A sandbox for websites - Find malicious websites and phishing - status.urlscan.io - urlscan.io/blog/ - #threatintel #cybercrime #infosec #web #phishing

The Cloud
Today we're launching urlscan Brand AI within our urlscan Pro portal. Brand AI will visually examine websites to determine the name of the brand the website claims to represent, a more robust approach than text-based queries. Read the details in our blog: urlscan.io/blog/2025/07/30/bโ€ฆ
1
28
95
11,822
urlscan.io retweeted
๐Ÿšฉ ๐—ง๐—ต๐—ฎ๐—ถ ๐—ฏ๐—ฟ๐—ผ๐—ฎ๐—ฑ๐—ฏ๐—ฎ๐—ป๐—ฑ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ๐—ฟ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜๐—ฒ๐—ฑ ๐˜ƒ๐—ถ๐—ฎ ๐—™๐—ผ๐—ฟ๐˜๐—ถ๐—š๐—ฎ๐˜๐—ฒ ๐—ฆ๐—ฆ๐—Ÿ-๐—ฉ๐—ฃ๐—ก ๐—ฎ๐—ป๐—ฑ ๐— ๐—ฒ๐˜€๐—ต๐—–๐—ฒ๐—ป๐˜๐—ฟ๐—ฎ๐—น An operator left their staging server open on Thai infrastructure. AttackCapture caught it while the intrusion was still live. Inside was the full picture of an attack against one of Thailand's largest fixed-line broadband providers. 298 files, 30 subdirectories, 19 MB. Recon scripts, exploits, brute-force tooling, a live MeshCentral config, and an inventory of machines the operator already controlled. What the toolkit shows: - CVE-2024-21762 used against a FortiGate 60F SSL-VPN, from fingerprinting to full RCE - MeshCentral set up as a backdoor, agents pointed at the operator's own management server under a dedicated device group - devices.json confirms multiple hosts were enrolled and connected at capture time, agents running as root - The provider's RADIUS databases targeted to pull subscriber credentials - A valid OpenVPN certificate from the provider's own PKI, giving persistent access to the network - A cleanup script staged to wipe logs and exploit files while leaving the MeshCentral agent in place Active session cookies for a second, linked provider point to a parallel operation, so this was not a single-org hit. Full breakdown, IOCs, and MITRE mapping here ๐Ÿ‘‡hunt.io/blog/thai-broadband-โ€ฆ
14
47
4,444
urlscan detected a Mouse System site dropping a malicious ShellA Loader APK, analyzed by Intel471. As traditional phishing pages slow on these Chinese frameworks, threat actors may now be shifting to delivering malicious APKs through the same channels. urlscan.io/pricing/urlscanprโ€ฆ
8
13
1,933
urlscan.io retweeted
๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿค– ๐—ก๐—˜๐—ช ๐—ฅ๐—˜๐—ฆ๐—˜๐—”๐—ฅ๐—–๐—›: ๐—–๐—ต๐—ถ๐—ป๐—ฒ๐˜€๐—ฒ-๐—ฆ๐—ฝ๐—ฒ๐—ฎ๐—ธ๐—ถ๐—ป๐—ด ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ ๐—จ๐˜€๐—ฒ๐˜€ ๐—”๐—œ ๐—”๐—ด๐—ฒ๐—ป๐˜๐˜€ ๐˜๐—ผ ๐—ง๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜ ๐—š๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ฎ๐—ป๐—ฑ ๐—˜๐—ฑ๐˜‚๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€ ๐—”๐—ฐ๐—ฟ๐—ผ๐˜€๐˜€ ๐—”๐˜€๐—ถ๐—ฎ Our research team identified five exposed open directories revealing a campaign that used an orchestration framework called SecFlow to coordinate Claude, Qwen, and DeepSeek AI workers across intrusions targeting government, education, consular, and healthcare systems in Asia. Key observations: - A shared SOCKS endpoint connected all five workspaces, confirmed through 120 code-search matches on our platform - The deepest compromise hit a Fengtai District government OA environment: command execution, LSASS dumps, registry hives, 822 account records extracted, and a Go implant called SecBox deployed - A Chinese education AI platform was compromised, exposing 23 agent configurations, production credentials, and student profile data across 169 conversations - SecFlow split reconnaissance, exploitation, and reporting across specialist AI workers, with the runtime swapping between Claude, Qwen, and DeepSeek without changing the task interface - GLUTTON webshells transported executable bytecode inside PNG image pixels using XOR encryption, loading directly into memory while the visible server file remained a generic decoder - A fake MySQL deserialization service delivered Linux second-stage payloads to vulnerable Java clients that connected to it - Eight CVEs in active workflows, including Shellshock, Spring4Shell, Ghostcat, Log4Shell, Shiro deserialization, Grafana and Nexus path traversals, and Nacos authentication bypass - The AI's shared context amplified a false positive: an unsupported Shiro success claim persisted and drove 27+ follow-up tasks that produced nothing This is the second separate campaign we've tracked where commercial AI models were used as operational components in intrusions. Different infrastructure and tooling from our July report, but the same pattern. Read the full report here๐Ÿ‘‡ hunt.io/blog/chinese-operatoโ€ฆ
17
59
6,308
This Pro-only Intel Brief is now available on our public blog in a slightly redacted form. Check it out: urlscan.io/blog/2026/09/03/Fโ€ฆ
We pivoted on NS infrastructure to uncover a UK banking phishing network powered by two central panels: FastFlux and FluxPanel. Pages prompt victims for a 6-digit code provided by a phone "advisor" to trigger downloads of a RAT disguised as verification. Report on urlscan Pro.
