Behind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry

Phishing panels are not just credential collection tools. They are infrastructure ecosystems.

Behind every convincing login page is a set of domains, hosting providers, certificates, exposed services, operator tooling, and recurring deployment patterns. Those signals matter. They give defenders a way to move beyond a single phishing domain and start understanding how the activity is built, hosted, rotated, and reused.

Push Security recently published an inside look at phishing panels used in campaigns linked to ShinyHunters and BlackFile. Their team gained direct access to active operator panels, observed real victim targeting, analyzed multiple variants of the tooling, and identified four primary infrastructure clusters. They also made an important point: while these panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.

That operator-side view is valuable because it shows how the attack works from inside the panel. Team Cymru’s view is different. Using Pure Signal Scout, we looked at the infrastructure layer to validate and expand part of the picture Push identified.

Our analysis focused on Cluster A, the Doko’s Panel infrastructure hosted on Mevspace AS201814. Push noted that Cluster A overlaps with Mandiant reporting on UNC6661, and that Mandiant attributes related extortion activity following UNC6661 intrusions to UNC6240, also known as ShinyHunters.

Using passive DNS, certificate data, open service observations, and hosting patterns, we identified two active Mevspace IPs consistent with Push’s Cluster A criteria. Those IPs were associated with more than 40 victim-themed domains, recurring naming conventions, and one Doko-branded hosting-layer artifact that provides additional pivot context.

This is not a reattribution of the activity. Push established the panel and cluster framework. Team Cymru’s contribution is infrastructure validation: confirming that infrastructure consistent with Push’s Cluster A reporting was active on Mevspace and surfacing additional indicators defenders can hunt against.

Why Cluster A matters

Cluster A matters because the targeting pattern is not random.

Push described campaigns that combine voice phishing with adversary-in-the-middle credential capture against enterprise identity providers and cryptocurrency platforms. The victim is typically directed to a domain that looks like an internal identity, support, passkey, or SSO page. Once credentials and MFA are captured, the operator can attempt to access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.

That makes the infrastructure behind these panels important. The domain is the visible piece, but it is rarely the whole picture. Hosting providers, ASN usage, TLS behavior, passive DNS history, certificates, and exposed services can show how the operation is being staged.

In this case, Push identified Mevspace AS201814 as the hosting provider for Cluster A. They also documented the Cluster A naming patterns, including:

<target>internal.com
<target>sso.com
my<target>.com
my<target>internal.com
my<target>manager.com
my<target>sso.com

Using those patterns as a starting point, Scout surfaced active infrastructure consistent with the same cluster.

Confirming Cluster A on Mevspace

Push identified Mevspace AS201814 as the Cluster A hosting provider but did not publish IP-level indicators. Starting from the hosting provider and domain naming criteria, a single Scout query returned three results:

asn="201814" pdns.domain="*internal.com,*sso.com"

Scout query result for Mevspace AS201814 with the Cluster A domain pattern

Figure 1: Scout returns three IPs for the Mevspace AS201814 plus *internal.com,*sso.com query. Two of them, 149.50.97.174 and 149.50.127.228, showed passive DNS associations consistent with Cluster A. The third, 149.86.225.36, was a shared-hosting box (earth.scnservers.net) with diverse unrelated tenants and was excluded from further analysis.

The two IPs consistent with Cluster A hosting patterns were 149.50.97.174 and 149.50.127.228. Both were hosted on Mevspace AS201814 and showed passive DNS associations consistent with Cluster A domain patterns.

Filter methodology

Each Mevspace IP carries a sizeable passive DNS history. For example, 149.50.97.174 shows 61 unique PDNS records over the last 30 days with 1,999 cumulative observation events across them, and 149.50.127.228 carries a comparable footprint. Not every recorded domain belongs to the actor. Historical tenants, wildcard records, scanner artifacts, and shared-hosting noise all appear in raw PDNS. To isolate domains consistent with Cluster A activity, we applied an explicit filter:

  • Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED (or its parent group CNOBIN INFORMATION TECHNOLOGY LIMITED)
  • Nameservers: ns0.1984.is and ns1.1984hosting.com
  • Recency: last seen within the last 30 days
  • A record: pointing to the Mevspace AS201814 IP

That filter matches Push’s published Cluster A fingerprint at the registrar and nameserver layer, applied per-domain rather than per-IP. Domains that did not meet all four criteria were excluded.

