Global threat intelligence map with glowing indicators

Threat Intel

Live phishing intelligence, defanged for training

Fresh campaigns, indicators and analyst notes — updated with every case wave so your investigations reflect what attackers are sending right now.

Threat Intel

Threat Intel

A simulated multi-source intelligence feed. A fresh drop lands every 24 hours at 00:00 UTC — indicators are defanged and safe to copy into your notes.

Next drop in 23:54:54

AiTM phishing kits remain the dominant credential-theft path

Sun, Aug 9, 2026 · 8 items · current drop

Spamhaus

Malicious
Malware
confidence 79%

QakBot delivered via ISO archive

Detonation shows child process spawning from the document handler, then beaconing out over HTTPS. 32 / 72 engines detecting.

sha256 · first seen 14h ago

5ae3f149eed3dec863bd19b2c53844efab305c2b515d13c3e8af37cdb92d7100

T1204.002 — Malicious File

Pivot

Any.Run

Suspicious
Campaign
confidence 77%

Gift-card BEC pretext circulating

Free-mail sender using a spoofed display name of a real executive, asking for 9 gift cards "for a client thank-you". No links, no attachment — content-only signal.

sender · first seen 10h ago

md.portal@invoice-billing[.]shop

T1656 — Impersonation

Pivot

Spamhaus

Malicious
Campaign
confidence 94%

TA4903 activity against legal mailboxes

Thread hijacking on compromised supplier accounts, followed by an inbox rule that files replies under RSS Feeds to hide the conversation.

sender · first seen 18h ago

hrdesk@portal-vault[.]top

T1114.003 — Email Forwarding Rule

Pivot

VirusTotal

Benign
Reputation
confidence 25%

Sender domain cleared after review

Bulk marketing sender previously flagged by two engines; SPF, DKIM and DMARC now align and no phishing content observed. Treat detections as false positive.

domain · first seen 7h ago

billing-payroll[.]live

Pivot

VirusTotal

Suspicious
Infrastructure
confidence 70%

Newly registered lookalike domain

Registered 5 day(s) ago behind privacy protection, MX live within an hour of registration — classic burn-after-use phishing infrastructure.

domain · first seen 11h ago

hrdesk-hrdesk[.]icu

T1656 — Impersonation

Pivot

URLScan.io

Suspicious
Reputation
confidence 74%

Bulletproof hosting range flagged

Sending IP with 70% abuse confidence and 7 reports in the last week. Also seen hosting 4 phishing landing pages.

ip · first seen 9h ago

22[.]103[.]41[.]129

T1566.002 — Spearphishing Link

Pivot

Cisco Talos

Suspicious
Credential theft
confidence 62%

QR-code (quishing) wave targeting Okta

PDF attachment with an embedded QR pointing at a shortener chain, aimed at moving the victim onto an unmanaged phone outside endpoint controls.

url · first seen 15h ago

hxxps://signin-secure[.]live/q/8x1b

T1566.002 — Spearphishing Link

Pivot

URLScan.io

Malicious
Campaign
confidence 85%

MFA fatigue push storm reported

Bursts of 11 Authenticator prompts within 6 minutes, followed by a help-desk callback attempting to talk the user into approving.

ip · first seen 7h ago

204[.]5[.]55[.]169

T1621 — MFA Request Generation

Pivot