Global threat intelligence map with glowing indicators

Threat Intel

Live phishing intelligence, defanged for training

Fresh campaigns, indicators and analyst notes — updated with every case wave so your investigations reflect what attackers are sending right now.

Threat Intel

A simulated multi-source intelligence feed. A fresh drop lands every 24 hours at 00:00 UTC — indicators are defanged and safe to copy into your notes.

Next drop in 19:51:22

AiTM phishing kits remain the dominant credential-theft path

Thu, Sep 24, 2026 · 6 items · current drop

Spamhaus

Malicious
Credential theft
confidence 81%

Greatness kit spoofing SharePoint

Adversary-in-the-middle landing page harvesting SharePoint credentials and session cookies. Proxies the real login, so MFA prompts look legitimate.

url · first seen 21h ago

hxxps://secure-hrdesk[.]wiki/auth/login

T1566.002 — Spearphishing Link

Pivot

AbuseIPDB

Suspicious
Reputation
confidence 67%

Bulletproof hosting range flagged

Sending IP with 42% abuse confidence and 15 reports in the last week. Also seen hosting 4 phishing landing pages.

ip · first seen 32h ago

68[.]155[.]182[.]75

T1566.002 — Spearphishing Link

Pivot

Recorded Future (community)

Benign
Reputation
confidence 25%

Sender domain cleared after review

Bulk marketing sender previously flagged by two engines; SPF, DKIM and DMARC now align and no phishing content observed. Treat detections as false positive.

domain · first seen 6h ago

verify-verify[.]icu

Pivot

URLhaus

Malicious
Credential theft
confidence 89%

OAuth consent app requesting mailbox scopes

Unverified publisher requesting Mail.ReadWrite and offline_access. Grants survive a password reset — revoke the grant, not just the session.

domain · first seen 4h ago

vault-billing[.]cfd

T1078 — Valid Accounts

Pivot

URLhaus

Malicious
Campaign
confidence 94%

Void Rabisu activity against legal mailboxes

Thread hijacking on compromised supplier accounts, followed by an inbox rule that files replies under RSS Feeds to hide the conversation.

sender · first seen 33h ago

hrdesk@invoice-signin[.]click

T1114.003 — Email Forwarding Rule

Pivot

AlienVault OTX

Malicious
Malware
confidence 92%

Lumma Stealer delivered via LNK shortcut

Detonation shows child process spawning from the document handler, then beaconing out over HTTPS. 32 / 72 engines detecting.

sha256 · first seen 16h ago

5adcc348ccebbbe2820e80e6a6ec2c31b2679e1c1614dad903f6de6cb7c3a1d0

T1204.002 — Malicious File

Pivot