The IOC tables and targeting profile below reflect that filtered subset.

149.50.97.174

The first IP was associated with a substantial set of victim-themed domains. Passive DNS linked the following domains to the host within the last 30 days, all matching the Cluster A registrar and nameserver fingerprint:

Passive DNS detail for 149.50.97.174 showing Cluster A victim-templated domains

Figure 2: Passive DNS associations for 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.

Domains observed on 149.50.97.174:

  • mydisneysso.com, mydisneymanager.com, mydisneyconnect.com
  • myyalemanager.com, cp.myyalemanager.com
  • myupennmanager.com
  • mykkrconnect.com
  • mynikemanager.com
  • myjbhifi.com
  • mydicksmanager.com
  • mypublixmanager.com
  • mypetcomanager.com
  • mypurpledirect.com, mypurpleconnect.com, mypurplemanager.com, mypurpleidsso.com, purpleidconnect.com
  • mynavmanagbsnsjser.com, mynavmanadbsnsger.com
  • shift4internal.com
  • accounts-nexo.com
  • account-ndax.com
  • amazoninternal.com
  • atocalculation.com
  • koinlylegal.io, legal-koinly.io
  • meridian-saving.com
  • lvmhinternal.com
  • brixmorssoo.com
  • vault-blofin.com
  • binanapi-912512.com
  • myiqeq.com
  • verify91358.com, verification12589.com

Several of these align with Push’s published Cluster A naming conventions. mydisneysso.com and amazoninternal.com are named verbatim in Push’s writeup. Others follow the same victim-themed pattern, including manager, internal, connect, direct, and sso language.

The observed target set spans higher education (Yale, UPenn), financial services (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi, Dick’s, Publix, Petco, Purple Mattress), cryptocurrency (Nexo, NDAX, Koinly, Blofin), and Australian taxation themes (atocalculation.com). Two domains (verify91358.com, verification12589.com) follow a generic verification pretext rather than a specific brand template, suggesting the operator also runs cross-platform credential-verification pages alongside the brand-specific kits. That is consistent with the broader campaign logic Push described: identity access and session capture are most valuable when they provide access to SaaS data, payment systems, crypto platforms, or other high-value enterprise environments.

Two operator-side artifacts stood out. First, cp.myyalemanager.com is a cp. subdomain on the Yale-targeted phishing domain. The cp. prefix is consistent with a control-panel or admin endpoint for the operator’s panel UI. Second, on port 21, the host presented a self-signed certificate with the following details:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            58:23:e9:3d:a7:48:1e:3e:7f:5c:85:12:15:d9:63:0c:f4:6e:f2:06
        Signature Algorithm: sha256WithRSAEncryption
        Issuer:  C=CN, ST=Guangdong, L=Dongguan, O=BT-PANEL, OU=BT,
                CN=149.50.97.174, emailAddress=admin@bt.cn
        Validity:
            Not Before: Oct 23 23:37:02 2025 GMT
            Not After:  Mar 19 23:37:02 2027 GMT
        Subject: C=CN, ST=Guangdong, L=Dongguan, O=BT-PANEL, OU=BT,
                CN=149.50.97.174, emailAddress=admin@bt.cn
        Public Key Algorithm: rsaEncryption
            Public-Key: (2048 bit)

BT-Panel self-signed certificate on port 21 of 149.50.97.174

Figure 3: BT-Panel self-signed certificate observed on port 21 of 149.50.97.174. Issued at install time on October 23, 2025, with a roughly seventeen-month validity window through March 2027.

BT-Panel is a Chinese-language web hosting management application. The certificate’s Not Before value of October 23, 2025 corresponds to when BT-Panel was installed on this host, which predates the earliest observed Cluster A domain registrations on the same IP by approximately four months. That is consistent with an operator preparation timeline where infrastructure is staged before campaign deployment, but it does not by itself prove operator preparation. It could equally reflect a longer-tenured BT-Panel installation that was later put to this use, or a hosting reseller’s default image.

The certificate’s presence is useful infrastructure context, but it should not be treated as attribution evidence on its own. It could reflect operator tooling, hosting defaults, reseller configuration, server reuse, or prior compromise. That distinction matters. The artifact adds color to the infrastructure picture. It does not prove actor origin. The certificate serial number 58:23:e9:3d:a7:48:1e:3e:7f:5c:85:12:15:d9:63:0c:f4:6e:f2:06 is unique to this installation and can be used as a precise hunting fingerprint for this specific host.

