logo

Pulling the Thread: APT should not usurp the identity of Leroy Merlin or there will be consequences

ID: 67af9e12-5fc0-5f32-a25c-c3c41c139bcf

STIX ID: report--67af9e12-5fc0-5f32-a25c-c3c41c139bcf

Feed Name: Plausible Deniablility

Threat Score
75/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}

...
...

This investigative report traces and analyzes C2 infrastructure tied to OctLurk and SilkLurk backdoors, identifying multiple domains and IPs, recurring registrar/DNS patterns (notably Tucows+Njalla and Internet Domain Service BS Corp+TopDNS), and instances of impersonation (including a TLS certificate for moi.gov.af). The findings suggest targeted cyber-espionage activity in Central Asia with measurable IoCs but limited public telemetry on active exploitation or victimization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.