predictive threat intelligence

Threat Flash:

38K MALICIOUS IPs CONFIRMED IN JUNE

62% INCREASE VS. 2025

Threat Research Team

Last month, 38K IP addresses flagged by Augur's patented predictive threat intelligence were verified as malicious by independent third-party sources. That’s 62% more than were confirmed in June 2025.

The data reinforces the fact that, despite the AI-acceleration of attacks, Augur continues to surface emerging threats long before traditional intelligence feeds.

While some preemptive security vendors focus only on lower-level risks such as domain lookalikes and basic spoofing, Augur does all of this via our Brand Protection Module while also targeting the operational backbone of more sophisticated cyber campaigns. It identifies the command-and-control servers, exfiltration staging nodes, and delivery infrastructure that advanced threat actors depend on. This includes infrastructure established by nation-state groups, ransomware operators, and organized cybercriminal networks, well before their activities escalate into public-facing incidents.

Let’s take a look at what Augur saw in June:

Most Active Threat Actors

APT 30 (espionage, aka Lotus Panda, Raspberry Typhoon) - 38 confirmations

Primitivebear (espionage, aka Gamaredon, Actinium, Aqua Blizzard) - 23

Sandworm_team (Cyber-sabotage, aka APT44, Iridium) - 17

APT 26 (espionage, aka Bronze Express, Turbine Panda)  - 11 confirmations

Shinyhunters (data theft) - 17 confirmations (read more)

Threats Seen in April

The following examples highlight the kinds of malicious operations Augur uncovers and disrupts.

Name Type IP Lead Time
Tsundere Backdoor / Botnet 82[.]25.63.130 +365 days
Vshell OST Framework 82[.]27.11.240 250 days
Tsunami Backdoor 144[.]31.151.138 141 days
Havoc Command & Control (C2) 185[.]115.161.32 65 days
KV Botnet 216[.]173.65.250 +365 days

If you aren’t already blocking these IP addresses, we highly recommend that you do so.

Augur Highlights

Over the past few months, Augur has uncovered IPs and domains that were later leveraged in high-profile attacks. From nation-state threats, to sophisticated phishing ops, to supply-chain exploits, here are just a few recent examples of the type of high-impact attacks Augur has predicted and prevented

Attack Threat Group Lead Time
Iran Targets US Critical Infrastructure (Learn more) PYROXENE (Iran state-affiliated) 201 days
DragonForce Ransomware Campaign (Learn more) Scattered Spider 300 days
WIN-Fingerprint Exploit (Learn more) Lazarus Group / Conti 360+ days

Not every IP we uncover ends up in the headlines, but the overwhelming majority of the IPs and domains we identify are ultimately weaponized by threat actors to launch real-world attacks.

How Does Augur Work?

Augur uses ML-powered behavioral modeling to detect the buildup of cybercriminal infrastructure online before attacks. We identify thousands of malicious IPs, IP ranges, and domains every month. Augur identifies threats on average 60 days before they’re first reported by traditional sources. Our predictions are highly accurate, with a near-zero false-positive rate (0.01%), providing organizations using Augur with preemptive protection against cyberattacks, zero-days, and novel threats.

The Augur Difference. Let Us Prove It To You.

Experience firsthand the benefits of preemptive cyber defense with a quick proof of value (POV). We can have you up and running in less than a day, and after 30 days, get an Augur report detailing:

  • Threats Augur identified
  • Advance warning timelines
  • Data-driven insight on alert reduction and improved SOC efficiency

Click here to talk to an Augur specialist now.