<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Huntbase Hub</title>
  <id>https://hub.huntbase.io</id>
<link rel="self" href="https://hub.huntbase.io/feed.xml"/>
  <link href="https://hub.huntbase.io/"/>  <updated>2026-09-21T05:29:22</updated>
  <entry>
    <title>Correlating Proxy-Obscured Identity and Endpoint Activity</title>
    <id>urn:huntbase:hunt:proxy-obscured-identity-endpoint-correlation</id>
    <link href="https://hub.huntbase.io/hunts/proxy-obscured-identity-endpoint-correlation/"/>
    <updated>2026-09-21T05:29:22</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is using multi-hop proxy infrastructure to authenticate via Okta and subsequently execute discovery commands on an endpoint, obscured by network egress to proxy relay ports.</summary>
<category term="T1059"/><category term="T1078"/><category term="T1090.003"/>  </entry>
  <entry>
    <title>Rapid Identity Breakout and Exfiltration</title>
    <id>urn:huntbase:hunt:rapid-identity-breakout-exfiltration</id>
    <link href="https://hub.huntbase.io/hunts/rapid-identity-breakout-exfiltration/"/>
    <updated>2026-09-21T05:26:11</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.</summary>
<category term="T1041"/><category term="T1078"/><category term="T1090.003"/>  </entry>
  <entry>
    <title>Endpoint-to-Cloud Phased Intrusion Hunt</title>
    <id>urn:huntbase:hunt:endpoint-to-cloud-phased-intrusion-hunt</id>
    <link href="https://hub.huntbase.io/hunts/endpoint-to-cloud-phased-intrusion-hunt/"/>
    <updated>2026-09-20T22:27:36</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.</summary>
<category term="T1021"/><category term="T1078"/><category term="T1090.003"/><category term="T1204"/>  </entry>
  <entry>
    <title>Multi-hop Proxy and Tor Infrastructure Activity</title>
    <id>urn:huntbase:hunt:multi-hop-proxy-tor-activity</id>
    <link href="https://hub.huntbase.io/hunts/multi-hop-proxy-tor-activity/"/>
    <updated>2026-09-20T21:41:51</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is masking command-and-control traffic by routing it through multi-hop proxies, Tor entry nodes, or tunneling services to bypass perimeter monitoring.</summary>
<category term="T1090.003"/>  </entry>
  <entry>
    <title>Multi-hop proxy and tunnel triage via identity context</title>
    <id>urn:huntbase:hunt:multi-hop-proxy-identity-triage</id>
    <link href="https://hub.huntbase.io/hunts/multi-hop-proxy-identity-triage/"/>
    <updated>2026-09-20T21:39:28</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder is using a multi-hop proxy or tunneling service to obfuscate C2 traffic, which can be distinguished from legitimate researcher activity by correlating network leads with user risk profiles and local port bindings.</summary>
<category term="T1090.003"/>  </entry>
  <entry>
    <title>Managed Access and Tenant Integrity</title>
    <id>urn:huntbase:hunt:managed-access-tenant-integrity</id>
    <link href="https://hub.huntbase.io/hunts/managed-access-tenant-integrity/"/>
    <updated>2026-09-20T21:36:14</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.</summary>
<category term="T1059"/><category term="T1078.004"/><category term="T1090.003"/><category term="T1219"/>  </entry>
  <entry>
    <title>Network Proxy and Relay Obfuscation Detection</title>
    <id>urn:huntbase:hunt:network-proxy-relay-obfuscation</id>
    <link href="https://hub.huntbase.io/hunts/network-proxy-relay-obfuscation/"/>
    <updated>2026-09-20T21:33:09</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is using multi-hop proxies or Operational Relay Box (ORB) networks to disguise command-and-control traffic, which can be identified by shell processes making outbound connections to rare external IP addresses and resolving proxy-related DNS infrastructure.</summary>
<category term="T1090.003"/>  </entry>
  <entry>
    <title>Vulnerable Driver Exploitation and Kernel Escalation</title>
    <id>urn:huntbase:hunt:vulnerable-driver-exploitation-kernel-escalation</id>
    <link href="https://hub.huntbase.io/hunts/vulnerable-driver-exploitation-kernel-escalation/"/>
    <updated>2026-09-20T21:30:18</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.</summary>
<category term="T1068"/><category term="T1105"/><category term="T1190"/>  </entry>
