Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

confirmed13
likely5
tentative0
needs review6

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
uat-10027-dohdoor-education-healthcare-2026-02-26 UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care UAT-10027 likely 1 suspected phishing-delivered PowerS... 1 cloudflare-dns.com DoH resolver ove... 3 remote staging URL serving .bat or ... 2 Dohdoor malicious DLL disguised as ... 2 http://GppiwoGwNdiakkDU.pnuiSckMHwa... 9e / 11r 2026-05-27 12:09:14
iim.chain.apt.2026.05.004 UAC-0057 Ghostwriter OYSTERFRESH to OYSTERSHUCK and OYSTERBLUES C2 UAC-0057 likely 1 PDF lure with active link to ZIP archive 2 ZIP archive containing OYSTERFRESH ... 3 OYSTERBLUES registry-staged payload 1 Cloudflare-fronted .icu C2 domain cluster 7e / 7r 2026-05-26 13:31:49
frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike UAC-0057 confirmed 1 53_7.03.2026_R.pdf 3 53_7.03.2026_R.rar 3 Update.js / PicassoLoader 2 hxxps://book-happy.needbinding[.]ic... 9e / 8r 2026-05-26 13:26:34
Showing 13 of 3 matching chains
Reset
Page 1 of 1. Showing 13 of 3 matching chains, 18 total.

uat-10027-dohdoor-education-healthcare-2026-02-26

UAT-10027 Dohdoor Cloudflare-fronted DoH C2 chain targeting education and health care

likely

Cisco Talos reported an ongoing campaign active since at least December 2025 against U.S. education and health care victims. The modeled chain follows the PowerShell downloader, remote batch script, C2-hosted malicious DLL retrieval, Dohdoor loader execution, DNS-over-HTTPS resolution through Cloudflare, Cloudflare-fronted C2 communication, and reflective next-stage payload retrieval

entry staging staging staging payload c2 redirector
UAT-10027 9 entities 11 relations 2026-05-27 12:09:14
IIM-T001 IIM-T011
Open chain analysis

iim.chain.apt.2026.05.004

UAC-0057 Ghostwriter OYSTERFRESH to OYSTERSHUCK and OYSTERBLUES C2

likely

CERT-UA/SOC Prime-documented Ukraine campaign: compromised-email lure with PDF link leads to ZIP/JavaScript OYSTERFRESH, registry-staged OYSTERBLUES, OYSTERSHUCK download, and HTTP POST C2 over Cloudflare-fronted .icu infrastructure.

entry staging staging payload payload c2 payload
UAC-0057 7 entities 7 relations 2026-05-26 13:31:49
IIM-T001 IIM-T010 IIM-T011 IIM-T019 IIM-T024
Open chain analysis

frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike

FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike

confirmed

ESET-documented Ukraine-targeting FrostyNeighbor chain: malicious PDF lure triggers geofenced RAR/JavaScript delivery, retrieves PicassoLoader tasking from a Cloudflare-fronted .icu host, then leads to Cobalt Strike infrastructure.

entry staging staging staging payload c2 payload
UAC-0057 9 entities 8 relations 2026-05-26 13:26:34
IIM-T001 IIM-T010 IIM-T011 IIM-T019 IIM-T020 IIM-T021 IIM-T024
Open chain analysis