9
12
1,672
Really cool use of the limited space in the urlscan Pro UI. Use a flip effect to show more metadata about a scan before you open it. Reach out to us if you'd like to take the urlscan Pro platform for a spin.
5
15
991
We pivoted on NS infrastructure to uncover a UK banking phishing network powered by two central panels: FastFlux and FluxPanel. Pages prompt victims for a 6-digit code provided by a phone "advisor" to trigger downloads of a RAT disguised as verification. Report on urlscan Pro.
6
12
4,726
urlscan.io retweeted
๐ŸŽฅ Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia NEW RESEARCH: A single operator left their entire working directory exposed on an open HTTP server. We crawled it and recovered 2,616 files, 407 MB, the full toolkit behind a 35-day camera-compromise campaign. The scanning ran global, but the confirmed compromises landed in ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine and ๐Ÿ‡ท๐Ÿ‡บ Russia, with Ukraine holding the largest share. What we found: โ†’ 14,530+ devices compromised in 35 days, the brute-force engine alone reaching 12,324 unique addresses โ†’ 1,923 cameras carrying a persistent backdoor account installed over RPC, surviving a password change and, on most firmware, a factory reset โ†’ 283 cameras reached by serial number alone through the cloud relay, most requiring no authentication to open a channel โ†’ A separate Windows stealer staged on the same host, unrelated to the camera activity โ†’ The toolkit assembled from at least six upstream developers' work, not authored from scratch We assess with moderate confidence the toolkit was built to hand access to a third party, based on its transferable recovery-code design and enterprise-format export pipeline. Full breakdown, indicators, and mitigations ๐Ÿ‘‡ hunt.io/blog/operation-camerโ€ฆ
21
48
10,602
This report is now available on our public blog as well: urlscan.io/blog/2026/08/17/Iโ€ฆ
New Research: Weโ€™ve uncovered two active phishing clusters (GSVerify & Knock) targeting YouTube creators with fake copyright strike lures and advanced Browser-in-the-Browser (BitB) Google login modals. The detailed report is available on urlscan Pro.
12
21
2,875
urlscan Pro University is officially LIVE! Master urlscan search through hands-on challenges - from basic to advanced Discover typosquat detection, threat verdicts, and phish hunting. Solve challenges, submit flags, track your progress. pro.urlscan.io/university
32
126
9,211
urlscan.io retweeted
๐Ÿ‡ท๐Ÿ‡บ ๐—œ๐—ป๐˜€๐—ถ๐—ฑ๐—ฒ ๐—ฎ ๐—ฅ๐˜‚๐˜€๐˜€๐—ถ๐—ฎ๐—ป-๐—ฆ๐—ฝ๐—ฒ๐—ฎ๐—ธ๐—ถ๐—ป๐—ด ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ'๐˜€ ๐—ง๐—ผ๐—ผ๐—น๐—ธ๐—ถ๐˜ ๐—ณ๐—ผ๐—ฟ ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ถ๐—ป๐—ด ๐—จ๐—ธ๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ฎ๐—ป ๐—œ๐—ฃ ๐—–๐—ฎ๐—บ๐—ฒ๐—ฟ๐—ฎ๐˜€ Our research team pulled apart two open directories and reconstructed how one operator found, exploited, and watched internet-exposed cameras across Ukraine. The whole toolkit was sitting in the operator's own files. What we found: โ†’ Two open directories recovered through our Attack Capture system, exposing the operator's own tooling and workflow โ†’ A custom project (the operator named it camview) that wraps the open-source Ingram scanner to exploit Hikvision and Dahua devices โ†’ The operator's own logs of live viewing sessions, 58 Ukrainian cameras opened as live video, not exposure inferred from a scan โ†’ Bash history capturing Tor-routed attempts against Ukrainian government and military sites, outcomes not confirmed โ†’ A second, separately run directory, tied to the first only by the shared scanner, building SOCKS5 proxies from compromised routers across 15 European countries โ†’ No state attribution. The value is the host-level view of how these camera operations get built and run Full breakdown and IOCs here ๐Ÿ‘‡ hunt.io/blog/russian-speakinโ€ฆ
16
30
2,872
There's a new public blog post about a phishing framework targeting multiple brands from the financial services sector. Check it out to understand how we hunt for threats using the urlscan Platform: urlscan.io/blog/2026/08/04/Pโ€ฆ
2
1
719
New Research: Weโ€™ve uncovered two active phishing clusters (GSVerify & Knock) targeting YouTube creators with fake copyright strike lures and advanced Browser-in-the-Browser (BitB) Google login modals. The detailed report is available on urlscan Pro.