  <entry>
    <title>Cloud Workload Identity and Network Triage</title>
    <id>urn:huntbase:hunt:cloud-workload-identity-network-triage</id>
    <link href="https://hub.huntbase.io/hunts/cloud-workload-identity-network-triage/"/>
    <updated>2026-09-20T21:23:32</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.</summary>
<category term="T1071.001"/><category term="T1078.004"/><category term="T1190"/>  </entry>
  <entry>
    <title>Cloud Workload Runtime and Exploitation Behavior</title>
    <id>urn:huntbase:hunt:cloud-workload-runtime-exploitation-behavior</id>
    <link href="https://hub.huntbase.io/hunts/cloud-workload-runtime-exploitation-behavior/"/>
    <updated>2026-09-20T21:20:25</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.</summary>
<category term="T1059"/><category term="T1190"/><category term="T1542"/>  </entry>
  <entry>
    <title>Edge AI Artifact Integrity and Data Exfiltration</title>
    <id>urn:huntbase:hunt:edge-ai-artifact-integrity-exfiltration</id>
    <link href="https://hub.huntbase.io/hunts/edge-ai-artifact-integrity-exfiltration/"/>
    <updated>2026-09-20T21:17:33</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has compromised the Edge AI supply chain to poison model artifacts, then manipulated those models via prompt injection to exfiltrate sensitive weights and credentials over high-volume network channels.</summary>
<category term="T1041"/><category term="T1090.003"/><category term="T1195"/><category term="T1204.002"/><category term="T1528"/><category term="T1552"/>  </entry>
  <entry>
    <title>Appliance Persistence and Identity Abuse</title>
    <id>urn:huntbase:hunt:appliance-persistence-identity-abuse</id>
    <link href="https://hub.huntbase.io/hunts/appliance-persistence-identity-abuse/"/>
    <updated>2026-09-20T21:15:31</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.</summary>
<category term="T1556"/><category term="T1566"/><category term="T1684.001"/>  </entry>
  <entry>
    <title>Collaboration Platform Phishing and Execution</title>
    <id>urn:huntbase:hunt:collaboration-platform-phishing-and-execution</id>
    <link href="https://hub.huntbase.io/hunts/collaboration-platform-phishing-and-execution/"/>
    <updated>2026-09-20T21:11:22</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.</summary>
<category term="T1566"/><category term="T1684.001"/>  </entry>
  <entry>
    <title>Build-Time Execution and Secret Harvesting</title>
    <id>urn:huntbase:hunt:build-time-execution-secret-harvesting</id>
    <link href="https://hub.huntbase.io/hunts/build-time-execution-secret-harvesting/"/>
    <updated>2026-09-20T20:55:30</updated>
    <author><name>Huntbase</name></author>
    <summary>An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment&#39;s configuration files.</summary>
<category term="T1003"/><category term="T1059.003"/><category term="T1059.007"/><category term="T1105"/><category term="T1195.002"/><category term="T1528"/><category term="T1552.004"/>  </entry>
  <entry>
    <title>AWS Cloud Identity Takeover Chain</title>
    <id>urn:huntbase:hunt:aws-cloud-identity-takeover-chain</id>
    <link href="https://hub.huntbase.io/hunts/aws-cloud-identity-takeover-chain/"/>
    <updated>2026-09-20T20:52:08</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.</summary>
<category term="T1078.004"/><category term="T1098"/><category term="T1110.001"/>  </entry>
  <entry>
    <title>Endpoint Data Staging and Exfiltration</title>
    <id>urn:huntbase:hunt:endpoint-data-staging-exfiltration</id>
    <link href="https://hub.huntbase.io/hunts/endpoint-data-staging-exfiltration/"/>
    <updated>2026-09-20T20:48:23</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.</summary>
<category term="T1041"/><category term="T1071.001"/><category term="T1074.001"/>  </entry>
  <entry>
    <title>Identity and Cloud Pivot from Web Exploits</title>
    <id>urn:huntbase:hunt:identity-cloud-pivot-web-exploits</id>
    <link href="https://hub.huntbase.io/hunts/identity-cloud-pivot-web-exploits/"/>
    <updated>2026-09-20T20:46:31</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.</summary>
<category term="T1078"/><category term="T1098"/><category term="T1190"/>  </entry>
  <entry>
