============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-07 12:55 UTC Report ID: IOC-20260907-125508 Total Indicators: 46 Classification: OPEN - Law Enforcement / DFIR use Sources: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms, CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ SHA256 Hash: 18 CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=46 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-85046 Severity: CRITICAL Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but Product: Chromium V8 (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85046 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-04 Tags: kev,cisa,active-exploitation #2 CVE-2026-59822 Severity: CRITICAL Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Product: LiteLLM (BerriAI) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59822 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #3 CVE-2026-48710 Severity: CRITICAL Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the Product: Starlette (Kludex) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48710 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #4 CVE-2026-49869 Severity: CRITICAL Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Product: Kestra OSS (Kestra) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #5 CVE-2026-82329 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82329 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #6 CVE-2026-9586 Severity: CRITICAL Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem Product: Switchvox (Sangoma) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9586 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #7 CVE-2026-83548 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83548 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #8 CVE-2026-83549 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83549 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #9 CVE-2026-82078 Severity: CRITICAL Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv Product: NG/MF (PaperCut) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82078 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation #10 CVE-2026-81578 Severity: CRITICAL Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. Product: NG/MF (PaperCut) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81578 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation ============================================================================== [SHA256 HASH] - 18 indicator(s) ============================================================================== #11 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #12 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #13 fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #14 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #15 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #16 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #17 ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #18 feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #19 d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #20 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #21 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #22 a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #23 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #24 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #25 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #26 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #27 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware #28 a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7 Severity: CRITICAL Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms URL: https://cybersecuritynews.com/dprk-linked-hackers/ Date: Tags: hash,malware ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #29 https://loyaltyprogram.ink/aQzXm Severity: CRITICAL Description: Active phishing URL: https://loyaltyprogram.ink/aQzXm Source: OpenPhish URL: https://loyaltyprogram.ink/aQzXm Date: Tags: phishing,openphish #30 http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Severity: CRITICAL Description: Active phishing URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Source: OpenPhish URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Date: Tags: phishing,openphish #31 http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Severity: CRITICAL Description: Active phishing URL: http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Source: OpenPhish URL: http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Date: Tags: phishing,openphish #32 https://ledgerw.vercel.app/login Severity: CRITICAL Description: Active phishing URL: https://ledgerw.vercel.app/login Source: OpenPhish URL: https://ledgerw.vercel.app/login Date: Tags: phishing,openphish #33 https://zwjf76j-h07j.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://zwjf76j-h07j.vercel.app/ Source: OpenPhish URL: https://zwjf76j-h07j.vercel.app/ Date: Tags: phishing,openphish #34 https://cjrb11r-h07r.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://cjrb11r-h07r.vercel.app/ Source: OpenPhish URL: https://cjrb11r-h07r.vercel.app/ Date: Tags: phishing,openphish #35 http://boaa.privatbanks.org/ Severity: CRITICAL Description: Active phishing URL: http://boaa.privatbanks.org/ Source: OpenPhish URL: http://boaa.privatbanks.org/ Date: Tags: phishing,openphish #36 http://wteamcommunity.com/ Severity: CRITICAL Description: Active phishing URL: http://wteamcommunity.com/ Source: OpenPhish URL: http://wteamcommunity.com/ Date: Tags: phishing,openphish #37 http://zavravo-kxt-felquro-p9t2dp56.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/ Source: OpenPhish URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #38 loyaltyprogram.ink Severity: CRITICAL Description: Phishing domain: loyaltyprogram.ink Source: OpenPhish URL: https://loyaltyprogram.ink/aQzXm Date: Tags: phishing,openphish,domain #39 nexusqalinka2.quest Severity: CRITICAL Description: Phishing domain: nexusqalinka2.quest Source: OpenPhish URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/ Date: Tags: phishing,openphish,domain #40 ledgerw.vercel Severity: CRITICAL Description: Phishing domain: ledgerw.vercel Source: OpenPhish URL: https://ledgerw.vercel.app/login Date: Tags: phishing,openphish,domain #41 zwjf76j-h07j.vercel Severity: CRITICAL Description: Phishing domain: zwjf76j-h07j.vercel Source: OpenPhish URL: https://zwjf76j-h07j.vercel.app/ Date: Tags: phishing,openphish,domain #42 cjrb11r-h07r.vercel Severity: CRITICAL Description: Phishing domain: cjrb11r-h07r.vercel Source: OpenPhish URL: https://cjrb11r-h07r.vercel.app/ Date: Tags: phishing,openphish,domain #43 boaa.privatbanks Severity: CRITICAL Description: Phishing domain: boaa.privatbanks Source: OpenPhish URL: http://boaa.privatbanks.org/ Date: Tags: phishing,openphish,domain #44 wteamcommunity.com Severity: CRITICAL Description: Phishing domain: wteamcommunity.com Source: OpenPhish URL: http://wteamcommunity.com/ Date: Tags: phishing,openphish,domain #45 zavravo-kxt-felquro-p9t2dp56.pages Severity: CRITICAL Description: Phishing domain: zavravo-kxt-felquro-p9t2dp56.pages Source: OpenPhish URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/ Date: Tags: phishing,openphish,domain #46 amplifyapp.com Severity: CRITICAL Description: Phishing domain: amplifyapp.com Source: OpenPhish URL: https://staging.d8yffvk7rzff1.amplifyapp.com/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260907-125508 ==============================================================================