← All hunts high TLP:CLEAR

Gamaredon Modular Espionage Chain

An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

Based on research by Sekoia 2026-09-28 12 steps · 5 queries T1041 T1053.005 T1059.001 T1071 T1190 T1218.005 T1555 T1566

Brief

The Matryoshka Chain

Gamaredon (UAC-0010) operates at a remarkable pace, primarily targeting government infrastructure. Sekoia recently detailed their latest infection lifecycles in "FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations" (https://www.sekoia.com/blog/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm). Their "Matryoshka" approach involves a series of nested loaders and modular components that hide using standard Windows utilities and the registry. This hunt identifies the full chain, from the initial file-based exploit to the final modular stealer.

Scoping the Vulnerable Surface

The first phase of the hunt inventories hosts for vulnerable versions of WinRAR (CVE-2025-8088). Identifying these hosts establishes the initial scope. Even without immediate evidence of an exploit, any host with this vulnerability represents a significant risk, as the adversary frequently targets path traversal to drop their first-stage payloads. By isolating these hosts early, we focus the remaining queries on the most likely points of entry.

Identifying Staging and Persistence

The hunt then searches for active signs of the GammaPhish and GammaLoad stages. We examine process telemetry for mshta.exe execution that reaches out to remote staging URLs or runs files from the user's Startup directory. In parallel, we inspect the registry Run and RunOnce keys for VBScript loaders. This dual approach identifies both the initial execution of the HTA payload and the persistent VBScript stagers used to maintain access before the more advanced modules arrive.

Detecting the Worm and Modular Stealer

The final phase tracks the transition to post-exploitation and propagation. We hunt for GammaWorm (LitterDrifter) by identifying the creation of Alternate Data Streams and suspicious LNK shortcut files on the filesystem. To find the GammaSteel stealer, we use a volume-based registry query. The adversary stores approximately 71 encrypted PowerShell modules in specific registry keys. By stacking the count of registry values per key path, we identify the high-volume footprint characteristic of this modular framework, which often bypasses traditional signature-based detections.

Blind Spots and Limitations

This hunt has specific visibility requirements and limitations. Encryption hides the specific logic of the GammaSteel PowerShell modules; while we can detect the existence of the modules via registry write volume, we cannot determine their functional behavior without forensic extraction. Additionally, the hunt depends on the endpoint sensor's ability to resolve NTFS Alternate Data Streams. If the telemetry truncates these stream identifiers, GammaWorm persistence remains invisible. Unmanaged hosts also represent a blind spot, as they can act as silent sources of propagation.

How to Run the Hunt

This hunt is packaged as an open hunt.md playbook. It imports directly into Huntbase or any hunt.md-aware runtime environment. Because it correlates initial vulnerability status with multi-stage behavioral indicators, it provides a more comprehensive view of the Gamaredon intrusion lifecycle than a collection of disconnected detection rules.

Steps

  1. Inventory vulnerable WinRAR instances

    Query · scoping

    Identify hosts in the estate that are vulnerable to the WinRAR path traversal vulnerability CVE-2025-8088, establishing the initial scope.

    reads hb_vulnerability_findingsql
    SELECT device_uid, resource_uid, affected_package_version, severity FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'

    What a hit looks like. A list of host UIDs and resource identifiers reporting the WinRAR vulnerability. Silence proves the vulnerability is not currently present in the scanned inventory.

  2. GammaPhish MSHTA staging

    Query · triage

    Identify mshta.exe executing payloads from remote URLs or the Startup directory, typical of GammaPhish staging.

    reads hb_process_activitysql
    SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\mshta.exe' OR LOWER(process_name) = 'mshta.exe') AND (LOWER(process_cmd_line) LIKE '%http%' OR LOWER(process_cmd_line) LIKE LOWER('{{startup_path_pattern}}')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Process events showing mshta.exe reaching out to staging URLs or running an HTA from a user startup path.

