Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,635
Relationships
18,025
Potential duplicates
0

Entities

The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.(2026-08-08:clickfix-bnb-chain-etherhiding-malware-campaign)event
d13d97df
Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.(2026-08-07:clickfix-bnb-chain-etherhiding-malware-campaign)event
21892432
Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.(2026-06-17:clickfix-bnb-chain-etherhiding-malware-campaign)event
8a29fe09
Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.(2026-04-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
c01eba34
CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.(2026-02-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
a896cb8c
Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.(2025-10-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
a6cbc76d
The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.(2023-10-16:clickfix-bnb-chain-etherhiding-malware-campaign)event
91028f9d
ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.(2023-08-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
e6262384
ClickFix BNB Chain EtherHiding Malware Campaignprotocol
1972268c
Zenith Security publicly confirmed it would cooperate with investigators and stated it had identified IP-level information about the operators to share with authorities. On-chain analysts BrutalTrade and SpecterAnalyst published wallet address linkages. Alleged prior projects ZinoFinance, Zero-G Finance, and PerfectSwap were identified as linked to the same operator network.(2025-09-27:hypervault-finance)event
18c29894
PeckShield publicly flagged 'abnormal withdrawal of ~$3.6M worth of crypto from @hypervaultfi.' Approximately 752 ETH (estimated $3 million) was confirmed deposited into Tornado Cash. Hypervault's website, X account, Discord server, and GitHub repositories were all deleted. The Block, Decrypt, CryptoNews, and other outlets began covering the incident.(2025-09-26:hypervault-finance)event
9bfefc4a
Rug pull executed. All nine Hypervault vaults on HyperEVM were drained by the project operators using privileged contract access. Funds were bridged from Hyperliquid to Ethereum via deBridge.(2025-09-25:hypervault-finance)event
4e238de6
TVL on Hypervault reached approximately $4.97–6.01 million according to DefiLlama, representing peak depositor exposure ahead of the drain.(2025-09-24:hypervault-finance)event
8cb4d26f
Zenith Security delivered a private draft audit report to the Hypervault team identifying 42 vulnerabilities — 6 high severity and 10 medium severity — with a recommendation for full re-audit after remediation. The report was never publicly disclosed by the project.(2025-09-21:hypervault-finance)event
ed0c7702
Hypervault publicly announced that an audit had commenced with Zenith Security, a legitimate audit firm.(2025-09-14:hypervault-finance)event
d83950e5
Community researcher HypingBull publicly warned on X that Hypervault's claimed audits from Spearbit, Pashov, and Code4rena appeared fabricated. Direct contact with Pashov Group returned the response: 'First time I hear the project with this name.' Code4rena's public listing showed no pending Hypervault audit. TVL was approximately $700,000 at time of warning.(2025-09-04:hypervault-finance)event
930c7c2a
Hypervault Financeprotocol
5a5ff7f0
Latest Hacking News and Help Net Security publish detailed analyses of ENCFORGE, including SHA-256 hashes, C2 infrastructure, and mitigation guidance.(2026-07-26:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
9307dc54
Sysdig publishes its ENCFORGE follow-on report detailing the compiled Go ransomware binary targeting AI model infrastructure, confirming operator continuity via the shared Proton Mail address.(2026-07-21:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
bd5d1164
TechTimes publishes analysis of what comes after JADEPUFFER, describing the lowered ransomware skill floor and anticipated increase in agentic campaigns.(2026-07-13:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
a155b8ff
The same JADEPUFFER operator returns with a new compiled Go ransomware binary (ENCFORGE), exploiting the same Langflow CVE and escaping via Docker socket to target AI model files (PyTorch, SafeTensors, GGUF, FAISS, Parquet, etc.) on the host filesystem.(2026-07-03:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
bd3a4f8e
Sysdig publishes its initial JADEPUFFER analysis, describing the operation as the first documented fully agentic ransomware campaign. Approximately 1,050 to 7,000 Langflow instances remain publicly reachable at this date.(2026-07-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
7f8097b3