    <title>Linux Fileless and In-Memory Execution</title>
    <id>urn:huntbase:hunt:linux-fileless-in-memory-execution</id>
    <link href="https://hub.huntbase.io/hunts/linux-fileless-in-memory-execution/"/>
    <updated>2026-09-20T20:42:51</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.</summary>
<category term="T1014"/><category term="T1059.004"/><category term="T1059.006"/><category term="T1070.004"/><category term="T1105"/><category term="T1620"/>  </entry>
  <entry>
    <title>Kubernetes Service Account Abuse and Escape</title>
    <id>urn:huntbase:hunt:kubernetes-service-account-abuse-and-escape</id>
    <link href="https://hub.huntbase.io/hunts/kubernetes-service-account-abuse-and-escape/"/>
    <updated>2026-09-20T20:40:13</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.</summary>
<category term="T1552.006"/><category term="T1609"/><category term="T1610"/><category term="T1611"/><category term="T1613"/>  </entry>
  <entry>
    <title>AI-Themed Social Engineering and Multi-Stage Fraud</title>
    <id>urn:huntbase:hunt:ai-themed-social-engineering-multi-stage-fraud</id>
    <link href="https://hub.huntbase.io/hunts/ai-themed-social-engineering-multi-stage-fraud/"/>
    <updated>2026-09-20T20:36:42</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.</summary>
<category term="T1190"/><category term="T1486"/><category term="T1555"/><category term="T1566"/>  </entry>
  <entry>
    <title>Linux eBPF Rootkit Execution and Manipulation</title>
    <id>urn:huntbase:hunt:linux-ebpf-rootkit-execution-manipulation</id>
    <link href="https://hub.huntbase.io/hunts/linux-ebpf-rootkit-execution-manipulation/"/>
    <updated>2026-09-20T20:34:19</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has deployed an eBPF rootkit that hides network connections and kernel objects by manipulating syscall returns and tampering with Netlink buffers.</summary>
<category term="T1014"/><category term="T1090.003"/><category term="T1204.002"/><category term="T1562.001"/>  </entry>
  <entry>
    <title>AD RMS Discovery and Administrative Reconnaissance</title>
    <id>urn:huntbase:hunt:ad-rms-discovery-recon</id>
    <link href="https://hub.huntbase.io/hunts/ad-rms-discovery-recon/"/>
    <updated>2026-09-20T20:32:15</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.</summary>
<category term="T1018"/><category term="T1078.002"/><category term="T1083"/><category term="T1090.003"/>  </entry>
  <entry>
    <title>Multi-Stage Intrusion and Ransomware Triage</title>
    <id>urn:huntbase:hunt:multi-stage-intrusion-ransomware-triage</id>
    <link href="https://hub.huntbase.io/hunts/multi-stage-intrusion-ransomware-triage/"/>
    <updated>2026-09-20T20:28:51</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has established a beachhead, moved laterally to host-314, exfiltrated data via Node.js to an AI service, and initiated ransomware encryption.</summary>
<category term="T1003"/><category term="T1021"/><category term="T1041"/><category term="T1486"/>  </entry>
  <entry>
    <title>Commodity Loader and Multi-Payload PPI Activity</title>
    <id>urn:huntbase:hunt:commodity-loader-ppi-activity</id>
    <link href="https://hub.huntbase.io/hunts/commodity-loader-ppi-activity/"/>
    <updated>2026-09-20T20:25:26</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.</summary>
<category term="T1059.003"/><category term="T1071.001"/><category term="T1090.003"/><category term="T1190"/><category term="T1195.002"/><category term="T1568.002"/><category term="T1572"/>  </entry>
  <entry>
    <title>Knight Office Token Theft and Device Persistence</title>
    <id>urn:huntbase:hunt:knight-office-token-theft-persistence</id>
    <link href="https://hub.huntbase.io/hunts/knight-office-token-theft-persistence/"/>
    <updated>2026-09-20T20:20:49</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has stolen Microsoft 365 session tokens via a device-code phishing flow and secured persistence by enrolling an unauthorized rogue device into the Entra ID tenant.</summary>
<category term="T1090.003"/><category term="T1098"/><category term="T1566"/>  </entry>
  <entry>
    <title>Knight Office Phishing Delivery and Redirects</title>
    <id>urn:huntbase:hunt:knight-office-delivery-redirection</id>
