{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The adversary maintained control for two months and exfiltrated sensitive data via FTP. Detecting these late-stage signals provides high-assurance evidence of data theft that simple endpoint rules may miss."
      },
      "name": "Persistence and Exfiltration of Lunar Spider",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1053.005",
        "attack.t1567.002",
        "attack.t1048.003",
        "attack.t1036.005"
      ],
      "series": {
        "slug": "from-a-single-click-how-lunar-spider-enabled-a-near-two-month-intrusion",
        "index": 3,
        "title": "From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion",
        "total": 3
      },
      "related": [
        {
          "hunt": "lunar-spider-initial-access",
          "reason": "Initial access via JS and Brute Ratel loading are handled in the first hunt of this series.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A static rule might flag 'lsassa.exe', but this hunt uses a baseline of FTP traffic to find rare exfiltration destinations and correlates that activity across scheduled tasks and script blocks, providing context for a two-month dwell time.",
      "coverage": [
        {
          "stage": "persistence-custom-backdoor",
          "steps": [
            "backdoor-process-lead",
            "persistence-tasks"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-rclone-ftp",
          "steps": [
            "ftp-prevalence",
            "exfiltration-scripts"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-js-downloader",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-brute-ratel-loader",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "discovery-reconnaissance-commands",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-latrodectus-backconnect",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-unattend-xml",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-and-propagation",
          "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Tax-themed JS Downloader",
            "slug": "initial-access-js-downloader",
            "tactic": "initial-access",
            "techniques": [
              "T1566.002",
              "T1204.002"
            ],
            "observables": [
              "Form_W-9_Ver-i40_53b043910-86g91352u7972-6495q3.js",
              "91.194.11.64/MSI.msi",
              "disk1.cab"
            ]
          },
          {
            "name": "Brute Ratel Loader Execution",
            "slug": "execution-brute-ratel-loader",
            "tactic": "execution",
            "techniques": [
              "T1218.011"
            ],
            "observables": [
              "rundll32.exe",
              "upfilles.dll",
              "stow",
              "wscadminui.dll",
              "wsca"
            ]
          },
          {
            "name": "Host and Domain Reconnaissance",
            "slug": "discovery-reconnaissance-commands",
            "tactic": "discovery",
            "techniques": [
              "T1087.002",
              "T1082",
              "T1016",
              "T1033"
            ],
            "observables": [
              "ipconfig",
              "systeminfo",
              "nltest",
              "whoami",
              "AdFind"
            ]
          },
          {
            "name": "Latrodectus and BackConnect C2",
            "slug": "c2-latrodectus-backconnect",
            "tactic": "command-and-control",
            "techniques": [
              "T1055",
              "T1071.001"
            ],
            "observables": [
              "193.168.143.196",
              "explorer.exe",
              "DLLHost.exe",
              "chcp 65001"
            ]
          },
          {
            "name": "Answer File Credential Access",
            "slug": "credential-access-unattend-xml",
            "tactic": "credential-access",
            "techniques": [
              "T1552.001"
            ],
            "observables": [
              "unattend.xml"
            ]
          },
          {
            "name": "Lateral Movement and Vulnerability Exploitation",
            "slug": "lateral-movement-and-propagation",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1570",
              "T1210"
            ],
            "observables": [
              "PsExec.exe",
              "runas",
              "rustscan",
              "CVE-2020-1472"
            ]
          },
          {
            "name": "Custom .NET Backdoor Persistence",
            "slug": "persistence-custom-backdoor",
            "tactic": "persistence",
            "techniques": [
              "T1053.005"
            ],
            "observables": [
              "lsassa.exe",
              "lsassa&&"
            ]
          },
          {
            "name": "Data Exfiltration via Rclone",
            "slug": "exfiltration-rclone-ftp",
            "tactic": "exfiltration",
            "techniques": [
              "T1567.002",
              "T1048.003"
            ],
            "observables": [
              "rclone",
              "FTP",
              "port 21"
            ]
          }
        ],
        "summary": "An intrusion attributed to Lunar Spider began with a tax-themed JavaScript loader that deployed Latrodectus and Brute Ratel C4. The actors escalated privileges by discovering plaintext credentials in an unattend.xml file and moved laterally using PsExec, RDP, and the Zerologon vulnerability. Over a two-month dwell period, they maintained persistence via custom .NET backdoors and exfiltrated data using Rclone over FTP."
