Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed32
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
ox.2026.malware-slop-npm-github-exfil Malware-Slop npm package to GitHub Contents API exfiltration chain unknown confirmed 1 https://www.npmjs.com/package/mouse... 1 github.com 3 /mnt/user-data 1 npm postinstall script disguised as... 2 https://api.github.com/repos/<actor... 8e / 7r 2026-05-28 13:32:24
microsoft.2026.poisoned-search-screenconnect-gpu-miner Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2 unknown confirmed 1 attacker-controlled lookalike utili... 5 direct-download.gleeze.com 7 autorun.dll variant set loaded by l... 7 directdownload.icu 20e / 23r 2026-05-27 17:02:04
glassworm.2026.developer-supply-chain.multi-resolver-c2 Glassworm developer supply-chain infection to redundant multi-resolver C2 Glassworm confirmed 4 Trojanized VS Code / OpenVSX extens... 3 solana://transaction-memo/c2-server... 1 Glassworm downloader / installer stage 1 GlasswormRAT Node.js remote access tool 2 commercial VPS-hosted direct C2 inf... 11e / 13r 2026-05-27 13:04:07
gamaredon.2025.zero-click-rar.pteranodon Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure MB-0001 confirmed 2 6aa9741f8b8629d0398049fa91dc5e7c28f... 5 hxxps://www.telegram[.]me/s/natural_blood 3 %APPDATA%\Microsoft\Windows\Start M... 1 Pteranodon Stage-2 loader 2 194.67.71.75 13e / 13r 2026-05-27 12:22:36
uat-10027-dohdoor-education-healthcare-2026-02-26 UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care UAT-10027 likely 1 suspected phishing-delivered PowerS... 1 cloudflare-dns.com DoH resolver ove... 3 remote staging URL serving .bat or ... 2 Dohdoor malicious DLL disguised as ... 2 http://GppiwoGwNdiakkDU.pnuiSckMHwa... 9e / 11r 2026-05-27 12:09:14
uat-10362-lucidrook-taiwan-2026-04-08 UAT-10362 LucidRook LNK archive chain against Taiwanese organizations UAT-10362 likely 1 spear-phishing email targeting Taiw... 1 shortened URL leading to password-p... 5 password-protected encrypted RAR ar... 2 LucidRook DLL stager written as Dis... 3 1.34.253.131 12e / 13r 2026-05-27 12:07:54
powmix-czech-workforce-2026-04-16 PowMix ZIP/LNK PowerShell botnet chain targeting Czech workforce unknown likely 1 malicious ZIP archive with complian... 3 Windows shortcut file inside ZIP 1 PowMix PowerShell botnet payload 3 herokuapp.com based C2 endpoint 8e / 8r 2026-05-27 12:05:45
silver-fox-abcdoor-2026-04-30 Silver Fox tax-themed RustSL to ValleyRAT and ABCDoor chain Silver Fox likely 1 tax-themed phishing email attachmen... 1 attacker-controlled external downlo... 5 tax-related malicious archive 3 ValleyRAT Login module / Winos 4.0 payload 1 207.56.138.28 11e / 11r 2026-05-27 12:03:50
webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane Webworm confirmed 1 wamanharipethe.s3.ap-south-1.amazon... 2 GraphWorm payload 2 graph.microsoft.com / Microsoft Graph API 5e / 4r 2026-05-26 14:05:46
iim.chain.apt.2026.05.009 Webworm GitHub staging to EchoCreep Discord C2 Webworm confirmed 1 64[.]176[.]85[.]158 1 github[.]com/anjsdgasdf/WordPress 1 EchoCreep DLL 1 discord[.]com / Discord API 4e / 3r 2026-05-26 14:05:20
Showing 2130 of 39 matching chains
Reset
Page 3 of 4. Showing 2130 of 39 matching chains, 39 total.

ox.2026.malware-slop-npm-github-exfil

Malware-Slop npm package to GitHub Contents API exfiltration chain

confirmed

IIM chain for the OX Security report published on 2026-05-27 about the malicious npm package mouse5212-super-formatter. The package presents itself as an internal archive deployment sync utility, but during post-installation it authenticates to GitHub using either a victim environment token or a hardcoded fallback token, checks or creates an actor-controlled repository, recursively walks the local /mnt/user-data directory, and uploads collected files through the GitHub Contents API. OX observed around seven active exfiltration sessions in the actor repository before takedown and reported 676 downloads at time of publication. The exact actor account, repository name, hardcoded token value, and package tarball hashes were not published in the text; those are intentionally not invented here.

entry payload staging redirector c2 c2 staging
unknown 8 entities 7 relations 2026-05-28 13:32:24
IIM-T006 IIM-T018
Open chain analysis

microsoft.2026.poisoned-search-screenconnect-gpu-miner

Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2

confirmed

IIM chain for the Microsoft-described cryptojacking campaign published on 2026-05-26. The operation uses search-engine poisoning and observed AI-chatbot referral contexts to send users looking for trusted GPU/system utilities to attacker-controlled lookalike download sites. Those sites deliver ZIP archives from Dynu-backed gleeze/giize Dynamic DNS subdomains. The archive contains a legitimate utility executable and malicious autorun.dll variants. The DLL silently installs a ScreenConnect payload masquerading as vcredist_x64.dll, establishing persistent RMM access to directdownload.icu / 193.42.11.108. After the ScreenConnect session is established, the operator transfers SimpleRunPE.exe, which installs RuntimeHost.exe, hollows Microsoft-signed .NET utilities, and connects to the encrypted WebSocket C2 wss://minemine.gleeze.com:8443/ws with hardcoded TLS certificate pinning. The same certificate was observed on three additional IPs Microsoft assesses as part of the C2 infrastructure. The hollowed loader later downloads GPU-focused mining tools at runtime