  3. GammaLoad VBScript persistence

    Query · triage

    Search for VBScript loaders established in standard registry Run/RunOnce keys, indicating GammaLoad persistence.

    reads hb_registry_activitysql
    SELECT device_hostname, reg_target, reg_value_data, time FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\currentversion\\run%' OR LOWER(reg_target) LIKE '%\\currentversion\\runonce%') AND (LOWER(reg_value_data) LIKE '%.vbs%' OR LOWER(reg_value_data) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Registry values pointing to VBScript files in autorun locations. Silence means no such persistence is present in the telemetry.

  4. Triage early infection stages

    Agent triage

    Correlate host vulnerability status with observed initial access and persistence events.

  5. GammaWorm ADS and LNK creation

    Query · enrichment

    Detect GammaWorm (LitterDrifter) activity by identifying the creation of Alternate Data Streams and suspicious LNK shortcut files.

    reads hb_file_activitysql
    SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (instr(substr(file_path, 4), ':') > 0 OR LOWER(file_name) LIKE '%.lnk') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. File paths containing colons past the drive letter (ADS) or a volume of new LNK files. Silence indicates no such visible propagation.

  6. GammaSteel modular registry storage

    Query · detection candidate

    Identify GammaSteel's modular footprint by counting high volumes of values written to a single registry key path, indicative of the 70+ encrypted modules.

    reads hb_registry_activitysql
    SELECT device_hostname, reg_key_path, COUNT(*) AS module_count, MIN(time) AS first_write FROM hb_registry_activity WHERE state_kind = 'log' AND (LOWER(reg_key_path) LIKE '%software\\microsoft\\%' OR LOWER(reg_key_path) LIKE '%software\\classes\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, reg_key_path HAVING module_count > 50

    What a hit looks like. A registry key on a host containing more than 50 values (Gamaredon uses ~71). This stack-count highlights modular deployment.

  7. Unified Matryoshka chain assessment

    Agent triage

    Synthesize early-stage and follow-on evidence to confirm a complete Gamaredon intrusion.

  8. Route on chain verdict

    Decision

    Direct response or forensic actions based on the confidence of the intrusion chain verdict.

  9. Isolate compromised host

    Response action

    Halt the exfiltration of sensitive documents by GammaSteel and prevent worm propagation.

  10. Forensic review and module recovery

    Analyst task

    Acquire the modular encrypted payloads from the registry for deeper analysis.

  11. Hunt close out

    Analyst task

    Document findings and assess detection gaps for modular registry storage.

Coverage

Scenario coverage

StageCoveredHow, or why not
GammaPhish Initial Access via WinRAR Exploit
T1190 · T1566 · T1218.005
Yes vulnerable-winrar-hosts, mshta-startup-or-remote
GammaLoad VBScript Staging
T1059.001 · T1071
Yes gammaload-registry-run
GammaWorm Propagation and Persistence
T1053.005 · T1059.001
Yes gammaworm-ads-lnk
GammaSteel PowerShell Exfiltration
T1041 · T1555 · T1059.001
Yes gammasteel-registry-blobs, intrusion-chain-agent

