{"search_term":"ransomware","iocs":[{"value":"https://bsky.app/profile/newsarea.bsky.social/post/3mr3fmmrewj24","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/newsarea.bsky.social/post/3mr3fmmrewj24"]},{"value":"https://bsky.app/profile/ninjaowl.ai/post/3mr47nkbhjy2g","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/ninjaowl.ai/post/3mr47nkbhjy2g"]},{"value":"https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wnc2eqj2z","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wnc2eqj2z"]},{"value":"https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wkwjkvn2d","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wkwjkvn2d"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":100,"comment":"Domain hosting the report about the RansomHouse ransomware/datatheft group's claim against Nichirei Corp.","links":["https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":100,"comment":"URL linking to the report about the RansomHouse ransomware/datatheft group's claim against Nichirei Corp.","links":["https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g"]},{"value":"thehackernews.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain extracted from the URL in the text","links":["https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27"]},{"value":"hxxp://thehackernews[.]com/20...","type":"url","subtype":null,"relevance":100,"comment":"Defanged URL extracted from the text","links":["https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27"]},{"value":"https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27"]},{"value":"https://bsky.app/profile/bhaveshverma.com/post/3mr7rnqczz22k","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/bhaveshverma.com/post/3mr7rnqczz22k"]},{"value":"https://www.wired.com/story/foxconn-ransomware-attack-shows-nothing-is-safe-forever/","type":"url","subtype":null,"relevance":100,"comment":"Article discussing Foxconn's ransomware attack and cybersecurity implications.","links":["https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o"]},{"value":"https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o"]},{"value":"https://ift.tt/xKtGioY","type":"url","subtype":null,"relevance":100,"comment":"Chaos ransomware msaRAT article URL","links":["https://t.me/c/1177932374/21076"]},{"value":"https://ift.tt/TeIfw3V","type":"url","subtype":null,"relevance":100,"comment":"Reddit discussion link about the article","links":["https://t.me/c/1177932374/21076"]},{"value":"@blueteamalerts","type":"username","subtype":null,"relevance":100,"comment":"Twitter handle mentioned in the text","links":["https://t.me/c/1177932374/21076"]},{"value":"https://t.me/c/1177932374/21076","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://t.me/c/1177932374/21076"]},{"value":"cyberwald.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain mentioned in the podcast link.","links":["https://social.tchncs.de/@cyberwald/116973406962300114"]},{"value":"https://cyberwald.com/podcast/2026-07-24.podcast.ogg","type":"url","subtype":null,"relevance":100,"comment":"Podcast URL provided in the text.","links":["https://social.tchncs.de/@cyberwald/116973406962300114"]},{"value":"CVE-2026-64600","type":"vulnerability","subtype":null,"relevance":100,"comment":"Referenced Linux Root-Lücke.","links":["https://social.tchncs.de/@cyberwald/116973406962300114"]},{"value":"CVE-2026-16232","type":"vulnerability","subtype":null,"relevance":100,"comment":"Referenced Check Point SmartConsole vulnerability.","links":["https://social.tchncs.de/@cyberwald/116973406962300114"]},{"value":"https://social.tchncs.de/@cyberwald/116973406962300114","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://social.tchncs.de/@cyberwald/116973406962300114"]},{"value":"Clop","type":"threat-actor","subtype":null,"relevance":100,"comment":"Clop ransomware gang name","links":["https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a"]},{"value":"Cl0p","type":"threat-actor","subtype":null,"relevance":100,"comment":"Alternative tracking name for Clop ransomware gang","links":["https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a"]},{"value":"https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a"]},{"value":"https://otx.alienvault.com/pulse/6a636223b470c7200c1cfac1","type":"external-report-link","subtype":"external-article","relevance":100,"comment":"Pulse link containing details about the msaRAT ransomware activity","links":["https://social.raytec.co/@techbot/116975086404545944"]},{"value":"cryptocti","type":"username","subtype":null,"relevance":100,"comment":"Pulse author associated with the msaRAT ransomware activity","links":["https://social.raytec.co/@techbot/116975086404545944"]},{"value":"Chrome","type":"browser-extension-id","subtype":null,"relevance":100,"comment":"Headless browser used for C2 communications by msaRAT","links":["https://social.raytec.co/@techbot/116975086404545944"]},{"value":"Edge","type":"browser-extension-id","subtype":null,"relevance":100,"comment":"Headless browser used for C2 communications by msaRAT","links":["https://social.raytec.co/@techbot/116975086404545944"]},{"value":"https://social.raytec.co/@techbot/116975086404545944","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://social.raytec.co/@techbot/116975086404545944"]},{"value":"www.bleepingcomputer.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain from the provided URL","links":["https://mastodon.social/@gtbarry/116975081792289798"]},{"value":"Everest","type":"threat-actor","subtype":null,"relevance":100,"comment":"Name of the ransomware gang mentioned","links":["https://mastodon.social/@gtbarry/116975081792289798"]},{"value":"Stadler Rail","type":"username","subtype":null,"relevance":100,"comment":"Name of the company mentioned in the attack","links":["https://mastodon.social/@gtbarry/116975081792289798"]},{"value":"https://mastodon.social/@gtbarry/116975081792289798","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://mastodon.social/@gtbarry/116975081792289798"]},{"value":"https://bsky.app/profile/undercodenews.bsky.social/post/3mrhhh65fdt2d","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/undercodenews.bsky.social/post/3mrhhh65fdt2d"]},{"value":"insicurezzadigitale.