PULSE NAME
REFUNDEE: Inside a Shadow Panel Phishing-as-a-Service Operation
WHITE AlienVault 2026-04-13 Modified: 2026-04-13
37
IOCs
MEDIUM VOLUME
An open directory discovery at refundonex[.]com exposed a complete Phishing-as-a-Service and RAT-as-a-Service platform targeting Spanish and Portuguese-speaking victims. The investigation uncovered 3,788 files including weaponized LNK, VBS, and AES-encrypted PowerShell payloads delivering a remote access trojan. The platform, called Shadow Panel, operates from Bulgarian infrastructure and offers capabilities including remote shell execution, screenshot capture, file management, browser credential theft, clipboard hijacking for cryptocurrency wallets, and multi-operator support. The C2 panel's frontend JavaScript was publicly accessible, revealing 29 API endpoints and the complete architecture. Infrastructure analysis linked the operation to nikola4010@proton[.]me through WHOIS data and historical malicious domain associations dating back to 2021, indicating a long-running cybercriminal operation with minimal detection coverage.
Indicators of Compromise (37)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL YARA domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1009fac37240f16e01e552cf87e61dde 2026-04-13
FileHash-MD5 4fd2128e4b4549c46e2c112e7dc34096 2026-04-13
FileHash-MD5 88e5c48cd7d0ba596c136967b28803aa 2026-04-13
FileHash-MD5 db2fefe7fa768504ac64b8ef6942738b 2026-04-13
FileHash-MD5 f5847ed553b087a7a684de6d4dee3df1 2026-04-13
FileHash-SHA1 5fe202ed78618d14675cbdac6fd176848f74cc30 2026-04-13
FileHash-SHA1 8c7048e8df52ecbd4d3af59de3d37cf6a2a19e10 2026-04-13
FileHash-SHA1 d06a579b6f79350104e5c0db253d24626f9991b3 2026-04-13
FileHash-SHA1 f243b93714ae55372bb849f7193044e17d6b146f 2026-04-13
FileHash-SHA1 ff6f3b93df69a7960cd9b20448dc522c5f715dd5 2026-04-13
FileHash-SHA256 010601e408a090be561e10c23ae17342d8d82ca65b2b280215bb9268bae8381a 2026-04-13
FileHash-SHA256 3a352caa662ec74a150e03ccc637eb347f4a0423f976837637ac1f2484f0d329 2026-04-13
FileHash-SHA256 439391f35a6cffcfa1c6cb3e5e8f25ed4055cd10664a7e9ed438dd0fdcda9965 2026-04-13
FileHash-SHA256 5a011813db8497a4db303c90cb5f1948fcf4fcdd8bbe16c0e029195e6734d4f2 2026-04-13
FileHash-SHA256 a23bd8eab005a0c7759ffa344b55a3e1fd83a871817d51621c97eee0b511b3da 2026-04-13
FileHash-SHA256 e47b9382d9ac1ba3992308d75993b69255b1e4f4fe47c2e2b6cf6a7ec266da73 2026-04-13
FileHash-SHA256 ee5b302161c9a29defd0a9d3be674e831775099475dbf02d10949e4a4e8ae265 2026-04-13
FileHash-SHA256 f74128de852336b27069a677eebbf7e4ee751c294b96b17c1200cbd65a90793d 2026-04-13
IPv4 87.121.52.71 2026-04-13
IPv4 87.121.52.72 2026-04-13
URL http://refundonex.com/cloud/ 2026-04-13
URL https://refundonex.com/admin/ 2026-04-13
URL https://refundonex.com/cloud/ 2026-04-13
URL https://winup.su/ 2026-04-13
URL https://winup.su/api/client/poll/ 2026-04-13
URL https://winup.su/dashboard.html 2026-04-13
YARA c9223704fd2f8be6fccb0b8b75826f4c1b8e66ee 2026-04-13
YARA d74dfa84e2ab6f290e46a9ffd9a5393b39317a41 2026-04-13
domain carweap.net 2026-04-13
domain febystm.net 2026-04-13
domain hchdko.net 2026-04-13
domain mrchexp.net 2026-04-13
domain refundonex.com 2026-04-13
domain sifr-infso.club 2026-04-13
domain winup.su 2026-04-13
email nikola4010@proton.me 2026-04-13
hostname inst.refundonex.com 2026-04-13