Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
iim.chain.apt.2026.05.004
UAC-0057 Ghostwriter OYSTERFRESH to OYSTERSHUCK and OYSTERBLUES C2
|
UAC-0057 | likely | 1 PDF lure with active link to ZIP archive | — | 2 ZIP archive containing OYSTERFRESH ... | 3 OYSTERBLUES registry-staged payload | 1 Cloudflare-fronted .icu C2 domain cluster | 7e / 7r | 2026-05-26 13:31:49 |
iim.chain.apt.2026.05.003
FrostyNeighbor Cobalt Strike lane via best-seller.lavanille.buzz
|
UAC-0057 | confirmed | — | — | 1 EdgeTaskMachine.js | 1 EdgeSystemConfig.dll | 2 best-seller.lavanille[.]buzz | 4e / 3r | 2026-05-26 13:31:09 |
frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike
FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike
|
UAC-0057 | confirmed | 1 53_7.03.2026_R.pdf | — | 3 53_7.03.2026_R.rar | 3 Update.js / PicassoLoader | 2 hxxps://book-happy.needbinding[.]ic... | 9e / 8r | 2026-05-26 13:26:34 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributioniim.chain.apt.2026.05.004
UAC-0057 Ghostwriter OYSTERFRESH to OYSTERSHUCK and OYSTERBLUES C2
CERT-UA/SOC Prime-documented Ukraine campaign: compromised-email lure with PDF link leads to ZIP/JavaScript OYSTERFRESH, registry-staged OYSTERBLUES, OYSTERSHUCK download, and HTTP POST C2 over Cloudflare-fronted .icu infrastructure.
iim.chain.apt.2026.05.003
FrostyNeighbor Cobalt Strike lane via best-seller.lavanille.buzz
FrostyNeighbor Cobalt Strike infrastructure lane based on ESET-published Beacon/dropper artifacts and Cobalt Strike C&C domains.
frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike
FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike
ESET-documented Ukraine-targeting FrostyNeighbor chain: malicious PDF lure triggers geofenced RAR/JavaScript delivery, retrieves PicassoLoader tasking from a Cloudflare-fronted .icu host, then leads to Cobalt Strike infrastructure.