Blind spots

  • Needs endpoint agent coverage. An unmanaged vulnerable host can act as a silent staging platform or propagation source. It would answer Which unmanaged hosts are vulnerable to CVE-2025-8088?.
  • Needs forensic DPAPI key extraction. While we can detect the existence of modules via registry write volume, their encrypted nature hides their specific functional logic from static analysis. It would answer What is the content and functionality of the individual PowerShell modules?.
  • Needs hb_file_activity that resolves NTFS streams. If the file sensor ignores or truncates stream identifiers, GammaWorm persistence will remain invisible to behavioral queries. It would answer Are NTFS Alternate Data Streams visible in the file sensor telemetry?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
cve_idstringCVE-2025-8088WinRAR vulnerability used in the initial GammaPhish stage.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Limit the hunt to specific hostnames; leave empty for fleet-wide analysis.
startup_path_patternpath%\Microsoft\Windows\Start Menu\Programs\Startup\%Standard startup folder path for HTA extraction.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A standard detection rule for mshta.exe or Run keys lacks the context to
  connect them to the 70+ registry modules or the ADS-hidden worm. This phased hunt
  correlates initial vulnerability status with high-volume modular writes and propagation
  indicators across the entire infection lifecycle.
blind_spots:
- id: no-endpoint-telemetry
  question: Which unmanaged hosts are vulnerable to CVE-2025-8088?
  requires: endpoint agent coverage
  risk: An unmanaged vulnerable host can act as a silent staging platform or propagation
    source.
- id: encryption-hides-payload
  question: What is the content and functionality of the individual PowerShell modules?
  requires: forensic DPAPI key extraction
  risk: While we can detect the existence of modules via registry write volume, their
    encrypted nature hides their specific functional logic from static analysis.
  stage: gammasteel-powershell-exfiltration
- id: ads-visibility
  question: Are NTFS Alternate Data Streams visible in the file sensor telemetry?
  requires: hb_file_activity that resolves NTFS streams
  risk: If the file sensor ignores or truncates stream identifiers, GammaWorm persistence
    will remain invisible to behavioral queries.
  stage: gammaworm-propagation-persistence
coverage:
- stage: gammaphish-initial-access-exploit
  status: covered
  steps:
  - vulnerable-winrar-hosts
  - mshta-startup-or-remote
- stage: gammaload-vbscript-staging
  status: covered
  steps:
  - gammaload-registry-run
- stage: gammaworm-propagation-persistence
  status: covered
  steps:
  - gammaworm-ads-lnk
- stage: gammasteel-powershell-exfiltration
  status: covered
  steps:
  - gammasteel-registry-blobs
  - intrusion-chain-agent
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Gamaredon is a high-tempo, FSB-linked actor targeting government
    infrastructure. Their modular approach using registry-resident payloads and ADS-hidden
    worms requires a multi-surface hunt to bypass standard detection layers.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has exploited a Windows WinRAR path traversal vulnerability
  to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident
  worm, and a modular PowerShell stealer persisting in the registry.
labels:
- hunt
- attack.t1190
- attack.t1566
- attack.t1218.005
- attack.t1059.001
- attack.t1071
- attack.t1053.005
- attack.t1041
- attack.t1555
name: Gamaredon Modular Espionage Chain
parameters:
  cve_id:
    default: CVE-2025-8088
    description: WinRAR vulnerability used in the initial GammaPhish stage.
    from:
      kind: article
      observed: '2026-06-11'
      ref: sekoia_gamaredon_2026
    type: string
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-06-11'
      ref: default_retention
    type: number
  scope_hosts:
    default: []
    description: Limit the hunt to specific hostnames; leave empty for fleet-wide
      analysis.
    from:
      kind: manual
      observed: '2026-06-11'
      ref: analyst_input
    type: list[host]
  startup_path_pattern:
    default: '%\Microsoft\Windows\Start Menu\Programs\Startup\%'
    description: Standard startup folder path for HTA extraction.
    from:
      kind: manual
      observed: '2026-06-11'
      ref: standard_windows_path
    type: path
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.sekoia.com/blog/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Scope the hunt to all Windows endpoints, prioritizing those with vulnerable
  versions of WinRAR as identified in hb_software_inventory.
references:
- name: "Sekoia \u2014 FSB\u2019s matryoshka #1/3: Inside Gamaredon Cyber Operations"
  url: https://www.sekoia.com/blog/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm
related:
- hunt: gammawiper-behavioral-hunt
  reason: GammaWipe is a destructive component often used against researchers; this
    hunt focuses on the espionage and exfiltration chain.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: GammaPhish Initial Access via WinRAR Exploit
    observables:
    - Weaponised xHTML files
    - Malicious RAR archives
    - CVE-2025-8088 exploitation
    - HTA files extracted to \Microsoft\Windows\Start Menu\Programs\Startup
    - mshta.exe execution calling remote staging URLs
    slug: gammaphish-initial-access-exploit
    tactic: initial-access
    techniques:
    - T1190
    - T1566
    - T1218.005
  - name: GammaLoad VBScript Staging
    observables:
    - Cascade of VBScript loaders
    - Host fingerprinting via script
    - Dead Drop Resolvers (DDR) stored in Windows registry
    - HTTP requests for additional VBScript payloads
    slug: gammaload-vbscript-staging
    tactic: execution
    techniques:
    - T1059.001
    - T1071
  - name: GammaWorm Propagation and Persistence
    observables:
    - Obfuscated VBScript worm (LitterDrifter)
    - Malicious code hidden in NTFS Alternate Data Streams (ADS)
    - Scheduled tasks for persistence
    - Creation of LNK shortcut files on USB and network drives
    - Hiding of legitimate directories on removable media
    slug: gammaworm-propagation-persistence
    tactic: persistence
    techniques:
    - T1053.005
    - T1059.001
  - name: GammaSteel PowerShell Exfiltration
    observables:
    - Modular PowerShell stealer
    - 71 distinct modules stored as encrypted registry values
    - Encryption using Windows Data Protection API (DPAPI)
    - Real-time monitoring of local/network file modifications
    - Exfiltration to S3-compatible cloud storage
    - Fallback C2 communication for remote code execution
    slug: gammasteel-powershell-exfiltration
    tactic: exfiltration
    techniques:
    - T1041
    - T1555
    - T1059.001
  summary: Gamaredon (FSB) 2026 espionage campaign targeting Ukrainian entities through
    a modular infection chain including GammaPhish initial access, GammaLoad staging,
    GammaWorm propagation, and GammaSteel exfiltration. The campaign leverages a critical
    WinRAR vulnerability (CVE-2025-8088) to drop payloads that persist via registry
    keys, NTFS Alternate Data Streams, and scheduled tasks.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Gamaredon Modular Espionage Chain

