Credentials gathering campaign: large clusters of malicious infrastructure targeting government bodies and other strategic entities
ID: ef4f5e21-60ac-4206-a4d4-d766d6e15a87
STIX ID: report--ef4f5e21-60ac-4206-a4d4-d766d6e15a87
Threat Score
78/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI discovered multiple clusters of malicious domains and subdomains (many resolving to 157.7.184.0/24) used in a widespread credential‑harvesting phishing campaign targeting ministries, diplomatic missions, think tanks and other strategic entities; the report maps registrant emails to domain clusters, lists likely targets and indicators of compromise, and notes technical links to reported APT activity (Kimsuky, Group123) as well as associated malware/C2 artifacts.
