Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:secureworks, report:talos, report:the_hacker_news, report:trend_micro
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news, report:trend_micro
tags: report:talos, report:the_hacker_news, report:trend_micro
tags: report:microsoft_mstic, report:talos, report:trend_micro
tags: report:secureworks, report:the_hacker_news
tags: report:microsoft_mstic, report:trend_micro
tags: report:the_hacker_news
tags: report:microsoft_mstic
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
ClickFix campaign abuses Deno runtime for infostealer delivery Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer Categories: Threat Research Tags: clickfix, Deno, WordPress ClickFix campaign abuses Deno runtime for infostealer deliv
ACR Stealer: Two observed intrusion chains amid increased threat activity From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browse
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. an
AI brands as bait: How threat actors are using the AI hype in social engineering As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat act
AutoJack: How a single page can RCE the host running your AI agent AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authenticatio
Deduped connector weight from graph context.