Cymru’s communications telemetry shows a peer profile consistent with two dominant traffic shapes. Cloudflare CDN peers (172.69.219.144, 172.69.219.145) on ports 80 and 443 are consistent with traffic reaching Cloudflare-fronted lure infrastructure. The remaining top peers (178.128.151.55, 170.64.252.169, 157.20.254.47, 193.147.107.216) have characteristics of internet-wide scanner background noise rather than actor activity. The pattern is consistent with expected traffic to Cloudflare-fronted phishing infrastructure: gated victim landing through CDN front, with ambient scanner volume layered on top.

Top peers for 149.50.97.174 — Sankey diagram showing inbound CDN and scanner traffic
Figure 4: Top peers for 149.50.97.174 rendered as a Sankey flow diagram in Scout, showing inbound peers and destination ports on the left and outbound peers and source ports on the right. Traffic on ports 80 and 443 dominates the inbound side.

149.50.127.228

The second IP showed a different mix of related domains, with a stronger crypto-platform focus:

Passive DNS detail for 149.50.127.228 showing crypto-themed domains and the Doko panel artifact 

Figure 5: Passive DNS associations for 149.50.127.228 including crypto-ato.com, the admin.<numeric-token>.<brand> campaign tracking pattern, and dokopanel.com.

Domains observed on 149.50.127.228:

  • crypto-ato.com, atocalculation.com-aligned theme
  • restriction-nexo.com, l6.restriction-nexo.com
  • overview-gmail.com
  • safety-river.com
  • account-ndax.com, account-ndax.io, 852319-ndax.com, admin.account-ndax.com, admin.account-ndax.io, admin.852319-ndax.com
  • 412721coinbase.com, 118507coinbase.com, 953536-cb.com, admin.412721coinbase.com, admin.118507coinbase.com
  • 419256crypto.com, admin.419256crypto.com
  • 501938binance.com, 53253binance.com, admin.501938binance.com, www.binance.us.53253binance.com, www.binance.com.53253binance.com
  • device-verizon.com, admin.device-verizon.com
  • accounts-bitpanda.com
  • help-cointracker.com, admin.help-cointracker.com
  • myvanecksso.com, myvaneckmanager.com
  • dokopanel.com, admin.dokopanel.com

The targeting set on this node is more concentrated on cryptocurrency platforms and tax-filing themes: Coinbase, Binance, NDAX, Bitpanda, Nexo, CoinTracker, Koinly, and the Australian Taxation Office. VanEck (asset management) and Verizon-themed device-attestation domains also appear.

A few notes on patterns visible in this dataset:

  • The <6-digit-token>-<brand>.com and admin.<6-digit-token><brand>.com shape recurs: 412721coinbase.com, 501938binance.com, 953536-cb.com, 852319-ndax.com, 118507coinbase.com, 419256crypto.com, and their admin. siblings. The numeric tokens are likely operator-side identifiers, routing values, build markers, or campaign tracking values. Their exact role remains unresolved without direct panel visibility.
  • The Binance subdomain typosquats www.binance.us.53253binance.com and www.binance.com.53253binance.com are designed so URL-bar truncation reads as the real binance.com or binance.us host. This is an additional TTP not always documented in panel-side reporting.
  • crypto-ato.com is consistent with the Australian Taxation Office–themed activity Push described in relation to a panel variant targeting cryptocurrency tax filing. Push identified independently branded forks of the tooling, including the “Lord Mensius’s Panel” variant and another Australian Tax Office–themed panel.

That said, consistency is not the same as confirmation. Without direct panel visibility, source code, or content capture from this specific domain, the safest assessment is that crypto-ato.com aligns with the theme Push described. It should not be presented as a confirmed instance of a specific fork based on naming alone.

Cymru’s communications telemetry for 149.50.127.228 shows a peer profile consistent with three distinct traffic shapes. Cloudflare CDN peers (172.69.219.146, 172.69.219.147) on ports 80 and 443 are consistent with traffic reaching Cloudflare-fronted lure infrastructure, matching the pattern Push documented for Clusters C and D. A heavy concentration of US, EU, and APAC geographies represents internet-wide scanner background noise rather than actor activity. A single Indonesian peer, 103.178.152.76, sits at the top of the inbound band with thirteen events — too few to draw operational conclusions from telemetry alone, but worth individual investigation. Outbound peers concentrate on a small set of addresses across the US, FR, and IN, plus one Russian IP (64.225.74.178), on non-standard high TCP ports. The diagram below summarizes the bidirectional traffic shape.

