Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

confirmed13
likely5
tentative0
needs review6

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
gamaredon.2025.zero-click-rar.pteranodon Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure MB-0001 confirmed 2 6aa9741f8b8629d0398049fa91dc5e7c28f... 5 hxxps://www.telegram[.]me/s/natural_blood 3 %APPDATA%\Microsoft\Windows\Start M... 1 Pteranodon Stage-2 loader 2 194.67.71.75 13e / 13r 2026-05-27 12:22:36
frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike UAC-0057 confirmed 1 53_7.03.2026_R.pdf 3 53_7.03.2026_R.rar 3 Update.js / PicassoLoader 2 hxxps://book-happy.needbinding[.]ic... 9e / 8r 2026-05-26 13:26:34
uac-0184-pseudo-png-passmark-2026-05 UAC-0184: Pseudo PNG Passmark MB-0005 confirmed 2 Ukraine-themed LNK lure 8 169.40.135.35 3 filter.bin decoded LZNT1 payload bundle 2 224.0.0.255 15e / 20r 2026-05-19 15:15:42
Showing 13 of 3 matching chains
Reset
Page 1 of 1. Showing 13 of 3 matching chains, 18 total.

gamaredon.2025.zero-click-rar.pteranodon

Gamaredon 2025 zero-click RAR to Pteranodon and rotating C2 infrastructure

confirmed

IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed delivery infrastructure, retrieves/launches Pteranodon, and then uses Telegram/graph.org dead-drop resolver infrastructure plus DynDNS/Fast-Flux C2 nodes for tasking and payload rotation.

entry entry staging staging payload redirector redirector
MB-0001 13 entities 13 relations 2026-05-27 12:22:36
IIM-T002 IIM-T003 IIM-T006 IIM-T007 IIM-T008 IIM-T010 IIM-T011 IIM-T013 +4
Open chain analysis

frostyneighbor-ukraine-pdf-lure-to-picassoloader-and-cobalt-strike

FrostyNeighbor Ukraine PDF lure to PicassoLoader and Cobalt Strike

confirmed

ESET-documented Ukraine-targeting FrostyNeighbor chain: malicious PDF lure triggers geofenced RAR/JavaScript delivery, retrieves PicassoLoader tasking from a Cloudflare-fronted .icu host, then leads to Cobalt Strike infrastructure.

entry staging staging staging payload c2 payload
UAC-0057 9 entities 8 relations 2026-05-26 13:26:34
IIM-T001 IIM-T010 IIM-T011 IIM-T019 IIM-T020 IIM-T021 IIM-T024
Open chain analysis

uac-0184-pseudo-png-passmark-2026-05

UAC-0184: Pseudo PNG Passmark

confirmed

Observed UAC-0184 chain from gated HTA and ZIP delivery into Plane9-based sideloading, encoded local blobs, pseudo-PNG IDAT staging, LZNT1 unpacking and a signed VSLauncher / PassMark network-capable payload bundle. The internal controller or C2 element remains tentative because no static C2 endpoint was present in the analyzed artifacts.

entry entry staging staging staging staging staging
MB-0005 15 entities 20 relations 2026-05-19 15:15:42
IIM-T019 IIM-T020 IIM-T021 IIM-T024 IIM-T025
Open chain analysis