mentioned as part of a targeted campaign, indicating attacker-controlled infrastructure",
      "first_seen": "2026-06-26T13:04:55+00:00",
      "last_seen": "2026-06-26T13:04:55+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Gbhackers",
          "url": "https://gbhackers.com/fossbilling-flaw-lets-admin-attackers-abuse-di-container/amp/",
          "pub_date": "2026-06-26T13:04:55+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "cdnexpress.cc",
      "confidence": "high",
      "reason": "Traffic involving cdnexpress.cc indicates potential attacker-controlled infrastructure.",
      "first_seen": "2026-06-25T16:51:35+00:00",
      "last_seen": "2026-06-25T16:51:35+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Socprime",
          "url": "https://socprime.com/active-threats/ghostshell-mb-0009-targeting-ukraines-uav-operations-and-defense-supply-chain/",
          "pub_date": "2026-06-25T16:51:35+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "cloudaxis.cc",
      "confidence": "high",
      "reason": "Traffic involving cloudaxis.cc indicates potential attacker-controlled infrastructure.",
      "first_seen": "2026-06-25T16:51:35+00:00",
      "last_seen": "2026-06-25T16:51:35+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Socprime",
          "url": "https://socprime.com/active-threats/ghostshell-mb-0009-targeting-ukraines-uav-operations-and-defense-supply-chain/",
          "pub_date": "2026-06-25T16:51:35+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "142.93.242.144",
      "confidence": "high",
      "reason": "Listed as network indicator associated with Backdoor.Mistic",
      "first_seen": "2026-06-24T10:20:25+00:00",
      "last_seen": "2026-06-24T19:15:44.065417+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.security.com",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modeloRAT",
          "pub_date": "2026-06-24T19:15:44.065417+00:00"
        },
        {
          "source": "Security",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat",
          "pub_date": "2026-06-24T13:55:32+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "144.31.53.78",
      "confidence": "high",
      "reason": "Listed as network indicator associated with Backdoor.Mistic",
      "first_seen": "2026-06-24T10:20:25+00:00",
      "last_seen": "2026-06-24T19:15:44.065417+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.security.com",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modeloRAT",
          "pub_date": "2026-06-24T19:15:44.065417+00:00"
        },
        {
          "source": "Security",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat",
          "pub_date": "2026-06-24T13:55:32+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "198.13.159.44",
      "confidence": "high",
      "reason": "Listed as network indicator associated with Backdoor.Mistic",
      "first_seen": "2026-06-24T10:20:25+00:00",
      "last_seen": "2026-06-24T19:15:44.065417+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.security.com",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modeloRAT",
          "pub_date": "2026-06-24T19:15:44.065417+00:00"
        },
        {
          "source": "Security",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat",
          "pub_date": "2026-06-24T13:55:32+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "199.91.221.42",
      "confidence": "high",
      "reason": "Listed as network indicator associated with Backdoor.Mistic",
      "first_seen": "2026-06-24T10:20:25+00:00",
      "last_seen": "2026-06-24T19:15:44.065417+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.security.com",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modeloRAT",
          "pub_date": "2026-06-24T19:15:44.065417+00:00"
        },
        {
          "source": "Security",
          "url": "https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat",
          "pub_date": "2026-06-24T13:55:32+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "putdrive.com",
      "confidence": "high",
      "reason": "Hosted malicious payloads used by Sandworm Team",
      "first_seen": "2026-06-24T19:05:05.454476+00:00",
      "last_seen": "2026-06-24T19:05:05.454476+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "attack.mitre.org",
          "url": "https://attack.mitre.org/groups/G0034/",
          "pub_date": "2026-06-24T19:05:05.454476+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "162.243.103.246",
      "confidence": "high",
      "reason": "Listed in a C2 IP blocklist associated with malware.",
      "first_seen": "2026-06-24T15:09:07+00:00",
      "last_seen": "2026-06-24T15:09:07+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Buttondown",
          "url": "https://buttondown.com/SecurityIntel/archive/securityintel-24-jun-active-exploitation-of-cisco/",
