Threat Hunting
Roster of tracked hunts and campaigns — each anchored to a deterministic structural fingerprint, a YARA rule, an SMQL query, or a TLS certificate. Every scanned script and page is matched against this roster automatically.
Lookalike domains registered by the actor against real aerospace/defence/industrial brands on cheap TLDs (.fit .ink .lol .online .site). Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
A scanned page that CONTACTS the actor's infrastructure - the compromised-victim case, rather than someone scanning the C2 itself. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
Second half of the lookalike set; split only to stay under the SMQL 20-node cap. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
Generalizing tripwire, not an IoC: ShadowPad C2 servers in this campaign present SELF-SIGNED TLS certificates whose subject organization impersonates a major brand. This catches infrastructure we have no indicator for yet. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
A scan whose entry or final URL is on the actor's own C2 / payload-staging infrastructure, or that resolves to 79.133.56.90. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
The actor's Cloudflare Workers C2 endpoints, by TENANT. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.
The older, pre-rotation naming generation of the same AiTM authentication proxy: seven .digital domains built from generic corporate-sounding compounds, several with a hyphen inserted mid-word to dodge string matching (wisemediapa-ttern, xsyst-emsquantum, tec-hnoplatform2025). Arctic Wolf tied these back to the toolkit because they exposed the same /st_58200519/class_identifier.php fingerprinting path as the current 'ms'-labelled generation, despite sharing none of its naming conventions. All were reported defunct as of 2026-07-30.
Adversary-in-the-middle credential/session theft feeding payroll-diversion BEC, overlapping the cluster Microsoft tracks as Storm-2755. Chain: voicemail-themed mail with subject '[Organization] :ATTN: Review messages. Ref id: [random]' -> redirect laundered through Google Meet linkredirect, Google Ads /ddm/clk/ click trackers and an S3 intermediary -> an 'idp.'-labelled Apache redirector 302s to the AiTM proxy -> the proxy bounces the victim once to /st_58200519/class_identifier.php to fingerprint the browser and cache a country code in an rcfh_country cookie -> the proxy relays the genuine login.microsoftonline.com flow, rewriting Microsoft's endpoints into its own path, and captures the authorization code and ID token at its callback. Post-compromise the actor signs in from residential proxies on an eight-hour cadence keeping one SessionID across ASNs, enumerates payroll/HR/finance staff over Microsoft Graph with an axios/1.18.1 user agent, and reads mail on payroll, invoices, banking and benefits.
The seven Hostinger addresses that served the published redirectors and AiTM proxies. Redirectors: 187.124.129.44 (idp.keyreniao.com), 194.5.157.204 (idp.korminel.com), 145.223.100.123 (idp.kualabemo.com). Proxies: 153.92.1.166 (mslogin.milocaroline.com), 31.97.76.103 (msauth.monlinelogicaline.com), 177.7.56.248 (msonline.logicalineonline.com), 72.62.0.181 (office.ofreace.com and office.ofercarc.com, two proxies co-located).
Toolkit-agnostic detection for the structural artefact every Evilginx-style AiTM proxy leaves behind. A real AiTM relay does not clone the Microsoft sign-in page — it forwards the genuine flow and rewrites the URLs in the response, so Microsoft's own endpoints end up embedded in the PATH of the attacker's origin: https://<attacker>/https://login.microsoftonline.com/common/GetCredentialType, .../common/login, .../common/SAS/BeginAuth, .../common/SAS/EndAuth. Because the page is the real Microsoft page, brand-similarity, favicon, screenshot-hash and OCR checks all agree it looks legitimate — which is exactly why the rewriting artefact, rather than the page's appearance, is the thing to key on.
Forward-looking tripwire for the naming convention the Payroll Pirates AiTM proxies used, rather than for the burned domains themselves. Arctic Wolf observed the proxy tier consistently fronted by a Microsoft-themed leftmost label — mslogin., msonline., msauth. — on a freshly registered, otherwise meaningless apex, with the redirector tier one step back on an idp. label. This anchor catches the next rotation of that convention rather than the last one, which matters here because the published domains were all under ten days old when used and are all now suspended.
Shared phishing framework documented by urlscan 2026-08-04, deployed against deliberately LOW-PROFILE financial and identity brands rather than megabrands: Prove (identity verification), US Bank SinglePoint, AMINA E-Banking, Currency Cloud, Pleo, Slim CD, PayMongo, Aspire. Cloudflare-fronted, several hosts sharing a nameserver pair. Anchored on the kit-unique global __panelFrontsDevtoolsTrapStarted__ (a devtools-detection-trap guard) — a framework identifier coded into the kit logic, so it survives host rotation and minification, unlike IP/domain/hash IoCs.
