{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "APT28 has shifted to using legitimate AI services and hijacked consumer-grade edge infrastructure to bypass traditional IP-based reputation filters; this hunt identifies the behavioural intersection of these trends."
      },
      "name": "APT28 Edge Hijacking and AI-Driven Exfiltration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1572",
        "attack.t1041",
        "attack.t1566",
        "attack.t1190"
      ],
      "series": {
        "slug": "apt28-an-evolution-of-tradecraft-from-x-agent-to-llm-malware",
        "index": 2,
        "title": "APT28: An Evolution of Tradecraft from X-Agent to LLM Malware",
        "total": 2
      },
      "related": [
        {
          "hunt": "apt28-gooseegg-privesc",
          "reason": "GooseEgg privilege escalation is a precursor to the harvesting phase; that hunt focuses on Print Spooler exploitation.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "apt28-outlook-printspooler-exploitation",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt correlates signals across three surfaces: DNS hijacking (edge manipulation), file activity (automated bulk harvesting), and rare network connections (AI-based exfiltration). A single detection rule would struggle to distinguish legitimate browser traffic to AI tools from automated malware exfiltration without this broader context.",
      "coverage": [
        {
          "stage": "c2-edge-device-hijacking",
          "steps": [
            "dns-hijacking-lead",
            "ai-and-tunnel-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-llm-infostealer",
          "steps": [
            "bulk-document-harvesting",
            "agent-triage"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-phishing-and-vulnerability-exploitation",
          "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "privilege-escalation-gooseegg",
          "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-harvesting-ntlm-relay",
          "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Initial Access via Phishing and Vulnerabilities",
            "slug": "initial-access-phishing-and-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1566",
              "T1190"
            ],
            "observables": [
              "CVE-2023-23397 (Outlook)",
              "CVE-2022-38028 (Windows Print Spooler)",
              "SedKit exploit kit",
              "Spear phishing emails",
              "UKR.NET phishing landing pages"
            ]
          },
          {
            "name": "Privilege Escalation via GooseEgg",
            "slug": "privilege-escalation-gooseegg",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "GooseEgg utility",
              "Windows Print Spooler service exploitation",
              "SYSTEM-level execution"
            ]
          },
          {
            "name": "Net-NTLMv2 Hash Harvesting",
            "slug": "credential-harvesting-ntlm-relay",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Net-NTLMv2 hashes",
              "Authentication to attacker-controlled SMB shares",
              "Crafted Outlook reminders",
              "Spoofed UKR.NET webmail portal"
            ]
          },
          {
            "name": "Infrastructure Hijacking on Edge Devices",
            "slug": "c2-edge-device-hijacking",
            "tactic": "command-and-control",
            "techniques": [
              "T1572"
            ],
            "observables": [
              "MooBot botnet",
              "FrostArmada campaign",
              "Ubiquiti EdgeRouters",
              "MikroTik and TP-Link routers",
              "Rewritten DNS/DHCP settings pointing to actor-controlled resolvers",
              "X-Tunnel network pivot"
            ]
          },
          {
            "name": "LLM-Integrated Data Exfiltration",
            "slug": "exfiltration-llm-infostealer",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "LLM-integrated infostealer",
              "Harvesting Office, PDF, and TXT documents",
              "Commands generated by legitimate AI services"
            ]
          }
        ],
        "summary": "APT28 (Fancy Bear) has transitioned from a decade-long reliance on a stable in-house implant suite like X-Agent to a highly fragmented, disposable toolkit and extensive infrastructure hijacking. The actor currently weaponizes edge devices such as Ubiquiti and MikroTik routers for proxying traffic and harvesting credentials, while integrating LLM-driven malware for automated document exfiltration."
