Andy
cyb3rsilhouette.bsky.social
Andy
@cyb3rsilhouette.bsky.social
Cybersecurity analyst. Helping track Kong (Tuke), SmartApe (SG), and friends.
Pinned
New #ClickFix technique observed on 2025-06-29:
Compromised website > #SmartApeSG > #ClickFix (new fake secure connection technique) > ???
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-09

IOCs:
hxxps://personal[.]courtpsychologists[.]com/3tCck6Xy//q68qah6OKwsa2k+eP86r7/v774+rC3w/W3vPmx8vLuseTy7eqoo/r8rKf9+rKh6fS6qPf+tbe+7g==
hxxps://files[.]kaliesthenics[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:05 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-09

IOCs:
hxxps://portwinejoke[.]icu/l
hxxps://pippyheydguide[.]com/endpoint/callback-fetch[.]js
hxxp://89[.]46[.]38[.]5/micro
hxxps://buldiakogroup[.]com/micro
January 27, 2026 at 5:05 AM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-08

IOCs:
hxxps://personal[.]courtpsychologists[.]com/zWhOurZKLdOpSnSI+1pimL4cK8rvUmzWrAYq06MPEdykBCuY4Uo8mPdKJMDvFQ==
hxxps://docs[.]exitdriving[.]school/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:04 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-08

IOCs:
hxxps://yuzagrisi[.]com/j[.]js
hxxps://foresposition[.]com/profile/redirect-hook[.]js
hxxp://89[.]46[.]38[.]5/rest
hxxps://buldiakogroup[.]com/rest
January 27, 2026 at 5:04 AM
Compromised website > #KongTuke > #ClickFix:

Date Observed: 2026-01-08

IOCs:
hxxps://frttsch[.]com/2w2w[.]js
hxxp://144[.]31[.]221[.]60/a
hxxp://144[.]31[.]221[.]60/b
January 27, 2026 at 5:03 AM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-07

IOCs:
hxxps://personal[.]courtpsychologists[.]com/RPesej/VzxMg1ZZIcsWAWDeDyQpmzY4WJZnIEyqQ8xwtm8lYaNXeWH7V3h431dE=
hxxps://export[.]galmabuna[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:03 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-07

IOCs
mercedesheritage[.]com/j[.]js
pippyheydguide[.]com/dashboard/redirect-state[.]js
79[.]141[.]172[.]170/profile
qilsao[.]us/profile
79[.]141[.]172[.]170/moon
bcf13c1e79ebffba07dcc635c05a5d2f826fe75b4e69f7541b6ce6af4a5e31c0
January 27, 2026 at 5:03 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-07

IOCs:
yuzagrisi[.]com/j[.]js
pippyheydguide[.]com/dashboard/redirect-state[.]js
79[.]141[.]172[.]170/profile
qilsao[.]us/profile
79[.]141[.]172[.]170/moon
bcf13c1e79ebffba07dcc635c05a5d2f826fe75b4e69f7541b6ce6af4a5e31c0
January 27, 2026 at 5:02 AM
Compromised website > #ClickFix:

Date Observed: 2026-01-06

IOCs:
hxxps://sotavpn[.]shop
hxxps://frosty-mouse-c2db[.]nasipi7409[.]workers[.]dev/verify[.]hta
hxxps://pw91[.]xyz/api/pw
January 27, 2026 at 5:01 AM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-06

IOCs:
hxxps://personal[.]courtpsychologists[.]com/RPesej/VzxMg1ZZIcsWAWDeDyQpmzY4WJZnIEyqQ8xwtm8lYaNXeWH7V3h431dE=
hxxps://order[.]lelispices[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:00 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-06

IOCs:
hxxps://posibblaks[.]icu/redirect/profile-script[.]js
hxxp://193[.]111[.]208[.]238/auth
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 27, 2026 at 5:00 AM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2026-01-06

IOCs:
dinozozo[.]com/menu[.]js
pippyheydguide[.]com/redirect/profile-script[.]js
193[.]111[.]208[.]238/auth
deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 27, 2026 at 5:00 AM
Compromised website > #KongTuke > #ClickFix:

Date Observed: 2025-12-29

IOCs:
hxxps://metavrze[.]com/5h5h[.]js
hxxp://144[.]31[.]221[.]150/a
hxxp://144[.]31[.]221[.]150/b
January 24, 2026 at 11:32 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-26

IOCs:
dinozozo[.]com/menu[.]js
loppyskapert[.]com/session/settings-module[.]js
79[.]141[.]160[.]28/machine
deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:21 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-24

IOCs:
hxxps://limenescarlett[.]top/router/callback-fetch[.]js
hxxp://193[.]42[.]38[.]178/auth
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:20 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-24

IOCs:
selcukpeker[.]com/d[.]js
mipisesho[.]top/router/callback-fetch[.]js
193[.]42[.]38[.]178/auth
deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:20 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-23

IOCs:
hxxps://toxicsnake-wifes[.]com/promise/scope[.]js
hxxp://79[.]141[.]172[.]212/int
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:19 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-23

IOCs:
hxxps://selcukpeker[.]com/d[.]js
hxxps://ourasolid[.]com/promise/scope[.]js
hxxp://79[.]141[.]172[.]212/int
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:19 PM
Compromised website > #KongTuke > #ClickFix:

Date Observed: 2025-12-23

IOCs:
hxxps://emierich[.]com/2o2o[.]js
hxxp://payload[.]bruemald[.]top
January 24, 2026 at 11:18 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-22

IOCs:
hxxps://misiolove[.]com/websockets/local-storage[.]js
hxxps://positivelike[.]com/porsche
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:18 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-22

IOCs:
cansupeker[.]com/d[.]js
ourasolid[.]com/websockets/local-storage[.]js
positivelike[.]com/porsche
deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 11:17 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-19

IOCs:
hxxps://nishbashposv[.]com/typescript/code-splitting[.]js
hxxps://inclimit[.]com/proper
hxxps://deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 10:46 PM
Compromised website > #SmartApeSG > #ClickFix:

Date Observed: 2025-12-19

IOCs:
cansupeker[.]com/d[.]js
jacketinno[.]top/typescript/code-splitting[.]js
inclimit[.]com/proper
deregulatedenergy[.]com/fdg2[.]zip
039b88209b3fb51bc0b4915ab2a1490de34448c6f5bfb66ac0fa3a5fa16927e8
January 24, 2026 at 10:29 PM
Compromised website > #KongTuke > #ClickFix:

Date Observed: 2025-12-19

IOCs:
hxxps://csmultimedia[.]com/5k5k[.]js
hxxp://64[.]95[.]12[.]232/a
hxxp://64[.]95[.]12[.]232/b
January 24, 2026 at 10:29 PM
Compromised website > #ClickFix:

Date Observed: 2025-12-18

IOCs:
hxxps://ksfldfklskdmbxcvb[.]com/
hxxps://ksdkgsdkgkgmgm[.]pro/iif[.]js
hxxps://1teamintl[.]com/pupu[.]php?page=
hxxps://reeditpros[.]com/oap[.]jpeg
January 14, 2026 at 5:04 AM