Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed32
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
enki.2026.kimsuky-webex-httpSpy-jsonping Kimsuky fake Webex page to fix-camera JSE, multi-stage HttpSpy variant, and chickenkiller C2 APT43 confirmed 1 https://conference.birdriver.org/ 1 C:\ProgramData\meeting.html decoy r... 5 https://download.birdriver.org/down... 3 engine.dat / spyInster.dll 1 http://hdrgdrfes.chickenkiller.com/... 11e / 13r 2026-05-31 19:22:26
Showing 11 of 1 matching chains
Reset
Page 1 of 1. Showing 11 of 1 matching chains, 39 total.

enki.2026.kimsuky-webex-httpSpy-jsonping

Kimsuky fake Webex page to fix-camera JSE, multi-stage HttpSpy variant, and chickenkiller C2

confirmed

ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installs cacheMon.dat/spyLoader.dll and the final HttpSpy main module. HttpSpy uses http://hdrgdrfes.chickenkiller.com/index.php as primary C2

entry staging staging redirector staging staging payload
APT43 11 entities 13 relations 2026-05-31 19:22:26
IIM-T015 IIM-T024
Open chain analysis