{
  "campaign_count": 24,
  "campaigns": [
    {
      "anchors": {
        "registered_domains": [
          "2tj40eda2f.dynv6.net",
          "4nu00ypt6u.dynv6.net",
          "5w9y60z9yy.dynv6.net",
          "73tlkp3alr.dynv6.net",
          "7l30nhkxuv.dynv6.net",
          "88q118.com",
          "88q858.com",
          "93vf4b71cv.dynv6.net",
          "RKM-20260614-1514.zip",
          "account-kakao.dynv6.net",
          "adworldlog.com",
          "alarm-doc-review.site",
          "alcatelonetouch.us",
          "altntspage.dynu.net",
          "altntspages.dynu.net",
          "antxzone.dynu.net",
          "anxtlog.dynuddns.net",
          "aoo.com.mx",
          "appleviewer.sbs",
          "appvpensan.com",
          "asentv.tv",
          "ataxed.dynuddns.net",
          "auction.dynv6.net",
          "bing-tost15.com",
          "blogauth.dynuddns.net",
          "blogreference.dynuddns.net",
          "bmfketsd2dvfghe3fvsgfhbefhut4fgsgew2dvfger.cfd",
          "cakhiaqq.io",
          "casepractice.com",
          "cdn-verifying.homes",
          "chromeupdate.mydns.vc",
          "clarifypost.forum",
          "clipsexvn.mobi",
          "cloudbarfbag.com",
          "confirm-userorder.biz",
          "corporateadworld.com",
          "courter.com",
          "covid19healthsystem.org",
          "d-n-s.name",
          "d2hfjvd3fkejghe3dkvmfbnrhdgwh3fbkglrihd3dkvmfh4dje.cfd",
          "dagatructiep.ph",
          "dagatructiep67.credit",
          "departmentndoc27s.dynv6.net",
          "departmentndoc35s.dynv6.net",
          "desaindigital.com",
          "digital-notice-kr.sbs",
          "digital-post.live",
          "djeu2fejwvndfj3gewobkdfmwej3jdfhbmne.cfd",
          "dns.army",
          "dns.navy"
        ],
        "tags": [
          "#AsyncRAT",
          "#DPRK",
          "#Kimsuky",
          "#Remcos",
          "#VenomRAT",
          "#Xworm"
        ],
        "url_path_patterns": [
          "/PonySecs/FakeCry",
          "/albaluzzgom-byte",
          "/centrelocuslabs/Jackpot-vN",
          "/lorenzoDick",
          "/mgothiclove",
          "/mgothiclove/subdata",
          "/staple.exe",
          "/ultrarenewrecargado-alt"
        ]
      },
      "confidence": "medium",
      "context": "A heterogeneous cluster of over 2,200 IOCs combines Kimsuky-attributed DPRK infrastructure - including account-kakao.dynv6.net and alarm-doc-review.site - with commodity RAT C2 nodes deploying AsyncRAT, VenomRAT, Remcos, and Xworm on dynv6.net and dynu.net dynamic DNS. GitHub-hosted paths serve as dead-drop delivery channels alongside a ZIP dropper (RKM-20260614-1514.zip) and C2 endpoints including red64.duckdns.org. Seven researchers reported IOCs from July 9 through July 15.",
      "first_seen": "2026-07-09",
      "id": "tfc-29a585bbb16e",
      "ioc_count": 2257,
      "iocs": [
        {
          "date": "2026-07-15 04:59:00",
          "tags": [
            "#ransomware"
          ],
          "tweet": "https://x.com/d1v35hresearch/status/2077256702785904918",
          "type": "url",
          "user": "d1v35hresearch",
          "value": "https://github.com/PonySecs/FakeCry"
        },
        {
          "date": "2026-07-14 23:03:00",
          "tags": [],
          "tweet": "https://x.com/RussianPanda9xx/status/2077167195650400414",
          "type": "url",
          "user": "RussianPanda9xx",
          "value": "https://github.com/centrelocuslabs/Jackpot-v1/"
        },
        {
          "date": "2026-07-14 17:05:00",
          "tags": [
            "#infostealer",
            "#malware"
          ],
          "tweet": "https://x.com/JamfThreatLabs/status/2077076932902969452",
          "type": "url",
          "user": "JamfThreatLabs",
          "value": "https://github.com/mgothiclove/subdata/blob/main/submod.cfg"
        },
        {
          "date": "2026-07-14 12:12:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2077003366643744812",
          "type": "domain",
          "user": "skocherhan",
          "value": "lastore7kajp1.duckdns.org"
        },
        {
          "date": "2026-07-14 12:12:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2077003366643744812",
          "type": "url",
          "user": "skocherhan",
          "value": "http://lastore7kajp1.duckdns.org"
        },
        {
          "date": "2026-07-14 08:45:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/tdatwja/status/2076950147431583983",
          "type": "url",
          "user": "tdatwja",
          "value": "http://192.252.180.45:4449"
        },
        {
          "date": "2026-07-14 08:45:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/tdatwja/status/2076950147431583983",
          "type": "md5",
          "user": "tdatwja",
          "value": "ba1243c5e73d05b1a2231a7a99447fb7"
        },
        {
          "date": "2026-07-14 08:45:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/tdatwja/status/2076950147431583983",
          "type": "ip",
          "user": "tdatwja",
          "value": "192.252.180.45"
        },
        {
          "date": "2026-07-13 15:20:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076688302522945662",
          "type": "url",
          "user": "skocherhan",
          "value": "http://alcatelonetouch.us"
        },
        {
          "date": "2026-07-13 15:20:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076688302522945662",
          "type": "url",
          "user": "skocherhan",
          "value": "http://104.18.21.221:443"
        },
        {
          "date": "2026-07-13 15:20:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076688302522945662",
          "type": "url",
          "user": "skocherhan",
          "value": "http://104.18.20.221:443"
        },
        {
          "date": "2026-07-13 15:20:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076688302522945662",
          "type": "domain",
          "user": "skocherhan",
          "value": "alcatelonetouch.us"
        },
        {
          "date": "2026-07-13 15:18:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076687664879677642",
          "type": "url",
          "user": "skocherhan",
          "value": "http://covid19healthsystem.org"
        },
        {
          "date": "2026-07-13 15:18:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076687664879677642",
          "type": "url",
          "user": "skocherhan",
          "value": "http://104.18.27.239:443"
        },
        {
          "date": "2026-07-13 15:18:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076687664879677642",
          "type": "domain",
          "user": "skocherhan",
          "value": "covid19healthsystem.org"
        },
        {
          "date": "2026-07-13 08:57:00",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/skocherhan/status/2076591757546995971",
          "type": "ip",
          "user": "skocherhan",
          "value": "37.27.30.5"
        },
        {
          "date": "2026-07-13 08:47:00",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/D3LabIT/status/2076589271499026873",
          "type": "url",
          "user": "D3LabIT",
          "value": "http://37.27.30.5"
        },
        {
          "date": "2026-07-13 08:47:00",
          "tags": [
            "#Remcos"
          ],
          "tweet": "https://x.com/D3LabIT/status/2076589271499026873",
          "type": "md5",
          "user": "D3LabIT",
          "value": "458cca0e2e189fb07656d414fdf5b574"
        },
        {
          "date": "2026-07-13 05:03:00",
          "tags": [
            "#AsyncRAT",
            "#VenomRAT"
          ],
          "tweet": "https://x.com/bomccss/status/2076532986087125238",
          "type": "url",
          "user": "bomccss",
          "value": "http://192.252.180.45:4449"
        },
        {
          "date": "2026-07-13 05:03:00",
          "tags": [
            "#AsyncRAT",
            "#VenomRAT"
          ],
          "tweet": "https://x.com/bomccss/status/2076532986087125238",
          "type": "ip",
          "user": "bomccss",
          "value": "192.252.180.45"
        },
        {
          "date": "2026-07-12 22:42:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076437149893685747",
          "type": "domain",
          "user": "skocherhan",
          "value": "skocherhan98740bb0d8b1f23fcc1293ede85d920agithub.com"
        },
        {
          "date": "2026-07-12 22:42:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076437149893685747",
          "type": "url",
          "user": "skocherhan",