      },
      "severity": "high",
      "rationale": "The intrusion spanned two months; ensure the lookback period covers the exfiltration phase (reported around day 20). Focus on file servers and backup servers where large volumes of data reside.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.",
      "parameters": {
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine; the original intrusion had a two-month dwell time."
        },
        "backdoor_names": {
          "from": {
            "ref": "https://thedfirreport.com/2025/09/29/from-a-single-click-how-lunar-spider-enabled-a-near-two-month-intrusion/",
            "kind": "article",
            "observed": "2024-05-01"
          },
          "type": "list[string]",
          "default": [
            "lsassa.exe",
            "lsasss.exe",
            "lssas.exe"
          ],
          "description": "Filename variations for the masqueraded .NET backdoor."
        },
        "exfil_keywords": {
          "from": {
            "ref": "common-ttp",
            "kind": "manual",
            "observed": "2025-01-01"
          },
          "type": "list[string]",
          "default": [
            "rclone.ps1",
            "backup_sync.ps1",
            "upload.exe"
          ],
          "description": "Filenames of scripts used to automate data exfiltration."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2025/09/29/from-a-single-click-how-lunar-spider-enabled-a-near-two-month-intrusion/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2025/09/29/from-a-single-click-how-lunar-spider-enabled-a-near-two-month-intrusion/",
          "name": "The DFIR Report \u2014 From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion"
        }
      ],
      "blind_spots": [
        {
          "id": "telemetry-retention-gap",
          "risk": "A standard 14-day window misses the day-20 exfiltration event cited in the two-month intrusion report.",
          "stage": "exfiltration-rclone-ftp",
          "question": "whether exfiltration happened before the current retention window",
          "requires": "60-day network and script telemetry retention"
        },
        {
          "id": "obfuscated-scripts",
          "risk": "Simple string matching fails if the attacker uses PowerShell character replacement or hex encoding for 'rclone'.",
          "stage": "exfiltration-rclone-ftp",
          "question": "whether rclone keywords are hidden by obfuscation",
          "requires": "script deobfuscation in hb_script_activity"
        }
      ]
    },
    "name": "Persistence and Exfiltration of Lunar Spider",
    "description": "This hunt targets the final phases of a multi-month intrusion. It focuses on identifying a custom .NET backdoor masquerading as 'lsassa.exe' and data exfiltration patterns using Rclone and FTP. The hunt identifies persistence via scheduled tasks and uses stack-counting to isolate rare outbound FTP connections, which are then corroborated by script activity."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "from-a-single-click-how-lunar-spider-enabled-a-near-two-month-intrusion",
          "index": 3,
          "title": "From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion",
          "total": 3
        },
        "coverage": [
          {
            "stage": "persistence-custom-backdoor",
            "steps": [
              "backdoor-process-lead",
              "persistence-tasks"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-rclone-ftp",
            "steps": [
              "ftp-prevalence",
              "exfiltration-scripts"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-js-downloader",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-brute-ratel-loader",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "discovery-reconnaissance-commands",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-latrodectus-backconnect",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-unattend-xml",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-and-propagation",
            "reason": "Belongs to another part of the 'From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.",
        "blind_spots": [
          {
            "id": "telemetry-retention-gap",
            "risk": "A standard 14-day window misses the day-20 exfiltration event cited in the two-month intrusion report.",
            "stage": "exfiltration-rclone-ftp",
            "question": "whether exfiltration happened before the current retention window",
            "requires": "60-day network and script telemetry retention"
          },
          {
            "id": "obfuscated-scripts",
            "risk": "Simple string matching fails if the attacker uses PowerShell character replacement or hex encoding for 'rclone'.",
            "stage": "exfiltration-rclone-ftp",
            "question": "whether rclone keywords are hidden by obfuscation",
            "requires": "script deobfuscation in hb_script_activity"
          }
        ],
        "scoping_notes": "The intrusion spanned two months; ensure the lookback period covers the exfiltration phase (reported around day 20). Focus on file servers and backup servers where large volumes of data reside.",
        "beyond_detection": "A static rule might flag 'lsassa.exe', but this hunt uses a baseline of FTP traffic to find rare exfiltration destinations and correlates that activity across scheduled tasks and script blocks, providing context for a two-month dwell time."
