SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

UNKK

❔ UnknownLast active: 2026-09-23First seen: 2026-09-23
0
linked CVEs
Targeted industries
Finance
Targeted regions
CanadaFranceItalyPolandPortugalSpain
Group-IB researchers discovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service since May 2026. The malware targets over 30 financial institutions across Western Europe, the Middle East, and Canada through fake TVTap IPTV download pages distributed via malvertising. RemControl abuses Android Accessibility Service to inject phishing overlays, stream device screens in real-time, log keystrokes, and provide full remote control. The investigation revealed that the criminal infrastructure was inadvertently built using AI assistance, with complete AI-generated responses found verbatim in production phishing pages. The C2 panel documentation describes credential theft as quiz completion, suggesting developers deceived AI assistants into building fraud infrastructure under false pretenses. The threat actor UNKK operates the campaigns, with possible links to the Medusa UNKN affiliate botnet based on overlapping infrastructure patterns and naming conventions.
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs28
sha25654efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d—2026-09-23
sha256c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0—2026-09-23
sha25628a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c—2026-09-23
sha256cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889—2026-09-23
sha256af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c—2026-09-23
sha25619fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1—2026-09-23
sha256b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3—2026-09-23
sha256ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f—2026-09-23
sha25645e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1—2026-09-23
domainff-de.shutgpt.ir—2026-09-23
domaincdn.dlmafi.top—2026-09-23
sha256fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e—2026-09-23
sha1b60cee64202c6ad48808c10226093540292ae4b8—2026-09-23
sha2565fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4—2026-09-23
domaintvtap-liveapp.com—2026-09-23
domaindefinatelynoone.com—2026-09-23
sha256dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730—2026-09-23
sha2561a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7—2026-09-23
sha25677ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a—2026-09-23
md5f9e6ea83e50b72a081aef44d22f19bcf—2026-09-23
sha2563b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb—2026-09-23
sha256648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1—2026-09-23
sha25676392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b—2026-09-23
ip216.126.229.216—2026-09-23
domainvpn.askarzadeh.com—2026-09-23
domainbnbnhura.top—2026-09-23
sha25695ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f—2026-09-23
domainvpn.doneplay.site—2026-09-23
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.