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain hosting the blog about Funky Mantis and DevMan ransomware gang.","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24"]},{"value":"http://insicurezzadigitale.com/funky-mantis","type":"url","subtype":null,"relevance":100,"comment":"URL of the blog post discussing Funky Mantis and DevMan ransomware gang.","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24"]},{"value":"https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24"]},{"value":"insicurezzadigitale.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain hosting the blog article about UNC6692's tradecraft","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r"]},{"value":"UNC6692","type":"threat-actor","subtype":null,"relevance":100,"comment":"Attributed threat actor mentioned in the blog title","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r"]},{"value":"https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r"]},{"value":"https://bsky.app/profile/undercodenews.bsky.social/post/3mrk6afuevd2f","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/undercodenews.bsky.social/post/3mrk6afuevd2f"]},{"value":"takethehop.com","type":"domain","subtype":null,"relevance":100,"comment":"Domain associated with the IncRansom ransomware attack on Texas regional transit network.","links":["https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q"]},{"value":"IncRansom","type":"threat-actor","subtype":null,"relevance":100,"comment":"Ransomware group that claimed the attack.","links":["https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q"]},{"value":"https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q"]},{"value":"https://bsky.app/profile/richardfreiberg.bsky.social/post/3mrmqvvdv2s2m","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/richardfreiberg.bsky.social/post/3mrmqvvdv2s2m"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":100,"comment":"Domain hosting the report about the Qilin ransomware/data theft group targeting Savills SASU.","links":["https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":100,"comment":"URL linking to the report about the Qilin ransomware/data theft group targeting Savills SASU.","links":["https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27","type":"external-report-link","subtype":"post-link","relevance":100,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27"]},{"value":"www.bleepingcomputer.com","type":"domain","subtype":null,"relevance":90,"comment":"Source article domain","links":["https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2"]},{"value":"hxxp://www[.]bleepingcomputer[.]com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/","type":"url","subtype":null,"relevance":90,"comment":"Source article URL (defanged)","links":["https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2"]},{"value":"https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2"]},{"value":"https://bsky.app/profile/kotosecurity.bsky.social/post/3mqunkpi2mb2u","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/kotosecurity.bsky.social/post/3mqunkpi2mb2u"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":90,"comment":"Domain hosting the report about the DragonForce ransomware/datatheft group's claim against NewNet S.A.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":90,"comment":"URL linking to the report about the DragonForce ransomware/datatheft group's claim against NewNet S.A.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":90,"comment":"Domain hosting the report about the LockBit 5.0 ransomware/data theft claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":90,"comment":"URL linking to the report about the LockBit 5.0 ransomware/data theft claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":90,"comment":"Domain hosting the report about LockBit 5.0 ransomware/datatheft group targeting Adventus Pte. Ltd.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":90,"comment":"URL linking to the report about LockBit 5.0 ransomware/datatheft group targeting Adventus Pte. Ltd.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a"]},{"value":"https://ecrime.ch/","type":"url","subtype":null,"relevance":90,"comment":"Link to the external report about the ransomware/datatheft group LockBit 5.0 claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27"]},{"value":"LockBit5.0","type":"threat-actor","subtype":null,"relevance":90,"comment":"Ransomware/datatheft group mentioned in the claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27"]},{"value":"Pioneer Coldstore & Cladding Pvt. Ltd.","type":"username","subtype":null,"relevance":90,"comment":"Organization name mentioned in the claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":90,"comment":"Domain hosting the report about the LockBit 5.0 ransomware/data theft claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":90,"comment":"URL linking to the report about the LockBit 5.0 ransomware/data theft claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b"]},{"value":"ecrime.ch","type":"domain","subtype":null,"relevance":90,"comment":"Domain hosting the report about the LockBit 5.0 ransomware/datatheft group claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q"]},{"value":"https://ecrime.ch","type":"url","subtype":null,"relevance":90,"comment":"URL linking to the report about the LockBit 5.0 ransomware/datatheft group claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q"]},{"value":"https://ecrime.ch/","type":"url","subtype":null,"relevance":90,"comment":"Link to the external report about the ransomware/datatheft group LockBit 5.0 and the claimed attack on Micropack S.A.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g"]},{"value":"LockBit5.0","type":"threat-actor","subtype":null,"relevance":90,"comment":"Name of the ransomware/datatheft group claiming the attack.