Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed33
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
wiz.2026.jinx-0164-velora-sdk-minirat-supply-chain JINX-0164 trojanized @velora-dex/sdk to MINIRAT macOS C2 chain JINX-0164 confirmed 2 https://www.npmjs.com/package/@velo... — 5 http://89.36.224.5/troubleshoot/mac... 3 0a8ab3d16b12d3a453ee5a3208fe04744ad... 5 datahub.ink 15e / 17r 2026-05-28 13:43:20
ox.2026.malware-slop-npm-github-exfil Malware-Slop npm package to GitHub Contents API exfiltration chain unknown confirmed 1 https://www.npmjs.com/package/mouse... 1 github.com 3 /mnt/user-data 1 npm postinstall script disguised as... 2 https://api.github.com/repos/<actor... 8e / 7r 2026-05-28 13:32:24
microsoft.2026.poisoned-search-screenconnect-gpu-miner Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2 unknown confirmed 1 attacker-controlled lookalike utili... — 5 direct-download.gleeze.com 7 autorun.dll variant set loaded by l... 7 directdownload.icu 20e / 23r 2026-05-27 17:02:04
glassworm.2026.developer-supply-chain.multi-resolver-c2 Glassworm developer supply-chain infection to redundant multi-resolver C2 Glassworm confirmed 4 Trojanized VS Code / OpenVSX extens... 3 solana://transaction-memo/c2-server... 1 Glassworm downloader / installer stage 1 GlasswormRAT Node.js remote access tool 2 commercial VPS-hosted direct C2 inf... 11e / 13r 2026-05-27 13:04:07
gamaredon.2025.zero-click-rar.pteranodon Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure MB-0001 confirmed 2 6aa9741f8b8629d0398049fa91dc5e7c28f... 5 hxxps://www.telegram[.]me/s/natural_blood 3 %APPDATA%\Microsoft\Windows\Start M... 1 Pteranodon Stage-2 loader 2 194.67.71.75 13e / 13r 2026-05-27 12:22:36
uat-10027-dohdoor-education-healthcare-2026-02-26 UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care UAT-10027 likely 1 suspected phishing-delivered PowerS... 1 cloudflare-dns.com DoH resolver ove... 3 remote staging URL serving .bat or ... 2 Dohdoor malicious DLL disguised as ... 2 http://GppiwoGwNdiakkDU.pnuiSckMHwa... 9e / 11r 2026-05-27 12:09:14
uat-10362-lucidrook-taiwan-2026-04-08 UAT-10362 LucidRook LNK archive chain against Taiwanese organizations UAT-10362 likely 1 spear-phishing email targeting Taiw... 1 shortened URL leading to password-p... 5 password-protected encrypted RAR ar... 2 LucidRook DLL stager written as Dis... 3 1.34.253.131 12e / 13r 2026-05-27 12:07:54
powmix-czech-workforce-2026-04-16 PowMix ZIP/LNK PowerShell botnet chain targeting Czech workforce unknown likely 1 malicious ZIP archive with complian... — 3 Windows shortcut file inside ZIP 1 PowMix PowerShell botnet payload 3 herokuapp.com based C2 endpoint 8e / 8r 2026-05-27 12:05:45
silver-fox-abcdoor-2026-04-30 Silver Fox tax-themed RustSL to ValleyRAT and ABCDoor chain Silver Fox likely 1 tax-themed phishing email attachmen... 1 attacker-controlled external downlo... 5 tax-related malicious archive 3 ValleyRAT Login module / Winos 4.0 payload 1 207.56.138.28 11e / 11r 2026-05-27 12:03:50
webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane Webworm confirmed — — 1 wamanharipethe.s3.ap-south-1.amazon... 2 GraphWorm payload 2 graph.microsoft.com / Microsoft Graph API 5e / 4r 2026-05-26 14:05:46
Showing 21–30 of 40 matching chains
Reset
Page 3 of 4. Showing 21–30 of 40 matching chains, 40 total.