          "value": "http://skocherhan98740bb0d8b1f23fcc1293ede85d920agithub.com/ultrarenewrecargado-alt"
        },
        {
          "date": "2026-07-12 22:41:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076436880535560450",
          "type": "url",
          "user": "skocherhan",
          "value": "http://github.com/ultrarenewrecargado-alt"
        },
        {
          "date": "2026-07-12 22:41:00",
          "tags": [
            "#AsyncRAT"
          ],
          "tweet": "https://x.com/skocherhan/status/2076436880535560450",
          "type": "md5",
          "user": "skocherhan",
          "value": "98740bb0d8b1f23fcc1293ede85d920a"
        },
        {
          "date": "2026-07-12 22:32:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2076434591854866547",
          "type": "url",
          "user": "skocherhan",
          "value": "http://github.com/albaluzzgom-byte"
        }
      ],
      "last_seen": "2026-07-15",
      "member_cluster_ids": [
        "tfc-29a585bbb16e"
      ],
      "name": "Kimsuky DPRK and commodity RAT multi-family C2 cluster",
      "reporters": [
        "D3LabIT",
        "JamfThreatLabs",
        "RussianPanda9xx",
        "_IMalihi_",
        "bomccss",
        "d1v35hresearch",
        "malwrhunterteam",
        "skocherhan",
        "tdatwja"
      ],
      "tags": [
        "#AsyncRAT",
        "#C2",
        "#DPRK",
        "#Kimsuky",
        "#Remcos",
        "#VenomRAT",
        "#Xworm",
        "#infostealer",
        "#malware",
        "#opendir",
        "#ransomware"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 1005,
        "ip": 64,
        "md5": 5,
        "url": 1183
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "000.pe",
          "c0m6.top",
          "clo0d.top",
          "ct.ws",
          "dwx2.top",
          "freewebhostmost.com",
          "fwh.is",
          "gt.tc",
          "p09x.top",
          "pro3n.xyz",
          "ra1n.xyz",
          "stylishvoting.online",
          "useraccord.com",
          "votingplc.online",
          "w9y.top",
          "webl3.top",
          "xo.je"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "high",
      "context": "A phishing operation places fake Spotify voting, podcast, and fashion-themed lure pages across free-hosting providers and disposable TLDs, including ct.ws, fwh.is, gt.tc, freewebhostmost.com, c0m6.top, and over a dozen .top, .xyz, and .online domains. Subdomains consistently use terms such as spotify, vote, podcast, stream, and glamour, consistent with credential harvesting under the guise of artist popularity contests. One primary researcher reported the bulk of over 200 IOCs spanning July 8 through July 15.",
      "first_seen": "2026-07-11",
      "id": "tfc-a592b55631c7",
      "ioc_count": 194,
      "iocs": [
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "widevote.000.pe"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "voting.c0m6.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votesite.dwx2.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votepoll.freewebhostmost.com"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "voteplatform.w9y.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votenow.ra1n.xyz"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votenow.p09x.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votenow.c0m6.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votelink.dwx2.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "votefairly.000.pe"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote7.gt.tc"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote17.ct.ws"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote1.gt.tc"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote02.gt.tc"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote006.ct.ws"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote.useraccord.com"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote-session.000.pe"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "vote-03.ct.ws"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "trustvote.ct.ws"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "trendyvote.ct.ws"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "top.w9y.top"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "submitvote.freewebhostmost.com"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "stylisticvote.freewebhostmost.com"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "stylish.useraccord.com"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "spotifyvote.freewebhostmost.com"
        }
      ],
      "last_seen": "2026-07-11",
      "member_cluster_ids": [
        "tfc-a592b55631c7",
        "tfc-143b6d8de638",
        "tfc-1b646e017ee9",
        "tfc-41d2bc6f13ed",
        "tfc-37454c6b7ff3",
        "tfc-c4ff4cc1f498",
        "tfc-0154c4e824ed",
        "tfc-fb826d8a1518",
        "tfc-0c71406bacfd",
        "tfc-27880eb53875",
        "tfc-2f95803d4ded",
        "tfc-6bbf74992538",
        "tfc-802c595bb61a",
        "tfc-8da9e770e181",
        "tfc-8f650c4231d8",
        "tfc-5e2260526f82",
        "tfc-aa71c41f134e"
      ],
      "name": "Fake Spotify voting and podcast phishing across free hosts",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Spotify",
      "types": {
        "domain": 97,
        "url": 97
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "auth-code-verif.beer",
          "egisss.net",
          "notifica.lat",
          "politicsinsights.com",
          "pub-620def1d93ef431dbdf24616a9b11c77.r2.dev",
          "rubicon-contract.ru",
          "rubikon-update.ru",
          "updata.net.cn"
        ],
        "tags": [
          "#AiTM",
          "#ClickFix",
          "#FakeCaptcha"
        ],
        "url_path_patterns": [
          "/Additional",
          "/ClickFix",
          "/Interestingly",
          "/Telegram",
          "/Yandex",
          "/active_desktop_launcher.exe",
          "/active_desktop_render_xN.dll",
          "/k/MAX",
          "/kBN.exe",
          "/verify.hta",
          "/verify.htaThe"
        ]
      },
      "confidence": "high",
      "context": "A ClickFix campaign with adversary-in-the-middle (AiTM) credential-interception capability hosts fake verification pages at rubicon-contract.ru and rubikon-update.ru, with subdomains mimicking Google (goog.) and Russian government services (gos.) alongside Telegram and Yandex-themed path names. Victims are prompted to execute a verify.hta file or run active_desktop_launcher.exe, which stages the credential-intercept agent. Four researchers reported 64 IOCs between July 9 and July 14.",
      "first_seen": "2026-07-09",
      "id": "tfc-f8e0c948e13d",
      "ioc_count": 64,
      "iocs": [
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "pub-620def1d93ef431dbdf24616a9b11c77.r2.dev"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "microsoft.updata.net.cn"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://pub-620def1d93ef431dbdf24616a9b11c77.r2.dev/kB2025072926.exe"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://microsoft.updata.net.cn"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "b127701d2be865e3dc9417f6e0975e73b55b44906f166dc7147c9b392d008a00"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "a71455506d7048f1dbbcdd48100860a8cd2088cbe4a0b3881cc8a179ce494e99"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "7bb5f352f582407330bba12d2ddd15e70a3c5002fe96b7366980e644bec8a565"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "5a514fb0caceb37000a716df626163f5f8856bc7703adfa2bc3c1b59103c4ff4"
        },
        {
          "date": "2026-07-14 20:31:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2077128769614254149",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "35ae900295477f1c47edc229cd08c049fa50c1c14fab9f308868027134db778d"
        },
        {
          "date": "2026-07-14 16:38:00",
          "tags": [
            "#ClickFix",
            "#FakeCaptcha",
            "#malware"
          ],
          "tweet": "https://x.com/urlyzeio/status/2077070274898657573",
          "type": "domain",
          "user": "urlyzeio",
          "value": "politicsinsights.com"
        },
        {
          "date": "2026-07-14 16:38:00",
          "tags": [
            "#ClickFix",
            "#FakeCaptcha",
            "#malware"
          ],
          "tweet": "https://x.com/urlyzeio/status/2077070274898657573",
          "type": "url",
          "user": "urlyzeio",
          "value": "http://politicsinsights.com"
        },
        {
          "date": "2026-07-14 16:38:00",
