Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
enki.2026.kimsuky-webex-httpSpy-jsonping
Kimsuky fake Webex page to fix-camera JSE, multi-stage HttpSpy variant, and chickenkiller C2
|
APT43 | confirmed | 1 https://conference.birdriver.org/ | 1 C:\ProgramData\meeting.html decoy r... | 5 https://download.birdriver.org/down... | 3 engine.dat / spyInster.dll | 1 http://hdrgdrfes.chickenkiller.com/... | 11e / 13r | 2026-05-31 19:22:26 |
Page 1 of 1. Showing 1–1 of 1 matching chains, 39 total.
Technique pressure
top observed IIM techniquesActor surface
published chain attributionenki.2026.kimsuky-webex-httpSpy-jsonping
Kimsuky fake Webex page to fix-camera JSE, multi-stage HttpSpy variant, and chickenkiller C2
ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installs cacheMon.dat/spyLoader.dll and the final HttpSpy main module. HttpSpy uses http://hdrgdrfes.chickenkiller.com/index.php as primary C2
entry
→
staging
→
staging
→
redirector
→
staging
→
staging
→
payload
IIM-T015
IIM-T024
Open chain analysis↗