LIVE
MembersA 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself OnwardMembersRussian-Registered AS213010 Has Hosted C2 Since 2019MembersRecycled Sectigo Certificate Links Loader and Banking-Trojan PayloadMembers5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper EspionageMembersTwo Shell Firms, One DigiCert Root: Adware's Signing Trick RepeatsMembersOne 2009 Compile Job Is the Only Real Link in 'Klovbot' ClusterMembersFake Adobe Audition Patch Fans Out Into Two Trojan FamiliesPublicA Two-Tier Certificate Strategy Behind a Freshly Rotating C2 ClusterMembersCracked-Software Lure Network Runs on Expired EV Cert, Shared HostingPublicEmotet 'C2 Servers' Entry Bundles 3 Unrelated IPs, No Shared FingerprintPublicFake Skype Installer Ran a Full Espionage Chain for a DecadeMembersA Hidden Macrosheet Reopens Emotet's Front DoorMembersA 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself OnwardMembersRussian-Registered AS213010 Has Hosted C2 Since 2019MembersRecycled Sectigo Certificate Links Loader and Banking-Trojan PayloadMembers5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper EspionageMembersTwo Shell Firms, One DigiCert Root: Adware's Signing Trick RepeatsMembersOne 2009 Compile Job Is the Only Real Link in 'Klovbot' ClusterMembersFake Adobe Audition Patch Fans Out Into Two Trojan FamiliesPublicA Two-Tier Certificate Strategy Behind a Freshly Rotating C2 ClusterMembersCracked-Software Lure Network Runs on Expired EV Cert, Shared HostingPublicEmotet 'C2 Servers' Entry Bundles 3 Unrelated IPs, No Shared FingerprintPublicFake Skype Installer Ran a Full Espionage Chain for a DecadeMembersA Hidden Macrosheet Reopens Emotet's Front Door
FILEMembersSep 23, 2026

A 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself Onward

A record attributed to 'Lazarus Group' turns out to rest on a single verified artifact: a 2019-vintage MyDoom worm that checks for debuggers, stalls execution, and re-mails itself via SMTP while disguised as lsass.exe. The other 40 hashes, seven IPs, and eight domains attached to the record carry no comparable telemetry.

ActorsLazarus Group · Hastati GroupRegionsCH CN JO USIOC56
APTMembers

Russian-Registered AS213010 Has Hosted C2 Since 2019

The most durable artifact in this record isn't a binary or a certificate — it's a network. Autonomous System 213010, registered to an entity RIPE lists as "Gening Nikita Dmitrievich," has hosted at least two IP addresses that anchor domains registered three years apart: 87.251.75.204, which carries a domain first registered on 2023-09-20 (poolfreshstep.com), and 80.66.76.210, which is fronting a domain that was only 14 days old when this record closed (bunnysecurityrelay.com, created…

#VoidArachne#SilverFox#CobaltStrike#AS213010#NICENIC
Sep 23, 2026Void Arachne · Silver FoxIOC 26
FILEMembers

Recycled Sectigo Certificate Links Loader and Banking-Trojan Payload

The same revoked leaf certificate — serial 00 8E 3E 9A 2F E7 3C 91 98 5B 4F 90 D5 95 77 CD 6C, issued under the name MASTER LIM LTD and chained through COMODO RSA Code Signing CA up to Sectigo (formerly Comodo CA) — is stamped on two files that sit at opposite ends of a delivery chain: an NSIS self-extracting installer and the banking-trojan DLL it ultimately drops.

#TA505#LDPinchbanker#Sectigocodesigningabuse#NSISinstaller#VBScriptstager
Sep 22, 2026TA505 · Hive0065IOC 11MITRE 37
FILEMembers

5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper Espionage

A stager built to pass as nothing more than a routine Windows update file is barely large enough to hold its own icon — five kilobytes of packed .NET code, unsigned, dropped straight into C:\Windows\Temp\update.exe. Despite the size, 55 of 76 antivirus engines flag it, and the record ties the sample (4f237b5a…) to the espionage-focused Tomiris and YoroTrooper clusters.

#Tomiris#YoroTrooper#AgentTesla#.NETstager#anti-debuggingevasion
Sep 22, 2026Tomiris · YoroTrooperIOC 3MITRE 12
Latest9stories
Current Coverage
Articles published
608
IOCs analysed
20,676
Threat Actor
451
MITRE techniques
209
Targeted regions
157
Targeted industries
32