PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS
Environment Threat Tracking Center

Enterprise Infiltration Console

Forensic timelines, indicators of compromise, and remediation logs for active adversary groups.

Select Adversary Group to Track
Target: Carbanak Group (FIN7)
Classification / TypeCybercriminal / APT Syndicate
Country AffiliationRussia / Eastern Europe
Primary MotivationsFinancial Theft, Ransomware Operations, Access Brokerage
Known Attack Patterns
Phishing AttachmentsCredential HarvestingRansomware DeploymentPoint-of-Sale (POS) Infiltration

Campaign Threat Assessment

94%Detections Triggered
100%Exfiltration Blocked
12mResponse Time

Observed Indicators (IOCs)Campaign Scope

185.220.101.44Blocked at Firewall
Command and Control server for Carbanak malware payload
invoice_detail_553.lnkFile Quarantine
Malicious LNK dropper initiating PowerShell execution
accounting-portal-sync.netDNS Sinkholed
C2 domain routing exfiltrated financial system audits

Remediation & Hardening Actions

  • LNK File Execution Blocking:

    Configured Group Policy Objects (GPO) to block execution of shortcut LNK files from public folders.

  • Accounting Access Hardening:

    Enforced strict MFA constraints for all access points to corporate payroll and accounting web interfaces.

Active Campaign & Infrastructure Radar

OPERATIONAL INTEL RADAR

Real-Time Threat Actor Campaign Progression, Live C2 Infrastructure & SOC Telemetry

This View: Active Campaign Radar (`/tracking`)

Focuses on WHAT adversaries are doing right now—live C2 IPs/domains, active intrusion steps, detection trigger rates, and real-time IOC feeds.

Strategic View: Threat Actor Dossiers (`/actors`)

Focuses on WHO adversaries are—country origin, threat group aliases, targeted industries, historical breach catalog, and MITRE ATT&CK technique mapping.

🏴‍☠️ MANDIANT UNC / RAASCRITICAL

UNC6671 (BlackFile)

Perimeter SSL-VPN breaches, credential dumping, and dual-extortion ransomware targeting global banks.

Target: Fintech / Banking3 Breaches
🇷🇺 RUSSIA / APT28CRITICAL

Void Blizzard (Fancy Bear)

Abusing M365 OAuth consent applications & edge VPN zero-days for financial access.

Target: Financial / M3653 Breaches
🏴‍☠️ RAAS CARTELCRITICAL

LockBit 3.0 Supporter Cluster

Active double-extortion ransomware targeting regional banks & core payment infrastructure.

Target: Core Banking14 Breaches
🇰🇵 DPRK / APT38HIGH

Lazarus / BlueNoroff

Spearphishing financial engineers with ClickFix fake update kits & browser malware.

Target: Fintech / Crypto1 Breach
LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.