{
    "count": 177,
    "indicators": [
        {
            "ioc_value": "https:\/\/www.f-secure.com\/v-descs\/backdoor_w32_hupigon_emv.shtml",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2019\/07\/08\/south-korean-users-backdoor-torrents\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.mandiant.com\/resources\/detecting-microsoft-365-azure-active-directory-backdoors",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "Linux.BackDoor.Fysbis",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?name=Backdoor:Win32\/Lamin.A",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/blogs.juniper.net\/en-us\/threat-research\/a-custom-python-backdoor-for-vmware-esxi-servers",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/intezer.com\/acbackdoor-analysis-of-a-new-multiplatform-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/intezer.com\/blog\/malware-analysis\/new-linux-backdoor-redxor-likely-operated-by-chinese-nation-state-actor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:31"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20240303094335\/https:\/\/x-c3ll.github.io\/posts\/PAM-backdoor-DNS\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Nidiran",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/github.com\/zephrax\/linux-pam-backdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.APT.FakeWinHTTPHelper",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2019\/06\/government-in-central-asia-targeted-with-hawkball-backdoor.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/02\/t9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/research\/powerless-trojan-iranian-apt-phosphorus-adds-new-powershell-backdoor-for-espionage",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2016\/02\/a-look-into-fysbis-sofacys-linux-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Backdoor:Win32\/Truvasys.A!dha",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Remsec",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Backdoor:Win32\/Coroxy.A&ThreatID=2147766831",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Backdoor:Win64\/KnuckleTouch.A!dha&threatId=-2147067254",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Nerex",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/security-research\/lyceum-net-dns-backdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/syssphinx-fin8-backdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2017\/05\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-macos-dacls-rat-backdoor-show-lazarus-multi-platform-attack-capability\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.splunk.com\/en_us\/blog\/security\/breaking-down-linux-gomir-understanding-this-backdoors-ttps.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/speakup-a-new-undetected-backdoor-linux-trojan\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.giac.org\/paper\/gcih\/342\/handle-cd00r-invisible-backdoor\/103631",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Solaris.BPFDOOR.ZAJE",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Backdoor:Win32\/Wingbird.A!dha",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Linfo",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Linux.BPFDOOR",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/g\/detecting-bpfdoor-backdoor-variants-abusing-bpf-filters.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.zscaler.com\/blogs\/research\/cobian-rat-backdoored-rat",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.deepinstinct.com\/blog\/bpfdoor-malware-evolves-stealthy-sniffing-backdoor-ups-its-game",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/sandflysecurity.com\/blog\/bpfdoor-an-evasive-linux-backdoor-technical-analysis\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.uptycs.com\/blog\/new-poc-exploit-backdoor-malware",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/blog\/2021\/09\/27\/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Wiarp",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/molerats-delivers-spark-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.APT.CookieCutter",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/muddywater-resurfaces-uses-multi-stage-backdoor-powerstats-v3-and-new-post-exploitation-tools\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.SofacyX",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.resecurity.com\/blog\/article\/f5-big-ip-source-code-leak-tied-to-state-linked-campaigns-using-brickstorm-backdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/web.archive.org\/web\/20200607025424\/https:\/\/www.fireeye.com\/blog\/threat-research\/2018\/07\/microsoft-office-vulnerabilities-used-to-distribute-felixroot-backdoor.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/hackread.com\/backdoors-python-npm-packages-windows-linux\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.MacOS.OCEANLOTUS",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit42-new-improved-macos-backdoor-oceanlotus\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-macos-backdoor-linked-to-oceanlotus-found\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/k\/new-macos-backdoor-connected-to-oceanlotus-surfaces.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2018\/10\/11\/new-telebots-backdoor-linking-industroyer-notpetya\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2018\/10\/mac-cryptocurrency-ticker-app-installs-backdoors\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.aquasec.com\/leveraging-kubernetes-rbac-to-backdoor-clusters",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "http:\/\/gosecure.net\/2018\/02\/14\/chaos-stolen-backdoor-rising\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/01\/new-mac-backdoor-using-antiquated-code\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/03\/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Briba",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Oldrea",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Darkmoon",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Vasport",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.checkpoint.com\/securing-the-cloud\/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.netlab.360.com\/stealth_rotajakiro_backdoor_en\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/attack.mitre.org\/software\/S9032)\u202fbackdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/autoit-compiled-worm-affecting-removable-media-delivers-fileless-version-of-bladabindi-njrat-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/threatpost.com\/fin7-backdoor-ethical-hacking-tool\/166194\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.aquasec.com\/blog\/leveraging-kubernetes-rbac-to-backdoor-clusters\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:18",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2017\/03\/30\/carbon-paper-peering-turlas-second-stage-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/researchcenter.paloaltonetworks.com\/2018\/01\/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "Backdoor.Mivast",
