🕷️ This IP is more interesting than it looks.
We found a tunneling-focused infrastructure stack containing:
wstunnel → WebSocket tunneling
OpenVPN → persistent connectivity
certbot-ip → HTTPS/WSS certificates
tunpanel → tunnel management
Vultr → cloud infrastructure
The combination suggests a deliberate focus on encrypted tunneling, proxying and perimeter evasion.
Our current hypothesis: potential Scattered Spider / UNC3944 infrastructure.
But don't take our word for it.
🔎 Investigate the IP + connected infrastructure:
👉 https://t.co/BqJp7Vo9jZ
See the relationships, artifacts, timeline, and attribution evidence in the portal.
One IP. Multiple connections. Follow the infrastructure.
#ThreatIntel #UNC3944 #ScatteredSpider #CyberSecurity #Threatactix
‼️🇺🇸 U.S. Bank has been claimed a victim to LockBit Ransomware
🇺🇸 U.S. Bank - A U.S.-based financial institution providing banking, lending, payments, investment, credit, and wealth-management services to individuals, businesses, and institutions.
The listing was posted by LockBit 5.0 with a deadline of September 4, 2026 for the claimed stolen files to be released.
We track infrastructure like this daily — new C2 servers are added constantly.
If you're an MSSP or research team that wants earlier visibility into activity like this, check out our Threat Actor Intelligence Portal.
🚨 Threat Intel Alert: We discovered a threat actor's open C2 repository actively targeting Internet-facing CCTV/NVR systems.
Inside: PoC exploits, Sliver C2, WP2Shell, Nuclei scan templates + AI-assisted exploit code.
Surveillance infra is now a target, not just enterprise apps. 🧵👇
Repo also contained WireGuard tunneling, NTLM hash harvesting via CVE-2025-24071, and Nuclei templates for automated large-scale scanning — a near-complete attack chain from recon to post-exploitation.
Full technical breakdown 👉https://t.co/0U6xUzyXpi
#Opendir found at http://114[.]215[.]207[.]150:8999/ with Inject_tool.exe
The main IP is 114.215.207.150, located in Hangzhou, China and belongs to ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd., CN. The main domain is 114.215.207.150.
@cyberfeeddigest@ShanHolo@BlinkzSec@midnight_comms@ch3tanK
#Opendir found with Phishing C2 as Gophish at http://34[.]79[.]236[.]195:8888/
The main IP is 114.215.207.150, located in Hangzhou, China and belongs to ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd., CN
@cyberfeeddigest@ShanHolo@BlinkzSec@midnight_comms@ch3tanK
Interesting files at Directory listing for /.config/google-chrome/
#Opendir found with Phishing C2 as Gophish at http://34[.]79[.]236[.]195:8888/
The main IP is 114.215.207.150, located in Hangzhou, China and belongs to ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd., CN
@cyberfeeddigest@ShanHolo@BlinkzSec@midnight_comms@ch3tanK
Interesting files at Directory listing for /.config/google-chrome/
#Opendir found at http://114[.]215[.]207[.]150:8999/ with Inject_tool.exe
The main IP is 114.215.207.150, located in Hangzhou, China and belongs to ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd., CN. The main domain is 114.215.207.150.
@cyberfeeddigest@ShanHolo@BlinkzSec@midnight_comms@ch3tanK
4. We discovered new toolsets that are related to AI and ML enhancement in their vulnerability scanning and exploitation patterns.
1. Red-Ultra or Red-Enhanced-Scanner
2. Nexus–inspired by combining DOFFS BOT with Nexus-inspired scanning techniques
3. Pulsar-V2 – This tool is enhanced with Grok AI capabilities
🚨 XWorm cybercrime ecosystem - Cybercriminals are no longer just writing malware — they’re augmenting it with AI capabilities, making threats more adaptable, stealthy, and scalable.
Our latest research highlights how attackers are now pairing traditional malware ecosystems with AI-powered tooling — dramatically increasing efficiency, precision, and reach.
https://t.co/7t5MGU2wel
#CyberSecurity #ThreatIntel #MalwareDev #AI #InfoSec @TheHackersNews@BleepinComputer@hackinarticles@TheCyberSecHub@ch3tanK@Threatactix
“Thread 🧵”
3. Why were these tools so effective? this IAB used 5 AI toolsets to enhance vulnerability and scanning activities. By embedding these tools in the workflow, the attacker used Machine Learning and AI capabilities to improve the tools’ performance. Also, we have discovered AI like Grok used first time for a new tool named ‘Pulsar’.
1. Grok – used in the new tool name Pulsar
2. Anthropic – Claude used in the OneForAll tool-[ Earlier in Anthropic also shared threat intelligence, but we believe this could be another threat actor ]
3. https://t.co/Vo50COgBk5 – used in a new scanner named Red-ultra-scanner-project
4. https://t.co/ygsx9Lm6F0
5. https://t.co/T2ucV1i46H