JADEPUFFER attack against a live production system takes place in late June 2026, exploiting CVE-2025-3248 in an internet-facing Langflow instance. The LLM agent conducts full reconnaissance, credential harvesting (including crypto wallet keys and seed phrases), lateral movement to a Nacos/MySQL server, and encrypts 1,342 production configuration records.(2026-06-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
6fdf7c14
Anthropic reports a Chinese state-linked operation conducting largely autonomous cyberattacks using LLM agents.(2025-11-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
2f97ff90
Anthropic discloses a real extortion campaign using Claude Code against 17 or more organizations — early evidence of LLM-assisted malicious operations at scale.(2025-08-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
8dda2468
CISA adds CVE-2025-3248 to the Known Exploited Vulnerabilities (KEV) catalog and directs federal agencies to patch.(2025-05-05:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
87445c41
Langflow releases version 1.3.0, patching CVE-2025-3248 (unauthenticated RCE via /api/v1/validate/code endpoint, CVSS 9.8).(2025-04-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
919249ce
JADEPUFFER – First Fully Autonomous AI Ransomware Targeting Crypto Wallet Keysprotocol
37cee203
688ea40c
Dakota Scout publishes investigation report on FBI and IRS probe into Benaiah Holdings; receiver's investigative authority subsequently expanded after court finds Wiener allegedly attempting to conceal cash.(2025-08-28:benjamin-paul-wiener-benaiah-capital)event
603c70e6
Benaiah Capital established. Two digital asset hedge funds launched by mid-2021, accepting investor funds in cash and digital currency.(2021-01-01:benjamin-paul-wiener-benaiah-capital)event
90f51f5e
SDGP-75 voting concludes, extending ex gratia compensation to Arbitrum asdCRV LlamaLend market borrowers unfairly liquidated during the vsdCRV price collapse on May 27.(2026-08-03:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
8ce5e3df
SDGP-70 compensation claims become available via Merkle tree contract on Ethereum mainnet through the Stake DAO portfolio interface, with a six-month claim window.(2026-07-01:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
873dbc20
Stake DAO publishes detailed post-mortem and SDGP-70 governance proposal for voluntary ex gratia compensation of 1,535,421.76 sdCRV (~$173,000) to 242 affected addresses. Stake DAO also confirms it has filed a criminal complaint with Swiss authorities.(2026-06-09:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
aa31181d
Attacker deposits extracted ETH proceeds into Tornado Cash in multiple transactions on Ethereum mainnet.(2026-05-31:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
661386ca
StakeDAO contributors secure mainnet vsdCRV backing within 47 minutes of the forged mint, preventing additional collateral loss. Arbitrum bridge permanently closed. Deployer owner privileges revoked and transferred to governance multisig same day.(2026-05-27:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
77d3c08f
Separate StakeDAO oracle message spoofing incident on Arbitrum and Base chains results in an alleged $176,000 loss — a distinct vulnerability class from the May deployer key exploit.(2026-03-12:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
63ff0b2e
StakeDAO deployer wallet (0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62) deploys vsdCRV LayerZero OFT contract on Arbitrum and retains owner privileges rather than transferring to governance multisig — the operational failure that later enabled the exploit.(2024-03-01:stakedao-vsdcrv-deployer-key-exploit-may-2026)event
8037351c
StakeDAO — vsdCRV Deployer Key Exploit (May 2026)organization
468c6829
noones.comdomain
dabac35b
noones.pissedconsumer.comdomain
df6e4465
weetracker.comdomain
3b8e59fb
noones.appdomain
19c7cd86
NoOnes reports surpassing 2.5 million users globally with 127 employees.(2026-05-31:noones-exchange)event
d5f45bf9
NoOnes confirms Ray Youssef has stepped down as CEO under undisclosed legal circumstances. The company states he no longer participates in management, operations, or decision-making. No successor is publicly named.(2026-02-20:noones-exchange)event
db6ce47f
Paxful Holdings, Inc. formally sentenced to $4 million criminal penalty.(2026-02-10:noones-exchange)event
a218174e
FinCEN issues $3.5 million civil penalty against Paxful Inc. and Paxful USA Inc. for willful BSA violations covering February 2015 to April 2023, including enabling over $500 million in suspicious transfers.(2025-12-01:noones-exchange)event
149aa2ab
Data refreshes every 5 minutes · All metrics derived from Supabase