This hunt reconstructs the multi-stage Gamaredon (UAC-0010) Matryoshka infection chain. It begins by identifying vulnerable WinRAR instances (CVE-2025-8088) and subsequent mshta.exe execution. It then pivots to find GammaLoad VBScript persistence and GammaWorm propagation via Alternate Data Streams and LNK files. Finally, the hunt identifies GammaSteel exfiltration modules by detecting high-volume encrypted registry values, which the group uses to maintain stealth and persistence across Ukrainian targets.

## vulnerable-winrar-hosts
<!-- Inventory vulnerable WinRAR instances -->
Identify hosts in the estate that are vulnerable to the WinRAR path traversal vulnerability CVE-2025-8088, establishing the initial scope.

```sqlite target=endpoint role=scoping params=(cve_id=cve_id)
~~~yaml
expected: A list of host UIDs and resource identifiers reporting the WinRAR vulnerability.
  Silence proves the vulnerability is not currently present in the scanned inventory.
reads:
- affected_package_version
- cve_uid
- device_uid
- resource_uid
- severity
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, resource_uid, affected_package_version, severity FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'
```

## early-stage-parallel
<!-- Parallel initial access investigation -->
parallel:
- → mshta-startup-or-remote
- → gammaload-registry-run
join: → early-stage-triage

## mshta-startup-or-remote
<!-- GammaPhish MSHTA staging -->
Identify mshta.exe executing payloads from remote URLs or the Startup directory, typical of GammaPhish staging.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, startup_path_pattern=startup_path_pattern, scope_hosts=scope_hosts)
~~~yaml
expected: Process events showing mshta.exe reaching out to staging URLs or running
  an HTA from a user startup path.
reads:
- device_hostname
- process_cmd_line
- process_name
- time
- user_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\mshta.exe' OR LOWER(process_name) = 'mshta.exe') AND (LOWER(process_cmd_line) LIKE '%http%' OR LOWER(process_cmd_line) LIKE LOWER('{{startup_path_pattern}}')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## gammaload-registry-run
<!-- GammaLoad VBScript persistence -->
Search for VBScript loaders established in standard registry Run/RunOnce keys, indicating GammaLoad persistence.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Registry values pointing to VBScript files in autorun locations. Silence
  means no such persistence is present in the telemetry.
reads:
- device_hostname
- reg_target
- reg_value_data
- time
silence: not_evidence_of_absence
source: hb_registry_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, reg_target, reg_value_data, time FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\currentversion\\run%' OR LOWER(reg_target) LIKE '%\\currentversion\\runonce%') AND (LOWER(reg_value_data) LIKE '%.vbs%' OR LOWER(reg_value_data) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-triage
<!-- Triage early infection stages -->
```agent target=hunter
cite: required
context:
- vulnerable-winrar-hosts
- mshta-startup-or-remote
- gammaload-registry-run
max_iterations: 4
objective: Identify if vulnerable WinRAR hosts show signs of successful HTA staging
  or VBScript loader execution.
success_criteria: A verdict for each host citing evidence of early-stage infection.
tools:
- endpoint
```

