STIX Bundles
STIX 2.1 Threat Intelligence
Per-campaign STIX 2.1 bundles — import into OpenCTI, MISP, or any STIX-aware platform. Licensed under CC BY-NC 4.0.
⬇ Download all campaigns (.zip)
No items match that filter.
Multi-Actor AI-Agent Framework Abuse (8 Operators) — STIX Bundle
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host — STIX Bundle
Korean Claude Code + OpenClaw Operator (221.150.15.104) — STIX Bundle
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220) — STIX Bundle
GHOST Cryptojacker Kit — Vova75Rus Supply Chain (77.110.96.200) — STIX Bundle
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158) — STIX Bundle
Russian Gemini CLI Credential Mill (213.165.51.115) — STIX Bundle
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49) — STIX Bundle
Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens) — STIX Bundle
BellaMain Turkish PhaaS Panel (79.137.192.3) — STIX Bundle
Rhadamanthys MaaS Customer Deep-Dive (79.137.192.3) — STIX Bundle
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign — STIX Bundle
AdaptixC2 Open Directory Exposure (45.130.148.125) — STIX Bundle
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13) — STIX Bundle
ShinyHunters Data Leak Site (91.215.85.22) — STIX Bundle
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08) — STIX Bundle
OpenStrike Beacon Toolkit (172.105.0.126) — STIX Bundle
Shadow RAT & XWorm Open Directory Campaign — STIX Bundle
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2 — STIX Bundle
ZeroTrace Multi-Family MaaS Operation (74.0.42.25) — STIX Bundle
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220) — STIX Bundle
Webserver Compromise Kit (91.236.230.250) — STIX Bundle
Remcos RAT OpenDirectory Campaign — STIX Bundle
NsMiner: Multi-Stage Cryptojacking Operation — STIX Bundle
Arsenal-237 New Files: Advanced Toolkit Analysis — STIX Bundle
Arsenal-237: Threat Actor R&D Repository Exposed — STIX Bundle
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm — STIX Bundle
PULSAR RAT (server.exe) — Technical Analysis & Business Risk Assessment — STIX Bundle
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou — STIX Bundle
Houselet.exe — The Go-Based Loader Masquerading as PlayStation Remote Play — STIX Bundle
AdvancedRouterScanner — STIX Bundle
From Webshells to The Cloud — STIX Bundle
Quasar + XWorm + PowerShell — STIX Bundle