Country
Moldova
- First Reported
- May 27, 2026
- Latest Reported
- Sep 8, 2026
Reported Context (4)
- throughout the toolkit also appears in a separate February 2026 open directory at 194.48.248[.]105 (Moldova), a Meterpreter and XMRig kit with no Redis component, pushing the operator's known activity back at Redis Cryptomining Botnet Compromised 3,562 Servers, Revealed by Operator’s Exposed Files
- Ukraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria. Research details toolkits targeting Ukrainian IP cameras and routers
- across 10 countries in the region, covering Belarus, Bulgaria, the Czech Republic, Hungary, Poland, Moldova, Romania, Russia, Slovakia, and Ukraine. Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe
- 32 backend IP addresses spanning 6 geographic regions, with infrastructure distributed across Tencent Cloud (15 IPs), Alibaba Cloud (3 IPs), Cloudflare CDN (14 IPs), and ALEXHOST in Moldova (2 IPs). Hunt.io Traces Smishing Campaign Targeting Services in 19 Countries
CVE (12)
Malware (13)
People (4)
Threat Actors (9)
MITRE ATT&CK (27)
Vendors (41)
Products (20)
Tools (28)
Industries (10)
Countries (34)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.