Top peers for 149.50.127.228 — Sankey diagram showing inbound CDN and scanner traffic and outbound DigitalOcean peers
Figure 6: Top peers for 149.50.127.228 rendered as a Sankey flow diagram in Scout. The left band shows inbound peers and the destination ports they reach on the IP; the right band shows outbound peers and source ports. Heavy CDN and scanner volume on ports 80, 443, and 22 dominates the inbound side; outbound traffic concentrates on a small set of IP addresses and one Russian peer on non-standard TCP ports.

A Doko-branded hosting-layer artifact: dokopanel.com

One domain on 149.50.127.228 warrants individual attention.

dokopanel.com resolved to 149.50.127.228 through April and into May 2026, with admin.dokopanel.com as a sibling subdomain. Push attributed the panel kit at the center of their analysis to a developer using the Telegram alias Doko, naming the kit “Doko’s Panel” after that alias. The presence of dokopanel.com on the same Mevspace IP as Cluster A aligned domains is a notable Doko-branded artifact. It provides useful pivot context, but should not be treated as proof of control by a specific individual.

dokopanel.com itself does not match the Cluster A registrar fingerprint:

  • Registrar: Tucows Domains Inc.
  • Nameservers: 1-you.njalla.no, 2-can.njalla.in, 3-get.njalla.fo
  • Registered: 2026-01-17

That is the Cluster B registrar and nameserver pair Push documented (Tucows plus Njalla), not the Cluster A pair (NICENIC plus 1984.is). The implication is straightforward and consistent with Push’s own framing: while the panel kits share a common code heritage and victim-side phishing domains use Cluster A registrars, the developer’s personal or brand-side infrastructure uses a different registrar profile. This suggests some overlap at the hosting or infrastructure-use layer, but it does not prove the same operator controls both clusters.

This observation does not, by itself, prove that any specific named individual operates 149.50.127.228. It is best treated as a hosting-layer artifact that defenders can pivot on, and as additional support for Push’s “shared heritage, separate operators” framing.

Targeting profile

Combining Push’s published examples with the additional domains observed through Scout, the Cluster A–aligned target set spans several categories:

  • Identity providers: Okta, Microsoft Entra, Google Workspace
  • Higher education: Yale University, University of Pennsylvania
  • Financial services and asset management: Shift4 Payments, KKR, VanEck, IQ-EQ, Meridian Savings
  • Real estate: Brixmor Property Group
  • Luxury goods: LVMH
  • Retail and consumer: Nike, Disney, Dick’s Sporting Goods, Publix, Petco, JB Hi-Fi, Purple Mattress
  • Cryptocurrency platforms and tax tools: Coinbase, Binance, Nexo, NDAX, Bitpanda, Blofin, CoinTracker, Koinly
  • Telecommunications and device attestation: Verizon
  • Generic credential-verification pretext: verify91358.com, verification12589.com
  • Originally Push-named: Dropbox, Xero, Amazon, Disney, Sonos, Adyen, Epic Games
  • Australian taxation–themed activity: crypto-ato.com, atocalculation.com

The pattern suggests a focus on organizations where compromised identity access could quickly create operational or financial leverage. That includes enterprise SaaS environments, financial services, payment processors, higher education, retail, and cryptocurrency platforms.

This is where infrastructure intelligence becomes useful. A single phishing domain may be taken down quickly. But when the same infrastructure patterns repeat across hosting providers, certificates, naming conventions, and exposed services, defenders can begin hunting the broader operational footprint rather than waiting for the next domain to appear in a user report.

What passive observation adds

Push’s research provided the operator-side view. They accessed active panels, observed real victim flows, analyzed source code, and documented how the phishing kits work from inside the attack chain.

Passive network telemetry answers a different set of questions. It can show where the infrastructure is hosted, what domains resolve to it, which certificates are present, what services are exposed, what fingerprints recur, and how related infrastructure clusters over time. That does not replace direct panel access. It complements it.