    <link href="https://hub.huntbase.io/hunts/knight-office-delivery-redirection/"/>
    <updated>2026-09-20T20:16:51</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is using Monday.com redirects and .vu landing pages to deliver Knight Office phishing lures to M365 users.</summary>
<category term="T1090.003"/><category term="T1566"/>  </entry>
  <entry>
    <title>Entra ID Agent User Impersonation and Teams Abuse</title>
    <id>urn:huntbase:hunt:entra-id-agent-user-impersonation-teams-abuse</id>
    <link href="https://hub.huntbase.io/hunts/entra-id-agent-user-impersonation-teams-abuse/"/>
    <updated>2026-09-20T20:13:56</updated>
    <author><name>Huntbase</name></author>
    <summary>An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.</summary>
<category term="T1059.001"/>  </entry>
  <entry>
    <title>Chrysalis DLL Side-Loading and Execution</title>
    <id>urn:huntbase:hunt:chrysalis-dll-side-loading-execution</id>
    <link href="https://hub.huntbase.io/hunts/chrysalis-dll-side-loading-execution/"/>
    <updated>2026-09-20T20:10:39</updated>
    <author><name>Huntbase</name></author>
    <summary>An attacker has achieved code execution by placing a malicious DLL in the same directory as a legitimate Bluetooth service, exploiting the search order to side-load code and bypass standard system directory protections.</summary>
<category term="T1574.002"/>  </entry>
  <entry>
    <title>BiTB Phishing to Rogue RMM Persistence</title>
    <id>urn:huntbase:hunt:bitb-phishing-rogue-rmm-persistence</id>
    <link href="https://hub.huntbase.io/hunts/bitb-phishing-rogue-rmm-persistence/"/>
    <updated>2026-09-20T20:06:32</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has used browser-in-the-browser phishing to deceive a user into installing a rogue ScreenConnect instance, which established service-based persistence and executed evasion tools to hide its activity.</summary>
<category term="T1059.003"/><category term="T1090.003"/><category term="T1105"/><category term="T1543.003"/><category term="T1562"/><category term="T1566"/>  </entry>
  <entry>
    <title>Bulk Directory Discovery via AAD Graph API</title>
    <id>urn:huntbase:hunt:bulk-directory-discovery-aad-graph</id>
    <link href="https://hub.huntbase.io/hunts/bulk-directory-discovery-aad-graph/"/>
    <updated>2026-09-20T20:01:09</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.</summary>
<category term="T1059.001"/><category term="T1190"/>  </entry>
  <entry>
    <title>ErrTraffic: WordPress Infrastructure and Backdoor Maintenance</title>
    <id>urn:huntbase:hunt:errtraffic-wordpress-infrastructure-compromise</id>
    <link href="https://hub.huntbase.io/hunts/errtraffic-wordpress-infrastructure-compromise/"/>
    <updated>2026-09-20T19:49:33</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.</summary>
<category term="T1078"/><category term="T1190"/><category term="T1505.003"/>  </entry>
  <entry>
    <title>SonicWall Appliance Zero-Day Exploitation and Webshells</title>
    <id>urn:huntbase:hunt:sonicwall-sma-zero-day-exploitation</id>
    <link href="https://hub.huntbase.io/hunts/sonicwall-sma-zero-day-exploitation/"/>
    <updated>2026-09-20T19:46:14</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.</summary>
<category term="T1090.003"/><category term="T1133"/><category term="T1190"/><category term="T1505.003"/><category term="T1572"/>  </entry>
  <entry>
    <title>SPIFFE/SPIRE Workload Identity Spoofing</title>
    <id>urn:huntbase:hunt:spiffe-spire-identity-spoofing</id>
    <link href="https://hub.huntbase.io/hunts/spiffe-spire-identity-spoofing/"/>
    <updated>2026-09-20T19:40:52</updated>
    <author><name>Huntbase</name></author>
    <summary>An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.</summary>
<category term="T1090.003"/><category term="T1190"/>  </entry>
  <entry>
    <title>Industrial-Scale AI Model Distillation and Extraction</title>
    <id>urn:huntbase:hunt:industrial-scale-ai-distillation-extraction</id>
    <link href="https://hub.huntbase.io/hunts/industrial-scale-ai-distillation-extraction/"/>
    <updated>2026-09-20T19:37:41</updated>
    <author><name>Huntbase</name></author>
