TLP:WHITE5 IOCs
Hackers Use Fake Fiscal Documents to Deliver NinjaOne RMM Agent for Remote Access
Threat Actors
Diamond Model
Adversary(1)
Infrastructure(5)
Capability
Victim
Attack Flow7 steps · MITRE ATT&CK mapped
5W+H Threat Analysis
Analysis unavailable
Indicators of Compromise
Indicators of Compromise5
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| Domain | sefaz.services intel-blognetworkphishing | High | 58 | Jun 12, 26 |
| Domain | lazybearpottery.net indicatorintel-blognetwork | High | 58 | Jun 12, 26 |
| Domain | rectalmania.com intel-blognetworkphishing | High | 58 | Jun 12, 26 |
| Domain | hairdb.com indicatorintel-blognetwork | High | 58 | Jun 12, 26 |
| Domain | r64.org indicatorintel-blognetwork | High | 58 | Jun 12, 26 |
IOC Relationship Graph
IOC Relationship Graph5 total IOCs
Domain