Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed32
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
redcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer ClearFake confirmed 1 <compromised website with injected JS> 1 injected JavaScript serving fake-CA... 1 <remote payload-retrieval host> 1 ACR Stealer (MaaS infostealer) 1 <ACR Stealer C2 endpoint> 5e / 4r 2026-05-30 21:31:45
securonix.2026.venomous-helper-ssa-rmm-double-compromised-host SSA-themed phishing delivering SimpleHelp RMM via two compromised legitimate hosting layers for persistent remote access unknown confirmed 1 <SSA-themed phishing email link> 1 gruta.com[.]mx 1 server.cubatiendaalimentos.com[.]mx 1 SSA_Statement.exe (JWrapper-package... 1 <SimpleHelp/ScreenConnect RMM relay... 5e / 4r 2026-05-30 21:24:57
godaddy.2026.wordpress-steam-community-deaddrop-js-backdoor Compromised WordPress malware abusing Steam Community profile comments as dead-drop resolver for JavaScript injection and cookie-authenticated backdoor control unknown confirmed 1 compromised WordPress plugin/theme ... 4 hxxps://steamcommunity[.]com/profil... 3 commentthread_comment_text invisibl... 3 hxxps://hello-mywordl[.]info/js/lod... 2 <compromised WordPress site> POST /... 13e / 17r 2026-05-30 11:26:11
seqrite.2026.operation-xenofiscal-sidecopy-xenorat Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2 SideCopy confirmed 2 spearphishing ZIP archive targeting... 13 mshta.exe LOLBIN execution of remot... 3 ayhui.vmxx reconstructed shellcode ... 1 185.235.137.106 19e / 18r 2026-05-29 20:01:27
uat-10362-lucidrook-taiwan-2026-04-08 UAT-10362 LucidRook LNK archive chain against Taiwanese organizations UAT-10362 likely 1 spear-phishing email targeting Taiw... 1 shortened URL leading to password-p... 5 password-protected encrypted RAR ar... 2 LucidRook DLL stager written as Dis... 3 1.34.253.131 12e / 13r 2026-05-27 12:07:54
Showing 15 of 5 matching chains
Reset
Page 1 of 1. Showing 15 of 5 matching chains, 39 total.

redcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer

ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer

confirmed

IIM chain for the ClearFake activity cluster, ranked the most prevalent threat in Red Canary's May 2026 intelligence insights. ClearFake injects JavaScript into compromised websites to deliver malware via drive-by techniques, frequently using fake CAPTCHA lures that trick users into executing code via malicious copy-and-paste (paste-and-run / ClickFix / fakeCAPTCHA). Red Canary reports ClearFake has delivered multiple payloads over time including ArechClient2 and LummaC2, and most recently ACR Stealer, a malware-as-a-service infostealer. The paste-and-run user-execution step is endpoint behaviour and is recorded only under attack_annotations.

entry redirector staging payload c2
ClearFake 5 entities 4 relations 2026-05-30 21:31:45
IIM-T004 IIM-T015
Open chain analysis

securonix.2026.venomous-helper-ssa-rmm-double-compromised-host

SSA-themed phishing delivering SimpleHelp RMM via two compromised legitimate hosting layers for persistent remote access

confirmed

IIM chain for the VENOMOUS#HELPER campaign reported by Securonix (covered 2026-05-04). A U.S. Social Security Administration (SSA) impersonation email instructs the recipient to verify their address and download a purported SSA statement. The embedded link points to a compromised legitimate Mexican business website used to evade email filters; the executable is then pulled from a second attacker-controlled domain staged through a single compromised cPanel account on a legitimate hosting server. The JWrapper-packaged Windows executable installs the SimpleHelp RMM tool, registers as a Windows service with Safe Mode persistence, and uses a self-healing watchdog. The chain models only the infrastructure layer; the watchdog, service install, and Safe Mode persistence are endpoint behaviour recorded under attack_annotations.

entry redirector staging payload c2
unknown 5 entities 4 relations 2026-05-30 21:24:57
IIM-T004
Open chain analysis

godaddy.2026.wordpress-steam-community-deaddrop-js-backdoor

Compromised WordPress malware abusing Steam Community profile comments as dead-drop resolver for JavaScript injection and cookie-authenticated backdoor control

confirmed

IIM chain for GoDaddy Security research published on 2026-05-28. The report describes WordPress malware found across roughly 1,980 infected sites since July 2025. The malware uses compromised WordPress plugin/theme PHP files to fetch Steam Community profile comments, extract the commentthread_comment_text content, decode an invisible-Unicode payload with optional AES-256-CTR/PBKDF2/HMAC protection, and inject the decoded URL as frontend JavaScript through wp_enqueue_script using the handle asahi-jquery-min-bundle. The observed decoded payload URL is hxxps://hello-mywordl[.]info/js/lodash[.]core[.]min[.]js. In parallel, the same PHP malware exposes a cookie-authenticated server-side backdoor that responds to DEpjndDbNc ping cookies and accepts base64-encoded PHP replacement code through tEcaKKXEsb plus POST parameter new_code, allowing remote modification of plugin and theme files. The initial WordPress compromise vector is not confirmed by GoDaddy, so this chain starts at the confirmed infected PHP/plugin/theme layer and records initial access as a limitation rather than inventing a vulnerable plugin, stolen credential, or supply-chain path.

entry redirector redirector redirector redirector staging staging
unknown 13 entities 17 relations 2026-05-30 11:26:11
IIM-T004 IIM-T006 IIM-T013 IIM-T018
Open chain analysis

seqrite.2026.operation-xenofiscal-sidecopy-xenorat

Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2

confirmed

IIM chain for Seqrite Operation XENOFISCAL, published 2026-05-29. The campaign targets Afghanistan Ministry of Finance provincial officials with a spearphishing ZIP containing a Pashto malicious LNK. The LNK launches mshta.exe and retrieves obfuscated HTA/JavaScript from compromised Afghan education domain abimj.edu.af/index.php. The script reconstructs an in-memory .NET loader, downloads an Afghan Ministry of Finance decoy PDF, persists zuidrt.hta, retrieves additional payload blobs from /institute/10/ or /institute/7/, reconstructs shellcode, loads XenoRAT, and connects to hardcoded C2 IP 185.235.137.106 hosted on AS59711/HZ Hosting infrastructure.

entry entry staging staging staging staging staging
SideCopy 19 entities 18 relations 2026-05-29 20:01:27
IIM-T003 IIM-T004 IIM-T021 IIM-T024
Open chain analysis

uat-10362-lucidrook-taiwan-2026-04-08

UAT-10362 LucidRook LNK archive chain against Taiwanese organizations

likely

Cisco Talos reported UAT-10362 spear-phishing Taiwanese NGOs and suspected universities with shortened URLs leading to password-protected archives. The modeled chain follows the LNK-based path: archive delivery, hidden nested folder staging, LucidPawn dropper, LucidRook stager, compromised FTP infrastructure used for payload retrieval and exfiltration, and a DNS beaconing domain observed in the IOC set

entry redirector staging staging staging staging payload
UAT-10362 12 entities 13 relations 2026-05-27 12:07:54
IIM-T004 IIM-T016 IIM-T024
Open chain analysis