Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:eset, report:microsoft_mstic, report:talos, report:the_hacker_news, report:trend_micro
tags: report:checkpoint_research, report:microsoft_mstic, report:the_hacker_news, report:trend_micro
tags: report:talos, report:the_hacker_news, report:trend_micro
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:talos
tags: report:checkpoint_research, report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operati
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Mis
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensi
ACR Stealer: Two observed intrusion chains amid increased threat activity From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browse
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achie
Deduped connector weight from graph context.