Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:microsoft_mstic, report:talos, report:the_hacker_news, report:trend_micro
tags: report:checkpoint_research, report:microsoft_mstic, report:the_hacker_news, report:trend_micro
tags: report:talos, report:the_hacker_news, report:trend_micro
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:talos
tags: report:checkpoint_research, report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, be
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined
ACR Stealer: Two observed intrusion chains amid increased threat activity From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browse
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achie
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. an
Deduped connector weight from graph context.