Critical APT Detection
APT29 campaign targeting your infrastructure detected
2 minutes ago
High Risk Score Alert
CORP-DC-01 risk score increased to 89
15 minutes ago
Threat Feed Updated
142 new IOCs added from MISP feed
1 hour ago
Scan Completed
Attack surface scan completed successfully
3 hours ago
AI Report Generated
Weekly threat intelligence report is ready
5 hours ago
Recent Searches
192.168.1.100
APT29
CVE-2024-1234
Appearance
Dark ModeUse dark theme
Compact ViewReduce spacing
Notifications
Desktop AlertsBrowser notifications
Sound EffectsPlay alert sounds
Data & Privacy
Auto-refreshUpdate data automatically
SC

Threat Intelligence

STRATUM Watch™ • External threat intelligence and adversary tracking

Severity:
Status:
Actor Type:
8
Active Campaigns
+2
23
Tracked Actors
12,847
IOCs Ingested (7d)
+156
47
Correlated Events
Adversary Campaigns
Operation Midnight Storm
APT29 / Cozy Bear • Nation State (Russia)
Active

Sophisticated spearphishing campaign targeting financial institutions. Uses custom Cobalt Strike beacons with domain fronting through legitimate cloud services. Primary objective appears to be financial data theft and long-term persistence.

Financial SectorSpearphishingCobalt StrikeDomain FrontingT1566.001
234
IOCs
12
Known Targets
3
Your Matches
87%
Confidence
HIGH
Relevance
Supply Chain Serpent
UNC2452 • Nation State (Suspected China)
Monitoring

Supply chain compromise targeting software vendors. Leverages legitimate update mechanisms to distribute malicious payloads. Similar TTP profile to SolarWinds attack but targeting different software ecosystem.

Software Supply ChainUpdate HijackSUNBURST VariantT1195.002
156
IOCs
8
Known Targets
0
Your Matches
92%
Confidence
MEDIUM
Relevance
BEC Blitz Q4
FIN7 Affiliate • Cybercrime
Active

Business email compromise campaign leveraging AI-generated content and deepfake voice synthesis. Targets executive assistants and finance departments with highly convincing impersonation attacks.

BECAI-GeneratedDeepfake AudioWire Fraud
89
IOCs
45
Known Targets
1
Your Matches
78%
Confidence
HIGH
Relevance
Featured Actor: APT29
APT29 / Cozy Bear
Nation State • Russia (SVR)
ACTIVE THREAT
Primary Targets
GovernmentFinancial ServicesHealthcareTechnologyEnergy
Common TTPs
Spearphishing LinksT1566.002
Valid AccountsT1078
Domain FrontingT1090.004
Cobalt StrikeS0154
3
Active Campaigns
478
Total IOCs
4
Your Matches
2019
First Seen
Recent Activity
New IOC added to Operation Midnight Storm
5 minutes ago
IOC correlated with internal alert
23 minutes ago
Feed updated from MISP source
1 hour ago
Alert rule triggered for APT29 indicators
2 hours ago
APT29 / Cozy Bear
Nation State • Russia
Active
3 campaigns 478 IOCs 4 matches
UNC2452
Nation State • China (Suspected)
Monitoring
1 campaign 156 IOCs 0 matches
FIN7 / Carbanak
Cybercrime
Active
2 campaigns 234 IOCs 1 match
Lazarus Group
Nation State • North Korea
Active
4 campaigns 892 IOCs 0 matches
APT41 / Winnti
Nation State • China
Monitoring
2 campaigns 567 IOCs 0 matches
Conti / Wizard Spider
Cybercrime • Ransomware
Dormant
0 campaigns 1,245 IOCs 0 matches
Type
Value
Associated Threat
Confidence
Source
First Seen
Actions
IP
185.220.101.34
Operation Midnight Storm
95%
MISP
2024-01-15
Domain
malware-c2.evil.com
APT29
92%
Internal
2024-01-14
SHA256
a1b2c3d4e5f6...
BEC Blitz Q4
78%
VirusTotal
2024-01-13
URL
https://phish.example.com/login
FIN7
88%
OTX
2024-01-12
attacker@malicious.org
BEC Blitz Q4
72%
Internal
2024-01-11
Showing 1-5 of 12,847 IOCs
...
Cobalt Strike
Commercial RAT / C2 Framework
Commercial penetration testing tool frequently abused by threat actors for post-exploitation activities.
156Samples
4Campaigns
2Detections
SUNBURST
Backdoor / Supply Chain
Sophisticated backdoor used in SolarWinds supply chain attack, capable of domain reconnaissance and lateral movement.
89Samples
1Campaigns
0Detections
Emotet
Loader / Banking Trojan
Modular banking trojan primarily used as a dropper for other malware. Spreads via malicious email attachments.
2,456Samples
3Campaigns
0Detections
QakBot
Banking Trojan / Loader
Banking trojan that has evolved into a versatile loader, often used as initial access for ransomware operations.
1,892Samples
2Campaigns
0Detections

MITRE ATT&CK Coverage

Detected Rules Active Coverage Gap
Initial Access
T1566
T1190
T1133
Execution
T1059
T1204
T1203
Persistence
T1547
T1053
T1078
Defense Evasion
T1027
T1070
T1036
C2
T1071
T1090
T1573

Recent TTP Detections

T1566.001Spearphishing Attachment12 detections
Associated with: APT29, FIN7 • Last seen: 2 hours ago
T1059.001PowerShell8 detections
Associated with: APT29 • Last seen: 5 hours ago
T1090.004Domain Fronting3 detections
Associated with: APT29 • Last seen: 1 day ago

Dark Web Monitoring Alerts

CRITICAL2 hours ago
Credential Dump Detected
47 corporate email credentials found in paste site dump. Matches company domain pattern.
Source: Paste Site Monitoring
HIGH1 day ago
Company Mention in Hacking Forum
Thread discussing potential vulnerabilities in company's external infrastructure. No confirmed breach.
Source: Forum Monitoring
MEDIUM3 days ago
Executive PII on Sale
Personal information of C-level executives listed on dark web marketplace. Includes phone numbers and addresses.
Source: Marketplace Monitoring

Monitoring Summary

3
Active Alerts
156
Sources Monitored
47
Exposed Credentials
12
Keywords Tracking

New IOC

Add an indicator of compromise to your threat database

IOC Type
IP Address
IPv4 or IPv6
Domain
Malicious domains
URL
Full URLs/paths
File Hash
MD5, SHA1, SHA256
Email
Email addresses
Filename
File names/paths

Select an IOC type above to continue

Campaign Details

IOC Details

Threat Actor Profile

Create Alert Rule

Custom Date Range