          "pub_date": "2026-06-24T15:09:07+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "178.62.3.223",
      "confidence": "high",
      "reason": "Listed in a C2 IP blocklist associated with malware.",
      "first_seen": "2026-06-24T15:09:07+00:00",
      "last_seen": "2026-06-24T15:09:07+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Buttondown",
          "url": "https://buttondown.com/SecurityIntel/archive/securityintel-24-jun-active-exploitation-of-cisco/",
          "pub_date": "2026-06-24T15:09:07+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "27.133.154.218",
      "confidence": "high",
      "reason": "Listed in a C2 IP blocklist associated with malware.",
      "first_seen": "2026-06-24T15:09:07+00:00",
      "last_seen": "2026-06-24T15:09:07+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Buttondown",
          "url": "https://buttondown.com/SecurityIntel/archive/securityintel-24-jun-active-exploitation-of-cisco/",
          "pub_date": "2026-06-24T15:09:07+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "34.204.119.63",
      "confidence": "high",
      "reason": "Listed in a C2 IP blocklist associated with malware.",
      "first_seen": "2026-06-24T15:09:07+00:00",
      "last_seen": "2026-06-24T15:09:07+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Buttondown",
          "url": "https://buttondown.com/SecurityIntel/archive/securityintel-24-jun-active-exploitation-of-cisco/",
          "pub_date": "2026-06-24T15:09:07+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "50.16.16.211",
      "confidence": "high",
      "reason": "Listed in a C2 IP blocklist associated with malware.",
      "first_seen": "2026-06-24T15:09:07+00:00",
      "last_seen": "2026-06-24T15:09:07+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "Buttondown",
          "url": "https://buttondown.com/SecurityIntel/archive/securityintel-24-jun-active-exploitation-of-cisco/",
          "pub_date": "2026-06-24T15:09:07+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "gs.thc.org",
      "confidence": "high",
      "reason": "Part of the GSRN relay infrastructure, indicating attacker-controlled domain",
      "first_seen": "2026-06-24T06:47:16.754750+00:00",
      "last_seen": "2026-06-24T06:47:16.754750+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.sygnia.co",
          "url": "https://www.sygnia.co/blog/operation-highland-velvet-ant/",
          "pub_date": "2026-06-24T06:47:16.75475+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "market0day.com",
      "confidence": "high",
      "reason": "Identified as an illicit online marketplace selling compromised credentials and phishing kits.",
      "first_seen": "2026-06-23T14:36:29+00:00",
      "last_seen": "2026-06-23T23:36:47+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "Feeds.Feedburner",
          "url": "https://www.scworld.com/brief/algerian-man-extradited-from-spain-charged-with-running-cybercrime-operation",
          "pub_date": "2026-06-23T23:36:47+00:00"
        },
        {
          "source": "Cyberscoop",
          "url": "https://cyberscoop.com/algerian-man-charged-cybercrime-marketplaces/",
          "pub_date": "2026-06-23T14:36:29+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "spoxy.us",
      "confidence": "high",
      "reason": "Identified as an illicit online marketplace selling compromised credentials and phishing kits.",
      "first_seen": "2026-06-23T14:36:29+00:00",
      "last_seen": "2026-06-23T23:36:47+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "Feeds.Feedburner",
          "url": "https://www.scworld.com/brief/algerian-man-extradited-from-spain-charged-with-running-cybercrime-operation",
          "pub_date": "2026-06-23T23:36:47+00:00"
        },
        {
          "source": "Cyberscoop",
          "url": "https://cyberscoop.com/algerian-man-charged-cybercrime-marketplaces/",
          "pub_date": "2026-06-23T14:36:29+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.238.204.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.238.220.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "181.215.182.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "193.163.194.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "193.239.236.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "194.33.45.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "45.86.208.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "77.247.126.0",
      "confidence": "high",
      "reason": "Listed as adversary infrastructure.",
      "first_seen": "2026-06-23T03:18:15.821101+00:00",
      "last_seen": "2026-06-23T03:18:15.821101+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.huntress.com",
          "url": "https://www.huntress.com/blog/exploitation-of-sonicwall-vpn",