          "tags": [
            "#ClickFix",
            "#FakeCaptcha",
            "#malware"
          ],
          "tweet": "https://x.com/urlyzeio/status/2077070274898657573",
          "type": "url",
          "user": "urlyzeio",
          "value": "http://auth-code-verif.beer"
        },
        {
          "date": "2026-07-14 16:38:00",
          "tags": [
            "#ClickFix",
            "#FakeCaptcha",
            "#malware"
          ],
          "tweet": "https://x.com/urlyzeio/status/2077070274898657573",
          "type": "domain",
          "user": "urlyzeio",
          "value": "auth-code-verif.beer"
        },
        {
          "date": "2026-07-14 08:22:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/suyog41/status/2076945482602127638",
          "type": "md5",
          "user": "suyog41",
          "value": "94b823b0780748f21d7170ccf2b86d2b"
        },
        {
          "date": "2026-07-14 08:22:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/suyog41/status/2076945482602127638",
          "type": "md5",
          "user": "suyog41",
          "value": "4b83cfbae973bea3425c3f2390cc77fb"
        },
        {
          "date": "2026-07-13 13:14:00",
          "tags": [
            "#AiTM",
            "#phishing"
          ],
          "tweet": "https://x.com/ShadowOpCode/status/2076656483652042764",
          "type": "url",
          "user": "ShadowOpCode",
          "value": "https://egisss.net"
        },
        {
          "date": "2026-07-13 13:14:00",
          "tags": [
            "#AiTM",
            "#phishing"
          ],
          "tweet": "https://x.com/ShadowOpCode/status/2076656483652042764",
          "type": "domain",
          "user": "ShadowOpCode",
          "value": "egisss.net"
        },
        {
          "date": "2026-07-10 12:48:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2075562729977364772",
          "type": "domain",
          "user": "skocherhan",
          "value": "notifica.lat"
        },
        {
          "date": "2026-07-10 12:48:00",
          "tags": [
            "#ClickFix",
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2075562729977364772",
          "type": "url",
          "user": "skocherhan",
          "value": "http://notifica.lat"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://99.98.13.61"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://172.86.126.195/active_desktop_render_x64.dll"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://172.86.126.195/active_desktop_launcher.exe"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://172.86.126.195"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "sha256",
          "user": "Malwarehunterr",
          "value": "f712c2a8b4abf2e299a2b480020333deb0f43364e9686cda78b1243c62e4830d"
        },
        {
          "date": "2026-07-10 12:44:00",
          "tags": [
            "#ClickFix"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075561856740007937",
          "type": "ip",
          "user": "Malwarehunterr",
          "value": "99.98.13.61"
        }
      ],
      "last_seen": "2026-07-14",
      "member_cluster_ids": [
        "tfc-f8e0c948e13d"
      ],
      "name": "ClickFix AiTM phishing via Russian-domain infrastructure",
      "reporters": [
        "Malwarehunterr",
        "ShadowOpCode",
        "skocherhan",
        "suyog41",
        "urlyzeio"
      ],
      "tags": [
        "#AiTM",
        "#ClickFix",
        "#FakeCaptcha",
        "#malware",
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 18,
        "ip": 3,
        "md5": 2,
        "sha256": 7,
        "url": 34
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "nexrogcapital.xyz"
        ],
        "tags": [],
        "url_path_patterns": [
          "/Bin/ScreenConnect.Client.application",
          "/Bin/ScreenConnect.Client.exe",
          "/Bin/ScreenConnect.Client.jnlp",
          "/Bin/ScreenConnect.Client.zip",
          "/Bin/ScreenConnect.ClientBootstrap.jnlp",
          "/Bin/ScreenConnect.ClientSetup.msi",
          "/Host",
          "/Login",
          "/Script.ashx",
          "/Services/AuthenticationService.ashx",
          "/Services/PageService.ashx",
          "/Services/SecurityService.ashx",
          "/Services/ToolboxService.ashx",
          "/Services/TriggerService.ashx"
        ]
      },
      "confidence": "medium",
      "context": "A threat actor deployed a self-hosted ConnectWise ScreenConnect instance at nexrogcapital.xyz, exposing the full client installer stack - MSI, ZIP, and JNLP files - alongside authentication, script execution, and trigger service endpoints. The domain name mimics a financial services firm, consistent with business email compromise or tech-support scam pretexts used to socially engineer victims into installing the remote access client. Two researchers reported 20 IOCs on July 13.",
      "first_seen": "2026-07-13",
      "id": "tfc-47ae73e30430",
      "ioc_count": 20,
      "iocs": [
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "nexrogcapital.xyz:8041"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Script.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Login"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Host"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.ClientBootstrap.jnlp"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.Client.zip"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.Client.jnlp"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.Client.exe"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.Client.application"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz:8041"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Services/TriggerService.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Services/ToolboxService.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Services/SecurityService.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Services/PageService.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Services/AuthenticationService.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Script.ashx"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Login"
        },
        {
          "date": "2026-07-13 13:16:00",
          "tags": [
            "#C2",
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076657066442433023",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nexrogcapital.xyz/Host"
        },
        {
          "date": "2026-07-13 11:22:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2076628219818598507",
          "type": "domain",
          "user": "skocherhan",
          "value": "nexrogcapital.xyz"
        },
        {
          "date": "2026-07-13 11:22:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2076628219818598507",
          "type": "url",
          "user": "skocherhan",
          "value": "https://nexrogcapital.xyz/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest"
        }
      ],
      "last_seen": "2026-07-13",
      "member_cluster_ids": [
        "tfc-47ae73e30430"
      ],
      "name": "ScreenConnect remote access C2 hosted on nexrogcapital.xyz",
      "reporters": [
        "Malwarehunterr",
        "skocherhan"
      ],
      "tags": [
        "#C2",
        "#malware"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 18
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "endpoint-api-v1.com",
          "larpers.fun",
          "larpers.su",
          "mvuianh.cn",
          "uutiod.asia"
        ],
        "tags": [],
        "url_path_patterns": [
          "/d/fNbNe",
          "/login"
        ]
      },
      "confidence": "medium",
      "context": "A phishing campaign targeting Japanese consumers places credential-harvesting login pages on attacker-registered domains including endpoint-api-v1.com, larpers.fun, and larpers.su, alongside Chinese-hosted domains (mvuianh.cn, uutiod.asia). Path patterns consistently end at /login, consistent with Rakuten Bank and NTT docomo impersonation identified in the prior reporting period. Three reporters flagged 14 IOCs between July 9 and July 13.",
      "first_seen": "2026-07-09",
      "id": "tfc-8b0b77cc6449",
      "ioc_count": 14,
      "iocs": [
        {
          "date": "2026-07-13 13:23:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2076658668146180128",
          "type": "domain",
          "user": "malwrhunterteam",
          "value": "larpers.su"
        },
        {
          "date": "2026-07-13 13:23:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2061777691758498296",
          "type": "domain",
