[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJ4Ltev6paIw3nDQQShigvedM7vA7U_NIlr2MO0Ci-_M":3},{"article":4,"iocs":38,"watch_terms":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"4fb8cc57-35f1-4b19-b8c2-5ce8692db242","\"since December\"\nAt least since November.\nAnd if you look at the relations of 188.214.34[.]20 (th...","since-december-at-least-since-november-and-if-you-look-at-the-relations-of-188-2-27be8f","\"since December\"\nAt least since November.\nAnd if you look at the relations of 188.214.34[.]20 (the IP that was used in the sample that was seen in November), you can find the zx.ado-read-parser[.]com subdomain still resolving to that IP. And the ado-read-parser[.]com domain was https:\u002F\u002Ft.co\u002FC8c1RL2VIi https:\u002F\u002Ft.co\u002FRRiBGb2uq1","Security researchers identified malicious infrastructure associated with a threat campaign active at least since November 2024. The investigation revealed an IP address (188.214.34.20) hosting malicious samples and C2 domains, including a subdomain of ado-read-parser.com that continues to resolve to the attacker's infrastructure.","Threat actor infrastructure linked to malware campaign active since November with persistent C2 domains.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2042195370051092967","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHFdUChoW8AA78ND.png","2026-04-09T10:58:13+00:00","2026-04-09T11:00:09.861403+00:00",7,[],"e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":18,"icon":11,"name":20,"slug":21},"Threat Intelligence","threat-intelligence",[23,28,33],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[39,43,47],{"type":40,"value":41,"context":42},"ip","188.214.34.20","IP address hosting malicious samples and C2 infrastructure since November 2024",{"type":44,"value":45,"context":46},"domain","ado-read-parser.com","Malicious domain associated with campaign infrastructure",{"type":44,"value":48,"context":49},"zx.ado-read-parser.com","Subdomain actively resolving to attacker IP 188.214.34.20",[]]