entry staging staging staging staging staging payload
unknown 20 entities 23 relations 2026-05-27 17:02:04
IIM-T008 IIM-T011 IIM-T012 IIM-T021 IIM-T024
Open chain analysis

glassworm.2026.developer-supply-chain.multi-resolver-c2

Glassworm developer supply-chain infection to redundant multi-resolver C2

confirmed

IIM chain for Glassworm as documented by CrowdStrike on 2026-05-26: the operators targeted developers through OpenVSX/VS Code-style extensions, npm and Python packages, and poisoned GitHub repositories. The installed malware delivered Glassworm downloader/RAT capability and resolved operational endpoints through four resilient C2 channels: Solana transaction memo dead-drops, BitTorrent DHT configuration lookup, Google Calendar event-title dead-drops, and direct commercial VPS C2 servers. CrowdStrike, Google and Shadowserver disrupted the channels simultaneously. Exact malicious package names and original VPS C2 addresses were not published in the source article; this chain models the confirmed infrastructure architecture without inventing unpublished IoCs.

entry entry entry entry staging payload redirector
Glassworm 11 entities 13 relations 2026-05-27 13:04:07
IIM-T002 IIM-T006 IIM-T013
Open chain analysis

gamaredon.2025.zero-click-rar.pteranodon

Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure

confirmed

IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery infrastructure, retrieves/launches Pteranodon, and then uses Telegram/graph.org dead-drop resolver infrastructure plus DynDNS/Fast-Flux C2 nodes for tasking and payload rotation.

entry entry staging staging payload redirector redirector
MB-0001 13 entities 13 relations 2026-05-27 12:22:36
IIM-T002 IIM-T003 IIM-T006 IIM-T007 IIM-T008 IIM-T010 IIM-T011 IIM-T013 +4
Open chain analysis

uat-10027-dohdoor-education-healthcare-2026-02-26

UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care

likely

Cisco Talos reported an ongoing campaign active since at least December 2025 against U.S. education and health care victims. The modeled chain follows the PowerShell downloader, remote batch script, C2-hosted malicious DLL retrieval, Dohdoor loader execution, DNS-over-HTTPS resolution through Cloudflare, Cloudflare-fronted C2 communication, and reflective next-stage payload retrieval

entry staging staging staging payload c2 redirector
UAT-10027 9 entities 11 relations 2026-05-27 12:09:14
IIM-T001 IIM-T011
Open chain analysis

uat-10362-lucidrook-taiwan-2026-04-08

UAT-10362 LucidRook LNK archive chain against Taiwanese organizations

likely

Cisco Talos reported UAT-10362 spear-phishing Taiwanese NGOs and suspected universities with shortened URLs leading to password-protected archives. The modeled chain follows the LNK-based path: archive delivery, hidden nested folder staging, LucidPawn dropper, LucidRook stager, compromised FTP infrastructure used for payload retrieval and exfiltration, and a DNS beaconing domain observed in the IOC set

entry redirector staging staging staging staging payload
UAT-10362 12 entities 13 relations 2026-05-27 12:07:54
IIM-T004 IIM-T016 IIM-T024
Open chain analysis

powmix-czech-workforce-2026-04-16

PowMix ZIP/LNK PowerShell botnet chain targeting Czech workforce

likely

Cisco Talos observed a campaign targeting Czech organizations and workforce-related victims. The chain uses a malicious ZIP, LNK-triggered PowerShell loader, an embedded PowMix payload hidden in the ZIP data blob, and C2 communication via Heroku-hosted infrastructure using REST-like URL paths.

entry staging staging staging payload c2 c2
unknown 8 entities 8 relations 2026-05-27 12:05:45
IIM-T002 IIM-T011 IIM-T024
Open chain analysis

silver-fox-abcdoor-2026-04-30

Silver Fox tax-themed RustSL to ValleyRAT and ABCDoor chain

likely

Observed Silver Fox campaign using tax-themed delivery to distribute a customized RustSL loader, ValleyRAT, custom ValleyRAT modules and the ABCDoor Python backdoor. The chain models only infrastructure and delivery composition aspects; endpoint persistence and execution details are kept in ATT&CK annotations or notes.

entry redirector staging staging staging payload c2
Silver Fox 11 entities 11 relations 2026-05-27 12:03:50
IIM-T019 IIM-T024
Open chain analysis

webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane

Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane

confirmed

ESET-documented Webworm infrastructure lane using Microsoft Graph / OneDrive for GraphWorm command traffic and Amazon S3 infrastructure for WormFrp-related reconnaissance/exfiltration.

payload c2 c2 payload staging
Webworm 5 entities 4 relations 2026-05-26 14:05:46
IIM-T002 IIM-T006 IIM-T018
Open chain analysis

iim.chain.apt.2026.05.009

Webworm GitHub staging to EchoCreep Discord C2

confirmed

ESET-documented Webworm lane targeting European government entities: malware stages from GitHub repository content and EchoCreep uses Discord API traffic as its C2 channel.

staging payload c2 redirector
Webworm 4 entities 3 relations 2026-05-26 14:05:20
IIM-T002 IIM-T006 IIM-T018 IIM-T026
Open chain analysis