09-09-2026
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Report completeness: High
Actors/Campaigns:
Cl-cri-1171
Threats:
Arktunnel
Docro_hijacker
Seo_poisoning_technique
Insomnia_rat
Gcleaner
Socks5systemz
Offerloader
Steganography_technique
Typosquatting_technique
Victims:
Young gamers, Corporate endpoints, Critical infrastructure, Government entities
Industry:
Entertainment, Government, Critical_infrastructure
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1027.003, T1036, T1036.005, T1053.005, T1059.001, T1059.006, T1059.007, T1071.001, T1082, T1105, have more...
IOCs:
Domain: 311
File: 16
Url: 5
Hash: 16
Soft:
WildFire, Chrome, WinRAR, macOS, Node.js, Windows Defender, Linux, Windows service
Algorithms:
zip, base64, sha256, hmac, xor
Languages:
pascal, powershell, python, javascript
Platforms:
cross-platform