PULSE NAME
MIT/m attack + Cloudflare/CDN Masking
WHITE msudosos 2026-05-07 Modified: 2026-05-12
1091
IOCs
HIGH VOLUME
Actor is utilizing uncertified "shadow" domains to execute Adversary-in-the-Middle (AiTM) attacks. By avoiding SSL/TLS certificates entirely, the infrastructure stays invisible to automated certificate monitoring tools.TECHNICAL ANALYSISZero-Cert Stealth: The absence of certificate data on email.mime.audio is a deliberate evasion tactic. It prevents the domain from appearing in public certificate databases, allowing the "fb hacker" proxy to operate in total darkness.Session Interception: Traffic is routed through the 104 IP space via HTTP. This allows the attacker to strip encryption and harvest session cookies and MFA tokens in plaintext before they ever reach the legitimate service provider.Library Mimicry: The mime.audio naming convention is designed to trick system admins into thinking the traffic is legitimate Python or email-handling library activity rather than an external exfiltration attempt.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 1091 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname IPv4 URL URI Mutex
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 acad80b8cba2542d5c9351b43f2f384c MD5 of 7f43dc8dd06fe9101315c94b5b7036faec276d085b0f0219c1ffe1943ea1d5b6 2026-05-07
FileHash-MD5 4a8bc195abdc93f0db5dab7f5093c52f MD5 of b371af3ce6cb5d0b411919a188d5274df74d5ee49f6dd7b1ccb5a31466121a18 2026-05-07
FileHash-MD5 d4e7c1546cf3131b7d84b39f8da9e321 MD5 of c4243ba85c2d130b4dec972cd291916e973d9d60fac5ceea63a01837ecc481c2 2026-05-07
FileHash-MD5 e2d5070bc28db1ac745613689ff86067 MD5 of d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0 2026-05-07
FileHash-MD5 19ee8d75425c6ba01429520904061578 MD5 of f55611f0f152606f0920baf3642a2771a5ea2d1f 2026-05-07
FileHash-MD5 0ab03984a3d85ecaa1535ca17349c6a0 2026-05-07