DOUBLECUP delivery domains and CountLoader C2
CRM-brand phishing pages that inject DOUBLECUP
Rented ClickFix delivery service active since June 2026. Operators embed a fixed frontend snippet into their own lure pages; DOUBLECUP hosts the steganographic PNG, the session endpoints and the encryption keys. Stage 1 is a clipboard command that finds the cached PNG by exact file size and carves an embedded script out of it, so nothing is downloaded at execution time. Stage 2 derives its decryption key from the victim's public IP, meaning the payload will not decrypt in an offline sandbox. Observed payloads: CountLoader 4.5p (Windows PowerShell and macOS Mach-O) and DeviceManager, a Python RAT that resolves C2 from Ethereum/Polygon smart contracts (EtherHiding) and tunnels over DNS using microsoft.com as a decoy apex.
Microsoft-reported campaign (2026-07-31): Storm-2945 (Midnight Blizzard / SVR) manipulates hospitality captive-portal traffic to deliver fake browser/OS updates (CornFlake RAT, ChocoShell stealer) and steal Microsoft 365 credentials via device-code-flow and AiTM phishing. Anchors: campaign domains (incl. statistic-g.com, community DNS pivot), C2/AiTM IPs, and the FruitStone operator-panel title "CloudSync Console".
Cloned Meta/Facebook 'Page Appeal' credential-phishing kit deployed across a burst of throwaway Cloudflare Pages hosts with the naming scheme sp[1-6]ct-<word>-biz8-<word>-<word>.pages.dev (55+ distinct hosts, 2026-07-20 onward). Decoy variants render a fake Facebook homepage (title 'Facebook', real fbcdn assets) or are already Cloudflare-blocked ('Suspected Malware | Cloudflare' interstitial). Real captures carry the kit React bundle and are verdict-floored by the sibling content anchors (#158 content_sha256 0693dd46…, #153 AST). This SMQL row tracks the full host cohort INCLUDING interstitial/decoy captures no JS anchor can reach; smql tier is verdict-inert by design.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Facebook/Meta Business Page-Appeal credential-phishing kit — NEW bundle cohort (rotated JS hash) not covered by the main.ca88c9b6.js / main.c3146523.js sibling anchors. Same 3-way datacenter cloaking (redirect to real facebook.com / blank decoy / lure); the 0693dd46 segment is present across all capture variants — Facebook-decoy title (232 hosts), 'Meta for Business | Page Appeal' lure (77), Cloudflare Suspected-Phishing interstitial. Byte-identical kit bundle, zero legit titles.
YARA content anchor for the Poczta webmail credential-phishing kit (sibling of tlsh/smql hunt #146). Custom authForm harvesting login/pass to first-party /api/login then redirecting to the real brand. Live auto-collection via trg_hunt_sightings_record_yara.
Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.
Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.
Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.
Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.
Facebook/Meta 'Meta Verified — rewards for you' credential-phishing campaign on disposable hosting (safe-badge-*/bluetick-* pages.dev tenants). A distinct kit from the Meta Page-Appeal campaign, luring users with a fake paid-verification reward. Anchored on the residential-capture lure title.
Facebook/Meta 'Meta Verified — rewards for you' credential-phishing campaign on disposable hosting (safe-badge-*/bluetick-* pages.dev tenants). A distinct kit from the Meta Page-Appeal campaign, luring users with a fake paid-verification reward. Anchored on the residential-capture lure title.
Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.
Byte-identical Polish-webmail ("Poczta") credential-phishing kit deployed across many throwaway *.vercel.app gibberish subdomains. Anchor = exact page TLSH (fuzzy_hashes->>tlsh); same ssdeep + favicon mmh3 -75849909. Generalizes across the campaign (caught 6 hosts at creation vs the 2 in hunt #145). Rule engine rates these low (known FN class); AI flags HIGH_RISK credential phishing. NOTE: smql/tlsh anchor is backfill-only (no live trigger) — re-backfill to catch new hosts, or add a YARA rule for live auto-collection. Provenance: 2026-07-02 health-alert verdict audit.
5 credential-phishing hosts confirmed TP in the 2026-07-02 health-alert verdict audit: webmail/Poczta login clones on throwaway hosting (hfmthsga.vercel.app, pljnsad.vercel.app, mid-scarlet-rqxuosjc.edgeone.dev, pub-<hash>.r2.dev), plus meritking2542.com (MeritKing casino brand-abuse). All render a password form; actions self-POST / javascript: / blob-with-embedded-target-email. smql-tier anchor (does not drive verdicts).
High-risk phishing kits hosted on Cloudflare Workers (*.workers.dev) — disposable gibberish-subdomain hosts impersonating brands (Adobe / Microsoft / DocuSign / GitHub / banks). Includes form-less device-code / OAuth-consent (EvilToken-style) kits that lure victims into authorising a Microsoft device code on the real identity provider, plus credential-harvest clones. Anchored on the throwaway platform + the AI malice verdict, so it captures the family without per-site rules.
Microsoft Defender for O365 "Attack simulation training" — Microsoft-owned decoy domains serving Microsoft-branded login pages for phishing-awareness testing. Benign; tracked for inventory only. Whole fleet shares one TLS cert (issuer Microsoft Corporation, CN www.attemplate.com, 131 SANs). Forward-collected via the tls_certificates trigger + security-analyzer cert classifier.
