Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
glassworm.2026.developer-supply-chain.multi-resolver-c2
Glassworm developer supply-chain infection to redundant multi-resolver C2
|
Glassworm | confirmed | 4 Trojanized VS Code / OpenVSX extens... | 3 solana://transaction-memo/c2-server... | 1 Glassworm downloader / installer stage | 1 GlasswormRAT Node.js remote access tool | 2 commercial VPS-hosted direct C2 inf... | 11e / 13r | 2026-05-27 13:04:07 |
gamaredon.2025.zero-click-rar.pteranodon
Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure
|
MB-0001 | confirmed | 2 6aa9741f8b8629d0398049fa91dc5e7c28f... | 5 hxxps://www.telegram[.]me/s/natural_blood | 3 %APPDATA%\Microsoft\Windows\Start M... | 1 Pteranodon Stage-2 loader | 2 194.67.71.75 | 13e / 13r | 2026-05-27 12:22:36 |
webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane
Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane
|
Webworm | confirmed | — | — | 1 wamanharipethe.s3.ap-south-1.amazon... | 2 GraphWorm payload | 2 graph.microsoft.com / Microsoft Graph API | 5e / 4r | 2026-05-26 14:05:46 |
iim.chain.apt.2026.05.009
Webworm GitHub staging to EchoCreep Discord C2
|
Webworm | confirmed | — | 1 64[.]176[.]85[.]158 | 1 github[.]com/anjsdgasdf/WordPress | 1 EchoCreep DLL | 1 discord[.]com / Discord API | 4e / 3r | 2026-05-26 14:05:20 |
uat-8302-snowlight-vshell-via-update-kaspersky.workers.dev
UAT-8302 SNOWLIGHT / VSHELL via update-kaspersky.workers.dev
|
UAT-8302 | confirmed | 1 benign executable loading wininet.dll | — | 1 SNOWLIGHT / SNOWRUST stager | 1 VSHELL payload | 2 image.update-kaspersky.workers[.]dev | 5e / 4r | 2026-05-26 14:00:43 |
iim.chain.apt.2026.05.006
UAT-8302 CloudSorcerer v3 dead-drop resolver to drivelivelime / msiidentity C2
|
UAT-8302 | confirmed | — | 2 github[.]com / public dead-drop resolver | — | 1 CloudSorcerer v3 side-loaded DLL triad | 3 www.drivelivelime[.]com | 6e / 7r | 2026-05-26 13:35:13 |
iim.chain.apt.2026.05.005
UAT-8302 NetDraft / FringePorch side-load to Microsoft Graph C2
|
UAT-8302 | confirmed | 1 benign executable used for DLL side-loading | — | — | 1 NetDraft / FringePorch backdoor | 2 graph.microsoft.com / Microsoft Graph API | 4e / 3r | 2026-05-26 13:33:29 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributionglassworm.2026.developer-supply-chain.multi-resolver-c2
Glassworm developer supply-chain infection to redundant multi-resolver C2
IIM chain for Glassworm as documented by CrowdStrike on 2026-05-26: the operators targeted developers through OpenVSX/VS Code-style extensions, npm and Python packages, and poisoned GitHub repositories. The installed malware delivered Glassworm downloader/RAT capability and resolved operational endpoints through four resilient C2 channels: Solana transaction memo dead-drops, BitTorrent DHT configuration lookup, Google Calendar event-title dead-drops, and direct commercial VPS C2 servers. CrowdStrike, Google and Shadowserver disrupted the channels simultaneously. Exact malicious package names and original VPS C2 addresses were not published in the source article; this chain models the confirmed infrastructure architecture without inventing unpublished IoCs.
gamaredon.2025.zero-click-rar.pteranodon
Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure
IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery infrastructure, retrieves/launches Pteranodon, and then uses Telegram/graph.org dead-drop resolver infrastructure plus DynDNS/Fast-Flux C2 nodes for tasking and payload rotation.
webworm-graphworm-wormfrp-cloud-service-c2-and-exfiltration-lane
Webworm GraphWorm / WormFrp cloud-service C2 and exfiltration lane
ESET-documented Webworm infrastructure lane using Microsoft Graph / OneDrive for GraphWorm command traffic and Amazon S3 infrastructure for WormFrp-related reconnaissance/exfiltration.
iim.chain.apt.2026.05.009
Webworm GitHub staging to EchoCreep Discord C2
ESET-documented Webworm lane targeting European government entities: malware stages from GitHub repository content and EchoCreep uses Discord API traffic as its C2 channel.
uat-8302-snowlight-vshell-via-update-kaspersky.workers.dev
UAT-8302 SNOWLIGHT / VSHELL via update-kaspersky.workers.dev
UAT-8302 side-load chain in which a SNOWLIGHT/SNOWRUST stager downloads or launches a VSHELL payload and communicates with Cloudflare Workers infrastructure.
iim.chain.apt.2026.05.006
UAT-8302 CloudSorcerer v3 dead-drop resolver to drivelivelime / msiidentity C2
CloudSorcerer v3 lane where malware retrieves C2 information from public web services and then connects to decoded UAT-8302 C2 domains published by Talos.
iim.chain.apt.2026.05.005
UAT-8302 NetDraft / FringePorch side-load to Microsoft Graph C2
Cisco Talos-documented UAT-8302 chain in which side-loaded NetDraft/FringePorch uses Microsoft Graph / OneDrive as a C2 channel.