In this case, passive observation added:

  • IP-level indicators for Cluster A hosting
  • More than 40 victim-themed domains active on Mevspace infrastructure across the two Cluster A aligned nodes
  • A repeatable filter (registrar, nameservers, recency, hosting) that isolates Cluster A domains from PDNS noise
  • A Doko-branded hosting-layer artifact, dokopanel.com, colocated with Cluster A aligned infrastructure
  • Certificate and exposed-service artifacts including the operator-side cp. and admin. subdomain patterns
  • TLS fingerprints useful for defender hunting
  • Repeatable Scout queries for scheduled discovery

No single vantage point gives the full picture. Browser telemetry, panel access, incident response data, passive DNS, certificate telemetry, and large-scale network visibility all answer different questions. The value comes from putting those perspectives together.

Analytic caveats

This analysis validates infrastructure patterns associated with Push Security’s Cluster A reporting. It does not independently attribute the activity to ShinyHunters based on passive telemetry alone.

There are several limits worth stating clearly.

First, passive telemetry can corroborate hosting, domain resolution, certificates, exposed services, and infrastructure overlap. It does not provide the same visibility as direct panel access, source code review, victim submission logs, or operator communications.

Second, passive DNS associations do not automatically prove common ownership of every domain. In this case, confidence is strengthened by the shared ASN, consistent registrar and nameserver pair, victim-themed naming conventions, certificate behavior, temporal clustering, and alignment with Push’s published Cluster A framework. The filter described above was applied to exclude domains that did not meet those criteria.

Third, infrastructure artifacts such as BT-Panel should be treated as context, not attribution evidence. They may reflect operator tooling, hosting defaults, reseller configuration, server reuse, or prior compromise.

Fourth, numeric tokens in domains such as 412721coinbase.com may be operator-side identifiers, routing values, build markers, or campaign tracking values. Their exact role remains unresolved without direct panel visibility.

Fifth, the dokopanel.com observation is a hosting-layer artifact. It places Doko-branded infrastructure on the same Mevspace IP as Cluster A victim domains, but it does not by itself identify any specific individual or prove operational control of the broader campaign.

Finally, Push explicitly noted that the panels share common heritage but appear to be deployed by separate groups with different infrastructure preferences and operational patterns. That distinction matters. Cluster A should not be treated as synonymous with the entire ShinyHunters or BlackFile ecosystem.

The most defensible conclusion is this: we independently validated active infrastructure consistent with Push Security’s Cluster A reporting, surfaced more than 40 additional victim-themed domains aligned with the same fingerprint, and identified a Doko-branded hosting-layer artifact colocated with Cluster A aligned infrastructure.

Hunting guidance

The following Scout queries can be used to reproduce and extend the analysis. The Scout API caps a single search to 30 days; for longer windows, run sequential queries and union the results.

Cluster A discovery on Mevspace:

asn="201814" pdns.domain="*internal.com,*sso.com,*manager.com,*connect.com,*direct.com"

Cluster A registrar and nameserver fingerprint:

pdns.registrar="NICENIC*,CNOBIN*" pdns.nameserver="*1984.is,*1984hosting.com"

Specific named-domain validation:

pdns.domain="mydisneysso.com,mydropboxinternal.com,myxerointernal.com,amazoninternal.com,
mydisneyconnect.com,myyalemanager.com,shift4internal.com,myupennmanager.com,mykkrconnect.com,
mynikemanager.com,myjbhifi.com,mydicksmanager.com,mypublixmanager.com,mypetcomanager.com,
accounts-nexo.com,account-ndax.com,account-ndax.io,852319-ndax.com,accounts-bitpanda.com,
help-cointracker.com,koinlylegal.io,legal-koinly.io,crypto-ato.com,atocalculation.com,
myvanecksso.com,myvaneckmanager.com,dokopanel.com"

Numeric-token domain pattern:

pdns.domain.regex="^[0-9]{6}-?(coinbase|binance|crypto|cb|ndax)\.com$"

Operator subdomain artifacts:

pdns.domain="cp.*.com,admin.*.com" asn="201814"

Cluster B discovery on Njalla:

asn="39287" pdns.domain="*internal.com,*sso.com"

Cloudflare-fronted Cluster C and D activity:

pdns.domain="*.passkeysetup.com,*.enrollms.com,*.keyokta.com,*.passkeywork.com,
*.passkeyportalsetup.com,*.addoktapasskey.com"

Panel HTTP fingerprints:

openports.banner="*backend.php*"
openports.banner="*api_FyekIDWY.php*"

TLS fingerprint hunting:

fingerprints.hash="7291ea5e449f2c7b17582541703e549d" fingerprints.type="ja3"
fingerprints.hash="15af977ce25de452b96affa2addb1036" fingerprints.type="ja3s"

Sweep adjacent Mevspace blocks:

pdns.ip="149.50.96.0/22"
asn="201814" openports.service="HTTPS.OPENDIR"

Cluster A operators rotate domains quickly. Scheduled hunts against AS201814 combined with the registrar and nameserver fingerprint can help defenders identify new deployments as they come online.