Same fake-CAPTCHA flow as the PowerShell variant but the copied command is a non-PowerShell Windows LOLBin (msiexec /i <URL>, mshta, wmic, certutil, regsvr32, curl, iex, Invoke-Expression). First validated live on 00c29c34fd.nxcli.io from threatfox's IClickFix-tagged feed (scan 52b189eb / 2f465516 / f6c071f8). Markup-tolerant string matchers (<b>R</b> / <b>V</b> / <b>Enter</b>) catch kits whose instruction text is HTML-formatted.
Fake-CAPTCHA HTML page that copies a `powershell -enc <base64>` command to clipboard for the victim to paste into Win+R. Social-engineering pretext: "Verify you are human" / "Not a robot" / "Verification Steps" / "Press Windows Key + R / Ctrl + V / Enter". YARA rule reports 283 samples matched, >60% zero AV detection at time of analysis.
360-yandex-mail cohort js.js — 9 hosts.
Naver (Korean) cohort js.js — 8 hosts.
PDF/Adobe cohort js.js — 16 hosts.
Excel/Office365 cohort js.js — 13 hosts.
"update" generic cohort js.js — 38 hosts.
GoDaddy SSO cohort js.js — 100 hosts.
Universal kit-internal js1.js across the multi-brand pages.dev operator. 206 hosts.
Multi-brand credential-phishing kit deployed across 220+ *.pages.dev hosts under one operator. Brand cohorts: sso-godaddy (100h), update (39h), excel (16h), pdf/adobe/adobe-pdf (19h), 360-yandex-mail (9h), hostinger-mail (7h), nid-naver-mail (6h), zoho-mail, mailhostbox, nate-mail, dropbox, dhl, outlook-mail, office365-mail, we-tl, mail-one-update. Page title "Are you not a robot?" — fake-CAPTCHA pretext. jg.js is the shared handler script across all cohorts.
127-host gambling/casino app Vue PWA kit. ONE operator running random brand hostnames across .shop/.world/.store/.site/.website/.com TLDs. Page titles include "Tower Rush", "Chicken Road", "Lucky Casino", "Chicken Road 2", "BEAST GAMES: ICE FISHING", "Ice Fishing", "Revolut Slots" (Revolut bank brand impersonation in a slots scam). Path pattern /assets/<chunk>-v431.js + PWA service workers (/PwaWorker.js, /push/vapp/VappWorker.js).
Desktop layout module for the Indonesian gambling kit.
Login chunk of the Indonesian gambling kit (UC framework: uc_login.js).
23+ host Indonesian gambling SPA. Brand titles: "Bansos188", "SKYLAR88", "SOGOSLOT", "Dausbet", "CAGURBET" — all Indonesian gambling brand patterns with "Slot Online", "Slot Gacor", "Anti Rungkat", "Maxwin" terminology. Hosts: gasing777tidakindex.shop, apktiptoplock.sbs, babejd.icu, cagurbetkyu.icu, ndxskylar88.click. Extensive feature set: live chat, login, banners, announcements, page searching.
Newer cohort build (v442) of the same gambling Vue PWA kit. Same operator, kit upgraded.
PWA service worker (/push/vapp/VappWorker.js) of the gambling kit. The PWA architecture is distinctive — most kits don't register service workers; this one does (for push notifications / offline-mode fake-app feel).
Marketplace page chunk for the gambling kit — renders the fake-casino game catalogue.
Vendor bundle of the gambling Vue PWA kit (Vue runtime core, v431 cohort).
Browser-compatibility probe of the fake-Telegram kit.
Extension of the existing btbuu-fake-crypto-exchange operator family targeting a new brand: Bursa Malaysia (Malaysian stock exchange). 7-host cluster including bursamalaysia.space, served from the same /Public/Static/js/layer/layer.js path the btbuu operator uses on btbuu.com and trade-maxs.com. Same operator, new brand.
Webpack chunk 7283 of the fake-Telegram kit.
Webpack chunk 5193 of the fake-Telegram kit.
Massive 139-host Telegram brand-impersonation operation. ONE operator running random-letter hostnames across .icu/.sbs/.xyz/.top/.lat/.homes/.shop/.cn/.com/.org/.love/.life TLDs (dashan.icu, danvato.icu, eldravox.icu, claw111a.xyz, ai123h.xyz, bot789c.xyz, euhe-tg.com, htrx-tg.com, hujli.shop, telegarm-jp.org, yfhmg.love, fdshfgjd.{lat,homes}, …). Pages titled "Telegram" or "Secure Messenger". Operator-built Vue.js SPA. The "-tg" suffix in domain names and Japan/JP brand hints suggest Telegram-Japan credential-harvest focus.
