Endpoint Social Engineering and Malicious Execution
An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.
Based on research by Huntress 2026-10-02 12 steps · 5 queries T1071.001 T1204.001 T1219 T1555 T1566
Brief
Why now
The Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses identifies social engineering and user-driven execution as persistent, high-prevalence threats. Attackers increasingly use AI-generated lures and ClickFix techniques to bypass technical controls by convincing users to manually paste commands into the Windows Run box. This bypasses many standard email filters and browser-based protections by placing the burden of execution on the end user.
How the hunt flows
The hunt begins by identifying Windows hosts within the hb_software_inventory to establish a target scope. This scoping phase ensures we focus on endpoints where manual shell execution is most impactful and helps filter out non-Windows systems that do not use the explorer.exe shell.
Next, the hunt runs two parallel checks to identify the point of infection. The first query examines hb_http_activity for outbound traffic to AI platforms or known lure domains like Railway and Claude.ai. The second query monitors hb_process_activity for shell processes where the parent is explorer.exe. This specific parent-child relationship is a direct indicator of a user pasting commands into the Run box or a folder address bar.
A triage phase uses an agent to evaluate these early-stage signals. The agent confirms if the lure traffic and shell execution happen within a close temporal window. This step filters out noise from users who might use the Run box for legitimate tasks, focusing the hunt on hosts with high-confidence compromise indicators.
After confirming the initial access, the hunt moves into evidence gathering for persistence and impact. It performs a stack-count on hb_process_activity to find RMM tools like AnyDesk or ScreenConnect that appear on three or fewer hosts. Tools found fleet-wide are typically sanctioned; rare ones suggest an attacker-installed instance used for persistence. Simultaneously, it audits hb_file_activity for unknown processes reading browser Login Data or Cookies, which is a signature of infostealers like LummaC2.
Finally, the hunt synthesizes these signals. By linking the initial web redirect to the manual execution and subsequent file theft or RMM deployment, we confirm a complete intrusion chain rather than treating each event as an isolated anomaly. An analyst then confirms the final verdict and isolates affected hosts.
What the hunt cannot see
This hunt has two primary blind spots. First, if a user clicks a redirect that bypasses endpoint HTTP logging—such as an internal browser redirect or a link that does not trigger a new request to a tracked domain—the hb_http_activity surface may stay silent. Second, command line truncation in process telemetry can hide indicators. If the attacker uses a very long, encoded PowerShell string, we might lose the iex or -enc flags required for high-fidelity detection.
In this series
Steps
-
Scope Windows Hosts
Query · scopingIdentify Windows endpoints in the software inventory to target the hunt.
reads hb_software_inventorysqlSELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (package_type = 'msi' OR package_type = 'exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)What a hit looks like. A list of hostnames representing the Windows estate. Silence means no Windows software inventory is present.
-
Phishing Lure Traffic
Query · triageFind HTTP requests to AI platforms or known redirectors identified in the article.
reads hb_http_activitysqlSELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE (instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{redirect_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Outbound traffic to domains like claude.ai or Railway following a redirect link. Silence means no report-specific traffic was found.
-
ClickFix Shell Execution
Query · detection candidateDetect shell processes spawned by explorer.exe with encoded commands, typical of Run box pasting.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%explorer.exe' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND (LOWER(process_cmd_line) LIKE '%iex%' OR LOWER(process_cmd_line) LIKE '%-enc%' OR LOWER(process_cmd_line) LIKE '%getstring%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A shell process launched directly from explorer.exe with suspicious arguments. This indicates a user-driven paste event.
-
Early Stage Triage
Agent triageDetermine which hosts show high-confidence signs of social engineering leading to manual shell execution.
-
Rogue RMM Check
Query · baselineFind rogue RMM tools by stack-counting common RMM names across the estate.
reads hb_process_activitysqlSELECT process_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3 ORDER BY host_count ASCWhat a hit looks like. An RMM tool seen on three or fewer hosts. Tools found fleet-wide are likely authorized; rare ones suggest rogue installation.
-
Infostealer File Access
Query · enrichmentIdentify non-browser processes accessing browser credential and session data using a list-based exclusion.
reads hb_file_activitysqlSELECT device_hostname, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{browser_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Any row showing an unknown process reading sensitive browser files. Silence means no such access was observed.
