Another day, another suspicious ISP: This time, a cluster of ๐ฃ phishing domains targeting Roblox drew our researchers' attention to EggyWall (AS219067), for which RIPE merely provides a residential address in northern ๐ฎ๐น Italy.
The sole prefix announced by AS219067, 5.175.169[.]0/24 (leased from ๐ฉ๐ช GHOSTnet GmbH), got listed in SBL and DROP on August 20. Peculiarly, a few hours later, a second announcement surfaced: 107.150.72[.]0/24 (leased from ๐บ๐ธ Inter Connects Inc). Even more interesting, a variety of phishing domains previously seen on the first prefix started resolving to the second, potentially indicating a deliberate evasion attempt.
At this time, AS219067 is exclusively routed by ๐ฉ๐ช Pfcloud UG (AS51396), which in turn obtains connectivity from ๐ฉ๐ช aurologic GmbH's AS30823. Both ISPs are known among anti-abuse circles for their persistent proliferation of bulletproof hosters.
EggyWall's domains previously resolved to AS36680 ( ๐บ๐ธ Netiface LLC), another bulletproof hoster in Pfcloud's realm. Have we sniffed out a phisher trying to emancipate themselves from a criminal competitor? We are sure time will reveal it all. ๐ต๏ธ
#Cybercrime #Phishing #BulletproofHosting
Traveling the world requires preparation, particularly when involving camping and exploring rural areas. The other day, our researchers encountered a potential equipment supplier: ๐บ๐ธ Evergreen Horizon Outdoor Camping Gear LLC (AS402664)
However, obtaining actual gear from them might prove tricky: Evergreen's postal address points to a flower shop in Vicksburg, Mississippi, while its domain, evergreenhorizonoutdoorcampinggear[.]com, merely displays a Namecheap default site at the time of writing. Perhaps they are currently enjoying summer vacation, testing their products? ๐ค
Should you require IPv6 address space while traveling, Evergreen for sure has you covered: AS402664 currently announces no fewer than five /29 prefixes; IPv6 stockpiling comes to mind: ๐๏ธ https://t.co/7EqT5rWgHN
Its upstream seems quite travel-experienced as well: Despite providing a postal address in ๐บ๐ธ Denver, Colorado, Nexus Telecom LLC (AS24062) has its ARIN database records' country set to ๐ฒ๐พ Malaysia.
It reminds us of "Sweet Dreams" ๐ถ by Eurythmics: "[...] some of them want to abuse you [...]" - Enjoy summer, and keep an eye out for suspicious ISPs! ๐ต๏ธ
#OSINT #IPv6
๐ช Contributor "FQ02" has made 1,028 raw source code submissions over the past 30 days ๐ฅ Thatโs a +51,300% increase, landing them in the Top10 on the leaderboard! Incredible work!
Contributor FQ02, don't forget to claim your name - it only takes a few minutes.
Login here to review your 'Display Name' ๐ https://t.co/XIn5BD7ijQ
Got malicious or suspicious IPs, domains, URLs, or raw source to share?
๐ Join the fight against cybercrime: https://t.co/Zy2YtyIac2
#CyberSecurity #ThreatIntelligence #ThreatHunting #Infosec
We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam ๐ง, first observed on August 1, 2026 ๐ญ๐
Key Capabilities โคต๏ธ
๐ต๏ธ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners ๐ธ
๐ Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) ๐ฎ
๐ค AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session cookies ๐ช
๐ฐ Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet ๐
Artifacts observed โคต๏ธ
1๏ธโฃ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log
2๏ธโฃ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication
HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed โคต๏ธ
๐ก 31.40.204.178:7080 WhiteLabel ๐น๐ท
๐ก 94.26.3.211:7443 Stellar Group SAS ๐ซ๐ท
๐ก 192.109.139.91:7443 Stellar Group SAS ๐บ๐ธ
๐ก 195.177.94.60:7443 Stellar Group SAS ๐ซ๐ท
๐ก 107.175.148.122:7443 HostPapa ๐บ๐ธ
๐ก 209.54.103.173:7443 HostPapa ๐บ๐ธ
๐ก 132.243.225.173:7080 QWINS-Hosting ๐ฉ๐ช
๐ก 78.40.209.113:7081 QWINS-Hosting ๐ซ๐ฎ
๐ก 31.77.138.55:5654 QWINS-Hosting ๐ซ๐ฎ
๐ฆ Releated IOCs on ThreatFox:
https://t.co/X0S6ihaSXz
๐ Releated malware samples on MalwareBazaar:
https://t.co/bdXcPm9i6e
๐ค Ever wondered what happens after you report a phishing link, suspicious domain, or malicious looking IP?
We check the resources you submit against Spamhaus reputation data. If thereโs a match, youโll see it reflected in your Threat Intel Community dashboard.
Once logged in, you can:
๐ Track your contributions over the last 30 days
โ ๏ธ See how many matched known threats
๐ฉ Report suspicious activity directly
๐ Submit at scale via API
...and donโt forget the leaderboards where you can see how your contributions stack up against the rest of the community.
