Today we're launching urlscan Brand AI within our urlscan Pro portal. Brand AI will visually examine websites to determine the name of the brand the website claims to represent, a more robust approach than text-based queries. Read the details in our blog: https://t.co/rNSL8HBFHS
Oriental Gudgeon ("CoGUI") is a structured phishing kit built on reusable components, storage artifacts, and API-driven workflows.
Designed for scale and persistence across campaigns.
Detection details inside ๐
Public reporting: https://t.co/pCAmH0iNBB - More on urlscan Pro
New TI report ๐ท
Chenlun (โOutsiderโ) is a feature-rich phishing kit using modern web frameworks, verification flows, and anti-bot techniques.
A step up in sophistication across Chinese Phishing-as-a-Service ecosystems.
Full analysis + detections ๐ท
https://t.co/xCeiZZZ37e
๐ธ๐ฆ ๐ฎ๐ท ๐ก๐ฒ๐ ๐ ๐ถ๐ฑ๐ฑ๐น๐ฒ ๐๐ฎ๐๐ ๐บ๐ฎ๐น๐ถ๐ฐ๐ถ๐ผ๐๐ ๐ถ๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐: ๐ญ,๐ฏ๐ฑ๐ฌ+ ๐๐ฎ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ๐ ๐ ๐ฎ๐ฝ๐ฝ๐ฒ๐ฑ ๐๐ฐ๐ฟ๐ผ๐๐ ๐ต๐ด ๐ฃ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ๐
Over a three-month window, we mapped more than 1,350 active C2 servers operating across 98 infrastructure providers in 14 Middle Eastern countries, covering telecoms, shared hosting, and VPS environments.
๐ Read the full report: https://t.co/Bnfwe2Yufq
Here's what the data shows:
โ A single telecom carrier accounts for nearly 72% of all detected regional C2 activity, most of it tied to compromised customer endpoints rather than provider-level abuse
โ C2 infrastructure makes up over 96% of all observed malicious artifacts in the region
โ Tactical RMM leads the malware family breakdown with 92 unique C2 IPs, followed by Keitaro TDS (71) and Acunetix (38)
โ The malware mix covers a wide range of attack types - IoT botnets (Mozi, Hajime, Mirai), remote access tools (AsyncRAT, Sliver, Cobalt Strike), active scanning (Acunetix), and phishing infrastructure (Gophish, Keitaro TDS)
โ Campaigns in the dataset include Eagle Werewolf espionage operations, the DYNOWIPER destructive campaign targeting Poland's energy sector, and RondoDox botnet exploitation infrastructure on Iranian hosting
The main takeaway is that malicious infrastructure in the region is not evenly spread. A small set of providers keeps showing up across unrelated campaigns and malware families, which is where the tracking value is.
Provider-level visibility is what lets defenders get ahead of that pattern, rather than reacting to individual indicators that rotate daily.
Full breakdown, including infrastructure observables, HuntSQL queries, and campaign examples, is in the report ๐
https://t.co/Bnfwe2Yufq
This is a much smaller Chinese phishing framework๐จ๐ณ
๐ชI bet you won't have heard of it before!
๐What makes this notable is the targeting of Chinese companies by the framework๐
๐ฏThis is a Pro only report
โ๏ธReach out to sales@ if you are not on the pro platform!
New TI report on urlscan Pro ๐ท
Flyfish is a lightweight phishing kit built around simple but effective API endpoints.
Despite its simplicity, itโs actively used for large-scale victim interaction and data capture.
Detection patterns included ๐ท
https://t.co/xCeiZZZ37e
๐จ NEW RESEARCH: TeamPCP's C2 fallback needs no attacker infrastructure.
@wiz_io covered the delivery and flagged some payload behavior (great job!). However, nobody went deeper into the full toolkit itself, the GovCloud targeting, or the infrastructure. We did.
Full analysis, IOCs, HuntSQL queries, and MITRE mapping: https://t.co/uRx7aPDML3
Last week we hosted a hands-on workshop at @pivot_con in Mรกlaga. Participants learned how to hunt and cluster web-based phishing activity using our urlscan Pro platform. If you did not manage to get in, just send us a message and we'll give you a private tour of the platform!
