IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE3 IOCs

Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs

HU
Huntress
Published October 7, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAkiraSandwormINFRASTRUCTUREinstance-g01s1n-relay…CAPABILITYAkiraCobalt StrikeMETA StealerVICTIMunknown
Adversary(2)
Infrastructure(1)
Capability(4)
Victim

Indicators of Compromise

Indicators of Compromise3

TypeIndicatorConfidenceScoreFirst Seen
SHA2565956f9afb3ba610c38b2cfda88dd15be98783963769a12020c93ce05e749b3c3
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
file-hashintel-blogmalware
High
85
Aug 25, 26
Domaininstance-g01s1n-relay.screenconnect.com
intel-blogmalwarenetwork
High
58
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph3 total IOCs
SHA256Domain
SHA2562Domain1Actors2Malware4REPORTPhishing Campaign Abuses MAkiraSandwormAkiraCobalt StrikeMETA StealerXMRig
scroll to zoom · drag to pan · click IOC to open