-
Full Chain Analysis
Agent triageCombine early-stage verdicts with follow-on evidence to identify complete intrusion chains.
-
Response Decision
DecisionDirect response actions based on the confidence of the intrusion chain.
-
Isolate Host
Response actionSever network access to prevent further data theft or command execution.
-
Analyst Review
Analyst taskVerify the agent's findings and identify any false positives in shell execution patterns.
-
Hunt Closure
Analyst taskDocument findings and close out the hunt.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Social Engineering with AI-Tuned Lures T1566 |
Yes | lure-traffic |
| User-Driven ClickFix Command Execution T1204.001 |
Yes | clickfix-execution |
| Persistence via Rogue RMM Installation T1219 |
Yes | rogue-rmm-check |
| Infostealer and RAT Deployment T1555 · T1071.001 |
Yes | infostealer-file-access |
| Adversary-in-the-Middle and Device Code Token Harvesting T1557 · T1528 |
Out of scope | Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series. |
| Stealthy Mailbox Rule Manipulation T1137.005 · T1564.008 |
Out of scope | Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series. |
Blind spots
- Needs hb_http_activity from a proxy or firewall. Endpoint agents may miss browser-internal redirects or specific AI-hosted artifacts that a network proxy would capture. It would answer Did the user click a redirect that bypasses endpoint-only HTTP logging?.
- Needs Full process_cmd_line length. Attackers use long, encoded PowerShell strings; if truncated, key indicators like 'iex' may be lost. It would answer What was the complete payload pasted into the Run box?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
browser_files | list[string] | login data, cookies, web data | Target files typically harvested by infostealers. |
legitimate_browsers | list[string] | chrome.exe, msedge.exe, firefox.exe | Legitimate browser process names to exclude from theft detection. |
lookback_days | number | 14 | Days of history to examine. |
lure_domains | list[domain] | claude.ai, railway.app, railway.com | Domains known to host malicious artifacts or lures. |
redirect_domains | list[domain] | cisco.com, trendmicro.com, mimecast.com | Legitimate service domains used as phishing redirectors. |
rmm_names | list[string] | anydesk.exe, screenconnect.exe, atera.exe, splashtop.exe, tvnserver.exe | Common RMM process names used to establish a prevalence baseline. |
scope_hosts | list[host] | — | Optional list of hostnames to narrow the search; leave empty for all hosts. |
shell_names | list[string] | powershell.exe, cmd.exe | Shell processes monitored for Run-box execution. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: A standing rule for explorer.exe spawning a shell is too noisy; this hunt
uses network lures and follow-on file-access patterns to provide the context an
analyst needs to act.
blind_spots:
- id: no-proxy-telemetry
question: Did the user click a redirect that bypasses endpoint-only HTTP logging?
requires: hb_http_activity from a proxy or firewall
risk: Endpoint agents may miss browser-internal redirects or specific AI-hosted
artifacts that a network proxy would capture.
stage: initial-access-phishing-lures
- id: cmd-line-truncation
question: What was the complete payload pasted into the Run box?
requires: Full process_cmd_line length
risk: Attackers use long, encoded PowerShell strings; if truncated, key indicators
like 'iex' may be lost.
stage: execution-clickfix-win-r
coverage:
- stage: initial-access-phishing-lures
status: covered
steps:
- lure-traffic
- stage: execution-clickfix-win-r
status: covered
steps:
- clickfix-execution
- stage: persistence-rmm-abuse
status: covered
steps:
- rogue-rmm-check
- stage: c2-infostealer-deployment
status: covered
steps:
- infostealer-file-access
- reason: 'Belongs to another part of the ''Huntress Tragic Quadrant: Top Cyber Threats
Wrecking Businesses'' series.'
stage: credential-access-token-theft
status: out_of_scope
- reason: 'Belongs to another part of the ''Huntress Tragic Quadrant: Top Cyber Threats
Wrecking Businesses'' series.'
stage: persistence-mailbox-manipulation
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: User-driven manual execution via social engineering is a top-prevalence
threat according to Huntress SOC data. This hunt provides the chain of evidence
required to distinguish rogue RMM use from normal administration.
methodology: model-assisted
trigger: intel-report
hypothesis: An attacker has used AI-tuned phishing lures or ClickFix social engineering
to trick a user into executing shell commands from the Run box, eventually deploying
rogue RMM tools or infostealers.
labels:
- hunt
- attack.t1566
- attack.t1204.001
- attack.t1219
- attack.t1555
- attack.t1071.001
- command and control
- credential access
- execution
- initial access
- persistence
name: Endpoint Social Engineering and Malicious Execution
parameters:
browser_files:
default:
- login data
- cookies
- web data
description: Target files typically harvested by infostealers.
type: list[string]
legitimate_browsers:
default:
- chrome.exe
- msedge.exe
- firefox.exe
description: Legitimate browser process names to exclude from theft detection.