wiz.2026.jinx-0164-velora-sdk-minirat-supply-chain

JINX-0164 trojanized @velora-dex/sdk to MINIRAT macOS C2 chain

confirmed

IIM chain for the Wiz Research report published on 2026-05-27 describing JINX-0164 supply-chain activity. The chain models trojanized npm package @velora-dex/sdk version 4.9.1, a malicious dist/index.js addition that decodes and runs a curl command to 89.36.224.5/troubleshoot/mac/install.sh, dropper delivery, MINIRAT macOS payload execution, and the shared datahub.ink / cloud-sync.online / byte-io.us C2 domain set. It intentionally does not invent npm account credentials, unpublished package download telemetry beyond Wiz/StepSecurity references, or a source-repository compromise because Wiz explicitly says the GitHub source code was not modified.

entry → entry → staging → staging → staging → staging → payload
JINX-0164 15 entities 17 relations 2026-05-28 13:43:20
IIM-T002 IIM-T006 IIM-T011
Open chain analysis↗

ox.2026.malware-slop-npm-github-exfil

Malware-Slop npm package to GitHub Contents API exfiltration chain

confirmed

IIM chain for the OX Security report published on 2026-05-27 about the malicious npm package mouse5212-super-formatter. The package presents itself as an internal archive deployment sync utility, but during post-installation it authenticates to GitHub using either a victim environment token or a hardcoded fallback token, checks or creates an actor-controlled repository, recursively walks the local /mnt/user-data directory, and uploads collected files through the GitHub Contents API. OX observed around seven active exfiltration sessions in the actor repository before takedown and reported 676 downloads at time of publication. The exact actor account, repository name, hardcoded token value, and package tarball hashes were not published in the text; those are intentionally not invented here.

entry → payload → staging → redirector → c2 → c2 → staging
unknown 8 entities 7 relations 2026-05-28 13:32:24
IIM-T006 IIM-T018
Open chain analysis↗

microsoft.2026.poisoned-search-screenconnect-gpu-miner

Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2

confirmed

IIM chain for the Microsoft-described cryptojacking campaign published on 2026-05-26. The operation uses search-engine poisoning and observed AI-chatbot referral contexts to send users looking for trusted GPU/system utilities to attacker-controlled lookalike download sites. Those sites deliver ZIP archives from Dynu-backed gleeze/giize Dynamic DNS subdomains. The archive contains a legitimate utility executable and malicious autorun.dll variants. The DLL silently installs a ScreenConnect payload masquerading as vcredist_x64.dll, establishing persistent RMM access to directdownload.icu / 193.42.11.108. After the ScreenConnect session is established, the operator transfers SimpleRunPE.exe, which installs RuntimeHost.exe, hollows Microsoft-signed .NET utilities, and connects to the encrypted WebSocket C2 wss://minemine.gleeze.com:8443/ws with hardcoded TLS certificate pinning. The same certificate was observed on three additional IPs Microsoft assesses as part of the C2 infrastructure. The hollowed loader later downloads GPU-focused mining tools at runtime

entry → staging → staging → staging → staging → staging → payload
unknown 20 entities 23 relations 2026-05-27 17:02:04
IIM-T008 IIM-T011 IIM-T012 IIM-T021 IIM-T024
Open chain analysis↗

glassworm.2026.developer-supply-chain.multi-resolver-c2

Glassworm developer supply-chain infection to redundant multi-resolver C2

confirmed

IIM chain for Glassworm as documented by CrowdStrike on 2026-05-26: the operators targeted developers through OpenVSX/VS Code-style extensions, npm and Python packages, and poisoned GitHub repositories. The installed malware delivered Glassworm downloader/RAT capability and resolved operational endpoints through four resilient C2 channels: Solana transaction memo dead-drops, BitTorrent DHT configuration lookup, Google Calendar event-title dead-drops, and direct commercial VPS C2 servers. CrowdStrike, Google and Shadowserver disrupted the channels simultaneously. Exact malicious package names and original VPS C2 addresses were not published in the source article; this chain models the confirmed infrastructure architecture without inventing unpublished IoCs.

