
Threat Intel
Live phishing intelligence, defanged for training
Fresh campaigns, indicators and analyst notes — updated with every case wave so your investigations reflect what attackers are sending right now.
Threat Intel
A simulated multi-source intelligence feed. A fresh drop lands every 24 hours at 00:00 UTC — indicators are defanged and safe to copy into your notes.
AiTM phishing kits remain the dominant credential-theft path
Sun, Aug 9, 2026 · 8 items · current drop
Spamhaus
QakBot delivered via ISO archive
Detonation shows child process spawning from the document handler, then beaconing out over HTTPS. 32 / 72 engines detecting.
sha256 · first seen 14h ago
5ae3f149eed3dec863bd19b2c53844efab305c2b515d13c3e8af37cdb92d7100
T1204.002 — Malicious File
Any.Run
Gift-card BEC pretext circulating
Free-mail sender using a spoofed display name of a real executive, asking for 9 gift cards "for a client thank-you". No links, no attachment — content-only signal.
sender · first seen 10h ago
md.portal@invoice-billing[.]shop
T1656 — Impersonation
Spamhaus
TA4903 activity against legal mailboxes
Thread hijacking on compromised supplier accounts, followed by an inbox rule that files replies under RSS Feeds to hide the conversation.
sender · first seen 18h ago
hrdesk@portal-vault[.]top
T1114.003 — Email Forwarding Rule
VirusTotal
Sender domain cleared after review
Bulk marketing sender previously flagged by two engines; SPF, DKIM and DMARC now align and no phishing content observed. Treat detections as false positive.
domain · first seen 7h ago
billing-payroll[.]live
—
VirusTotal
Newly registered lookalike domain
Registered 5 day(s) ago behind privacy protection, MX live within an hour of registration — classic burn-after-use phishing infrastructure.
domain · first seen 11h ago
hrdesk-hrdesk[.]icu
T1656 — Impersonation
URLScan.io
Bulletproof hosting range flagged
Sending IP with 70% abuse confidence and 7 reports in the last week. Also seen hosting 4 phishing landing pages.
ip · first seen 9h ago
22[.]103[.]41[.]129
T1566.002 — Spearphishing Link
Cisco Talos
QR-code (quishing) wave targeting Okta
PDF attachment with an embedded QR pointing at a shortener chain, aimed at moving the victim onto an unmanaged phone outside endpoint controls.
url · first seen 15h ago
hxxps://signin-secure[.]live/q/8x1b
T1566.002 — Spearphishing Link
URLScan.io
MFA fatigue push storm reported
Bursts of 11 Authenticator prompts within 6 minutes, followed by a help-desk callback attempting to talk the user into approving.
ip · first seen 7h ago
204[.]5[.]55[.]169
T1621 — MFA Request Generation