          "user": "malwrhunterteam",
          "value": "larpers.fun"
        },
        {
          "date": "2026-07-13 13:23:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2076658668146180128",
          "type": "url",
          "user": "malwrhunterteam",
          "value": "https://larpers.su/login"
        },
        {
          "date": "2026-07-13 13:23:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2061777691758498296",
          "type": "url",
          "user": "malwrhunterteam",
          "value": "https://larpers.fun/login"
        },
        {
          "date": "2026-07-13 04:10:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2076519676725870873",
          "type": "domain",
          "user": "masaomi346",
          "value": "uutiod.asia"
        },
        {
          "date": "2026-07-13 04:10:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2076519676725870873",
          "type": "url",
          "user": "masaomi346",
          "value": "https://uutiod.asia/login"
        },
        {
          "date": "2026-07-10 11:57:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2075549893503131698",
          "type": "url",
          "user": "masaomi346",
          "value": "https://2.mvuianh.cn/login"
        },
        {
          "date": "2026-07-10 11:57:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2075549893503131698",
          "type": "url",
          "user": "masaomi346",
          "value": "https://1.mvuianh.cn/login"
        },
        {
          "date": "2026-07-10 11:57:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2075549893503131698",
          "type": "domain",
          "user": "masaomi346",
          "value": "2.mvuianh.cn"
        },
        {
          "date": "2026-07-10 11:57:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2075549893503131698",
          "type": "domain",
          "user": "masaomi346",
          "value": "1.mvuianh.cn"
        },
        {
          "date": "2026-07-10 10:42:00",
          "tags": [],
          "tweet": "https://x.com/SquiblydooBlog/status/2075531016077508880",
          "type": "url",
          "user": "SquiblydooBlog",
          "value": "http://endpoint-api-v1.com/d/f1b24e"
        },
        {
          "date": "2026-07-10 10:42:00",
          "tags": [],
          "tweet": "https://x.com/SquiblydooBlog/status/2075531016077508880",
          "type": "domain",
          "user": "SquiblydooBlog",
          "value": "endpoint-api-v1.com"
        },
        {
          "date": "2026-07-09 21:11:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2075327083975254436",
          "type": "url",
          "user": "malwrhunterteam",
          "value": "https://endpoint-api-v1.com/login"
        },
        {
          "date": "2026-07-09 21:11:00",
          "tags": [],
          "tweet": "https://x.com/malwrhunterteam/status/2075327083975254436",
          "type": "domain",
          "user": "malwrhunterteam",
          "value": "endpoint-api-v1.com"
        }
      ],
      "last_seen": "2026-07-13",
      "member_cluster_ids": [
        "tfc-8b0b77cc6449"
      ],
      "name": "Japanese consumer phishing: Rakuten Bank, docomo",
      "reporters": [
        "SquiblydooBlog",
        "malwrhunterteam",
        "masaomi346"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Rakuten Bank",
      "types": {
        "domain": 7,
        "url": 7
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "mooo.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A set of disparate subdomains on mooo.com - including powerbalance, denisprog, dlore, and iot123 - were flagged as phishing infrastructure, likely representing multiple small operators exploiting the free dynamic DNS service. The subdomains share no coherent lure theme, suggesting unrelated actors reusing the same hosting provider. One researcher reported 12 IOCs on July 13.",
      "first_seen": "2026-07-13",
      "id": "tfc-eb59f32a1674",
      "ioc_count": 12,
      "iocs": [
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "warkelen.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "nikitasliva.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "iot123.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://warkelen.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://nikitasliva.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://iot123.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://dlore.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://denisprog.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "dlore.mooo.com"
        },
        {
          "date": "2026-07-13 21:28:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076780800130097478",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "denisprog.mooo.com"
        },
        {
          "date": "2026-07-13 20:10:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076761329587954174",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "powerbalance.mooo.com"
        },
        {
          "date": "2026-07-13 20:10:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076761329587954174",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://powerbalance.mooo.com"
        }
      ],
      "last_seen": "2026-07-13",
      "member_cluster_ids": [
        "tfc-eb59f32a1674"
      ],
      "name": "Miscellaneous phishing clusters on mooo.com free DNS",
      "reporters": [
        "Malwarehunterr"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 6,
        "url": 6
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "glitch.me"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A phishing cluster abuses Glitch.me's trusted developer platform by hosting credential-harvesting pages on auto-generated adjective-noun subdomains such as coral-unique-wasabi.glitch.me and harmless-loving-mousepad.glitch.me. The platform's reputation and free-tier availability make it attractive for evading URL reputation filters. One researcher reported 10 IOCs on July 11.",
      "first_seen": "2026-07-11",
      "id": "tfc-c6f5fe8d026d",
      "ioc_count": 10,
      "iocs": [
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "teal-fluoridated-parsley.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "successful-uncovered-dead.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "knowledgeable-defiant-trapezoid.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "url",
          "user": "skocherhan",
          "value": "http://teal-fluoridated-parsley.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "url",
          "user": "skocherhan",
          "value": "http://successful-uncovered-dead.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "url",
          "user": "skocherhan",
          "value": "http://knowledgeable-defiant-trapezoid.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "url",
          "user": "skocherhan",
          "value": "http://harmless-loving-mousepad.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "url",
          "user": "skocherhan",
          "value": "http://coral-unique-wasabi.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "harmless-loving-mousepad.glitch.me"
        },
        {
          "date": "2026-07-11 13:23:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075934107029164502",
          "type": "domain",
          "user": "skocherhan",
          "value": "coral-unique-wasabi.glitch.me"
        }
      ],
      "last_seen": "2026-07-11",
      "member_cluster_ids": [
        "tfc-c6f5fe8d026d"
      ],
      "name": "Phishing pages on randomly-named Glitch.me subdomains",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 5,
        "url": 5
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "theleaguechampions.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A phishing operation uses theleaguechampions.com as primary infrastructure, with ns1, ns2, and server subdomains indicating a self-hosted DNS setup capable of supporting multiple abuse operations. The sports-competition-themed domain may serve as a social engineering lure or simply as unbranded hosting infrastructure. One researcher reported 8 IOCs on July 12.",
      "first_seen": "2026-07-12",
      "id": "tfc-a922b24257b0",
      "ioc_count": 8,
      "iocs": [
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "server.theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "ns2.theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "ns1.theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://server.theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ns2.theleaguechampions.com"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ns1.theleaguechampions.com"
