rule bulwark_https_bulwarkblack_com_infostealer_infection_unmasks_dprk_operative_behind_polyfill_io_s { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/infostealer-infection-unmasks-dprk-operative-behind-polyfill-io-supply-chain-attack-and-us-crypto-exchange-infiltration/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-08-27T00:00:00Z" tlp = "TLP:CLEAR" indicator_count = "9" strings: $s0 = "funnull.host" ascii wide nocase // Domains $s1 = "gate.us" ascii wide nocase // Domains $s2 = "infostealers.com" ascii wide nocase // Domains $s3 = "polyfill.com" ascii wide nocase // Domains $s4 = "polyfill.io" ascii wide nocase // Domains $s5 = "polyfillcache.com" ascii wide nocase // Domains $s6 = "t2.funnull.host" ascii wide nocase // Domains $s7 = "www.mediafire.com" ascii wide nocase // Domains $s8 = "192.161.60.132" ascii wide nocase // IPv4 condition: any of ($s*) }