IOC Feeds
Indicators of Compromise
Structured feeds ready for ingestion into your SIEM, EDR, or CTI platform. Licensed under CC BY-NC 4.0.
Recent
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign — IOC Feed
AdaptixC2 Open Directory Exposure (45.130.148.125) — IOC Feed
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13) — IOC Feed
ShinyHunters Data Leak Site (91.215.85.22) — IOC Feed
All Feeds
OpenStrike Expanded Toolkit (172.105.0.126) — IOC Feed
Apr 2026
OpenStrike Beacon Toolkit (172.105.0.126) — IOC Feed
Apr 2026
Shadow RAT & XWorm Open Directory Campaign — IOC Feed
Apr 2026
Open Directory at 193.56.255.154 — XiebroC2 and Covenant C2 IOC Feed
Apr 2026
ZeroTrace Multi-Family MaaS Operation — IOC Feed
Mar 2026
Sliver C2 / ScareCrow Loader Open Directory — IOC Feed
Mar 2026
Webserver Compromise Kit 91.236.230.250 — IOC Feed
Feb 2026
Remcos RAT OpenDirectory Campaign — IOC Feed
Feb 2026
NsMiner Cryptojacker — IOC Feed
Feb 2026
Arsenal-237 New Files: full_test_enc.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: new_enc.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: dec_fixed.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: enc_c2.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: chromelevator.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: nethost.dll — IOC Feed
Jan 2026
Arsenal-237 New Files: rootkit.dll — IOC Feed
Jan 2026
Arsenal-237 New Files: BdApiUtil64.sys — IOC Feed
Jan 2026
Arsenal-237 New Files: lpe.exe — IOC Feed
Jan 2026
Arsenal-237 New Files: killer_crowdstrike.dll — IOC Feed
Jan 2026
Arsenal-237 New Files: killer.dll — IOC Feed
Jan 2026
Arsenal-237: enc/dec Ransomware Family — IOC Feed
Jan 2026
Arsenal-237: uac_test.exe — IOC Feed
Jan 2026
Arsenal-237: FleetAgentFUD.exe — IOC Feed
Jan 2026
Arsenal-237: FleetAgentAdvanced.exe — IOC Feed
Jan 2026
Arsenal-237: agent_xworm_v2.exe — IOC Feed
Jan 2026
Arsenal-237: agent_xworm.exe — IOC Feed
Jan 2026
Arsenal-237: agent.exe (PoetRAT) — IOC Feed
Jan 2026
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm — IOC Feed
Dec 2025
PULSAR RAT (server.exe) — IOC Feed
Dec 2025
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou — IOC Feed
Nov 2025
Houselet.exe — IOC Feed
Nov 2025
AdvancedRouterScanner — IOC Feed
Oct 2025
From Webshells to The Cloud — IOC Feed
Oct 2025
QuasarRAT + XWorm + PowerShell Loader — IOC Feed
Oct 2025