Sister cohort of forum-tld-kit-b86d1a / forum-tld-kit-6ed2. 39 .forum hosts with uniform 8-char random hostnames (bgvwaihj.forum, bosmehqu.forum, …). Path pattern /js/app.<hash>.js — different chunk path than the earlier forum kits.
4-host operator: login-client-6i5.pages.dev, metasuite-business.com cohort. Numbered "login-client" Cloudflare Pages deployments paired with "metasuite-business" branding — textbook MS 365 / business-suite credential-harvest naming.
5-host operator running random-named .top hostnames anchored on htxnadf.top.
5-host Chinese WhatsApp brand impersonation: it-web-whatsapp.hl.cn, llg-whatsapp.com.cn, etc. Third-region sister of whatsapp-bd-771c (Bangladesh) and whatsapp-pk-96b1 (Pakistan) — same kit-as-a-service operator targeting more countries.
Sister cohort of random-letter-com-199c. 18 hosts with 10-letter random .com hostnames (2zrlupki.com, luckrfbyjg.com, …). Different bundler path (/js/app.<hash>.js) than the original 199c kit.
Sister cohort #2 of the .forum-TLD rotation family. 17 hosts with random 10-char hostnames (hvwvwvjwso.forum, nbilrwodrt.forum, …). Different build hash from f969.
42-host Chinese gambling operator running "Kaiyun" brand impersonation across cn-kaiyunapp.vip, zh-kaiyuntiyu.vip, danti4833.com subdomains with random hostname prefixes. Path pattern /js/app.<hash>.js. Kaiyun (开云) is a known Chinese gambling brand frequently impersonated; "kaiyun" naming + Chinese-numeric subdomains is a strong operator signature.
Sister cohort of multi-broker-impersonation-195a. 3 hosts: cmenyses.com (CME+NYSE), cmekeya.com (CME+Keya). Same operator running additional broker-name combinations.
1 host (mufolio-portal-x.com) impersonating a portfolio/asset-management brand. "Mufolio" is operator-coined.
1 host (minexusvip.com) — Minexus is a real crypto-mining brand. The "vip" suffix is operator-added.
1 host (trustucoin.com) impersonating Trust Wallet / Trust Coin brand.
1 host (mtsgoldr.com) impersonating MTS Gold (real precious-metals broker). The trailing "r" is typo-brand phishing.
1 host (www.whaleoex.com) impersonating Whale (real crypto-derivatives exchange / similar branding).
1 host (shoopeifyus.com) impersonating Shopify. Triple-vowel "shoopeify" + "us" suffix is a textbook brand-typo phishing pattern.
Companion build of the Tokyo Financial Exchange impersonation kit. Same host (tokyofinancialexchange.work) but second chunk hash — different cohort build of the same kit.
1 host so far (tokyofinancialexchange.work) impersonating Tokyo Financial Exchange (real Japanese exchange). Operator-built anchor — canonical_ast_hash trigger will catch any future cohort rebuilds.
2-host operator impersonating FP Markets (real Australian forex broker). fpmarts.com cohort.
2-host operator: zhesinc.com, zhesinr.com (variants of "zhesin" brand prefix). Surfaced via cosine pivot.
2-host operator impersonating OneKey (real crypto-wallet brand). onekey1.com cohort. Crypto wallets are high-value phishing targets — credential theft = drained wallets.
3-host random-domain sister cohort surfaced via cosine pivot. tuops.top cohort.
3-host operator impersonating MeridianLink (real US lending/banking tech company). meridianlinkgroup.com cohort.
3-host operator impersonating BitMart (real crypto exchange). Surfaced via cosine pivot on btbuu-fake-crypto-exchange anchors. Hosts include bitmartsweb.com.
Companion build of the zhesin-sister kit.
4-host numbered brand sister of the existing nyedfrt-top-3af6 kit. Hosts: nyadegd856.top, nyduehs598.top, nyduehs621.top.
Sister cohort of the existing random-letter-multitld-4ba7 kit. 6 hosts: klajlzmopkiak9kanz.{icu,qpon}, myj9qlcd05jj.qpon, nhgijgskjmriaks.icu, yjksnolkdjhikakr.{click,cyou}. Cosine-pivoted at sim=1.0000.
Sister cohort of the random-letter-multitld kit family. 3 hosts: hjuiwansdjjsdjks.cyou, nbjiwuqnskdkza.icu, nuhjsjjjskwjaksjs.icu. Cosine-pivoted from existing 9d69 and 4ba7 anchors.
Sister cohort of the existing click-tld-kit-a260ef. 2 hosts: manwasite.cc, mwxz10.cc. Cosine-pivoted at sim=1.0000.
5-host operator impersonating Pionex (real crypto trading bot platform): pioddnexqye.com, pionexadv.com, etc. The "pionex" substring is the operator's mimicry of the brand.
5-host operator impersonating BitMax (real crypto exchange now rebranded to AscendEX). bitmax123.com cohort.
