Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:unit42
tags: report:microsoft_mstic, report:unit42
tags: report:microsoft_mstic, report:unit42
tags: report:microsoft_mstic, report:unit42
tags: report:unit42
tags: report:microsoft_mstic
tags: report:unit42
tags: report:microsoft_mstic
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer's Evolved Tactics: Hidi
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals cre
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion. Executive Summary SentinelLABS has identified PCPJack, a credential
Deduped connector weight from graph context.