Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:microsoft_mstic, report:secureworks
tags: report:checkpoint_research, report:microsoft_mstic, report:secureworks
tags: report:microsoft_mstic
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:secureworks
tags: report:checkpoint_research
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI
deno-case-studies Attack TTPs combine fileless execution, wide LOLBin use Categories: Threat Research Abuse of alternative runtime environments Deno-tes defender headaches | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get help now Sign in Sophos C
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. Thi
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on compa
Deduped connector weight from graph context.