Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3
Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers
|
MB-0001 | confirmed | 1 Weaponized xHTML lure (HTML smuggli... | 6 graph.org (Telegra.ph / Teletype de... | 4 Malicious RAR archive exploiting CV... | 2 GammaWorm (VBScript worm, formerly ... | 3 Operator-controlled C2 server (dedi... | 16e / 18r | 2026-06-18 11:31:44 |
jumpsec.2026.blacktoad-autoit-remcos-network-blackout
BlackToad phishing to AutoIt crypter and Remcos Dynamic-DNS C2 chain
|
BlackToad | confirmed | 1 Thai-language image-based financial... | — | 7 MediaFire-hosted malware download l... | 1 payload.bin / decoded Remcos Pro implant | 7 pmitm.ddns.net | 16e / 25r | 2026-05-28 16:12:38 |
microsoft.2026.poisoned-search-screenconnect-gpu-miner
Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2
|
unknown | confirmed | 1 attacker-controlled lookalike utili... | — | 5 direct-download.gleeze.com | 7 autorun.dll variant set loaded by l... | 7 directdownload.icu | 20e / 23r | 2026-05-27 17:02:04 |
gamaredon.2025.zero-click-rar.pteranodon
Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure
|
MB-0001 | confirmed | 2 6aa9741f8b8629d0398049fa91dc5e7c28f... | 5 hxxps://www.telegram[.]me/s/natural_blood | 3 %APPDATA%\Microsoft\Windows\Start M... | 1 Pteranodon Stage-2 loader | 2 194.67.71.75 | 13e / 13r | 2026-05-27 12:22:36 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributionsekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3
Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers
IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.
jumpsec.2026.blacktoad-autoit-remcos-network-blackout
BlackToad phishing to AutoIt crypter and Remcos Dynamic-DNS C2 chain
IIM chain for JUMPSEC DART research published on 2026-05-27. The campaign starts with a Thai-language, image-based financial payment-slip phishing email containing a MediaFire link, delivers a masqueraded .pdf.scr WinRAR SFX executable, launches a VBS loader, runs a renamed AutoIt3 interpreter with an obfuscated AutoIt script and INI-like configuration, decodes a substitution-hex encoded Remcos payload, and connects to three Dynamic-DNS C2 domains on port 50240. The report highlights a network-blackout execution window using ipconfig /release before AutoIt execution and ipconfig /renew afterwards; this behavior is kept as evidence/context because it is host execution logic rather than a separate network infrastructure node. The actual MediaFire URL and original recipient details were not published and are therefore not invented.
microsoft.2026.poisoned-search-screenconnect-gpu-miner
Poisoned search and AI-assisted fake utility downloads to ScreenConnect and GPU-miner C2
IIM chain for the Microsoft-described cryptojacking campaign published on 2026-05-26. The operation uses search-engine poisoning and observed AI-chatbot referral contexts to send users looking for trusted GPU/system utilities to attacker-controlled lookalike download sites. Those sites deliver ZIP archives from Dynu-backed gleeze/giize Dynamic DNS subdomains. The archive contains a legitimate utility executable and malicious autorun.dll variants. The DLL silently installs a ScreenConnect payload masquerading as vcredist_x64.dll, establishing persistent RMM access to directdownload.icu / 193.42.11.108. After the ScreenConnect session is established, the operator transfers SimpleRunPE.exe, which installs RuntimeHost.exe, hollows Microsoft-signed .NET utilities, and connects to the encrypted WebSocket C2 wss://minemine.gleeze.com:8443/ws with hardcoded TLS certificate pinning. The same certificate was observed on three additional IPs Microsoft assesses as part of the C2 infrastructure. The hollowed loader later downloads GPU-focused mining tools at runtime
gamaredon.2025.zero-click-rar.pteranodon
Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure
IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery infrastructure, retrieves/launches Pteranodon, and then uses Telegram/graph.org dead-drop resolver infrastructure plus DynDNS/Fast-Flux C2 nodes for tasking and payload rotation.