4-host operator impersonating DDEX (decentralized exchange brand): ddex319.top, ddex329.top, plus raw IP 112.213.125.56:35971. The raw-IP serving is suspicious infrastructure.
4-host operator running "Golden Shield AI" investment-scam brand across multi-TLD: goldenshieldai.homes, goldenshieldai.lat, goldenshieldai.online. Same brand, throwaway TLDs.
6-host numbered-brand series: crimsonagility[22|33|55|…].com.
5-host Brazilian Portuguese gambling sister of pt-brazil-gambling-80be. Hosts: 7v-elefante.com, 7v-leao.vip ("elephant", "lion"). Same operator, 7v-prefix cohort.
4-host numbered brand series: slh005.com, slh006.com, …, slhofworld.vip.
4-host same-prefix multi-TLD operator: aazzkf.cc, aazzkf.com, aazzkf.org, aazz-kf.com. Sister pattern to aaoopg-eejjkf-02d6.
4-host numbered brand series: ldwebsync[32|73|78|…].top.
4-host same-prefix multi-TLD operator: dhptgo.cc, dhptgo.sbs, dhptgo.top.
4-host wildcard-DNS abuse sister of nested-subdomain-9003, serving on non-standard port 3443: tyyx.dakowe.1bdbr3.com:3443, tyyx.ooios.mgqlfa.com:3443.
6-host sister cohort of the random-letter-multitld kit family. Random keyboard-mash hostnames on .icu/.shop.
Sister of the existing `cloud-storage-abuse-72ea` kit. 5 hosts on Azure Static Web Apps: abw219, hk3091, london25, nsd90317, xdl719 — geographic-cohort naming (HK=Hong Kong, london, etc.) suggests targeted-region phishing.
Sister of the existing `nested-subdomain-9003` kit using wildcard-DNS abuse with deeply-nested random subdomains: lycl.cjilea.b7ryzkx.com, lypz.j9ado3.ikxoxfjp.com, uicl.oiusnx0w0.c7m26j3n2k.com:3443 (also serving on non-standard port 3443).
Sister cohort of the existing `cimamedia-speedride-682f` kit: cimamedia0i.com, cimamedia99.com, cimamediaia.com, speedride0i.com, speedridecc.com, speedridezz.com. Same operator, second build hash.
4-host operator running Huawei brand impersonation: huaw3.cn, huaw3.com plus wzg56.cc, wzg71.cc sister hosts. "huaw" is the operator-chosen prefix mimicking "huawei".
Pakistan-targeting WhatsApp brand impersonation: pak2whatsapp.com, pak3whatsapp.com, pakwhatsapp.com, pk2wapp.com, pk3wagetmoney.com, pk7wagetmoney.com. Sister of the existing `whatsapp-bd-771c` Bangladesh cohort — same kit-as-a-service operator targeting different countries.
6-host operator: comex-ex.com, comex-glob.com, comex-next.com, comex-next-desk.com, ortexlabs.com, ortexportal.com. COMEX + Ortex (real institutional trading-research firm) impersonation. Sister of the d7a2 cluster.
6-host operator running MULTIPLE major financial-brand impersonations from a single template: cmeamex.com, cmeamexs.com, cmenyse.com (CME+AMEX, CME+NYSE), schwabvs.com (Charles Schwab), tradesoksca.com, tradesokscs.com. Single SPA deployed under each broker's name.
6-host operator hosting fake trading platform on Azure Static Web Apps + .top with port: comex309.z1.web.core.windows.net + secondary, tada1912.z23.web.core.windows.net + tada93179, web6699.313675.top:39395. "COMEX" = Commodity Exchange impersonation; "tada" branding signals throwaway cohorts.
Companion pages/_app build for the Indonesian gambling Next.js SPA.
Next.js SPA deployed across 37+ Indonesian-language online gambling sites. Brand+number naming (ammo88jaya, apek88-apk2, banteng328bersama, banteng328goyang.site, bos56.xyz, dragon969resmi.site, elang55b.com, eth77original.site, …). Page titles in Bahasa Indonesia: "Situs Slot Online Gampang Menang", "Login Situs Slot 4d Mahjong yang Pasti Bayar 2025", "RTP Gacor Hari Ini" (slot/mahjong/RTP terminology).
Brand-impersonation phishing kit targeting Telcel (Mexico's dominant mobile carrier). 23 hosts on .top/.vip with mx-prefixed names (mxstelcec.top, mxtecelah.top, mxtelelsuy.top, mxtelesvip.vip, …). URL path /apps/MX_PT_06/assets/index-*.js — the "MX_PT_06" naming matches the Tigo SV kit's "SV_PT_01", strong evidence of one operator running localized LATAM carrier kits.
19-host operator running numbered Cloudflare Pages deployments: status-account-{8,10,13,14,16-21,43,53,70,71,75,122,123,124,125}.pages.dev. Hostnames are textbook account-suspended phishing pattern (Microsoft/Google "your account has been suspended" credential harvest).
