Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:mandiant, report:talos, report:unit42
tags: report:mandiant, report:talos, report:unit42
tags: report:mandiant, report:talos, report:unit42
tags: report:talos, report:unit42
tags: report:unit42
tags: report:talos
tags: report:talos
tags: report:talos
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Late
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks i
GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Introduction In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to acceler
Deduped connector weight from graph context.