Known malicious kitcriticalphishing
RCFH AiTM toolkit — .digital proxy cohort (Payroll Pirates / Storm-2755)
family: rcfh-aitm-storm2755
The older, pre-rotation naming generation of the same AiTM authentication proxy: seven .digital domains built from generic corporate-sounding compounds, several with a hyphen inserted mid-word to dodge string matching (wisemediapa-ttern, xsyst-emsquantum, tec-hnoplatform2025). Arctic Wolf tied these back to the toolkit because they exposed the same /st_58200519/class_identifier.php fingerprinting path as the current 'ms'-labelled generation, despite sharing none of its naming conventions. All were reported defunct as of 2026-07-30.
Anchors
YARA ruleDetect_RCFH_AiTM_Geofence_Redirect
SMQL queryrun
domain:*wisemediapa-ttern.digital OR domain:*sky2025forge.digital OR domain:*skyprimeworks.digital OR domain:*1systemsevolve.digital OR domain:*xsyst-emsquantum.digital OR domain:*tec-hnoplatform2025.digital OR domain:*evolveelevateunion.digitalProvenance
Added: 2026-08-10 20:57
Split from the sibling domains row purely to stay under the 20-node cap, and kept separate because the attribution is different in kind: these six of seven are ALSO in trails.csv, but labelled 'interlock'/'interlock-1 (malware)' rather than as BEC infrastructure, so a sighting here is worth reading as a possible overlap between this AiTM toolkit and Interlock-associated infrastructure rather than as a clean Storm-2755 hit. The seventh, wisemediapa-ttern.digital, is in MISP event 20948 only. Paired with the geofencing YARA rule rather than the fingerprint-path one so the two rows produce distinguishable sightings. 7 filter nodes.
Sightings (0)
No sightings recorded yet.