← All campaigns

Objective

unknown (intent unproven)

2 campaigns

Compare these two campaigns →

Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS

A three-node cluster on a bulletproof-hosting provider split a fake-Windows-update dropper, an Apple-impersonation TLS relay, and a DGA-style command-and-control node across one address block. All three are offline now, but the role-split and two-hour-certificate pattern are still worth hunting for.

2026-09-30

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

Over two days we watched a single operator chain two PAN-OS vulnerabilities in one request to install a custom-compiled, fully-obfuscated Sliver implant that appears in no public malware database and beacons to domains absent from every threat feed. A step-by-step walkthrough of the intrusion, with deployable Sigma and YARA detection.

2026-07-09