        }
      ],
      "last_seen": "2026-07-12",
      "member_cluster_ids": [
        "tfc-a922b24257b0"
      ],
      "name": "Phishing infrastructure at theleaguechampions.com",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 4,
        "url": 4
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "doblelaidentedi.duckdns.org",
          "newzamrecarga.duckdns.org"
        ],
        "tags": [
          "#Dcrat",
          "#Njrat"
        ],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "A RAT cluster uses DuckDNS subdomains (doblelaidentedi.duckdns.org, newzamrecarga.duckdns.org) and a Latin American IP (45.225.135.22) as C2 endpoints for DCrat and Njrat, with listeners on ports 50001 and 8987. Spanish-language subdomain terms and the geolocated IP suggest a Spanish-speaking operator or targeting. One researcher flagged 7 IOCs on July 12.",
      "first_seen": "2026-07-12",
      "id": "tfc-f4271eb2afee",
      "ioc_count": 7,
      "iocs": [
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "domain",
          "user": "skocherhan",
          "value": "newzamrecarga.duckdns.org"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "url",
          "user": "skocherhan",
          "value": "http://newzamrecarga.duckdns.org"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "url",
          "user": "skocherhan",
          "value": "http://doblelaidentedi.duckdns.org"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "url",
          "user": "skocherhan",
          "value": "http://45.225.135.22:8987"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "url",
          "user": "skocherhan",
          "value": "http://45.225.135.22:50001"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "domain",
          "user": "skocherhan",
          "value": "doblelaidentedi.duckdns.org"
        },
        {
          "date": "2026-07-12 22:54:00",
          "tags": [
            "#Dcrat",
            "#Njrat"
          ],
          "tweet": "https://x.com/skocherhan/status/2076440022161424893",
          "type": "ip",
          "user": "skocherhan",
          "value": "45.225.135.22"
        }
      ],
      "last_seen": "2026-07-12",
      "member_cluster_ids": [
        "tfc-f4271eb2afee"
      ],
      "name": "DCrat and Njrat C2 via DuckDNS with Latin American IP",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#Dcrat",
        "#Njrat"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "ip": 1,
        "url": 4
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "download-msoffice.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "Subdomains of download-msoffice.com serve malicious content under the guise of Microsoft Office downloads, with a Training.docx file used as a social engineering lure consistent with Sidewinder (APT-C-17) targeting of South Asian government and military organizations. The domain typosquats the legitimate Microsoft namespace to add credibility to the lure. Two researchers reported 7 IOCs on July 10.",
      "first_seen": "2026-07-10",
      "id": "tfc-f98ccf717d57",
      "ioc_count": 7,
      "iocs": [
        {
          "date": "2026-07-10 14:10:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2075583391060103433",
          "type": "url",
          "user": "skocherhan",
          "value": "http://Training.docx2a2e3e78e76bcc759905da3f1532a4b8C2word.download-msoffice.com"
        },
        {
          "date": "2026-07-10 14:10:00",
          "tags": [],
          "tweet": "https://x.com/skocherhan/status/2075583391060103433",
          "type": "domain",
          "user": "skocherhan",
          "value": "Training.docx2a2e3e78e76bcc759905da3f1532a4b8C2word.download-msoffice.com"
        },
        {
          "date": "2026-07-10 14:01:00",
          "tags": [],
          "tweet": "https://x.com/suyog41/status/2075581101003972979",
          "type": "domain",
          "user": "suyog41",
          "value": "word.download-msoffice.com"
        },
        {
          "date": "2026-07-10 14:01:00",
          "tags": [],
          "tweet": "https://x.com/suyog41/status/2075581101003972979",
          "type": "url",
          "user": "suyog41",
          "value": "http://word.download-msoffice.com"
        },
        {
          "date": "2026-07-10 13:31:00",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2075573597700059268",
          "type": "url",
          "user": "skocherhan",
          "value": "http://ceh.download-msoffice.com#Sidewinder"
        },
        {
          "date": "2026-07-10 13:31:00",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/skocherhan/status/2075573597700059268",
          "type": "domain",
          "user": "skocherhan",
          "value": "ceh.download-msoffice.com"
        },
        {
          "date": "2026-07-10 13:26:00",
          "tags": [
            "#APT"
          ],
          "tweet": "https://x.com/suyog41/status/2075572390315311333",
          "type": "url",
          "user": "suyog41",
          "value": "http://ceh.download-msoffice.com"
        }
      ],
      "last_seen": "2026-07-10",
      "member_cluster_ids": [
        "tfc-f98ccf717d57"
      ],
      "name": "Sidewinder APT lure via download-msoffice.com",
      "reporters": [
        "skocherhan",
        "suyog41"
      ],
      "tags": [
        "#APT"
      ],
      "targeted_brand": "Microsoft",
      "types": {
        "domain": 3,
        "url": 4
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "masgravr.online"
        ],
        "tags": [],
        "url_path_patterns": [
          "/HomeGoogle.cmd",
          "/UpdateN.zip",
          "/UpdateN.zipFilename",
          "/getsN.psN"
        ]
      },
      "confidence": "low",
      "context": "A malware delivery site at masgravr.online hosts a PowerShell script (gets2.ps1), a CMD file (HomeGoogle.cmd), and a ZIP archive (Update2.zip) consistent with a multi-stage dropper chain using a Google-themed pretext for the initial execution step. The specific malware family deployed in the final stage is not identified from available data. Two reporters flagged 6 IOCs on July 11.",
      "first_seen": "2026-07-11",
      "id": "tfc-45c25b04383e",
      "ioc_count": 6,
      "iocs": [
        {
          "date": "2026-07-11 22:01:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2076064283679506658",
          "type": "domain",
          "user": "skocherhan",
          "value": "masgravr.online"
        },
        {
          "date": "2026-07-11 22:01:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2076064283679506658",
          "type": "url",
          "user": "skocherhan",
          "value": "http://masgravr.online/gets2.ps1"
        },
        {
          "date": "2026-07-11 22:01:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2076064283679506658",
          "type": "url",
          "user": "skocherhan",
          "value": "http://masgravr.online/Update2.zipFilename"
        },
        {
          "date": "2026-07-11 22:01:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/skocherhan/status/2076064283679506658",
          "type": "url",
          "user": "skocherhan",
          "value": "http://masgravr.online/HomeGoogle.cmd"
        },
        {
          "date": "2026-07-11 21:58:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076063563630928369",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://masgravr.online/Update2.zip"
        },
        {
          "date": "2026-07-11 21:58:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076063563630928369",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://masgravr.online"
        }
      ],
      "last_seen": "2026-07-11",
      "member_cluster_ids": [
        "tfc-45c25b04383e"
      ],
      "name": "Multi-stage malware dropper staged on masgravr.online",
      "reporters": [
        "Malwarehunterr",
        "skocherhan"
      ],
      "tags": [
        "#malware"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 1,
        "url": 5
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "brunaecass.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/N/HubStream",
          "/N/index",
          "/N/intercepts.js",
          "/N/window"
        ]
      },
      "confidence": "low",
      "context": "A session-hijacking operation uses log.brunaecass.com with paths including /HubStream, /intercepts.js, and /window, consistent with a browser-based AiTM or session-intercept framework that captures credentials or session tokens via injected JavaScript. One researcher reported 6 IOCs on July 12.",