            "ioc_type": "other",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2015\/04\/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/eset-research\/moon-backdoors-lunar-landing-diplomatic-missions\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:30"
        },
        {
            "ioc_value": "https:\/\/blog.malwarebytes.com\/threat-analysis\/2021\/06\/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.security.com\/threat-intelligence\/springtail-kimsuky-backdoor-espionage",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.ibm.com\/think\/x-force\/hive0154-mustang-panda-shifts-focus-tibetan-community-deploy-pubload-backdoor",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/gopuram-backdoor-deployed-through-3cx-supply-chain-attack\/109344\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/cactuspete-apt-groups-updated-bisonal-backdoor\/97962\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2018\/03\/13\/oceanlotus-ships-new-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/05\/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 8,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/redbaldknight-bronze-butler-daserf-backdoor-now-using-steganography\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/documents.trendmicro.com\/assets\/pdf\/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/eset-research\/operation-akairyu-mirrorface-invites-europe-expo-2025-revives-anel-backdoor\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 5,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2021\/06\/10\/backdoordiplomacy-upgrading-quarian-turian\/",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 7,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2017\/06\/behind-the-carbanak-backdoor.html",
            "ioc_type": "url",
            "category": "ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 6,
            "first_seen": "2026-08-06 13:09:17",
            "last_seen": "2026-08-06 14:48:29"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/windows-backdoor-for-novel-c2-communication\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/decoded.avast.io\/luigicamastra\/apt-group-planted-backdoors-targeting-high-profile-networks-in-central-asia",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2020\/05\/14\/mikroceen-spying-backdoor-high-profile-networks-central-asia",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.FSZO",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/2013\/01\/24\/linux-sshdoor-a-backdoored-ssh-daemon-that-steals-passwords\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.f-secure.com\/v-descs\/backdoor_w32_poisonivy.shtml",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.Win32.PoisonIvy",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=Backdoor%3aWin32%2fZegost.BW",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.jamf.com\/blog\/chillyhell-a-modular-macos-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sonicwall-secure-mobile-access-exploitation-overstep-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/travle-aka-pylot-backdoor-hits-russian-speaking-targets\/83455\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "http:\/\/news.softpedia.com\/news\/Exforel-Backdoor-Implemented-at-NDIS-Level-to-Be-More-Stealthy-Experts-Say-313567.shtml",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/www.welivesecurity.com\/en\/eset-research\/ghostredirector-poisons-windows-servers-backdoors-side-potatoes\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.Moudoor",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.Pirpi",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/cl-sta-1062-tinyrct-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "APT.Backdoor.Win.DOGCALL",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/redcanary.com\/blog\/threat-intelligence\/mocha-manakin-nodejs-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.APT.Karae",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.APT.POORAIM",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "APT.Backdoor.SHUTTERSPEED",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.APT.WINERACK",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/global.ptsecurity.com\/en\/research\/pt-esc-threat-intelligence\/taxoff-um-you-ve-got-a-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2016\/02\/a-look-into-fysbis-sofacys-linux-backdoor\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.Dripion",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/eagerbee-backdoor\/115175\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-slub-backdoor-uses-github-communicates-via-slack\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/lancefly-merdoor-zxshell-custom-backdoor",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 4,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "Backdoor.Tinybaron",
            "ioc_type": "other",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blogs.forcepoint.com\/security-labs\/mm-core-memory-backdoor-returns-bigboss-and-sillygoose",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blogs.forcepoint.com\/security-labs\/trojanized-adobe-installer-used-install-dragonok%E2%80%99s-new-custom-backdoor",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/securityintelligence.com\/news\/ta505-delivers-new-gelup-malware-tool-flowerpippi-backdoor-via-spam-campaign\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/blog.xlab.qianxin.com\/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/advanced-backdoor-squidoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "http:\/\/researchcenter.paloaltonetworks.com\/2017\/05\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/",
            "ioc_type": "url",
            "category": "Malware Families",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:03",
            "last_seen": "2026-08-06 14:45:34"
        },
        {
            "ioc_value": "https:\/\/securelist.com\/the-icefog-apt-hits-us-targets-with-java-backdoor\/58209\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/detecting-disrupting-malvertising-backdoors\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/e\/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor\/",
            "ioc_type": "url",
            "category": "ICS ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:09:23",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "BackDoor.RemShell",