8
21
4,778
urlscan.io retweeted
Interested in learning about How AI can Help Detect Modern Web-based Threats? Johannes Gilger, CEO of @urlscanio, will join us on #ThursDef tomorrow at 12:30pm CT! Secure your spot โ€“ register here: thursdef.com #ThursdayDefensive #cybersecurity #infosec
2
2
441
urlscan.io retweeted
๐Ÿ‘ป Open Directory Stages NGINX Rift and Ghost CMS Exploits, Targeting 11 Countries We found an open directory on a Singapore VPS (165.154.236[.]93): an attack server that was also set up to receive reverse shells. One host, seven exploits, wired to verify its own blind attempts over DNS callbacks. On the box: - NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and Ghost CMS blind SQLi (CVE-2026-26980) - Splunk, PaperCut, Samba, WebLogic, D-Link NAS tooling alongside them - OOB DNS callbacks to per-target subdomains to check whether blind attempts landed - A full AdaptixC2 build and SuperShell install files - Country and sector target lists: government, universities, healthcare, finance across 11 countries Simplified Chinese comments and the use of Goby and Supershell suggest an operator comfortable with the language. That is a comfort signal, not attribution or a state nexus. ๐Ÿ‘‰ Full research: hunt.io/blog/open-directory-โ€ฆ #nginx #ghostcms #threatintel #threathunting #cybersecurity #opendir
5
23
1,622
urlscan.io retweeted
Mark your calendars!
2
12
26
2,632
urlscan.io retweeted
๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿค– ๐—ฆ๐˜‚๐˜€๐—ฝ๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—–๐—ต๐—ถ๐—ป๐—ฒ๐˜€๐—ฒ ๐—ผ๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ๐˜€ ๐˜„๐—ถ๐—ฟ๐—ฒ๐—ฑ ๐—–๐—น๐—ฎ๐˜‚๐—ฑ๐—ฒ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐——๐—ฒ๐—ฒ๐—ฝ๐—ฆ๐—ฒ๐—ฒ๐—ธ ๐—ถ๐—ป๐˜๐—ผ ๐—ฎ ๐—น๐—ถ๐˜ƒ๐—ฒ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ถ๐—ป๐˜๐—ฟ๐˜‚๐˜€๐—ถ๐—ผ๐—ป ๐—ฐ๐—ฎ๐—บ๐—ฝ๐—ฎ๐—ถ๐—ด๐—ป In June 2026, a pivot off known TencShell C2 infrastructure covered by Cato Networks, led our research team to an open directory exposing an active intrusion. Inside were victim source code, custom exploits, operator logs, and cloned login pages, with the attack notes written in Simplified Chinese. The part that caught our attention was the tooling. Claude Code and DeepSeek-v4-pro were running as working parts of the operation, not sitting off to the side. What we found: โ†’ Claude Code handled execution and session persistence while DeepSeek-v4-pro drove the reasoning, a split documented across the recovered logs โ†’ Hands-on exploitation of government systems in Afghanistan, Thailand, and Taiwan, plus recon and staged phishing against U.S. government portals โ†’ A single HTTP header fingerprint pivoted out to 13 Hong Kong servers across four ASNs โ†’ Scanning of 5,890+ government hosts across 10 countries with a custom Python scoring script โ†’ A parallel run at financial services firms across Europe, Australia, and Asia โ†’ A likely second C2 framework, Gshell, with no prior public reporting we could find This lines up with Anthropic's November 2025 disclosure of a China-linked operation that leaned on Claude Code for large-scale intrusions. ๐Ÿ‘‰ Read the full research and IOCs: hunt.io/blog/chinese-operatoโ€ฆ
36
95
8,484
urlscan.io retweeted