      "first_seen": "2026-07-12",
      "id": "tfc-585457a484d5",
      "ioc_count": 6,
      "iocs": [
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "log.brunaecass.com"
        },
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://log.brunaecass.com/9730502/window"
        },
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://log.brunaecass.com/9730502/intercepts.js"
        },
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://log.brunaecass.com/9730502/index"
        },
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://log.brunaecass.com/9730502/HubStream"
        },
        {
          "date": "2026-07-12 11:36:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076269554972700946",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://log.brunaecass.com"
        }
      ],
      "last_seen": "2026-07-12",
      "member_cluster_ids": [
        "tfc-585457a484d5"
      ],
      "name": "Browser session interception framework at brunaecass.com",
      "reporters": [
        "Malwarehunterr"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 1,
        "url": 5
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "ministry-information-broadcasting-jihad-mndgdfdf.pages.dev",
          "ptnrmat.xyz"
        ],
        "tags": [
          "#Android"
        ],
        "url_path_patterns": [
          "/rolex/ulpdN.php"
        ]
      },
      "confidence": "low",
      "context": "An Android malware sample (MD5: d5a0a491d0a062e2d57c09497837e311) is distributed via a Cloudflare Pages domain whose name references a government ministry alongside a PHP payload handler at ptnrmat.xyz/rolex/ulpd1.php. The pages.dev domain name implies a politically-themed government-impersonation social engineering lure. Two reporters flagged 6 IOCs between July 9 and July 14.",
      "first_seen": "2026-07-09",
      "id": "tfc-6a24279443d3",
      "ioc_count": 6,
      "iocs": [
        {
          "date": "2026-07-14 08:50:00",
          "tags": [
            "#Android",
            "#C2",
            "#RAT"
          ],
          "tweet": "https://x.com/Fact_Finder03/status/2076952338955370806",
          "type": "ip",
          "user": "Fact_Finder03",
          "value": "8.156.82.11"
        },
        {
          "date": "2026-07-09 15:30:00",
          "tags": [
            "#Android"
          ],
          "tweet": "https://x.com/volrant136/status/2075241178543378489",
          "type": "domain",
          "user": "volrant136",
          "value": "ptnrmat.xyz"
        },
        {
          "date": "2026-07-09 15:30:00",
          "tags": [
            "#Android"
          ],
          "tweet": "https://x.com/volrant136/status/2075241178543378489",
          "type": "domain",
          "user": "volrant136",
          "value": "ministry-information-broadcasting-jihad-mndgdfdf.pages.dev"
        },
        {
          "date": "2026-07-09 15:30:00",
          "tags": [
            "#Android"
          ],
          "tweet": "https://x.com/volrant136/status/2075241178543378489",
          "type": "url",
          "user": "volrant136",
          "value": "https://ptnrmat.xyz/rolex/ulpd1.php"
        },
        {
          "date": "2026-07-09 15:30:00",
          "tags": [
            "#Android"
          ],
          "tweet": "https://x.com/volrant136/status/2075241178543378489",
          "type": "url",
          "user": "volrant136",
          "value": "http://ministry-information-broadcasting-jihad-mndgdfdf.pages.dev"
        },
        {
          "date": "2026-07-09 15:30:00",
          "tags": [
            "#Android"
          ],
          "tweet": "https://x.com/volrant136/status/2075241178543378489",
          "type": "md5",
          "user": "volrant136",
          "value": "d5a0a491d0a062e2d57c09497837e311"
        }
      ],
      "last_seen": "2026-07-14",
      "member_cluster_ids": [
        "tfc-6a24279443d3"
      ],
      "name": "Android malware via Cloudflare Pages government lure",
      "reporters": [
        "Fact_Finder03",
        "volrant136"
      ],
      "tags": [
        "#Android",
        "#C2",
        "#RAT"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "ip": 1,
        "md5": 1,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "bkrvmdtcm.com",
          "idnqjedtcm.com"
        ],
        "tags": [
          "#NetSupport"
        ],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "Two randomly-named domains (bkrvmdtcm.com, idnqjedtcm.com) with DGA-style labels host NetSupport RAT infrastructure, a legitimate remote management tool routinely abused for persistent access following initial compromise. The absence of any branding or theme is typical of commodity RAT deployments by financially-motivated groups. One researcher reported 5 IOCs on July 13.",
      "first_seen": "2026-07-13",
      "id": "tfc-9561440b2f01",
      "ioc_count": 5,
      "iocs": [
        {
          "date": "2026-07-13 07:47:00",
          "tags": [
            "#NetSupport"
          ],
          "tweet": "https://x.com/skocherhan/status/2076574330926817361",
          "type": "domain",
          "user": "skocherhan",
          "value": "idnqjedtcm.com"
        },
        {
          "date": "2026-07-13 07:47:00",
          "tags": [
            "#NetSupport"
          ],
          "tweet": "https://x.com/skocherhan/status/2076574330926817361",
          "type": "url",
          "user": "skocherhan",
          "value": "http://idnqjedtcm.com"
        },
        {
          "date": "2026-07-13 07:47:00",
          "tags": [
            "#NetSupport"
          ],
          "tweet": "https://x.com/skocherhan/status/2076574330926817361",
          "type": "url",
          "user": "skocherhan",
          "value": "http://bkrvmdtcm.com"
        },
        {
          "date": "2026-07-13 07:47:00",
          "tags": [
            "#NetSupport"
          ],
          "tweet": "https://x.com/skocherhan/status/2076574330926817361",
          "type": "domain",
          "user": "skocherhan",
          "value": "bkrvmdtcm.com"
        },
        {
          "date": "2026-07-13 07:47:00",
          "tags": [
            "#NetSupport"
          ],
          "tweet": "https://x.com/skocherhan/status/2076574330926817361",
          "type": "md5",
          "user": "skocherhan",
          "value": "4f88a13abda5f0a5747d7bb180cdec4c"
        }
      ],
      "last_seen": "2026-07-13",
      "member_cluster_ids": [
        "tfc-9561440b2f01"
      ],
      "name": "NetSupport RAT C2 on randomly-named domains",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#NetSupport"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "md5": 1,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "opendinnerrslpartiee.icu"
        ],
        "tags": [],
        "url_path_patterns": [
          "/N/download.php",
          "/api/request-code.php"
        ]
      },
      "confidence": "low",
      "context": "A site at opendinnerrslpartiee.icu delivers a malicious MSI installer named RSVPINVITES.msi via a /download.php endpoint alongside /api/request-code.php suggesting multi-stage activation. The domain and filename use a dinner or party invitation as a social engineering lure. One researcher reported 4 IOCs on July 10.",
      "first_seen": "2026-07-10",
      "id": "tfc-072967d6b834",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-10 19:39:00",
          "tags": [
            "#malware",
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075666199724331085",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "opendinnerrslpartiee.icu"
        },
        {
          "date": "2026-07-10 19:39:00",
          "tags": [
            "#malware",
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075666199724331085",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://www.opendinnerrslpartiee.icu/api/request-code.php"
        },
        {
          "date": "2026-07-10 19:39:00",
          "tags": [
            "#malware",
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075666199724331085",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://www.opendinnerrslpartiee.icu/54746/download.php?name=RSVPINVITES.msi"
        },
        {
          "date": "2026-07-10 19:39:00",
          "tags": [
            "#malware",
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2075666199724331085",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "http://opendinnerrslpartiee.icu"
        }
      ],
      "last_seen": "2026-07-10",
      "member_cluster_ids": [
