HideLink malware family
HideLink is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-11. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-07-29
- Last seen: 2026-08-11
- Verdicts: malicious 3
- File types: html 3
ATT&CK techniques used by HideLink
- T1112 - 2 samples
Extracted command-and-control infrastructure
- http://gmpg.org/xfn/11 - 2 samples
- http://cashadvances2two.com/payday-loans/advance-payday-loans - 1 sample
- http://fastcashloans2two.com/ - 1 sample
- http://gossipandglam.com/comments/feed/ - 1 sample
- http://gossipandglam.com/feed/ - 1 sample
- http://gossipandglam.com/tag/instyle-com/feed/ - 1 sample
- http://gossipandglam.com/wp-content/plugins/i-love-social-bookmarking/includes/ilsb.js?ver=0.3 - 1 sample
- http://gossipandglam.com/wp-content/plugins/i-love-social-bookmarking/includes/style.css - 1 sample
- http://gossipandglam.com/wp-content/themes/scrappy/img/polkadots.gif - 1 sample
- http://gossipandglam.com/wp-content/themes/scrappy/js/html5.js - 1 sample
- http://gossipandglam.com/wp-content/themes/scrappy/style.css?ver=3.3.2 - 1 sample
- http://gossipandglam.com/wp-includes/js/jquery/jquery.js?ver=1.7.1 - 1 sample
- http://gossipandglam.com/wp-includes/wlwmanifest.xml - 1 sample
- http://gossipandglam.com/xmlrpc.php - 1 sample
- http://gossipandglam.com/xmlrpc.php?rsd - 1 sample
- http://guaranteedpaydayadvancerates2two.com/ - 1 sample
- http://paydayadvanceloans2two.com/payday-loans/loans-until-payday - 1 sample
- http://paydaycashadvance2two.com/cash-loan/easy-cash-loan - 1 sample
- http://statelicensedcashadvances2two.com/cash-advance/online-cash-advance-loans - 1 sample
- http://theboondockbetties.com/2010/02/07/juliebenz-s-chocolate-pistachio-cake-recipe/ - 1 sample
Recent HideLink samples
- ba669491637c25f360da4feadbc69141a41aa87244030cd161f1d11374fb4de9 - malicious (2026-08-11)
- 8f12ffd34b43591b69342e634d81e90254371d6d16d632fdcee042d1c0e9c859 - malicious (2026-08-08)
- 15ce5b744b20e5ac50fd1fe2c4eb6a3b473a1f43d0049acf243494a627ac67a6 - malicious (2026-07-29)
Frequently asked about HideLink
- What is HideLink?
- HideLink is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-11. Observed ATT&CK techniques include T1112.
- How many HideLink samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to HideLink, first seen 2026-07-29 and most recently 2026-08-11. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does HideLink use?
- Across our HideLink samples the most frequently observed techniques are T1112 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does HideLink use?
- HideLink samples in this corpus are distributed as html (3).
- Does HideLink use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from HideLink samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is HideLink malicious?
- 3 of 3 analyzed HideLink samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends