IOC Feeds
Indicators of Compromise
Structured feeds ready for ingestion into your SIEM, EDR, or CTI platform. Licensed under CC BY-NC 4.0.
No items match that filter.
Multi-Actor AI-Agent Framework Abuse (8 Operators) — IOC Feed
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host — IOC Feed
Korean Claude Code + OpenClaw Operator (221.150.15.104) — IOC Feed
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220) — IOC Feed
GHOST Cryptojacker Kit — Vova75Rus Supply Chain (77.110.96.200) — IOC Feed
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158) — IOC Feed
Russian Gemini CLI Credential Mill (213.165.51.115) — IOC Feed
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49) — IOC Feed
Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens) — IOC Feed
BellaMain Turkish PhaaS Panel (79.137.192.3) — IOC Feed
Multi-Cluster Open Directory 79.137.192.3 (Rhadamanthys MaaS / BellaMain / Inkognito) — IOC Feed
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign — IOC Feed
AdaptixC2 Open Directory Exposure (45.130.148.125) — IOC Feed
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13) — IOC Feed
ShinyHunters Data Leak Site (91.215.85.22) — IOC Feed
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08) — IOC Feed
OpenStrike Beacon Toolkit (172.105.0.126) — IOC Feed
Shadow RAT & XWorm Open Directory Campaign — IOC Feed
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2 — IOC Feed
ZeroTrace Multi-Family MaaS Operation (74.0.42.25) — IOC Feed
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220) — IOC Feed
Webserver Compromise Kit (91.236.230.250) — IOC Feed
Remcos RAT OpenDirectory Campaign — IOC Feed
NsMiner: Multi-Stage Cryptojacking Operation — IOC Feed
Arsenal-237: agent.exe (PoetRAT) — IOC Feed
Arsenal-237: agent_xworm.exe (XWorm RAT v6) — IOC Feed
Arsenal-237: agent_xworm_v2.exe (XWorm RAT v2.4.0) — IOC Feed
Arsenal-237: FleetAgentAdvanced.exe — IOC Feed
Arsenal-237: FleetAgentFUD.exe — IOC Feed
Arsenal-237: uac_test.exe — IOC Feed
Arsenal-237: enc/dec Ransomware Family — IOC Feed
Arsenal-237 New Files: killer.dll (BYOVD Process Termination) — IOC Feed
Arsenal-237 New Files: killer_crowdstrike.dll (CrowdStrike-Specific Termination) — IOC Feed
Arsenal-237 New Files: lpe.exe (Privilege Escalation) — IOC Feed
Arsenal-237 New Files: BdApiUtil64.sys (Vulnerable Baidu Driver) — IOC Feed
Arsenal-237 New Files: rootkit.dll (Kernel-Mode Rootkit) — IOC Feed
Arsenal-237 New Files: nethost.dll (DLL Hijacking Persistence) — IOC Feed
Arsenal-237 New Files: chromelevator.exe (Browser Credential Theft) — IOC Feed
Arsenal-237 New Files: enc_c2.exe (Rust Ransomware with Tor C2) — IOC Feed
Arsenal-237 New Files: dec_fixed.exe (Ransomware Decryptor) — IOC Feed
Arsenal-237 New Files: new_enc.exe (Human-Operated Rust Ransomware) — IOC Feed
Arsenal-237 New Files: full_test_enc.exe (Advanced Rust Ransomware) — IOC Feed
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm — IOC Feed
PULSAR RAT (server.exe) — Technical Analysis & Business Risk Assessment — IOC Feed
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou — IOC Feed
Houselet.exe — The Go-Based Loader Masquerading as PlayStation Remote Play — IOC Feed
AdvancedRouterScanner — IOC Feed
From Webshells to The Cloud — IOC Feed
Quasar + XWorm + PowerShell — IOC Feed