This past week, we handled 48 incidents.
Here are the reported losses by category:
- Protocol compromise: $3.81M
- Infrastructure exploit: $3M
- Wallet compromise: $1.2M
- DPRK intrusion: $400K
- Malware: $119K
- Social engineering: $110K
- Malicious ad 100: BTC

What we collected
- 2,450 phishing domains
- 2,487 indicators published
- 54 wallets
- 30 URLs


IOCs
Fake meetings cluster (tracked by SEAL as SINT-69 - an uncategorized intrusion set). New infrastructure this week:
- 02uweb[.]us
- 02weba[.]us
- 03webr[.]us
- 04rweb[.]us
- o3webu[.]us
- web02z[.]us
Confirmed DPRK activity related domain we saw this week:
- teams0live[.]com
- teamsliues[.]us
- teamsliving[.]chat
- tearmslize[.]com
- teasmliue[.]com
- tecmslives[.]com
- tevmslive[.]com
- tezmslives[.]com
- whereby[.]surf
Fake podcast and recording lures:
- docsend[.]in
- kakaochat[.]app
- teams9web[.]com
- host09eu[.]com
- panel-control-terminal[.]com
Fake TradingView application, resulting in seed compromise:
- lebellearti[.]com
- leveragefresh[.]com
Our incident response service is free to anyone who needs it, and stays that way because people from the community fund it.If this week's numbers are useful to you, fund the next one: https://securityalliance.org/donate
If you require a direct data feed from SEAL-ISAC, contact us at [email protected].