Companion build of the Tigo SV kit — same 19 hosts, second anchor chunk.
Brand-impersonation phishing kit targeting Tigo El Salvador (major LATAM telecom). 19 hosts on .cc/.help/.click/.art/.sbs/.top with tigo-prefixed names (sv-tigo.cc, tigoboss.help, tigosrwvp.help, tigovseop.click, tigovspom.help, …). Page title: "La primera Red 5G de El Salvador | Tigo El Salvador" (direct quote from real Tigo SV marketing). URL path /apps/SV_PT_01/assets/index-*.js — sister to the Telcel MX MX_PT_06 kit, same operator.
Companion build of the Telcel MX kit — same 23 hosts, second anchor chunk under the same /apps/MX_PT_06/ path.
Brand-impersonation phishing kit targeting AMP Futures (US futures broker, ampfutures.com). Deployed across 62 random-letter .xyz hostnames matching pattern [a-z][0-9][a-z][0-9][a-z].xyz (a2q6w.xyz, a4k7n.xyz, b2k9t.xyz, …). All 62 hosts serve the page title "AMP Futures"; all were graded Low Risk or Medium Risk by the verdict layer.
7-host operator using DEEPLY-NESTED random subdomains (4+ labels): cccys.zokide.6x1qko1.com, ccyy.xmsck.jluoo8h.com, cuiu.yw9u2e.esh536.com, cyppt.apxpiff.ztlcsqwf.com, cyqqt.x01jjex.ay9fc.com, cyttp.cokpa.lyaj69w.com, hue.oaiweu.6o99od.com. Wildcard-DNS abuse pattern.
7-host operator: aeychdent.com, caichdfdt.com, daochderu.com, ejgchdcbt.com, fjhchdlep.com, gajchdvbt.com, hajchdkru.com. Uniform `chd` substring at positions 4-6 in random-alpha .com hostnames.
7-host operator impersonating WhatsApp: bd1whatsapp.com, bd2wapp.com, bd2whatsapp.com, bd3wapp.com, bd3whatsapp.com, bdwhatsapp.com, pk6wagetmoney.com. The "bd"/"pk" prefixes suggest Bangladesh/Pakistan targeting.
7-host operator running long random alphanumeric .vip hostnames: cxwf0r2o9t9w1o9w7.vip, hiut9h0v4l2d7a7v0.vip, ijne8g2c1f5q0f9l5.vip, kmkf1e3z8z8s5q2k0.vip, vbja9y9n8u0w5s2b6.vip, vbjk2x2t9z3m6g7s2.vip, vcve2mcixbkl3kfd32fg.vip.
7-host operator on .cn TLD with letter+digit random pattern: j3h1k9.cn, m9u6y0.cn, n4c6v5.cn, p4i6o3.cn, q4x9v6.cn, q7e2r6.cn, q8t4y7.cn.
7-host operator: xtcuf.com, xtdli.com, xtfue.com, xtjvn.com, xtlwh.com, xtnmc.com, xtpxd.com. Uniform xt[CCC].com pattern.
7-host mix of Cloudflare Pages + .top TLDs: elmapp.pages.dev, ggzszfl.top, ghtsmr.top, hptsmn.top, mgtred.top, qnqb61.top, sizeg.top.
7-host operator: 266229.com, 500698.com, 500798.com, klyl6.net, www.uuyl.net, www.uuyl.xyz, xpj2487.com. Chinese-style numeric gambling/lottery brands.
7-host operator abusing free cloud storage to host the SPA: 5 Azure Static Web Apps (*.zNN.web.core.windows.net) + Tencent Cloud Object Storage (*.pichk.myqcloud.com). The cloud-vendor domains lend false legitimacy.
8-host operator running Portuguese/Brazilian-language gambling brands: 54rr.win, 91-earring-pg.vip, muito-777.win ("777" + Portuguese for "a lot"), okokflash.mom, voy-brow-pg.vip, we-operapg.mom ("opera-pg"), wgbetkk.win, wg-relogio.win ("relogio" = watch).
8-host operator running andes-prefixed brands: andekhu5, andesapply24, andesapply8k, andeshsk11, andesiodshuqian22, andesjhsh2, andessdf3, andsskli8 on .com.
9-host operator running aaoopg.{app,cc,net,one,vip} + eejjkf.{app,com,net,one}. Same prefix across multiple TLDs — characteristic of bulk-domain phishing.
9-host operator running Portuguese-language brand impersonation: bbq-kf.com, bbqkf.com, bbqkfpg.com, carros-ty.com, carrosty.com, okcarros.com, ty-carros.com, tycarros.com, vip-carros.com (BBQ + cars).
10-host numbered series: hanhan12.com + hhmh1[386|387|388|389|390|397|398|399|400].com.
10-host numbered series operator: 532810.top, nyadegd[326|517].top, nydash812.com, nyedfrt[017|195|367|591|728|937].top.