New report: Darcula (โMagic Catโ) is one of the most active phishing frameworks weโre tracking.
From API-driven infra to socket-based comms and fake shop deployments, this kit continues to evolve rapidly.
Breakdown, detections: https://t.co/jnu2zKf8QL
Full report on urlscan Pro
New urlscan report ๐จ
Weโre kicking off our Chinese phishing series with a deep dive into the Sailor framework.
A modular kit leveraging client-side storage for session tracking and victim management at scale.
Detection included ๐
https://t.co/pJ00o12FtW
๐จ NEW RESEARCH: xlabs_v1 DDoS-for-Hire IoT Botnet Exposed - One Open Directory. An Entire Operation Revealed.
https://t.co/Iutpdqpw2r
The operator built a full commercial DDoS-for-hire operation. Tiered pricing, 21 flood variants, competitor-killing routines baked in.
Then left the whole toolkit on a public server with no login. https://t.co/aojFWxKETZ AttackCapture tool had it indexed before they noticed.
Key findings:
- Botnet branded xlabs_v1, operator handle Tadashi, targeting game servers and Minecraft hosts
- 21 flood variants including RakNet and OpenVPN-shaped UDP to dodge common filters
- TCP/5555 observed open on 4M+ hosts in the past 180 days, any running ADB is a potential target
- ChaCha20 encryption broken via known-plaintext, full nonce reuse across all 16 calls
- C2, staging, distribution, and Monero cryptojacking all inside one bulletproof /24 in the Netherlands
๐ Full IOCs, MITRE mapping, and HuntSQL queries: https://t.co/Iutpdqpw2r
This is going to be huge ๐งจ
๐Myself and the team worked so hard on these. It is going to uncover and expose the true scale of multiple frameworks
Watch this space...
New urlscan Pro Threat Intel Report: We uncovered 7 distinct phishing kit clusters hiding behind Calendly-themed lures. Same brand, very different tooling & infrastructure. The report includes hunting queries & technical fingerprints for defenders.
New research drop ๐จ
We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th:
https://t.co/mJfli7zYHI
๐จ ๐ท๐บ We tracked 1,252 active C2 servers across 165 Russian hosting providers over 90 days.
Here's what's running inside those networks.
C2 traffic accounts for 88.6% of all observed malicious artifacts. The rest splits between malicious open directories (5.3%), phishing infrastructure (4.9%), and public IOCs (1.2%).
The hosting concentration is notable:
- TimeWeb leads with 311 C2 detections
- WebHost1 follows with 140, REG[.]RU with 138
- PROSPERO OOO hosts 80 C2s alongside 30 malicious open directories and 50 phishing sites
- Yandex[.]Cloud carries the widest malware diversity: 11 distinct families across 39 C2 endpoints
On the malware side:
- Keitaro dominates with 587 unique C2 IPs
- Hajime (191), Mozi (48), and Mirai (13) show IoT botnet infrastructure is still active
- Cobalt Strike, Sliver, and Ligolo-ng are all present across the ecosystem
Specific campaigns tied to this infrastructure include Latrodectus via ClickFix on TimeWeb, Lumma Stealer on REG[.]RU, Remcos RAT via SmartApeSG on Hosting Technology LTD, and intrusion activity attributed to Head Mare inside LLC Smart Ape.
Full research with Host Radar breakdowns and HuntSQL queries ๐
https://t.co/beGsn80vxO
#ThreatHunting #ThreatIntelligence #C2 #Malware #CyberSecurity
TAs are weaponising client-side proxy frameworks like Ultraviolet & Scramjet to deliver stealthy phishing campaigns that evade traditional detection. Our latest urlscan Pro report covers techniques, artifacts, and detection strategies for this new threat: https://t.co/xCeiZZZ37e
New urlscan Pro Threat Intel Report: We uncovered 7 distinct phishing kit clusters hiding behind Calendly-themed lures. Same brand, very different tooling & infrastructure. The report includes hunting queries & technical fingerprints for defenders.