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g"]},{"value":"Micropack S.A.","type":"username","subtype":null,"relevance":90,"comment":"Organization name mentioned in the claim.","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g"]},{"value":"https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g"]},{"value":"intel.threadlinqs.com","type":"domain","subtype":null,"relevance":90,"comment":"Domain from the provided threat intelligence link","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"CVE-2025-7771","type":"vulnerability","subtype":null,"relevance":90,"comment":"CVE associated with Qilin Ransomware","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"AgendaCrypt","type":"threat-actor","subtype":null,"relevance":90,"comment":"Ransomware family mentioned in the context","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"Gentlemen","type":"threat-actor","subtype":null,"relevance":90,"comment":"Ransomware family mentioned in the context","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"MedusaLocker","type":"threat-actor","subtype":null,"relevance":90,"comment":"Ransomware family mentioned in the context","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"Qilin","type":"threat-actor","subtype":null,"relevance":90,"comment":"Ransomware family mentioned in the context","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"https://mastodon.social/@threadlinqs/116935905990302882","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://mastodon.social/@threadlinqs/116935905990302882"]},{"value":"https://otx.alienvault.com/pulse/6a5da9de7880be3a0bc9f970","type":"external-report-link","subtype":"external-article","relevance":90,"comment":"Link to the AlienVault OTX Pulse for the Spirals ransomware campaign.","links":["https://social.raytec.co/@techbot/116950596218040788"]},{"value":"Tr1sa111","type":"username","subtype":null,"relevance":90,"comment":"Pulse author or threat actor username.","links":["https://social.raytec.co/@techbot/116950596218040788"]},{"value":"https://social.raytec.co/@techbot/116950596218040788","type":"external-report-link","subtype":"post-link","relevance":90,"comment":"Link to the post","links":["https://social.raytec.co/@techbot/116950596218040788"]},{"value":"https://bsky.app/profile/cti.fyi/post/3mrhjblcayh2o","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/cti.fyi/post/3mrhjblcayh2o"]},{"value":"https://bsky.app/profile/digitfyi.bsky.social/post/3mrhha6tx6n2l","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/digitfyi.bsky.social/post/3mrhha6tx6n2l"]},{"value":"https://bsky.app/profile/intelfusions.com/post/3mrjyw5bhco2m","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/intelfusions.com/post/3mrjyw5bhco2m"]},{"value":"https://cti.fyi/groups/securotrop.html","type":"url","subtype":null,"relevance":85,"comment":"Group blog post link mentioning Securotrop ransomware group","links":["https://infosec.exchange/@CTI_FYI/116978709528287501"]},{"value":"securotrop","type":"threat-actor","subtype":null,"relevance":85,"comment":"Name of the ransomware group","links":["https://infosec.exchange/@CTI_FYI/116978709528287501"]},{"value":"https://infosec.exchange/@CTI_FYI/116978709528287501","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://infosec.exchange/@CTI_FYI/116978709528287501"]},{"value":"https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk5l542ww2m","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk5l542ww2m"]},{"value":"Deadlock","type":"threat-actor","subtype":null,"relevance":85,"comment":"Name of the ransomware group claimed to be behind the attack.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j"]},{"value":"tramex grilles","type":"filename","subtype":null,"relevance":85,"comment":"Product type mentioned in the context of the attack.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j"]},{"value":"https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j"]},{"value":"Deadlock ransomware","type":"threat-actor","subtype":null,"relevance":85,"comment":"Likely refers to the Deadlock ransomware group or strain mentioned in the context of the attack.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j"]},{"value":"carrierab.se","type":"domain","subtype":null,"relevance":85,"comment":"Swedish transport and logistics company targeted in the attack.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j"]},{"value":"jordbro.se","type":"domain","subtype":null,"relevance":85,"comment":"Location of the targeted company.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j"]},{"value":"stockholm.se","type":"domain","subtype":null,"relevance":85,"comment":"Capital city of Sweden, contextually relevant to the attack.","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j"]},{"value":"https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j"]},{"value":"cyberthreats247.com","type":"domain","subtype":null,"relevance":85,"comment":"Domain mentioned in the article as the source for further reading","links":["https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e"]},{"value":"Anubis","type":"threat-actor","subtype":null,"relevance":85,"comment":"Name of the ransomware group responsible for the attack","links":["https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e"]},{"value":"https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e"]},{"value":"cti.fyi","type":"domain","subtype":null,"relevance":85,"comment":"Domain extracted from the provided URLs related to the ransom group 'genesis'.","links":["https://infosec.exchange/@CTI_FYI/116988828814892222"]},{"value":"https://cti.fyi/groups/genesis.html","type":"url","subtype":null,"relevance":85,"comment":"URL pointing to the ransom group 'genesis' blog posts.","links":["https://infosec.exchange/@CTI_FYI/116988828814892222"]},{"value":"https://infosec.exchange/@CTI_FYI/116988828814892222","type":"external-report-link","subtype":"post-link","relevance":85,"comment":"Link to the post","links":["https://infosec.exchange/@CTI_FYI/116988828814892222"]}],"latest_ingestion_time":"2026-07-28T11:58:05.901000"}