            "ioc_type": "other",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/23\/b\/earth-kitsune-delivers-new-whiskerspy-backdoor.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/20\/j\/operation-earth-kitsune-a-dance-of-two-new-backdoors.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/decoded.avast.io\/threatintel\/avast-finds-backdoor-on-us-government-commission-network\/?utm_source=rss&utm_medium=rss&utm_campaign=avast-finds-backdoor-on-us-government-commission-network",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.secureworks.com\/blog\/ransomware-groups-use-tor-based-backdoor-for-persistent-access",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 3,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_za\/research\/23\/e\/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/redbaldknight-bronze-butler-daserf-backdoor-now-using-steganography\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.forcepoint.com\/de\/blog\/x-labs\/trojanized-adobe-installer-used-install-dragonok-s-new-custom-backdoor",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/github.com\/m0n0ph1\/APT_CyberCriminal_Campagin_Collections-1\/blob\/master\/2017\/2017.02.15.deep-dive-dragonok-rambo-backdoor\/Deep%20Dive%20on%20the%20DragonOK%20Rambo%20Backdoor%20_%20Morphick%20Cyber%20Security.pdf",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/apt41-using-new-speculoos-backdoor-to-target-organizations-globally\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/ta505-group-adopts-new-servhelper-backdoor-and-flawedgrace-rat\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.cybereason.com\/blog\/threat-actor-ta505-targets-financial-enterprises-using-lolbins-and-a-new-backdoor-malware",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/turla-outlook-backdoor-uses-clever-tactics-for-stealth-and-persistence\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/vinfo\/vn\/security\/news\/cyber-attacks\/cyberespionage-group-turla-deploys-backdoor-ahead-of-g20-summit",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/springtail-kimsuky-backdoor-espionage",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/unit42.paloaltonetworks.com\/kimsuky-new-keylogger-backdoor-variant\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/labs.sentinelone.com\/top-tier-russian-organized-cybercrime-group-unveils-fileless-stealthy-powertrick-backdoor-for-high-value-targets\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2014\/09\/forced-to-adapt-xslcmd-backdoor-now-on-os-x.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.elastic.co\/security-labs\/disclosing-the-bloodalchemy-backdoor",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/another-potential-muddywater-campaign-uses-powershell-based-prb-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/fin7carbanak-threat-actor-unleashes-bateleur-jscript-backdoor",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:12:59",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/01\/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/decoded.avast.io\/luigicamastra\/backdoored-client-from-mongolian-ca-monpass",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/research.checkpoint.com\/2021\/chinese-apt-group-targets-southeast-asian-government-with-previously-unknown-backdoor\/",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "https:\/\/www.trendmicro.com\/en_us\/research\/21\/a\/earth-wendigo-injects-javascript-backdoor-to-service-worker-for-.html",
            "ioc_type": "url",
            "category": "Threat Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:13:00",
            "last_seen": "2026-08-06 14:45:33"
        },
        {
            "ioc_value": "SecuriteInfo.com.BackDoor.Remcos",
            "ioc_type": "other",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:31",
            "last_seen": "2026-08-06 14:44:08"
        },
        {
            "ioc_value": "SecuriteInfo.com.Linux.BackDoor.Fgt",
            "ioc_type": "other",
            "category": "Malware Attribution",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:31",
            "last_seen": "2026-08-06 14:44:08"
        },
        {
            "ioc_value": "https:\/\/www.fortinet.com\/blog\/threat-research\/malware-disguised-as-document-ukraine-energoatom-delivers-havoc-demon-backdoor",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:09",
            "last_seen": "2026-08-06 14:43:50"
        },
        {
            "ioc_value": "https:\/\/www.malekal.com\/bossabotv2-another-linux-backdoor-irc\/",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "https:\/\/blog.sucuri.net\/2019\/10\/cryptominers-backdoors-found-in-fake-plugins.html",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:11:08",
            "last_seen": "2026-08-06 14:43:48"
        },
        {
            "ioc_value": "backdoorcloud.digital",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "backdoor.cyou",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "backdoorddns.net",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "backdoor.fun88mb5.com",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "backdoor-hub.com",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "backdoor.nikio.io",
            "ioc_type": "other",
            "category": "Malware Domains",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:37",
            "last_seen": "2026-08-06 14:42:15"
        },
        {
            "ioc_value": "https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/droidjack-uses-side-load-backdoored-pokemon-go-android-app",
            "ioc_type": "url",
            "category": "Mobile ATT&CK",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 2,
            "first_seen": "2026-08-06 13:09:20",
            "last_seen": "2026-08-06 14:41:54"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/pokemongo-ransomware-installs-backdoor-accounts-and-spreads-to-other-drives\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.advanced-intel.com\/post\/secret-backdoor-behind-conti-ransomware-operation-introducing-atera-agent",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/news.sophos.com\/en-us\/2021\/02\/03\/mtr-casebook-uncovering-a-backdoor-implant-in-a-solarwinds-orion-server\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-devs-added-a-backdoor-to-cheat-affiliates\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/operation-endtrade-finding-multi-stage-backdoors-that-tick\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "http:\/\/www.bleepingcomputer.com\/news\/security\/pompous-ransomware-dev-gets-defeated-by-backdoor\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/www.flashpoint-intel.com\/blog\/revils-cryptobackdoor-con-ransomware-groups-tactics-roil-affiliates-sparking-a-fallout\/",
            "ioc_type": "url",
            "category": "Ransomware Actors",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:13:01",
            "last_seen": "2026-08-06 13:13:01"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/s3q\/blackdoor\/main\/backdoor.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/raw.githubusercontent.com\/pistacchietto\/win-python-backdoor\/master\/standalone_payload.exe",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        },
        {
            "ioc_value": "https:\/\/github.com\/pistacchietto\/Win-Python-Backdoor\/raw\/master\/win.bat",
            "ioc_type": "url",
            "category": "Domains\/URLs",
            "threat_score": "0.50",
            "confidence_score": "0.50",
            "sighting_count": 1,
            "first_seen": "2026-08-06 13:07:42",
            "last_seen": "2026-08-06 13:07:42"
        }
    ]
}