        "tfc-072967d6b834"
      ],
      "name": "MSI installer dropper via fake event invitation",
      "reporters": [
        "Malwarehunterr"
      ],
      "tags": [
        "#malware",
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 1,
        "url": 3
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "vagaro.online"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A phishing site at vagaro.online impersonates Vagaro, a legitimate salon and spa booking platform, using a newsletter subdomain likely deployed for email-delivered credential theft targeting Vagaro customers. The lookalike domain (vagaro.online vs. vagaro.com) is a direct brand typosquat. One researcher reported 4 IOCs on July 12.",
      "first_seen": "2026-07-12",
      "id": "tfc-1b495b3699d4",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "vagaro.online"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "domain",
          "user": "skocherhan",
          "value": "newsletter.vagaro.online"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://vagaro.online"
        },
        {
          "date": "2026-07-12 11:40:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2076270427035296011",
          "type": "url",
          "user": "skocherhan",
          "value": "http://newsletter.vagaro.online"
        }
      ],
      "last_seen": "2026-07-12",
      "member_cluster_ids": [
        "tfc-1b495b3699d4"
      ],
      "name": "Vagaro booking platform phishing on vagaro.online",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Vagaro",
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "obktclg.cn",
          "pldqwsqd.cn"
        ],
        "tags": [],
        "url_path_patterns": [
          "/NHgNml/loginbab"
        ]
      },
      "confidence": "low",
      "context": "A phishing operation uses subdomains of two .cn domains (obktclg.cn, pldqwsqd.cn) to host credential-harvesting pages at a consistent /loginbab path, with subdomain labels using legitimacy-themed names. The .cn registration and uniform URL structure suggest a single operator running a templated phishing kit. One reporter flagged 4 IOCs between July 10 and July 13.",
      "first_seen": "2026-07-10",
      "id": "tfc-41220cbb97a6",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-13 05:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2076544305964200160",
          "type": "domain",
          "user": "Metemcyber",
          "value": "leviization.obktclg.cn"
        },
        {
          "date": "2026-07-13 05:48:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2076544305964200160",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://leviization.obktclg.cn/8Hg97ml/loginbab"
        },
        {
          "date": "2026-07-10 05:37:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2075454331600695611",
          "type": "domain",
          "user": "Metemcyber",
          "value": "sourceture.pldqwsqd.cn"
        },
        {
          "date": "2026-07-10 05:37:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2075454331600695611",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://sourceture.pldqwsqd.cn/8Hg97ml/loginbab"
        }
      ],
      "last_seen": "2026-07-13",
      "member_cluster_ids": [
        "tfc-41220cbb97a6"
      ],
      "name": "Login credential phishing on .cn domains via /loginbab",
      "reporters": [
        "Metemcyber"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "z11.web.core.windows.net"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A phishing campaign abuses Azure Static Web Apps (z11.web.core.windows.net) to host fake pages on short alphanumeric subdomains, exploiting the trusted windows.net domain to evade URL reputation filtering. One researcher reported 4 IOCs on July 9.",
      "first_seen": "2026-07-09",
      "id": "tfc-4154d3f9f84a",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-09 09:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075148354141433941",
          "type": "url",
          "user": "skocherhan",
          "value": "http://hk3091.z11.web.core.windows.net"
        },
        {
          "date": "2026-07-09 09:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075148354141433941",
          "type": "url",
          "user": "skocherhan",
          "value": "http://h5g.z11.web.core.windows.net"
        },
        {
          "date": "2026-07-09 09:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075148354141433941",
          "type": "domain",
          "user": "skocherhan",
          "value": "hk3091.z11.web.core.windows.net"
        },
        {
          "date": "2026-07-09 09:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/skocherhan/status/2075148354141433941",
          "type": "domain",
          "user": "skocherhan",
          "value": "h5g.z11.web.core.windows.net"
        }
      ],
      "last_seen": "2026-07-09",
      "member_cluster_ids": [
        "tfc-4154d3f9f84a"
      ],
      "name": "Phishing pages hosted on Azure Static Web Apps",
      "reporters": [
        "skocherhan"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "destinystealer.com"
        ],
        "tags": [],
        "url_path_patterns": [
          "/fileicin.php"
        ]
      },
      "confidence": "low",
      "context": "A dedicated stealer endpoint at destinystealer.com exposes a /fileicin.php handler consistent with credential or file exfiltration. The self-descriptive domain name and purpose-built PHP endpoint structure suggest attacker-controlled infrastructure rather than a compromised host. One researcher reported 4 IOCs on July 9.",
      "first_seen": "2026-07-09",
      "id": "tfc-44d04791f95f",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-09 13:30:00",
          "tags": [],
          "tweet": "https://x.com/anyrun_app/status/2075210985539866988",
          "type": "url",
          "user": "anyrun_app",
          "value": "https://destinystealer.com/fileicin.php"
        },
        {
          "date": "2026-07-09 13:30:00",
          "tags": [],
          "tweet": "https://x.com/anyrun_app/status/2075210982469554324",
          "type": "url",
          "user": "anyrun_app",
          "value": "http://destinystealer.com/fileicin.php"
        },
        {
          "date": "2026-07-09 13:30:00",
          "tags": [],
          "tweet": "https://x.com/anyrun_app/status/2075210985539866988",
          "type": "url",
          "user": "anyrun_app",
          "value": "http://destinystealer.com"
        },
        {
          "date": "2026-07-09 13:30:00",
          "tags": [],
          "tweet": "https://x.com/anyrun_app/status/2075210982469554324",
          "type": "domain",
          "user": "anyrun_app",
          "value": "destinystealer.com"
        }
      ],
      "last_seen": "2026-07-09",
      "member_cluster_ids": [
        "tfc-44d04791f95f"
      ],
      "name": "Credential stealer infrastructure at destinystealer.com",
      "reporters": [
        "anyrun_app"
      ],
      "tags": [],
      "targeted_brand": null,
      "types": {
        "domain": 1,
        "url": 3
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "lulzsyndicate.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A domain named lulzsyndicate.com exposes a panel subdomain consistent with an attacker-controlled administration panel for crimeware tooling. The deliberate brand-style name suggests an established actor identity rather than a compromised host. One researcher reported 4 IOCs on July 14.",
      "first_seen": "2026-07-14",
      "id": "tfc-4c975a568f5d",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-14 10:08:00",
          "tags": [],
          "tweet": "https://x.com/500mk500/status/2076972201228542364",
          "type": "domain",
          "user": "500mk500",
          "value": "panel.lulzsyndicate.com"
        },
        {
          "date": "2026-07-14 10:08:00",
          "tags": [],
          "tweet": "https://x.com/500mk500/status/2076972201228542364",
          "type": "domain",
          "user": "500mk500",
          "value": "lulzsyndicate.com"
        },
        {
          "date": "2026-07-14 10:08:00",
          "tags": [],
          "tweet": "https://x.com/500mk500/status/2076972201228542364",
          "type": "url",
          "user": "500mk500",
          "value": "http://panel.lulzsyndicate.com"
        },
        {
          "date": "2026-07-14 10:08:00",
          "tags": [],
          "tweet": "https://x.com/500mk500/status/2076972201228542364",
          "type": "url",
          "user": "500mk500",