## follow-on-parallel
<!-- Investigate follow-on propagation and exfiltration -->
parallel:
- → gammaworm-ads-lnk
- → gammasteel-registry-blobs
join: → intrusion-chain-agent

## gammaworm-ads-lnk
<!-- GammaWorm ADS and LNK creation -->
Detect GammaWorm (LitterDrifter) activity by identifying the creation of Alternate Data Streams and suspicious LNK shortcut files.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: File paths containing colons past the drive letter (ADS) or a volume of
  new LNK files. Silence indicates no such visible propagation.
reads:
- device_hostname
- file_name
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (instr(substr(file_path, 4), ':') > 0 OR LOWER(file_name) LIKE '%.lnk') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## gammasteel-registry-blobs
<!-- GammaSteel modular registry storage -->
Identify GammaSteel's modular footprint by counting high volumes of values written to a single registry key path, indicative of the 70+ encrypted modules.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: new_this_window
  window: '{{lookback_days}}d'
expected: A registry key on a host containing more than 50 values (Gamaredon uses
  ~71). This stack-count highlights modular deployment.
prevalence:
  by: device_hostname
  key:
  - reg_key_path
  rare_below: 3
reads:
- device_hostname
- reg_key_path
- state_kind
- time
silence: not_evidence_of_absence
source: hb_registry_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, reg_key_path, COUNT(*) AS module_count, MIN(time) AS first_write FROM hb_registry_activity WHERE state_kind = 'log' AND (LOWER(reg_key_path) LIKE '%software\\microsoft\\%' OR LOWER(reg_key_path) LIKE '%software\\classes\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, reg_key_path HAVING module_count > 50
```

## intrusion-chain-agent
<!-- Unified Matryoshka chain assessment -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- gammaworm-ads-lnk
- gammasteel-registry-blobs
max_iterations: 5
objective: Determine if the evidence supports a full-chain Gamaredon compromise, building
  on the early-stage triage.
success_criteria: A detailed verdict citing the transition from initial access to
  modular stealer deployment.
tools:
- endpoint
```

## route-on-verdict
<!-- Route on chain verdict -->
if~: "the intrusion-chain-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → manual-review
unavailable: → manual-review (blind_spot: no-endpoint-telemetry)
else: → manual-review

## isolate-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network immediately to prevent data exfiltration and further worm propagation.
```
→ manual-review

## manual-review
<!-- Forensic review and module recovery -->
```manual target=analyst
Collect the registry hives from identified hosts to extract GammaSteel modules. Verify the content of Alternate Data Streams on the filesystem to confirm worm persistence. Review USB insertion history for possible propagation events.
```
→ close-out

## close-out
<!-- Hunt close out -->
```manual target=analyst
Summarize the findings per host. If the high-volume registry module query provided high-fidelity results, recommend promoting it to a permanent detection rule for modular malware storage.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.