ATT&CK technique
T1036.005
3 campaigns
A three-node cluster on a bulletproof-hosting provider split a fake-Windows-update dropper, an Apple-impersonation TLS relay, and a DGA-style command-and-control node across one address block. All three are offline now, but the role-split and two-hour-certificate pattern are still worth hunting for.
2026-09-30
A threat actor breached a Jenkins server through its unauthenticated Script Console, then installed a self-healing SSH backdoor: delete the key and a systemd timer disguised as an update checker puts it back within five minutes. They stole the keys that decrypt the entire Jenkins credential store, harvested AWS credentials, and two days later deployed a cryptominer throttled to avoid detection. Full kill chain, IOCs, and Sigma detection rules inside.
2026-09-02
Over two days we watched a single operator chain two PAN-OS vulnerabilities in one request to install a custom-compiled, fully-obfuscated Sliver implant that appears in no public malware database and beacons to domains absent from every threat feed. A step-by-step walkthrough of the intrusion, with deployable Sigma and YARA detection.
2026-07-09