Malware
HSEWH-Ur
- First Reported
- Jul 14, 2026
- Latest Reported
- Jul 14, 2026
Reported Context (1)
- 1111 on 112.213.124[.]132 triggered the download of a previously unreported Linux/ARM 32-bit binary, HSEWH-Ur. The Golang-compiled, statically linked executable beacons over WebSocket to port 4081 on the same host, Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems
Malware (1)
MITRE ATT&CK (7)
Vendors (5)
Products (6)
Tools (7)
Industries (7)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.