      },
      "severity": "high",
      "rationale": "Prioritize hosts with frequent external lookups. Widen the scope if the network connection surface shows traffic to the AI domains even without the high NXDOMAIN count, as some edge devices may selectively hijack traffic.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.",
      "parameters": {
        "ai_domains": {
          "from": {
            "ref": "sekoia-apt28-evolution",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[domain]",
          "default": [
            "api.openai.com",
            "api.anthropic.com",
            "api.cohere.ai"
          ],
          "description": "Legitimate AI service domains used by modern infostealers for command generation and data processing."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Comma-separated list of hostnames to narrow the search; leave empty for the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/apt28-an-evolution-of-tradecraft",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/apt28-an-evolution-of-tradecraft",
          "name": "Sekoia \u2014 APT28: An Evolution of Tradecraft from X-Agent to LLM Malware"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry-gap",
          "risk": "If an edge router rewrites DNS responses at the network level, the local host log only sees a successful resolution from its expected upstream, masking the rogue resolver.",
          "stage": "c2-edge-device-hijacking",
          "question": "Whether the host is receiving malicious responses from an edge device that the local agent logs as valid traffic",
          "requires": "Network-level packet capture for DNS"
        },
        {
          "id": "encrypted-exfiltration-visibility",
          "risk": "While we can identify connections to AI APIs, we cannot confirm if the request body contained a harvested document without decryption.",
          "stage": "exfiltration-llm-infostealer",
          "question": "What specific data was contained in the requests to AI service providers",
          "requires": "TLS inspection on HTTP/HTTPS traffic"
        }
      ]
    },
    "name": "APT28 Edge Hijacking and AI-Driven Exfiltration",
    "description": "This hunt targets the modernization of APT28 tradecraft, specifically the shift toward edge infrastructure exploitation (MooBot and FrostArmada) for C2 and the use of LLM-integrated malware for automated data theft. It identifies hosts exhibiting DNS resolver hijacking signatures, such as excessive internal resolution failures alongside external successes. The flow then correlates these leads with bulk document access patterns and rare process communication to legitimate AI service providers or non-standard proxy ports used by X-Tunnel. An agent weighs the multi-surface evidence to identify high-confidence intrusions."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "apt28-an-evolution-of-tradecraft-from-x-agent-to-llm-malware",
          "index": 2,
          "title": "APT28: An Evolution of Tradecraft from X-Agent to LLM Malware",
          "total": 2
        },
        "coverage": [
          {
            "stage": "c2-edge-device-hijacking",
            "steps": [
              "dns-hijacking-lead",
              "ai-and-tunnel-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-llm-infostealer",
            "steps": [
              "bulk-document-harvesting",
              "agent-triage"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-phishing-and-vulnerability-exploitation",
            "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "privilege-escalation-gooseegg",
            "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-harvesting-ntlm-relay",
            "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry-gap",
            "risk": "If an edge router rewrites DNS responses at the network level, the local host log only sees a successful resolution from its expected upstream, masking the rogue resolver.",
            "stage": "c2-edge-device-hijacking",
            "question": "Whether the host is receiving malicious responses from an edge device that the local agent logs as valid traffic",
            "requires": "Network-level packet capture for DNS"
          },
          {
            "id": "encrypted-exfiltration-visibility",
            "risk": "While we can identify connections to AI APIs, we cannot confirm if the request body contained a harvested document without decryption.",
            "stage": "exfiltration-llm-infostealer",
            "question": "What specific data was contained in the requests to AI service providers",
            "requires": "TLS inspection on HTTP/HTTPS traffic"
          }
        ],
        "scoping_notes": "Prioritize hosts with frequent external lookups. Widen the scope if the network connection surface shows traffic to the AI domains even without the high NXDOMAIN count, as some edge devices may selectively hijack traffic.",
        "beyond_detection": "This hunt correlates signals across three surfaces: DNS hijacking (edge manipulation), file activity (automated bulk harvesting), and rare network connections (AI-based exfiltration). A single detection rule would struggle to distinguish legitimate browser traffic to AI tools from automated malware exfiltration without this broader context."
      }
    },
    {
      "id": "dns-hijacking-lead",
      "type": "query",
      "label": "DNS anomalies and edge hijacking",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, COUNT(CASE WHEN rcode = 'NXDOMAIN' AND (LOWER(query_hostname) LIKE '%.local' OR LOWER(query_hostname) LIKE '%.internal') THEN 1 END) AS internal_fail_count, COUNT(CASE WHEN rcode = 'NOERROR' AND LOWER(query_hostname) NOT LIKE '%.local' AND LOWER(query_hostname) NOT LIKE '%.internal' THEN 1 END) AS external_success_count FROM hb_dns_activity WHERE time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING internal_fail_count > 100 AND external_success_count > 0 ORDER BY internal_fail_count DESC",
        "surface": "hb_dns_activity",
        "description": "Identify hosts showing signatures of hijacked DNS resolvers where internal domain resolution fails while external connectivity remains intact.",
        "expected_signal": "Hosts with over 100 NXDOMAIN errors for internal resources despite successful external lookups, suggesting the edge device is misdirecting or failing to resolve local zones."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "DNS anomalies and edge hijacking",
        "reads": [
          "device_hostname",
          "query_hostname",
          "rcode",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, COUNT(CASE WHEN rcode = 'NXDOMAIN' AND (LOWER(query_hostname) LIKE '%.local' OR LOWER(query_hostname) LIKE '%.internal') THEN 1 END) AS internal_fail_count, COUNT(CASE WHEN rcode = 'NOERROR' AND LOWER(query_hostname) NOT LIKE '%.local' AND LOWER(query_hostname) NOT LIKE '%.internal' THEN 1 END) AS external_success_count FROM hb_dns_activity WHERE time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING internal_fail_count > 100 AND external_success_count > 0 ORDER BY internal_fail_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts with over 100 NXDOMAIN errors for internal resources despite successful external lookups, suggesting the edge device is misdirecting or failing to resolve local zones.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "bulk-document-harvesting",
      "type": "query",
      "label": "Bulk document access patterns",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, actor_user_name, strftime('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(DISTINCT file_path) AS unique_files FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id = 2 AND (LOWER(file_path) LIKE '%.doc%' OR LOWER(file_path) LIKE '%.pdf%' OR LOWER(file_path) LIKE '%.txt') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, actor_user_name, hour_bucket HAVING unique_files > 100 ORDER BY unique_files DESC",
        "surface": "hb_file_activity",
        "description": "Detect automated document harvesting by processes reading an unusual volume of sensitive file types within a short window.",
        "expected_signal": "A single process reading more than 100 unique documents in an hour. This distinguishes automated harvesting from normal user file interaction."
