UAT-11795
Reports
4
First seen
Jul 16, 2026
Last seen
Jul 16, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×2×2
United States×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×3T1059.001 PowerShell ×3T1566.002 Phishing: Spearphishing Link ×2T1005 Data from Local System ×2T1562.001 Impair Defenses: Disable or Modify Tools ×2T1003 OS Credential Dumping ×2T1547.001 Registry Run Keys / Startup Folder ×2T1027 Obfuscated Files or Information ×2T1204 User Execution ×2T1555 Credentials from Password Stores ×1T1136 Create Account ×1T1041 Exfiltration Over C2 Channel ×1
Indicators
filename ×16domain ×11hash_md5 ×4hash_sha256 ×4cve ×3ethereum_address ×1ip_v4 ×1registry_key ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High