Threat Theaters

💻 Cyber Crime theater

Covers financially motivated cybercrime — fraud, banking trojans, phishing, and access brokerage — driving the criminal economy that funds broader threats.

Live indicators

0
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

8
documented

Mapped sources

0
in catalog

🧭 Intelligence disciplines

CYBINT →FININT →OSINT →SOCMINT →

📜 Cyber Crime Playbook

  1. Aggregate fraud, phishing, and banking-trojan indicators from abuse.ch, IC3, and spam telemetry.
  2. Normalize and deduplicate indicators, resolving redirect chains and fast-flux hosting.
  3. Link campaigns to affiliates and money mules via infrastructure reuse and shared crypto wallets.
  4. Attribute activity to a financially motivated crew by TTP and toolkit overlap.
  5. Report actionable indicators to affected banks, registrars, and law enforcement.
  6. Trigger takedowns of malicious domains and freeze or flag laundering wallets.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php