SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Water Hydra

❔ UnknownLast active: 2026-09-23First seen: 2026-09-23
3
linked CVEs
Targeted industries
Finance
DarkMe, a Visual Basic 6 spy-RAT previously linked to financially-motivated APT group Water Hydra, was observed in two separate incidents affecting organizations in August 2026. Previously notable for weaponizing zero-day exploits including CVE-2023-38831 and CVE-2024-21412, this campaign abandoned sophisticated exploits in favor of basic social engineering tactics. Victims received phishing emails containing links disguised as images that delivered PIF executables. The attack chain utilized MSI installers, VB6 loaders, COM objects, and process hollowing into legitimate signed Microsoft binaries. Novel tradecraft includes using PIF files as initial payloads and implementing custom protocol handlers for persistence. The malware targets cryptocurrency wallets, password managers, trading platforms, and gaming applications, employing an inverted sandbox check against 329 applications to identify genuine user environments rather than analysis systems. This shift from targeted, exploit-driven operations to high-...
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2024-21412
suspected

Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS 8.1
KEVransomware
CVE-2023-38831
suspected

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

CVSS 7.8
KEVransomware
CVE-2023-27532
suspected

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

KEVransomware
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs20
domainsharedfuturetech.com—2026-09-23
domainonlineview365.com—2026-09-23
domainmegchartedbk7.com—2026-09-23
sha256394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04—2026-09-23
sha188bdcc4c6a78430a21d41ee088ffc0dac518a17d—2026-09-23
sha2569fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f—2026-09-23
sha2561c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918—2026-09-23
sha256d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93—2026-09-23
urlhttps://onlineview365.com/propi.msi—2026-09-23
domainreadonline365.com—2026-09-23
sha25652b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a—2026-09-23
domainadvancedfuturetechnology.com—2026-09-23
domainviewdocument.live—2026-09-23
urlhttps://readonline365.com/view/image.png—2026-09-23
sha25654ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76—2026-09-23
domainthatawful.boutique—2026-09-23
md50928d307c1fe675079d40c3a3d1f5c78—2026-09-23
sha2564a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0—2026-09-23
domainstorageonline.me—2026-09-23
sha2563052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634—2026-09-23
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.