10-host operator running auto-generated word-pair brand names: deeply-marketsearch.com, deeps-datastudy.com, finely-stylecraft.com, quicks-cdbuild.com on .com + findraregive/getfastrun/grabfreshsell/keepgoodsave/makesweetbake/picksmartubuy on .shop. Lure: looks like quick-build / market-research / save-money brand.
11-host operator running 10-letter random .com hostnames (cjnwqvprty.com, dkpvtrmzla.com, fgrtqpxlme.com, …).
12-host operator running acce[afae|afaf|dew|dzz|eann|haiu|kioa|lnn|mfg|mmrk|qrf|rmk].com sister hosts. Uniform `acce` prefix, two-three random suffix characters.
Vue.js webpack SPA across 13 random-letter hostnames on .shop/.sbs/.cyou/.icu TLDs.
15-host operator running two parallel brand prefixes: cimamedia[88|92|9i|aa|io|ip|vi|vip|vvip].com and speedride[88|92|9i|ia|io|vi].com.
Vue.js webpack SPA across 15 random-letter hostnames on .icu/.click/.cyou/.cfd/.shop/.sbs TLDs.
Vue.js webpack SPA across 15 random-letter hostnames on .icu/.shop/.cyou/.sbs TLDs.
Operator across 16 hosts impersonating Meituan (Chinese super-app): qiqimeituan.xyz, shengmeituan.xyz, plus generic Chinese-themed names (songsong123.xyz, tangtang123.asia, zhanxupeng6.asia) and qazwsxNNN.asia placeholders.
Vue.js webpack SPA across 16 random-letter hostnames on .cyou/.icu/.shop/.sbs TLDs.
Vue.js webpack SPA across 17 .forum TLD hosts (bqetfpng.forum, bvgapqrm.forum, djtzmlwl.forum, …). Distinct operator from the migration-080 b86d1a cluster.
Operator running multi-brand crypto-wallet impersonation across 17 hosts: rwusdtc[a-y].com (USDT impersonation), axexclub/axexhub on .com+.top, safeger/safegnr/safetar.com, plus dbecrede.com, exintir.com. Fake-wallet credential harvesting.
Vue.js webpack SPA across 17 hostnames mostly on .click TLD (bpqsfyum.click, deddrvta.click, hxrygdhl.click, …) plus shakti.top and tea01.bahfn.cn. Different operator from a260ef.
Operator running a numbered series of `yjdm[NNNN].com` + `yjdm[NNN].club` sister hosts (yjdm1371-1395.com, yjdm332-355.club — 18 hosts total). Likely Chinese gambling/lottery brand.
Vue.js webpack SPA across 21 random-letter hostnames on .icu/.cyou/.qpon/.shop/.click/.sbs TLDs. Sister cohort of the kit-as-a-service template.
Vue.js webpack SPA across 26 random-letter hostnames on .cyou/.shop/.qpon/.click/.icu TLDs (huwhnkjahksjwnak.cyou, klajlkza12jasdjk131.click, mblgfkltkllpuoprfltp.icu, …). Same kit-as-a-service template as the migration-080 random-domain kits.
Vue.js webpack SPA across 16 random-letter hostnames on .shop/.cyou/.icu/.sbs TLDs.
Vue.js webpack SPA deployed across 63 random-letter hostnames on .icu/.sbs/.cyou/.shop TLDs. Hostnames are keyboard-mash strings (e.g. baiiwerogkasdfg.sbs, bbqupospdkgkaj.shop, bjioqjksdjkskzx.cyou). Every host in the cluster was graded "Low Risk" or "Medium Risk" by the verdict layer.
Vue.js webpack SPA deployed across 31 hostnames ALL on the .click TLD with 8-character random hostnames (aicjgkjk.click, cbcsljlc.click, pshhttokse.click, qhzelnxa.click, …). Uniform TLD + hostname pattern is a strong operator signal.
Vue.js webpack SPA deployed across 32 random-letter hostnames on .sbs/.qpon/.cyou/.click/.icu TLDs (iewyrgajdghfvdhdjs.sbs, jkahskdnzl6kajhmza.qpon, …). Includes the .qpon TLD which is rare and a strong scam-infrastructure marker.
Vue.js webpack SPA deployed across 33 random-letter hostnames on .cyou/.shop/.sbs/.icu TLDs (oodjdfuigewjkfdssf.cyou, bcmnrjwyrishfdjdgf.shop, dsfjngfwisdjfoisdjs.shop, …). TLSH body identical to the 0e990c cluster — likely the same template, different operator cohort.
Vue.js webpack SPA deployed across 40 hostnames ALL on the .forum TLD with 8-character random hostnames (cmkpxlpv.forum, lhivtxfx.forum, ruxkxjyybs.forum, …). The uniformity of TLD + filename-length is a strong operator signal.
