Infoblox Threat Intel says dropcatch registrations are now close to one in five new domains, and one actor spent over $7 million on 10,000 of them. Clean history is being bought, not earned.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 62%
- Investor
- Investor 11%
Reality
- Evidence66
- Adoption18
- Hype gap+20
- Incentives
- Insufficient
- Confidence64
Aikido found the Graphalgo implant inside two Terraform providers and two Go modules. The Go build polls a hard-coded testnet contract every three seconds and keeps a Slack bot channel open as its second route.
Reality
- Evidence66
- Adoption21
- Hype gap+14
- Incentives72
- Confidence58
Aikido found the Graphalgo campaign's Go port inside two Terraform providers, one of them a typosquat of kreuzwerker/docker. The payload decrypts only when containerName and networkID hash to a hardcoded SHA256.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence61
ThreatFabric says the Android trojan hands collected data to nearby infected devices over Wi-Fi Direct or Bluetooth until one can reach command and control.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives70
- Confidence52
Astrolavos Lab counted 27,758 blacklisted and 238,279 malware-resolved domains that expired and were then maliciously re-registered, including an expired APT name.
Publishers:astrolavos.gatech.edu
Reality
- Evidence52
- Adoption31
- Hype gap+12
- Incentives58
- Confidence44