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
lure_domains:
default:
- claude.ai
- railway.app
- railway.com
description: Domains known to host malicious artifacts or lures.
from:
kind: article
observed: '2026-10-01'
ref: huntress-tragic-quadrant
type: list[domain]
redirect_domains:
default:
- cisco.com
- trendmicro.com
- mimecast.com
description: Legitimate service domains used as phishing redirectors.
from:
kind: article
observed: '2026-10-01'
ref: huntress-tragic-quadrant
type: list[domain]
rmm_names:
default:
- anydesk.exe
- screenconnect.exe
- atera.exe
- splashtop.exe
- tvnserver.exe
description: Common RMM process names used to establish a prevalence baseline.
type: list[string]
scope_hosts:
default: []
description: Optional list of hostnames to narrow the search; leave empty for
all hosts.
type: list[host]
shell_names:
default:
- powershell.exe
- cmd.exe
description: Shell processes monitored for Run-box execution.
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Focus on Windows endpoints where users have local administrative rights.
Servers where RMM tools are expected can be filtered by hostname to reduce noise.
references:
- name: "Huntress \u2014 Tragic Quadrant: Top Cyber Threats Wrecking Businesses"
url: https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats
related:
- hunt: mailbox-manipulation-persistence
reason: Persistence via M365 mailbox rules is an identity-layer hunt and out of
scope for this endpoint-focused lifecycle.
relation: out-of-scope-alternative
scenario:
stages:
- name: Social Engineering with AI-Tuned Lures
observables:
- claude.ai
- Railway
- Cisco redirect URLs
- Trend Micro redirect URLs
- Mimecast redirect URLs
- AI-tuned lures
- fake document shares
- service agreement lures
slug: initial-access-phishing-lures
tactic: initial-access
techniques:
- T1566
- name: User-Driven ClickFix Command Execution
observables:
- Win+R
- Windows Run box
- Human Verification prompt
- multi-stage infection command
slug: execution-clickfix-win-r
tactic: execution
techniques:
- T1204.001
- name: Adversary-in-the-Middle and Device Code Token Harvesting
observables:
- session token
- device code login flow
- access token
- Microsoft 365 login page impersonation
slug: credential-access-token-theft
tactic: credential-access
techniques:
- T1557
- T1528
- name: Persistence via Rogue RMM Installation
observables:
- rogue RMM tool
- Remote Monitoring and Management tools
slug: persistence-rmm-abuse
tactic: persistence
techniques:
- T1219
- name: Stealthy Mailbox Rule Manipulation
observables:
- inbox rules
- RSS Feeds folder
- Archive folders
slug: persistence-mailbox-manipulation
tactic: persistence
techniques:
- T1137.005
- T1564.008
- name: Infostealer and RAT Deployment
observables:
- LummaC2
- SectopRAT
- FakeAgent
slug: c2-infostealer-deployment
tactic: command-and-control
techniques:
- T1555
- T1071.001
summary: The Huntress Tragic Quadrant outlines common 2026 threats targeting SMBs,
where attackers use AI-enhanced social engineering (ClickFix, fake lures) and
trusted platforms (Claude.ai) to deliver infostealers and rogue RMM tools. The
campaign progresses from initial access via session token theft (AiTM) or user-driven
command execution to persistence through mailbox manipulation and remote management
software abuse.
series:
index: 1
slug: huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses
title: 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses'
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Endpoint Social Engineering and Malicious Execution
This phased hunt investigates the full lifecycle of host-based infection as described in the Huntress Tragic Quadrant. It begins by identifying suspicious URI redirects and shell processes spawned directly by the Windows desktop shell (explorer.exe), which is the primary indicator of ClickFix social engineering. In the second phase, the hunt corroborates these findings by identifying unauthorized RMM tools and sensitive file access patterns characteristic of infostealers like LummaC2. An agent-driven analysis weighs the early-stage access signals against follow-on persistence and impact evidence to confirm the intrusion chain.