๐—›๐˜‚๐—ป๐˜ ๐Ÿฏ.๐Ÿฌ ๐—ถ๐˜€ ๐—น๐—ถ๐˜ƒ๐—ฒ. ๐—ฃ๐˜‚๐—น๐—น ๐˜๐—ต๐—ฒ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐—ฑ. ๐Ÿš€ Most threat hunting tools stop at the lookup. You get a result, maybe a tag, and then you're on your own figuring out what connects to what. We built v3 to fix that. Every indicator, whether it's an IP, a domain, or a hash, should open into the full picture automatically. ๐Ÿ‘‰ Here's what's new: hunt.io/blog/introducing-hunโ€ฆ โ†’ 60+ API endpoints across C2, AttackCapture, Vulnerability Intel, SQL, and more โ†’ Remote MCP server, connect Claude or other AI tools straight to Hunt data โ†’ Cloudflare Buster turns one domain into a full infrastructure cluster โ†’ Passive DNS History gives you a real timeline of DNS changes, not just a point-in-time snapshot โ†’ Attack Reports turns exposed attacker directories into structured campaign reports, tied to specific IPs, IOCs, and CVEs โ†’ Exploit Capture indexes 54,000+ AI-classified files staged in attacker open directories right now โ†’ Provider Radar now includes Registrar intelligence, catching domain provisioning patterns before those domains go live in an attack โ†’ Flattened data architecture so HuntSQL joins are finally possible, no workarounds โ†’ And much more! And the best part: you get 14 days free, no credit card needed. Open an account and start hunting today ๐Ÿ‘‡ portal.hunt.io/sign-up
1
19
27
4,429
New TI report ๐Ÿšจ Mouse System ("Phoenix" / "Haozi") is a full-feature phishing platform with admin panels, tokenised APIs, and modular campaign management. One of the more mature ecosystems we've tracked. Analysis + detections ๐Ÿ‘‡ urlscan.io/pricing/urlscanprโ€ฆ
7
14
1,503
New report ๐Ÿšจ CY-Kit leverages socket-based communication and structured config files to manage phishing workflows. A flexible framework built for scalable campaign execution. The report is available on our public blog: urlscan.io/blog/2026/06/22/Cโ€ฆ
5
20
2,542
urlscan.io retweeted
๐Ÿ‡ฎ๐Ÿ‡ท ๐—”๐—ฏ๐—ฎ๐—ฏ๐—ถ๐—น ๐—ผ๐—ณ ๐— ๐—ถ๐—ป๐—ฎ๐—ฏ ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ: ๐—Ÿ๐—” ๐— ๐—ฒ๐˜๐—ฟ๐—ผ ๐—ฆ๐—–๐—”๐——๐—” ๐—•๐—ฎ๐—ฐ๐—ธ๐˜‚๐—ฝ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—œ๐˜€๐—ฟ๐—ฎ๐—ฒ๐—น๐—ถ ๐—ฉ๐—ถ๐—ฐ๐˜๐—ถ๐—บ ๐——๐—ฎ๐˜๐—ฎ ๐—Ÿ๐—ฒ๐—ณ๐˜ ๐—ข๐—ฝ๐—ฒ๐—ป ๐—ผ๐—ป ๐—ฎ๐—ป ๐—œ๐—ฟ๐—ฎ๐—ป๐—ถ๐—ฎ๐—ป ๐—ฆ๐˜๐—ฎ๐—ด๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ A pro-Iranian group called Ababil of Minab claimed destructive intrusions against targets in the US, Israel, Saudi Arabia, and Turkey, including a breach LA Metro confirmed in April. A later public report described the campaign but held back the rest of the victims. We found the operator's staging server sitting wide open and read the list ourselves. What AttackCapture captured at 5.255.127[.]55:8020: โ†’ 2,238 files across 545 subdirectories, around 5 GB of exfiltrated data โ†’ Over 1 GB of LA Metro SQL Server backups covering transit ops, personnel records, SCADA configs, and yard management โ†’ Named victims the public report withheld: Ruppin Academic Center, bac(.)org(.)il, adabroker(.)com(.)tr, courier(.)co(.)il, Ifat Media Group โ†’ The custom Flask receiver, the operator's bash history, plaintext Chrome password dumps, VPN credentials, and switch configs โ†’ A 404 handler that quietly redirected to fbi(.)gov to look harmless The server stayed up for at least four weeks, into late May, after the public report dropped and after the group went quiet on Telegram. That mistake handed us the full picture. Full research here ๐Ÿ‘‡: hunt.io/blog/ababil-of-minabโ€ฆ
1
16
29
3,781