entry → entry → entry → entry → staging → payload → redirector
Glassworm 11 entities 13 relations 2026-05-27 13:04:07
IIM-T002 IIM-T006 IIM-T013
Open chain analysis↗

gamaredon.2025.zero-click-rar.pteranodon

Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure

confirmed

IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery infrastructure, retrieves/launches Pteranodon, and then uses Telegram/graph.org dead-drop resolver infrastructure plus DynDNS/Fast-Flux C2 nodes for tasking and payload rotation.

entry → entry → staging → staging → payload → redirector → redirector
MB-0001 13 entities 13 relations 2026-05-27 12:22:36
IIM-T002 IIM-T003 IIM-T006 IIM-T007 IIM-T008 IIM-T010 IIM-T011 IIM-T013 +4
Open chain analysis↗

uat-10027-dohdoor-education-healthcare-2026-02-26

UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care

likely

Cisco Talos reported an ongoing campaign active since at least December 2025 against U.S. education and health care victims. The modeled chain follows the PowerShell downloader, remote batch script, C2-hosted malicious DLL retrieval, Dohdoor loader execution, DNS-over-HTTPS resolution through Cloudflare, Cloudflare-fronted C2 communication, and reflective next-stage payload retrieval

entry → staging → staging → staging → payload → c2 → redirector
UAT-10027 9 entities 11 relations 2026-05-27 12:09:14
IIM-T001 IIM-T011
Open chain analysis↗

uat-10362-lucidrook-taiwan-2026-04-08

UAT-10362 LucidRook LNK archive chain against Taiwanese organizations

likely

Cisco Talos reported UAT-10362 spear-phishing Taiwanese NGOs and suspected universities with shortened URLs leading to password-protected archives. The modeled chain follows the LNK-based path: archive delivery, hidden nested folder staging, LucidPawn dropper, LucidRook stager, compromised FTP infrastructure used for payload retrieval and exfiltration, and a DNS beaconing domain observed in the IOC set

entry → redirector → staging → staging → staging → staging → payload
UAT-10362 12 entities 13 relations 2026-05-27 12:07:54
IIM-T004 IIM-T016 IIM-T024
Open chain analysis↗

powmix-czech-workforce-2026-04-16

PowMix ZIP/LNK PowerShell botnet chain targeting Czech workforce

likely

Cisco Talos observed a campaign targeting Czech organizations and workforce-related victims. The chain uses a malicious ZIP, LNK-triggered PowerShell loader, an embedded PowMix payload hidden in the ZIP data blob, and C2 communication via Heroku-hosted infrastructure using REST-like URL paths.

entry → staging → staging → staging → payload → c2 → c2
unknown 8 entities 8 relations 2026-05-27 12:05:45
IIM-T002 IIM-T011 IIM-T024
Open chain analysis↗

silver-fox-abcdoor-2026-04-30

Silver Fox tax-themed RustSL to ValleyRAT and ABCDoor chain

likely

Observed Silver Fox campaign using tax-themed delivery to distribute a customized RustSL loader, ValleyRAT, custom ValleyRAT modules and the ABCDoor Python backdoor. The chain models only infrastructure and delivery composition aspects; endpoint persistence and execution details are kept in ATT&CK annotations or notes.

entry → redirector → staging → staging → staging → payload → c2
Silver Fox 11 entities 11 relations 2026-05-27 12:03:50
IIM-T019 IIM-T024
Open chain analysis↗

webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane

Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane

confirmed

ESET-documented Webworm infrastructure lane using Microsoft Graph / OneDrive for GraphWorm command traffic and Amazon S3 infrastructure for WormFrp-related reconnaissance/exfiltration.

payload → c2 → c2 → payload → staging
Webworm 5 entities 4 relations 2026-05-26 14:05:46
IIM-T002 IIM-T006 IIM-T018
Open chain analysis↗