Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
iim.chain.apt.2026.05.009
Webworm GitHub staging to EchoCreep Discord C2
|
Webworm | confirmed | — | 1 64[.]176[.]85[.]158 | 1 github[.]com/anjsdgasdf/WordPress | 1 EchoCreep DLL | 1 discord[.]com / Discord API | 4e / 3r | 2026-05-26 14:05:20 |
uac-0247-ukrvarta-fpv-dopomoga-2026-03
UAC-0247 - UKRVARTA FPV
|
MB-0006 | confirmed | 2 UkrVarta humanitarian-aid themed ZI... | 1 search-ms:query=lnk&crumb=location:... | 4 ukrvarta.online | 6 https://ukrvarta.online/dopomoga/up... | 1 109.237.97.4 | 14e / 13r | 2026-05-20 17:04:53 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributioniim.chain.apt.2026.05.009
Webworm GitHub staging to EchoCreep Discord C2
ESET-documented Webworm lane targeting European government entities: malware stages from GitHub repository content and EchoCreep uses Discord API traffic as its C2 channel.
uac-0247-ukrvarta-fpv-dopomoga-2026-03
UAC-0247 - UKRVARTA FPV
Campaign chain for a Ukraine-focused lure targeting FPV/UAV-related audiences. The flow starts with a humanitarian-aid themed archive/LNK and HTA delivery layer on ukrvarta.online, moves through external JavaScript and updater.txt payload staging, persists as OneDriveUpdater, injects a decoded shellcode stage into RuntimeBroker.exe, unpacks EncryptedReverseShell.exe, and communicates with 109.237.97.4:8443.