          "pub_date": "2026-06-23T03:18:15.821101+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.195.105",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.195.106",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.212.114",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.212.115",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.227.105",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.227.106",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.244.114",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.244.115",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "104.28.244.116",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "163.61.198.15",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "38.54.6.28",
      "confidence": "high",
      "reason": "Observed as part of multiple IP addresses used by the actor",
      "first_seen": "2026-06-22T11:19:11.236707+00:00",
      "last_seen": "2026-06-22T11:19:11.236707+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.fortiguard.com",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-060",
          "pub_date": "2026-06-22T11:19:11.236707+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "208.68.36.90",
      "confidence": "high",
      "reason": "Identified as a key IP address used in the campaign",
      "first_seen": "2026-06-21T07:29:14+00:00",
      "last_seen": "2026-06-21T08:32:58.847602+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.anomali.com",
          "url": "https://www.anomali.com/blog/salesloft-drift-breach-recap",
          "pub_date": "2026-06-21T08:32:58.847602+00:00"
        },
        {
          "source": "Rescana",
          "url": "https://www.rescana.com/post/salesloft-drift-oauth-token-breach-enables-salesforce-data-theft-in-unc6395-icarus-attack-campaign-august-2026",
          "pub_date": "2026-06-21T07:29:14+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "44.215.108.109",
      "confidence": "high",
      "reason": "Identified as a key IP address used in the campaign",
      "first_seen": "2026-06-21T07:29:14+00:00",
      "last_seen": "2026-06-21T08:32:58.847602+00:00",
      "source_count": 2,
      "sources": [
        {
          "source": "www.anomali.com",
          "url": "https://www.anomali.com/blog/salesloft-drift-breach-recap",
          "pub_date": "2026-06-21T08:32:58.847602+00:00"
        },
        {
          "source": "Rescana",
          "url": "https://www.rescana.com/post/salesloft-drift-oauth-token-breach-enables-salesforce-data-theft-in-unc6395-icarus-attack-campaign-august-2026",
          "pub_date": "2026-06-21T07:29:14+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "207.148.64.0",
      "confidence": "high",
      "reason": "Part of the IP range used by FishMonger operators as a SprySOCKS delivery server.",
      "first_seen": "2026-06-19T16:03:16.891727+00:00",
      "last_seen": "2026-06-19T16:03:16.891727+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.welivesecurity.com",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "pub_date": "2026-06-19T16:03:16.891727+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "207.148.75.122",
      "confidence": "high",
      "reason": "Explicitly mentioned as used by FishMonger operators for communication.",
      "first_seen": "2026-06-19T16:03:16.891727+00:00",
      "last_seen": "2026-06-19T16:03:16.891727+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "www.welivesecurity.com",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "pub_date": "2026-06-19T16:03:16.891727+00:00"
        }
      ]
    },
    {
      "type": "domain",
      "value": "tracksystem.info",
      "confidence": "high",
      "reason": "Clearly associated with Circles and indicated as part of their infrastructure.",
      "first_seen": "2026-06-19T11:34:11.606269+00:00",
      "last_seen": "2026-06-19T11:34:11.606269+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "citizenlab.ca",
          "url": "https://citizenlab.ca/research/running-in-circles-uncovering-the-clients-of-cyberespionage-firm-circles/",
          "pub_date": "2026-06-19T11:34:11.606269+00:00"
        }
      ]
    },
    {
      "type": "ipv4",
      "value": "41.242.50.50",
      "confidence": "high",
      "reason": "Explicitly mentioned as part of the FinFisher C&C server.",
      "first_seen": "2026-06-19T11:34:11.606269+00:00",
      "last_seen": "2026-06-19T11:34:11.606269+00:00",
      "source_count": 1,
      "sources": [
        {
          "source": "citizenlab.ca",
          "url": "https://citizenlab.ca/research/running-in-circles-uncovering-the-clients-of-cyberespionage-firm-circles/",
          "pub_date": "2026-06-19T11:34:11.606269+00:00"
        }
      ]
    }
  ],
  "license": "CC-BY 4.0 \u2014 attribute ThreatCluster (https://threatcluster.io)",
  "report_false_positive": "hello@threatcluster.io"
}