Threat Intelligence

Expert analysis, curated IOCs, and emerging threat trends from our research team

Our Mission

We transform threat intelligence into impact. By accelerating attribution through infrastructure analysis, predictive models, and expert insights, we connect malicious activity to real-world actors faster. Our mission is simple: make cybercrime matter by ensuring defenders can anticipate threats, disrupt adversaries, and help bring criminals to justice.

What You'll Find Here

Threat Analysis

In-depth analysis of APT groups, malware families, and active campaigns

Emerging Trends

Early detection of new attack vectors and evolving adversary tactics

Actor Profiling

Detailed profiles of threat actors, motivations, and capabilities

Expert Discussion

Join discussions with security professionals and researchers


Latest Threat Intelligence

Stay ahead of emerging threats with our latest analysis and intelligence reports

Latest 6 posts

EvilTokens: Device Code Phishing Goes Industrial

Free

We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped the full infrastructure architecture: a Cloudflare CDN frontend, fragmented backend hosting with DocuSign lures and Exim mail servers, a bridge cluster with Google Trust Services certificates on compromised business domains, Cobalt Strike C2 via domain fronting, and an unreported IoT proxy layer of compromised Hikvision/Dahua surveillance cameras on Chinese telecom networks.

eviltokens
phishing
device-code
+7
0 comments
0 likes
09/04/2026

Profiling the Largest Identifiable Exposed AI Infrastructure on the Internet

Free

Over 1,500 IPs from Shodan's exposed Ollama index were analyzed through ClusterHawk. After filtering 60% honeypots, 13 of 27 clusters pointed to a single operator — XRUI TECHNOLOGY LIMITED — running identical nginx/MySQL/Ollama stacks with unauthenticated qwen3-vl inference across 35+ hosts alongside a Chinese sports gambling site. This is the largest identifiable exposed AI infrastructure we've found in one operator's hands.

ollama
llmjacking
qwen
+6
0 comments
0 likes
13/03/2026

OVERCAST: Tracking 1,900 Nation-State RDP Nodes Across Cloudzy's C2P Ecosystem

Free

We received 50 validated IPs linked to a suspected Russian state-sponsored APT. We profiled them through ClusterHawk and extracted a common fingerprint — then pivoted on that profile against internet scanning data and surfaced approximately 1,900 matching assets across 15 countries. We designate this infrastructure tracking effort OVERCAST.

overcast
nation-state
rdp
+7
0 comments
0 likes
22/02/2026

The Pattern in the Noise: What 1,602 Exposed Modbus Systems Reveal About Industrial Security's Systemic Failures

Free

Analyzing 1,602 internet-visible Modbus systems revealed not scattered misconfigurations but systematic patterns—95% shared TLS fingerprints, identical certificates, same CVEs across clusters. This isn't about individual negligence; it's how the entire ICS ecosystem deploys critical infrastructure in predictable, exploitable ways.

ics
scada
modbus
+5
0 comments
0 likes
06/01/2026

When Your Router Becomes Someone Else's Weapon: Uncovering a 800+ Proxy Network via KeeneticOS Router

Free

Through infrastructure clustering analysis, we identified a proxy network containing 832 compromised KeeneticOS routers operating across Russian ISPs. This investigation reveals how consumer devices become weaponized infrastructure in the modern threat landscape.

botnet
iot
proxy-network
+4
0 comments
0 likes
26/11/2025

SideWinder's Click Once campaign - independent validation with ClusterHawk

Free

We confirm Trellix’s reporting on SideWinder’s PDF ClickOnce chain and targets, and we prove our methodology by deliberately injecting a broad VirusTotal communicated IPs pivot and then separating CDN/search noise (~85%) from a compact nginx micro-cluster (~15%) that’s worth watching. Below are ready-to-run hunts (SIEM/Sigma + Shodan/Censys) and cluster fingerprints you can use as predictive seeds.

sidewinder
apt
clickonce
+6
0 comments
0 likes
02/11/2025

Join the Discussion

Premium subscribers can participate in expert discussions, share insights, and collaborate with other security professionals.

SE
Swift Eagle
Senior Security Analyst • 2 hours ago

Excellent analysis of the APT28 infrastructure changes. We've observed similar patterns in our network monitoring. The shift to European hosting providers is particularly interesting...

MW
Mystic Wolf
Threat Researcher • 1 hour ago

Agreed! The geographic distribution shift suggests they're adapting to sanctions and regulatory pressure...

Unlock Premium Threat Intelligence

Access exclusive analysis, detailed IOCs, and expert discussions