Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
uac-0184-pseudo-png-passmark-2026-05
UAC-0184: Pseudo PNG Passmark
|
MB-0005 | confirmed | 2 Ukraine-themed LNK lure | — | 8 169.40.135.35 | 3 filter.bin decoded LZNT1 payload bundle | 2 224.0.0.255 | 15e / 20r | 2026-05-19 15:15:42 |
Page 1 of 1. Showing 1–1 of 1 matching chains, 17 total.
Technique pressure
top observed IIM techniquesActor surface
published chain attributionuac-0184-pseudo-png-passmark-2026-05
UAC-0184: Pseudo PNG Passmark
Observed UAC-0184 chain from gated HTA and ZIP delivery into Plane9-based sideloading, encoded local blobs, pseudo-PNG IDAT staging, LZNT1 unpacking and a signed VSLauncher / PassMark network-capable payload bundle. The internal controller or C2 element remains tentative because no static C2 endpoint was present in the analyzed artifacts.
entry
→
entry
→
staging
→
staging
→
staging
→
staging
→
staging
IIM-T019
IIM-T020
IIM-T021
IIM-T024
IIM-T025
Open chain analysis↗