Malware
Balada
- First Reported
- Aug 13, 2026
- Latest Reported
- Aug 13, 2026
Reported Context (1)
- The infrastructure consists almost entirely of dropped domains that once served malicious infrastructure for various actors, including TA2726, and actors running Magecart and Balada injection campaigns. Expired malicious domains let three actors redirect compromised-site visitors to scams and malware
Malware (1)
People (1)
Threat Actors (7)
MITRE ATT&CK (8)
Vendors (5)
Products (8)
Tools (3)
Industries (4)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.