[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvHf4EGkfqbl2-VoGXZUqkGLO0XsZLUdND78k3o3bWwY":3},{"article":4,"iocs":30,"watch_terms":42},{"id":5,"title":6,"slug":7,"summary":6,"ai_summary":8,"brief":9,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":20,"category":21,"article_tags":24},"f19afd0a-1f5c-41e8-9e97-c2fa0b12f3b4","systemautoupdater[.]com\nmon.systemautoupdater[.]com\n23.27.141[.]44\n🤔\n🤷‍♂️ https:\u002F\u002Ft.co\u002FExbR94BUE2","systemautoupdater-com-mon-systemautoupdater-com-23-27-141-44-https-t-co-exbr94bu","Security researchers have identified malicious infrastructure related to a fake system updater campaign, including two domains (systemautoupdater[.]com and mon.systemautoupdater[.]com) and an associated IP address (23.27.141[.]44). This appears to be part of a broader malware distribution or command-and-control network leveraging legitimate-sounding system update branding.","Suspicious domains and IP address associated with system updater malware infrastructure identified.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2041877789029068955","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHFY0vvSXoAAFZ89.jpg","2026-04-08T13:56:15+00:00","2026-04-08T14:00:27.941348+00:00",7,[17],{"name":18,"type":19},"System Updater Malware Campaign","campaign","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":20,"icon":10,"name":22,"slug":23},"Threat Intelligence","threat-intelligence",[25],{"category":26},{"id":27,"icon":10,"name":28,"slug":29},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[31,35,38],{"type":32,"value":33,"context":34},"domain","systemautoupdater[.]com","Malicious domain masquerading as system updater",{"type":32,"value":36,"context":37},"mon.systemautoupdater[.]com","Subdomain of malicious system updater domain",{"type":39,"value":40,"context":41},"ip","23.27.141.44","IP address hosting malicious updater infrastructure",[]]