      },
      "parents": [
        {
          "id": "dns-hijacking-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Bulk document access patterns",
        "reads": [
          "device_hostname",
          "process_name",
          "actor_user_name",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, actor_user_name, strftime('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(DISTINCT file_path) AS unique_files FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id = 2 AND (LOWER(file_path) LIKE '%.doc%' OR LOWER(file_path) LIKE '%.pdf%' OR LOWER(file_path) LIKE '%.txt') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, actor_user_name, hour_bucket HAVING unique_files > 100 ORDER BY unique_files DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A single process reading more than 100 unique documents in an hour. This distinguishes automated harvesting from normal user file interaction.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ai-and-tunnel-activity",
      "type": "query",
      "label": "Rare process AI and tunnel communication",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{ai_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR dst_endpoint_port IN (1080, 8080) OR dst_endpoint_port > 10000) AND LOWER(process_name) NOT LIKE '%chrome%' AND LOWER(process_name) NOT LIKE '%firefox%' AND LOWER(process_name) NOT LIKE '%msedge%' AND LOWER(process_name) NOT LIKE '%safari%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3",
        "surface": "hb_network_connection",
        "description": "Identify non-browser processes communicating with AI service providers or using high ports typical of the X-Tunnel pivot.",
        "expected_signal": "Connections to OpenAI/Anthropic APIs or high-port outbound tunnels from processes that are rare across the fleet and are not standard web browsers."
      },
      "parents": [
        {
          "id": "dns-hijacking-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare process AI and tunnel communication",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_hostname",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{ai_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR dst_endpoint_port IN (1080, 8080) OR dst_endpoint_port > 10000) AND LOWER(process_name) NOT LIKE '%chrome%' AND LOWER(process_name) NOT LIKE '%firefox%' AND LOWER(process_name) NOT LIKE '%msedge%' AND LOWER(process_name) NOT LIKE '%safari%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Connections to OpenAI/Anthropic APIs or high-port outbound tunnels from processes that are rare across the fleet and are not standard web browsers.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-triage",
      "type": "analytic",
      "label": "Weigh correlated evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "dns-hijacking-lead",
          "bulk-document-harvesting",
          "ai-and-tunnel-activity"
        ],
        "objective": "Determine if any host exhibits combined indicators of DNS resolver hijacking, automated document harvesting (100+ files/hour), and rare process communication with AI domains or high-port proxies.",
        "description": "Correlate the DNS hijacking lead with the file harvesting and network activity findings.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict identifying whether an automated exfiltration chain is active.",
        "success_criteria": "A verdict of malicious or suspicious citing specific rows where a non-browser process accessed many documents and subsequently communicated with an AI domain or tunnel proxy."
      },
      "parents": [
        {
          "id": "bulk-document-harvesting",
          "kind": "merge"
        },
        {
          "id": "ai-and-tunnel-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on agent verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict is malicious or suspicious for at least one host due to correlated exfiltration and C2 behavior.",
        "condition": "The triage verdict is malicious or suspicious for at least one host due to correlated exfiltration and C2 behavior.",
        "blind_spot": "incomplete-telemetry-gap",
        "confidence": "high",
        "description": "Direct the hunt based on the triage verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Endpoint",
      "config": {
        "target": "endpoint",
        "description": "Sever the exfiltration and C2 channel on confirmed compromised hosts.",
        "instructions": "Isolate the host from the network. Collect the suspicious process binary and capture a memory dump for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the harvesting intent and check for manual DNS configuration overrides.",
        "instructions": "Review the file paths accessed by the process. Check the local hosts file and registry DNS settings for anomalies. Confirm if the AI service interaction was an expected part of a legitimate business tool (e.g., an LLM desktop client)."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update technical controls.",
        "instructions": "Record the total count of documents potentially exfiltrated. Document any new AI service endpoints or proxy ports found to improve future detection rules."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}