← Back to Pulse Feed
PULSE DETAIL
Actor is utilizing uncertified "shadow" domains to execute Adversary-in-the-Middle (AiTM) attacks. By avoiding SSL/TLS certificates entirely, the infrastructure stays invisible to automated certificate monitoring tools.TECHNICAL ANALYSISZero-Cert Stealth: The absence of certificate data on email.mime.audio is a deliberate evasion tactic. It prevents the domain from appearing in public certificate databases, allowing the "fb hacker" proxy to operate in total darkness.Session Interception: Traffic is routed through the 104 IP space via HTTP. This allows the attacker to strip encryption and harvest session cookies and MFA tokens in plaintext before they ever reach the legitimate service provider.Library Mimicry: The mime.audio naming convention is designed to trick system admins into thinking the traffic is legitimate Python or email-handling library activity rather than an external exfiltration attempt.
Indicators of Compromise (6 / 1091 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | acad80b8cba2542d5c9351b43f2f384c | MD5 of 7f43dc8dd06fe9101315c94b5b7036faec276d085b0f0219c1ffe1943ea1d5b6 | 2026-05-07 | |
| FileHash-MD5 | 4a8bc195abdc93f0db5dab7f5093c52f | MD5 of b371af3ce6cb5d0b411919a188d5274df74d5ee49f6dd7b1ccb5a31466121a18 | 2026-05-07 | |
| FileHash-MD5 | d4e7c1546cf3131b7d84b39f8da9e321 | MD5 of c4243ba85c2d130b4dec972cd291916e973d9d60fac5ceea63a01837ecc481c2 | 2026-05-07 | |
| FileHash-MD5 | e2d5070bc28db1ac745613689ff86067 | MD5 of d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0 | 2026-05-07 | |
| FileHash-MD5 | 19ee8d75425c6ba01429520904061578 | MD5 of f55611f0f152606f0920baf3642a2771a5ea2d1f | 2026-05-07 | |
| FileHash-MD5 | 0ab03984a3d85ecaa1535ca17349c6a0 | — | 2026-05-07 |