Indicators of compromise

Cluster A aligned IPs

IP ASN Country Last seen
149.50.97.174 AS201814 MEVSPACE PL 2026-05-07
149.50.127.228 AS201814 MEVSPACE PL 2026-05-07

Domains on 149.50.97.174 (Cluster A fingerprint applied)

mydisneysso.com
mydisneymanager.com
mydisneyconnect.com
myyalemanager.com
cp.myyalemanager.com
myupennmanager.com
mykkrconnect.com
mynikemanager.com
myjbhifi.com
mydicksmanager.com
mypublixmanager.com
mypetcomanager.com
mypurpledirect.com
mypurpleconnect.com
mypurplemanager.com
mypurpleidsso.com
purpleidconnect.com
mynavmanagbsnsjser.com
mynavmanadbsnsger.com
shift4internal.com
accounts-nexo.com
account-ndax.com
amazoninternal.com
atocalculation.com
koinlylegal.io
legal-koinly.io
meridian-saving.com
lvmhinternal.com
brixmorssoo.com
vault-blofin.com
binanapi-912512.com
myiqeq.com
verify91358.com
verification12589.com

Domains on 149.50.127.228 (Cluster A fingerprint applied)

crypto-ato.com
restriction-nexo.com
l6.restriction-nexo.com
overview-gmail.com
safety-river.com
account-ndax.com
account-ndax.io
852319-ndax.com
admin.account-ndax.com
admin.account-ndax.io
admin.852319-ndax.com
412721coinbase.com
118507coinbase.com
953536-cb.com
admin.412721coinbase.com
admin.118507coinbase.com
419256crypto.com
admin.419256crypto.com
501938binance.com
53253binance.com
admin.501938binance.com
www.binance.us.53253binance.com
www.binance.com.53253binance.com
device-verizon.com
admin.device-verizon.com
accounts-bitpanda.com
help-cointracker.com
admin.help-cointracker.com
myvanecksso.com
myvaneckmanager.com
dokopanel.com
admin.dokopanel.com

Push Security’s published indicators (mirrored for completeness)

Cluster A, Doko’s Panel client.js SHA-256:

8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c
f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692

Cluster B, heartbeat variant client.js SHA-256:

c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26
d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb
9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21
e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86

Cluster C, heartbeat + Cloudflare Turnstile:

cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102

Cluster D, minified:

9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a

Push’s full collection of 400+ campaign domains is published in their VirusTotal collection.

Closing

Push Security provided the inside view of the phishing panels. Their research showed how the panels operate, how victims are handled in real time, and how related variants are being deployed across multiple infrastructure clusters.

Team Cymru’s telemetry provides the infrastructure view. Using Pure Signal Scout, we validated active Cluster A–aligned infrastructure on Mevspace, surfaced more than 40 victim-themed domains across the two Cluster A aligned nodes, identified a Doko-branded hosting-layer artifact colocated with Cluster A aligned infrastructure, and developed repeatable hunting logic defenders can use to track related activity.

Continued monitoring of AS201814 and the associated registrar, nameserver, and domain patterns can help defenders identify follow-on deployments as infrastructure rotates. The value of network-telemetry-driven detection is highest when visibility is continuous rather than one-off.

Acknowledgments

This work would not exist without the Push Security research team and the Mandiant / Google Threat Intelligence Group reporting on UNC6240, UNC6661, and UNC6671 that established the actor framework these clusters fit into. Passive intelligence is most useful when paired with operator-side observation and incident-response data. Thanks to those teams for the work that made this corroboration possible.

References

The Team Cymru threat research team monitors actor infrastructure across the global internet using Pure Signal Recon and Pure Signal Scout. To learn more about how Cymru helps defenders track adversary infrastructure at scale, visit team-cymru.com.