MalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G609309532026-06-26
malwrhunterteammalwareItaly
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Group-IB Threat Intelligence: Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and resilience, making detection more challenging. The #Telegram Bot API remains the core C2 mechanism.2026-06-25
GroupIB_TImalwareUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
StealthMole: Security OSINT Highlights — First Week of June 2026 Reporting collected during the first week of June 2026 is dominated by vulnerability disclosures and exploitation-related alerts, with a secondary concentration in malware, espionage, and intrusion activity supported by file-hash and IP indicators.2026-06-10
stealthmole_intmalwareUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Group-IB Threat Intelligence: SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. These additions reflect the growing focus on direct monetization within modern #malware ecosystems.2026-06-10
GroupIB_TImalwareUnited States
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.