Every submission helps strengthen the intelligence used by CERTs, CSIRTs, and security teams around the world to identify and take action against malicious infrastructure.
Join the community and turn what youโre seeing into intelligence that helps protect others.
๐ https://t.co/wqsZ8IUqLQ
#ThreatIntelligence #CyberSecurity #Spamhaus #InfoSec #CommunityDefense
Hat tip to @soverinteam for alerting us to this activity. We are contacting Google and now actively listing the compromised domains.
Is anyone else seeing this activity originating from compromised Google Workspaces? If so, please share any suspicious domains with us via the #ThreatIntel Portal ๐๏ธ https://t.co/c0zdOt0TUi
3/3
โ๏ธ A large number of @GoogleWorkspace accounts are being compromised and used to send #phishing and #scam emails - see screenshot attached.
Weโve observed the same target domain across multiple #spam campaigns.
Education appears to be particularly affected. So far, weโve identified 450+ compromised education domains using Google Workspace - although the activity isnโt limited to this sector.
1/3
Initially, the spam pointed to the same domain, but weโre now seeing links hosted directly on IP addresses and URLs masked through services that can resolve to different IPs. One example follows the pattern 1-2-3-4[.]cprapid[.]com, although a range of more obscure domains and hosting providers are being used.
Weโre also seeing Google Drawings being used as an intermediary: the drawing contains an image and a link that redirects the recipient to the target.
2/3
Over the past days, active #malspam campaigns targeting LatAm users ๐ฆ๐ท๐ง๐ท๐ฒ๐ฝ have been delivering the Grandoreiro banking trojan ๐ฆ๐ฐ
๐ง Email โ ๐ JS file โ ๐ Fake PDF download
Final payload is hosted on MediaFire ๐ฅ free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent ๐ฅ๏ธโคต๏ธ
User-Agent: Embarcadero URI Client/1.0
๐ Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com ๐
๐ก Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
๐ Payloads URLs:
https://t.co/Q73Q0GNtfh
๐ Malware samples:
https://t.co/ihQKiwQt8t
๐ฆ Relevant IOCs are available on ThreatFox:
https://t.co/M3qnAFJkCN
๐ค Not using Spamhaus' DROP lists already?
You can access them for FREE and gain protection against the worst of the worst IP traffic at the routing level.
Lists are available for IPv4, IPv6 and ASN filtering:
โก๏ธ https://t.co/VmclctN5Vm
#CyberSecurity#ThreatIntel #NetworkSecurity #Infosec
3/3
โHere's the most recent additions to Spamhaus DROP (Do Not Route or Peer) list - including hijacked IPs, suspected snowshoe spam and cybercrime hosting โคต๏ธ
1/3
Understanding malicious domain registration data requires looking beyond the numbers. A new #ICANN blog examines the distinction between reported and confirmed #DNSAbuse, the scope of ICANNโs definition, and the importance of methodology and context.
Read more: https://t.co/KoXR1HkmNJ
NSA joins the @FBI and others in releasing a joint Cybersecurity Advisory, โ#StopRansomware: Gunra Ransomware,โ as an ongoing effort to publish information about various ransomware variants and threat actors. Learn more: https://t.co/1gi9DRjwdY
๐จ New entrant alert: Stark Industries Solutions debuts at #2 for newly observed botnet C&Cs between Jan and Jun 2026, with 931 detections in just six months. This ๐ฌ๐ง UK-registered host is widely assessed to be ๐ท๐บ Russian-operated bulletproof hosting, and it's now on Spamhaus's DROP and ASN-DROP lists.
Network operators: treat traffic to/from this ASN accordingly โ ๏ธ
Read the full report๐
https://t.co/VJO4al9sbq
#BotnetCC #BulletproofHosting #ThreatIntel
Spamhaus keeps observing internet abuse involving dangling CNAME DNS records, a threat we first highlighted in 2024: ๐๏ธ https://t.co/BxUeLF9igj
One particular, long-standing threat actor is currently disseminating snowshoe spam from about 2.5k IPv4 addresses, leveraging dangling CNAMEs. While our CSS and DBL datasets cover this campaign, our ticketing team encounters a steady stream of domain owners (whose dangling CNAMEs are actively abused) wondering why their legitimate domains' reputation deteriorated. ๐ง
If you oversee an organizations' domain petting zoo, we strongly recommend implementing (in addition to the robust monitoring, compliance and internet asset decommissioning procedures you undoubtedly have in place ๐) periodic checks against Spamhaus DBL โ particularly for domains outside your control, such as third-party services used as CNAME targets. Any DBL listing indicates an ongoing abuse incident, and should prompt an investigation.
Your help in draining the swamp of orphaned internet infrastructure prone to abuse is greatly appreciated โ every deleted dangling DNS record helps! ๐
#TicketDeskTales #DomainReputation #Cybersecurity #DNS