Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
sabotage
RussiaThreat Actor
Active Threat
Sandworm
4.8k
IOCs Tracked
253
Intel Reports
Associated IOCs50 total
IP35
109.73.193.24246.151.182.205162.248.225.16567.219.102.24415.204.95.2285.101.86.985.101.86.105178.16.54.248206.188.196.221172.245.195.20688.119.167.14383.98.39.5484.21.189.225107.175.148.68139.159.203.44195.123.240.23638.181.42.16018.118.196.24447.236.24.11235.220.177.232101.133.148.668.130.26.216185.174.101.24034.64.98.20182.156.219.31110.40.176.194124.220.164.98178.128.171.206118.25.91.1518.153.205.30196.251.69.25337.72.172.58154.201.91.224103.215.81.15642.121.150.29Domain14
software-2.2.zip2026-10-09High
software-v1.5.zip2026-10-07High
software-v2.0.zip2026-10-07High
software-1.2.zip2026-10-07High
software-v3.3.zip2026-10-08High
software_v2.4.zip2026-10-09High
software_3.0.zip2026-10-09High
software_v3.0.zip2026-10-09High
software-v1.9.zip2026-10-09High
software_v1.1.zip2026-10-09High
bins.sh2026-10-06High
tabb_1.5.zip2026-10-06High
subtitle_translator_youtube_v1.4.zip2026-10-06High
software-2.6.zip2026-10-09High
SHA2561
1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498Related Reports253 total
Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding
NetbyteSEC BlogAug 20, 2026
Meduza Stealer or The Return of The Infamous Aurora Stealer
RussianPandaJun 28, 2023
Pure Logs Stealer Fails to Impress
RussianPandaDec 26, 2023
The GlorySprout or a Failed Clone of Taurus Stealer
RussianPandaMar 16, 2024
Unleashing the Viper : A Technical Analysis of WhiteSnake Stealer
RussianPandaJul 4, 2023
From Russia With Code: Disarming Atomic Stealer
RussianPandaJan 15, 2024
MetaStealer - Redline's Doppelgänger
RussianPandaNov 20, 2023
MacOS ClickFix AMOS Campaign
Ransom-ISACSep 17, 2026
Perl based macOS/linux Stealer
Randy McEoinJul 20, 2025
Inside Valkyrie Stealer: Capabilities, Evasion Techniques, and Operator Profile
DeXposeNov 25, 2025
Deep Dive into Arkanix Stealer and its Infrastructure
DeXposeDec 22, 2025
DynoWiper: From Russia with Love
t0asts blogFeb 6, 2026
MATCHBOIL: New tricks, same old evil intentions
ESET ResearchOct 8, 2026
Stealc Stealer
Aziz FarghlyNov 9, 2023
Reversing FUD AMOS Stealer
Denwp ResearchMar 20, 2025
FamousSparrow Takes Flight with New SparroWocky Backdoor
PolySwarmSep 25, 2026
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
PolySwarmSep 8, 2026
Gamers Get Played: Fake GTA6 Leaks Deliver a Grab Bag of Malware
PolySwarmSep 14, 2026
China and the Cyber Arms Race for AI Supremacy
PolySwarmSep 21, 2026
BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns
PolySwarmSep 21, 2026
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer
PolySwarmOct 2, 2026
CLOSEDQUORUM: Malware Puts AI in the C2 Loop
PolySwarmSep 28, 2026
Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations
PolySwarmOct 5, 2026
BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace
PolySwarmSep 11, 2026
Malicious Crypto Shell Packages Target RubyGems
OpenSourceMalwareOct 5, 2026
Xenorat Malware Analysis/reports/xenorat En.md at Main · Yavuzhanzgen/xenorat Malware Analysis
ORKL Threat Library
Technical Analysis of Marco Stealer
Zscaler ThreatLabzFeb 5, 2026
ClaudeFix: Shared Claude Chats Meet ClickFix
Zscaler ThreatLabzJul 15, 2026
Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs
HuntressOct 7, 2026
Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack
HuntressOct 6, 2026
Threat Profile
Motivationsabotage
Origin
Russia
Last seenOct 2026
IOCs tracked4,768