Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| QRCode/Phishingcampaign | Uses | T1598technique | — | Correlated cluster | 2026-08-19 |
| FudModulecampaign | Uses | T1608.006technique | — | Correlated cluster | 2026-09-03 |
| CornFlakecampaign | Uses | T1053.005technique | — | Correlated cluster | 2026-08-20 |
| MacSynccampaign | Uses | T1585.001technique | — | Correlated cluster | 2026-08-18 |
| LegacyHivecampaign | Uses | T1204technique | — | Correlated cluster | 2026-08-11 |
| payload · XMRigcampaign | Uses | T1105technique | — | Correlated cluster | 2026-08-26 |
| Information stealerscampaign | Uses | T1583.006technique | — | Correlated cluster | 2026-09-03 |
| JSCealcampaign | Uses | Node.js-based JavaScript implantmalware | — | Correlated cluster | 2026-09-02 |
| SPECTREcampaign | Uses | DeepAuditmalware | — | Correlated cluster | 2026-08-20 |
| SPECTREcampaign | Uses | PentestGPTmalware | — | Correlated cluster | 2026-08-20 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | DXSCAN C2 v1.0malware | — | Correlated cluster | 2026-09-16 |
| AnyDeskcampaign | Uses | AV-killermalware | — | Correlated cluster | 2026-09-17 |
| AnyDeskcampaign | Uses | Oyster (CleanBoost)malware | — | Correlated cluster | 2026-09-17 |
| Dysphoriacampaign | Uses | CloudAtlasGomalware | — | Correlated cluster | 2026-08-24 |
| PhantomCorecampaign | Uses | PhantomCoremalware | — | Correlated cluster | 2026-08-25 |
| AnyDeskcampaign | Uses | Jump Desktopmalware | — | Correlated cluster | 2026-09-17 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | Codexmalware | — | Correlated cluster | 2026-09-16 |
| SPECTREcampaign | Uses | QuasarRATmalware | — | Correlated cluster | 2026-08-20 |
| BadIIScampaign | Uses | SPECTREmalware | — | Correlated cluster | 2026-08-26 |
| UNC1549 / TA455 · NightLedgercampaign | Uses | PowerCloudmalware | — | Correlated cluster | 2026-08-12 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | badsecretsmalware | — | Correlated cluster | 2026-09-16 |
| AnyDeskcampaign | Uses | BOATBEAMmalware | — | Correlated cluster | 2026-09-17 |
| AnyDeskcampaign | Uses | COBALTSPINmalware | — | Correlated cluster | 2026-09-17 |
| payload · Amateracampaign | Uses | ValleyRATmalware | — | Correlated cluster | 2026-09-24 |
| GoogleService.dllcampaign | Uses | CommunicationUxTheme.dllmalware | — | Correlated cluster | 2026-09-04 |
| BADBOXcampaign | Uses | zhimamalware | — | Correlated cluster | 2026-08-27 |
| payload · XMRigcampaign | Uses | QN Wallpapermalware | — | Correlated cluster | 2026-09-03 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | ASHX web shellsmalware | — | Correlated cluster | 2026-09-16 |
| AnyDeskcampaign | Uses | PhantomCoremalware | — | Correlated cluster | 2026-09-17 |
| payload · Amateracampaign | Uses | ZigCryptoStealermalware | — | Correlated cluster | 2026-09-24 |
| Shai-Huludcampaign | Uses | Bulk-mail platform (Tubely-themed spam campaign)malware | — | Correlated cluster | 2026-08-06 |
| UNC1549 / TA455 · NightLedgercampaign | Uses | BINDCLOAKmalware | — | Correlated cluster | 2026-08-12 |
| Qilin (fka Agenda) · Qilincampaign | Uses | NinjaRMMmalware | — | Correlated cluster | 2026-09-25 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | DX SCAN H2 C2 Command Centermalware | — | Correlated cluster | 2026-09-16 |
| JSCealcampaign | Uses | MISTPENmalware | — | Correlated cluster | 2026-09-02 |
| Qilin ransomwarecampaign | Uses | AnonyMousKITmalware | — | Correlated cluster | 2026-09-11 |
| JSCealcampaign | Uses | SecurityPDFmalware | — | Correlated cluster | 2026-09-02 |
| MacSynccampaign | Uses | MacSyncmalware | — | Correlated cluster | 2026-08-18 |
| Information stealerscampaign | Uses | DDoS botnet toolingmalware | — | Correlated cluster | 2026-09-03 |
| Astarothcampaign | Uses | SHAMOSmalware | — | Correlated cluster | 2026-08-18 |
| BADBOXcampaign | Uses | JarServicemalware | — | Correlated cluster | 2026-08-27 |
| payload · XMRigcampaign | Uses | RelayShellmalware | — | Correlated cluster | 2026-09-03 |
| Qilin (fka Agenda) · Qilincampaign | Uses | ConnectWisemalware | — | Correlated cluster | 2026-09-25 |
| PowerShell-based RATcampaign | Uses | PetitPotammalware | — | Correlated cluster | 2026-08-31 |
| Qilin ransomwarecampaign | Uses | SSH tunneling utilitymalware | — | Correlated cluster | 2026-09-11 |
| LegacyHivecampaign | Uses | LegacyHivemalware | — | Correlated cluster | 2026-08-11 |
| Dysphoriacampaign | Uses | IceCubemalware | — | Correlated cluster | 2026-08-24 |
| SPECTREcampaign | Uses | Meterpretermalware | — | Correlated cluster | 2026-08-20 |
| MacSync Stealercampaign | Uses | GSocketmalware | — | Correlated cluster | 2026-08-18 |
| SPECTREcampaign | Uses | Gh0stCringemalware | — | Correlated cluster | 2026-08-20 |