Online-gambling/betting kit deployed across 43 brand-prefixed hostnames on .win/.mom/.vip TLDs. Includes 1xbet-style impersonation (1x-clz.vip, 1x-gzm.vip, 1x-xl.vip) and generic bet/win brands (0227bet.win, 107win.mom, 208win2.vip). All hosts graded "Low Risk" or "Medium Risk".
Cloudflare-Pages-hosted Vue.js fake-investment kit. ONE operator running brand cohorts (vindax/mint/digtal/pimco impersonation) on *.pages.dev, all sharing the same Vue.js webpack skeleton with cohort-specific branding strings. This anchor catches the vindax-1xy / vindax-9io / mint-5st cohort.
mint-34z.pages.dev cohort build of the Pages.dev Vue investment-scam kit.
PIMCO-impersonation cohort of the Pages.dev Vue investment-scam kit. PIMCO (Pacific Investment Management Company) is a major real-world asset manager — this kit lures users into a fake investment platform under that brand.
mint-b1v.pages.dev cohort build of the Pages.dev Vue investment-scam kit.
digtal-du.pages.dev cohort build of the Pages.dev Vue investment-scam kit. "Digital" finance brand impersonation (misspelt).
mint-bnq.pages.dev cohort build of the Pages.dev Vue investment-scam kit.
Index page chunk for the Pages.dev Vue investment-scam kit (vindax cohort build). Shows the fake exchange order book.
Entry chunk for the Pages.dev Vue investment-scam kit (vindax cohort build).
Brand-impersonation phishing kit targeting Medtronic (the medical-device manufacturer). Vue.js SPA deployed across 4 sister hosts (medtronicwmn.com, medtronicwrr.cc, medtronicwrz.com, medtronicwtt.cc) under /static/js/ paths. Chunks reveal a fake-login + fake-account-detail flow (pages-login, pages-welcome, pages-account-account-detail, pages-Detail, pages-Particulars).
Webpack-bundled SPA deployed across an 8-host rotation that all share the `teje` prefix on cheap/suspicious TLDs (tejehqnfih.work, tejehqzjxt.club, tejeiviusk.asia, tejeiwdeow.cloud, tejeiycpyh.asia, tejeizzifa.wiki, …). Most graded Malicious by the verdict layer, some Low Risk — the roster catches the misses.
Vendor bundle for the Medtronic brand-impersonation kit. Vue+ElementUI+etc. compiled by the operator's specific webpack build.
Welcome-page chunk for the Medtronic brand-impersonation kit. Small, highly diagnostic.
Single shared main.v2.js deployed across 17 throwaway domains on cheap/suspicious TLDs (.icu, .sbs, .cfd, .cyou, .shop, .wiki, .one, .asia, .club). Includes telegran.one — Telegram brand impersonation. The 17 hosts have inconsistent verdicts (Low Risk → Malicious); the roster catches all of them via a single fingerprint.
WebSocket feed client used by the btbuu fake crypto-exchange UI to render fake real-time price ticks.
Fake crypto-derivatives exchange kit. Operator-deployed K-line / Contract / Trade UI across btbuu.com, wbitx.cfd, trade-maxs.com, evergreen-capital.org. Path pattern /Public/Static/js/*, page pattern /Contract/index, /Trade/index?type=buy&symbol=*. Earlier sweep had bounced on the kit's pako.min.js (real zlib library) — these are the operator-specific files.
Numeric webpack chunk for the teje-rotating-domain kit.
Browser-compatibility probe used by the teje-rotating-domain kit. Tiny but unique.
Login page chunk for the mailNNN.com fake-credits Vue SPA. Renders the credential-harvesting form.
Home/dashboard chunk showing fabricated account balances after login.
Vue.js single-page application deployed across mailNNN.com sister hosts (mail238/279/799 known) as a fake credits / fake banking platform. Users register, "recharge" (deposit), see fabricated balances, and cannot actually withdraw. Chunk names: pages-login-login, pages-recharge-index, pages-withdrawal-index, pages-record-index, pages-user-address-index. index.js is the SPA's entry chunk.
Long-poll companion to Comet.js — secondary WebSocket channel used by the J365 illegal-gambling platform.
Chinese-language illegal online-gambling platform served from a rotating set of brand-prefixed landing domains (j365*.xyz, lvs*.vip, hgty*.vip, hg*.vip, usdbetvip*.biz, xpj*.com — including punycoded variants) backed by a small set of operator CDN hosts on pham.xin and yqdkrj.com under the path /ftl/commonPage/. Offers fish-shooter, casino, sports, chess games. gui-base.js is the kit's shared UI framework.
Custom WebSocket C2/heartbeat code (/websocket/Comet.js) used by the J365 illegal-gambling platform. Operator-specific real-time channel for bet placement, balance updates, and admin control.
Okta-themed brand-impersonation phishing kit. Landing URL has the ?passtoken=&redirect=/ signature; backend.php polls for MFA-bypass state; pingServer heartbeat; Telegram-channel credential exfiltration. Attributed to the ShinyHunters cluster.