    <summary>China-based adversaries are using fraudulent accounts and proxy transfer stations to conduct high-volume, automated extraction of proprietary AI model capabilities through systematic distillation.</summary>
<category term="T1041"/><category term="T1090.003"/><category term="T1190"/>  </entry>
  <entry>
    <title>Anomalous Cloud Identity Behavior</title>
    <id>urn:huntbase:hunt:anomalous-cloud-identity-behavior</id>
    <link href="https://hub.huntbase.io/hunts/anomalous-cloud-identity-behavior/"/>
    <updated>2026-09-20T19:34:58</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has compromised an administrative cloud identity and is accessing the environment through multi-hop proxies or Tor to perform discovery and initial access.</summary>
<category term="T1078.004"/><category term="T1090.003"/><category term="T1190"/>  </entry>
  <entry>
    <title>Public app exploitation and cloud identity drift</title>
    <id>urn:huntbase:hunt:public-app-exploitation-cloud-identity-drift</id>
    <link href="https://hub.huntbase.io/hunts/public-app-exploitation-cloud-identity-drift/"/>
    <updated>2026-09-20T19:31:29</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has exploited a public-facing application on a cloud instance to obtain its identity, which is now being used for activity that deviates from the host&#39;s established behavioral profile.</summary>
<category term="T1078.004"/><category term="T1190"/><category term="T1204.002"/>  </entry>
  <entry>
    <title>WMI Lateral Movement and Proxy-based C2</title>
    <id>urn:huntbase:hunt:wmi-lateral-movement-proxy-c2</id>
    <link href="https://hub.huntbase.io/hunts/wmi-lateral-movement-proxy-c2/"/>
    <updated>2026-09-20T18:41:29</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has moved laterally using WMI to execute code on internal Windows hosts and is maintaining command-and-control through multi-hop proxies or Tor to obfuscate traffic.</summary>
<category term="T1047"/><category term="T1090.003"/>  </entry>
  <entry>
    <title>Bypass of npm Cooldown and Dependency Compromise</title>
    <id>urn:huntbase:hunt:bypass-npm-cooldown-dependency-compromise</id>
    <link href="https://hub.huntbase.io/hunts/bypass-npm-cooldown-dependency-compromise/"/>
    <updated>2026-09-20T18:38:25</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.</summary>
<category term="T1195.001"/><category term="T1562.001"/>  </entry>
  <entry>
    <title>Obfuscated Identity and Host Access</title>
    <id>urn:huntbase:hunt:obfuscated-identity-host-access</id>
    <link href="https://hub.huntbase.io/hunts/obfuscated-identity-host-access/"/>
    <updated>2026-09-20T18:36:09</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary is using multi-hop proxies or tunnels to mask their origin during authentication to cloud identity providers, subsequently using that access to reach internal hosts and execute local commands.</summary>
<category term="T1021.001"/><category term="T1059"/><category term="T1078"/><category term="T1090.003"/>  </entry>
  <entry>
    <title>MacSync Binary Persistence and Application Tampering</title>
    <id>urn:huntbase:hunt:macsync-binary-persistence-tampering</id>
    <link href="https://hub.huntbase.io/hunts/macsync-binary-persistence-tampering/"/>
    <updated>2026-09-20T18:31:20</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.</summary>
<category term="T1071.001"/><category term="T1113"/><category term="T1491"/><category term="T1539"/><category term="T1543.001"/><category term="T1548.004"/><category term="T1552"/><category term="T1573.002"/>  </entry>
  <entry>
    <title>MacSync Scripted Execution and Credential Theft</title>
    <id>urn:huntbase:hunt:macsync-scripted-execution-credential-theft</id>
    <link href="https://hub.huntbase.io/hunts/macsync-scripted-execution-credential-theft/"/>
    <updated>2026-09-20T18:25:21</updated>
    <author><name>Huntbase</name></author>
    <summary>An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.</summary>
<category term="T1027"/><category term="T1059.002"/><category term="T1059.004"/><category term="T1140"/><category term="T1204.002"/><category term="T1548.004"/><category term="T1555.001"/><category term="T1566.002"/>  </entry>
  <entry>
    <title>Malicious C2 Infrastructure Polling</title>
