Threat Intelligence
STRATUM Watch™ • External threat intelligence and adversary tracking
Sophisticated spearphishing campaign targeting financial institutions. Uses custom Cobalt Strike beacons with domain fronting through legitimate cloud services. Primary objective appears to be financial data theft and long-term persistence.
Supply chain compromise targeting software vendors. Leverages legitimate update mechanisms to distribute malicious payloads. Similar TTP profile to SolarWinds attack but targeting different software ecosystem.
Business email compromise campaign leveraging AI-generated content and deepfake voice synthesis. Targets executive assistants and finance departments with highly convincing impersonation attacks.
185.220.101.34malware-c2.evil.coma1b2c3d4e5f6...https://phish.example.com/loginattacker@malicious.org