          "value": "http://lulzsyndicate.com"
        }
      ],
      "last_seen": "2026-07-14",
      "member_cluster_ids": [
        "tfc-4c975a568f5d"
      ],
      "name": "Crimeware panel infrastructure at lulzsyndicate.com",
      "reporters": [
        "500mk500"
      ],
      "tags": [],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "31thbi.info",
          "khs4ik.info"
        ],
        "tags": [],
        "url_path_patterns": [
          "/HNAoO"
        ]
      },
      "confidence": "low",
      "context": "A phishing operation uses two .info domains (31thbi.info, khs4ik.info) with legitimacy-themed subdomains and a consistent short alphanumeric path (/H80AoO) to host credential-harvesting pages, a URL structure typical of bulk phishing kits that rotate campaign identifiers across host pairs. The specific brand or sector targeted is not identifiable from available IOCs. Two researchers reported 4 IOCs between July 13 and July 14.",
      "first_seen": "2026-07-13",
      "id": "tfc-5edbb82a1f18",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-14 03:52:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2076877586026914244",
          "type": "url",
          "user": "masaomi346",
          "value": "https://canrsa.31thbi.info/H80AoO"
        },
        {
          "date": "2026-07-14 03:52:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/masaomi346/status/2076877586026914244",
          "type": "domain",
          "user": "masaomi346",
          "value": "canrsa.31thbi.info"
        },
        {
          "date": "2026-07-13 05:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2076537601067221315",
          "type": "domain",
          "user": "Metemcyber",
          "value": "secnond.khs4ik.info"
        },
        {
          "date": "2026-07-13 05:21:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Metemcyber/status/2076537601067221315",
          "type": "url",
          "user": "Metemcyber",
          "value": "https://secnond.khs4ik.info/H80AoO"
        }
      ],
      "last_seen": "2026-07-14",
      "member_cluster_ids": [
        "tfc-5edbb82a1f18"
      ],
      "name": "Phishing kit on .info domains with short campaign-code paths",
      "reporters": [
        "Metemcyber",
        "masaomi346"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "eletroshopoficial.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "low",
      "context": "A scam site at eletroshopoficial.com impersonates a Brazilian electronics retailer using a name that closely mimics legitimate shop naming conventions. The domain was flagged for both phishing and scam activity targeting Brazilian consumers. One researcher reported 4 IOCs between July 13 and July 14.",
      "first_seen": "2026-07-13",
      "id": "tfc-8f709e399e52",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-14 17:49:00",
          "tags": [
            "#phishing",
            "#scam"
          ],
          "tweet": "https://x.com/Coolcarlos17/status/2077088035292741979",
          "type": "url",
          "user": "Coolcarlos17",
          "value": "https://eletroshopoficial.com"
        },
        {
          "date": "2026-07-14 17:49:00",
          "tags": [
            "#phishing",
            "#scam"
          ],
          "tweet": "https://x.com/Coolcarlos17/status/2077088035292741979",
          "type": "domain",
          "user": "Coolcarlos17",
          "value": "eletroshopoficial.com"
        },
        {
          "date": "2026-07-13 21:31:00",
          "tags": [
            "#phishing",
            "#scam"
          ],
          "tweet": "https://x.com/Coolcarlos17/status/2076781554991255801",
          "type": "url",
          "user": "Coolcarlos17",
          "value": "https://eletroshopoficial.com"
        },
        {
          "date": "2026-07-13 21:31:00",
          "tags": [
            "#phishing",
            "#scam"
          ],
          "tweet": "https://x.com/Coolcarlos17/status/2076781554991255801",
          "type": "domain",
          "user": "Coolcarlos17",
          "value": "eletroshopoficial.com"
        }
      ],
      "last_seen": "2026-07-14",
      "member_cluster_ids": [
        "tfc-8f709e399e52"
      ],
      "name": "Brazilian e-commerce scam site at eletroshopoficial.com",
      "reporters": [
        "Coolcarlos17"
      ],
      "tags": [
        "#phishing",
        "#scam"
      ],
      "targeted_brand": null,
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "7zip.com"
        ],
        "tags": [],
        "url_path_patterns": []
      },
      "confidence": "medium",
      "context": "A malware distribution domain at 7zip.com typosquats the official 7-Zip project website (7-zip.org), likely used to serve trojanized archives to users searching for the legitimate archiver. Two researchers reported 4 IOCs between July 9 and July 10.",
      "first_seen": "2026-07-09",
      "id": "tfc-904cabebf348",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-10 12:55:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/CyberTLDR/status/2075564630198395326",
          "type": "url",
          "user": "CyberTLDR",
          "value": "http://7zip.com"
        },
        {
          "date": "2026-07-10 12:55:00",
          "tags": [
            "#malware"
          ],
          "tweet": "https://x.com/CyberTLDR/status/2075564630198395326",
          "type": "domain",
          "user": "CyberTLDR",
          "value": "7zip.com"
        },
        {
          "date": "2026-07-09 07:36:00",
          "tags": [],
          "tweet": "https://x.com/blackorbird/status/2021493127975231567",
          "type": "url",
          "user": "blackorbird",
          "value": "http://7zip.com"
        },
        {
          "date": "2026-07-09 07:36:00",
          "tags": [],
          "tweet": "https://x.com/blackorbird/status/2021493127975231567",
          "type": "domain",
          "user": "blackorbird",
          "value": "7zip.com"
        }
      ],
      "last_seen": "2026-07-10",
      "member_cluster_ids": [
        "tfc-904cabebf348"
      ],
      "name": "7-Zip typosquat domain 7zip.com serving malware",
      "reporters": [
        "CyberTLDR",
        "blackorbird"
      ],
      "tags": [
        "#malware"
      ],
      "targeted_brand": "7-Zip",
      "types": {
        "domain": 2,
        "url": 2
      }
    },
    {
      "anchors": {
        "registered_domains": [
          "exoduuss.online"
        ],
        "tags": [],
        "url_path_patterns": [
          "/en/completo.php",
          "/en/seguranca_validacao.php"
        ]
      },
      "confidence": "low",
      "context": "A phishing site at exoduuss.online uses a /seguranca_validacao.php endpoint and /completo.php path to harvest credentials under a security-check pretext, with Portuguese-language path names indicating Brazilian targeting. The typosquat domain closely mimics the Exodus cryptocurrency wallet brand (exodus.com). One researcher reported 4 IOCs on July 11.",
      "first_seen": "2026-07-11",
      "id": "tfc-a0263ae47042",
      "ioc_count": 4,
      "iocs": [
        {
          "date": "2026-07-11 20:09:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076036227208454223",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://exoduuss.online/en/seguranca_validacao.php"
        },
        {
          "date": "2026-07-11 20:09:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076036227208454223",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://exoduuss.online/en/completo.php"
        },
        {
          "date": "2026-07-11 20:09:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076036227208454223",
          "type": "url",
          "user": "Malwarehunterr",
          "value": "https://exoduuss.online"
        },
        {
          "date": "2026-07-11 20:09:00",
          "tags": [
            "#phishing"
          ],
          "tweet": "https://x.com/Malwarehunterr/status/2076036227208454223",
          "type": "domain",
          "user": "Malwarehunterr",
          "value": "exoduuss.online"
        }
      ],
      "last_seen": "2026-07-11",
      "member_cluster_ids": [
        "tfc-a0263ae47042"
      ],
      "name": "Portuguese Exodus wallet phishing on exoduuss.online",
      "reporters": [
        "Malwarehunterr"
      ],
      "tags": [
        "#phishing"
      ],
      "targeted_brand": "Exodus",
      "types": {
        "domain": 1,
        "url": 3
      }
    }
  ],
  "generated_at": "2026-07-15T06:35:16Z",
  "stale": false,
  "stale_since": null,
  "version": 1,
  "window": "week"
}
