Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

confirmed12
likely5
tentative0
needs review6

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
uac-0184-pseudo-png-passmark-2026-05 UAC-0184: Pseudo PNG Passmark MB-0005 confirmed 2 Ukraine-themed LNK lure 8 169.40.135.35 3 filter.bin decoded LZNT1 payload bundle 2 224.0.0.255 15e / 20r 2026-05-19 15:15:42
Showing 11 of 1 matching chains
Reset
Page 1 of 1. Showing 11 of 1 matching chains, 17 total.

uac-0184-pseudo-png-passmark-2026-05

UAC-0184: Pseudo PNG Passmark

confirmed

Observed UAC-0184 chain from gated HTA and ZIP delivery into Plane9-based sideloading, encoded local blobs, pseudo-PNG IDAT staging, LZNT1 unpacking and a signed VSLauncher / PassMark network-capable payload bundle. The internal controller or C2 element remains tentative because no static C2 endpoint was present in the analyzed artifacts.

entry entry staging staging staging staging staging
MB-0005 15 entities 20 relations 2026-05-19 15:15:42
IIM-T019 IIM-T020 IIM-T021 IIM-T024 IIM-T025
Open chain analysis