Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign
ID: bdb0483d-5ebd-546d-9f5f-38e17e570048
STIX ID: report--bdb0483d-5ebd-546d-9f5f-38e17e570048
Feed Name: Threat Intelligence
Threat Score
This report is an IOC feed documenting an active malware campaign's infrastructure: multiple C2 IPs and hosting servers, numerous dynamic/DDNS domains used as C2, SoftEther VPN servers and attacker IPs, two GRIDTIDE-related User-Agent strings, and a self-signed X.509 certificate SHA256 hash — intended for detection, blocking, and enrichment rather than detailed analysis of exploitation or victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