    <id>urn:huntbase:hunt:malicious-c2-infrastructure-polling</id>
    <link href="https://hub.huntbase.io/hunts/malicious-c2-infrastructure-polling/"/>
    <updated>2026-09-20T18:12:43</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.</summary>
<category term="T1071.001"/><category term="T1102"/>  </entry>
  <entry>
    <title>Cross-Platform Malware Execution and Persistence</title>
    <id>urn:huntbase:hunt:cross-platform-malware-execution-persistence</id>
    <link href="https://hub.huntbase.io/hunts/cross-platform-malware-execution-persistence/"/>
    <updated>2026-09-20T18:08:58</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.</summary>
<category term="T1005"/><category term="T1059.001"/><category term="T1059.004"/><category term="T1074.001"/><category term="T1204.002"/><category term="T1539"/><category term="T1543.001"/><category term="T1547.001"/><category term="T1555"/>  </entry>
  <entry>
    <title>AI-Impersonation Driven Script Execution and Data Theft</title>
    <id>urn:huntbase:hunt:ai-impersonation-script-execution-data-theft</id>
    <link href="https://hub.huntbase.io/hunts/ai-impersonation-script-execution-data-theft/"/>
    <updated>2026-09-20T18:04:14</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.</summary>
<category term="T1053.005"/><category term="T1059.001"/><category term="T1059.004"/><category term="T1539"/><category term="T1552"/><category term="T1555"/>  </entry>
  <entry>
    <title>AI Platform Mediated Malvertising and Redirection</title>
    <id>urn:huntbase:hunt:ai-platform-mediated-malvertising-redirection</id>
    <link href="https://hub.huntbase.io/hunts/ai-platform-mediated-malvertising-redirection/"/>
    <updated>2026-09-20T18:00:05</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.</summary>
<category term="T1204.001"/><category term="T1566.002"/>  </entry>
  <entry>
    <title>Tampered Exodus Wallet Persistence and C2</title>
    <id>urn:huntbase:hunt:tampered-exodus-persistence-c2</id>
    <link href="https://hub.huntbase.io/hunts/tampered-exodus-persistence-c2/"/>
    <updated>2026-09-20T17:55:52</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.</summary>
<category term="T1027"/><category term="T1053.005"/><category term="T1059.001"/><category term="T1071.001"/><category term="T1564.003"/>  </entry>
  <entry>
    <title>ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation</title>
    <id>urn:huntbase:hunt:chaindrop-worm-persistence-propagation</id>
    <link href="https://hub.huntbase.io/hunts/chaindrop-worm-persistence-propagation/"/>
    <updated>2026-09-20T17:50:07</updated>
    <author><name>Huntbase</name></author>
    <summary>An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.</summary>
<category term="T1102"/><category term="T1534"/><category term="T1546"/><category term="T1574.006"/>  </entry>
  <entry>
    <title>ChainDrop: NPM Worm Endpoint and CI Runner Activity</title>
    <id>urn:huntbase:hunt:chaindrop-npm-worm-activity</id>
    <link href="https://hub.huntbase.io/hunts/chaindrop-npm-worm-activity/"/>
    <updated>2026-09-20T17:45:30</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.</summary>
<category term="T1003.001"/><category term="T1059.003"/><category term="T1105"/><category term="T1195.002"/><category term="T1552.001"/><category term="T1555"/>  </entry>
  <entry>
    <title>Kimwolf Blockchain C2 and DDoS Impact</title>
    <id>urn:huntbase:hunt:kimwolf-blockchain-c2-ddos-impact</id>
    <link href="https://hub.huntbase.io/hunts/kimwolf-blockchain-c2-ddos-impact/"/>
    <updated>2026-09-20T17:41:42</updated>
    <author><name>Huntbase</name></author>
    <summary>IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.</summary>
<category term="T1090"/><category term="T1102.003"/><category term="T1498.001"/>  </entry>
  <entry>
    <title>Kimwolf ADB Propagation and Evasion</title>
    <id>urn:huntbase:hunt:kimwolf-adb-propagation-evasion</id>
    <link href="https://hub.huntbase.io/hunts/kimwolf-adb-propagation-evasion/"/>
    <updated>2026-09-20T17:38:42</updated>
    <author><name>Huntbase</name></author>
    <summary>An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.</summary>
<category term="T1036.005"/><category term="T1059"/><category term="T1190"/>  </entry>
</feed>