## scope-windows-hosts
<!-- Scope Windows Hosts -->
Identify Windows endpoints in the software inventory to target the hunt.
```sqlite target=endpoint role=scoping params=(scope_hosts=scope_hosts)
~~~yaml
expected: A list of hostnames representing the Windows estate. Silence means no Windows
software inventory is present.
reads:
- device_hostname
- package_type
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (package_type = 'msi' OR package_type = 'exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```
## early-stage-parallel
<!-- Early Stage Parallel Analysis -->
parallel:
- → lure-traffic
- → clickfix-execution
join: → early-stage-triage
## lure-traffic
<!-- Phishing Lure Traffic -->
Find HTTP requests to AI platforms or known redirectors identified in the article.
```sqlite target=web role=triage params=(lure_domains=lure_domains, redirect_domains=redirect_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Outbound traffic to domains like claude.ai or Railway following a redirect
link. Silence means no report-specific traffic was found.
reads:
- device_hostname
- url_hostname
- url_full
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE (instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{redirect_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## clickfix-execution
<!-- ClickFix Shell Execution -->
Detect shell processes spawned by explorer.exe with encoded commands, typical of Run box pasting.
```sqlite target=endpoint role=detection-candidate params=(shell_names=shell_names, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A shell process launched directly from explorer.exe with suspicious arguments.
This indicates a user-driven paste event.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%explorer.exe' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND (LOWER(process_cmd_line) LIKE '%iex%' OR LOWER(process_cmd_line) LIKE '%-enc%' OR LOWER(process_cmd_line) LIKE '%getstring%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-stage-triage
<!-- Early Stage Triage -->
```agent target=hunter
cite: required
context:
- lure-traffic
- clickfix-execution
max_iterations: 3
objective: Determine which hosts show high-confidence signs of social engineering
leading to manual shell execution.
success_criteria: A list of hosts with confirmed early-stage social engineering activity.
tools:
- endpoint
- web
```
## follow-on-parallel
<!-- Follow-on Parallel Analysis -->
parallel:
- → rogue-rmm-check
- → infostealer-file-access
join: → full-chain-analysis
## rogue-rmm-check
<!-- Rogue RMM Check -->
Find rogue RMM tools by stack-counting common RMM names across the estate.
```sqlite target=endpoint role=baseline params=(rmm_names=rmm_names, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: An RMM tool seen on three or fewer hosts. Tools found fleet-wide are likely
authorized; rare ones suggest rogue installation.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 3
reads:
- process_name
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT process_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3 ORDER BY host_count ASC
```
## infostealer-file-access
<!-- Infostealer File Access -->
Identify non-browser processes accessing browser credential and session data using a list-based exclusion.
```sqlite target=endpoint role=enrichment params=(browser_files=browser_files, legitimate_browsers=legitimate_browsers, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Any row showing an unknown process reading sensitive browser files. Silence
means no such access was observed.
reads:
- device_hostname
- process_name
- file_name
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{browser_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## full-chain-analysis
<!-- Full Chain Analysis -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- rogue-rmm-check
- infostealer-file-access
max_iterations: 6
objective: Determine whether the social engineering confirmed in early-stage-triage
led to rogue persistence or infostealer activity.
success_criteria: A final per-host verdict citing evidence from both early and follow-on
stages.
tools:
- endpoint
- web
```
## response-decision
<!-- Response Decision -->
if~: "the final verdict identifies malicious activity linking the initial lure to execution and subsequent RMM or infostealer activity" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-proxy-telemetry)
else: → close-out
## isolate-host
<!-- Isolate Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the affected host using the EDR. Revoke active SaaS session tokens and force a password reset for the logged-in user.
```
→ analyst-review
## analyst-review
<!-- Analyst Review -->
```manual target=analyst
Review the full process command line from the shell execution step. Confirm if the rare RMM identified is a rogue instance or a one-off approved project tool. If the shell query is high-fidelity, promote it to a standing rule.
```
→ close-out
## close-out
<!-- Hunt Closure -->
```manual target=analyst
Record the hosts examined, any confirmed threats, and false positives for baseline tuning. Document coverage gaps for the HTTP surface if lures were missed.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.