<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Potassium update: the Mirai fork @synthient reported in March (https:&#x2F;&#x2F;x]]></title><description><![CDATA[<p>Potassium update: the Mirai fork <span><a href="https://cyberplace.social/@synthient">@<span>synthient</span></a></span> reported in March (<a href="https://x.com/deobfuscately/status/2033923869782712514" rel="nofollow noopener"><span>https://</span><span>x.com/deobfuscately/status/203</span><span>3923869782712514</span></a>) is still active and the operator appears to have taken up Dutch poetry. The new C2 domathreatintelkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)</p><p>Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.</p><p>IoCs:</p><p>a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e<br />6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9<br />3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85</p><p>C2: ikhebkankerinmijnrechterteelbal[.]st → 34.245.45[.]153<br />Dropper: 92.38.186[.]44 (HTTP + netcat :25565)</p><p><a href="https://infosec.exchange/tags/mirai" rel="tag">#<span>mirai</span></a> <a href="https://infosec.exchange/tags/DDoS" rel="tag">#<span>DDoS</span></a> <a href="https://infosec.exchange/tags/threatintel" rel="tag">#<span>threatintel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/7b24d57a-cdd4-4d0b-8781-e1e58d7e753c/potassium-update-the-mirai-fork-@synthient-reported-in-march-https-x</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:25:49 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/7b24d57a-cdd4-4d0b-8781-e1e58d7e753c.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 May 2026 07:52:39 GMT</pubDate><ttl>60</ttl></channel></rss>