      }
    },
    {
      "id": "backdoor-process-lead",
      "type": "query",
      "label": "Masqueraded Backdoor Process Execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{backdoor_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR (LOWER(process_path) LIKE '%\\\\users\\\\public\\\\%' AND LOWER(process_name) LIKE '%.exe')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify the execution of the masqueraded .NET backdoor binary based on its reported filename or suspicious execution path.",
        "expected_signal": "A process execution with a name like 'lsassa.exe' or a binary running from a public user directory. This serves as the primary lead for the persistence phase."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Masqueraded Backdoor Process Execution",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{backdoor_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR (LOWER(process_path) LIKE '%\\\\users\\\\public\\\\%' AND LOWER(process_name) LIKE '%.exe')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A process execution with a name like 'lsassa.exe' or a binary running from a public user directory. This serves as the primary lead for the persistence phase.",
        "verified": "dry-run",
        "verified_at": "2026-09-23"
      }
    },
    {
      "id": "persistence-tasks",
      "type": "query",
      "label": "Scheduled Task Persistence",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE (LOWER(job_cmd_line) LIKE '%lsassa%' OR LOWER(job_cmd_line) LIKE '%\\\\users\\\\public\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\programdata\\\\%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_scheduled_job",
        "description": "Corroborate the process lead by finding scheduled tasks configured to execute the backdoor binary.",
        "expected_signal": "A scheduled job entry pointing to the suspected backdoor path or name, confirming long-term persistence."
      },
      "parents": [
        {
          "id": "backdoor-process-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Scheduled Task Persistence",
        "reads": [
          "device_hostname",
          "job_name",
          "job_cmd_line",
          "job_user_name",
          "time"
        ],
        "source": "hb_scheduled_job",
        "target": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE (LOWER(job_cmd_line) LIKE '%lsassa%' OR LOWER(job_cmd_line) LIKE '%\\\\users\\\\public\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\programdata\\\\%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A scheduled job entry pointing to the suspected backdoor path or name, confirming long-term persistence.",
        "verified": "dry-run",
        "verified_at": "2026-09-23"
      }
    },
    {
      "id": "ftp-prevalence",
      "type": "query",
      "label": "Rare FTP Destination Baseline",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT dst_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 21 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip HAVING host_count <= 2 ORDER BY total_bytes DESC",
        "surface": "hb_network_connection",
        "description": "Detect rare outbound FTP connections that might represent data exfiltration to attacker-controlled infrastructure.",
        "expected_signal": "FTP connections to external IPs seen from very few internal hosts. High traffic volume to these rare destinations is a strong indicator of exfiltration."
      },
      "parents": [
        {
          "id": "backdoor-process-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare FTP Destination Baseline",
        "reads": [
          "dst_endpoint_ip",
          "device_hostname",
          "traffic_bytes",
          "time",
          "dst_endpoint_port"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT dst_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 21 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip HAVING host_count <= 2 ORDER BY total_bytes DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "FTP connections to external IPs seen from very few internal hosts. High traffic volume to these rare destinations is a strong indicator of exfiltration.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-23"
      }
    },
    {
      "id": "exfiltration-scripts",
      "type": "query",
      "label": "Exfiltration Script Execution",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_name, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%rclone%' OR instr(',' || '{{exfil_keywords}}' || ',', ',' || LOWER(script_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Identify the use of Rclone or FTP automation scripts in the environment.",
        "expected_signal": "Script logs containing rclone commands (sync, copy) or filenames specified in the exfil_keywords parameter."
      },
      "parents": [
        {
          "id": "backdoor-process-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Exfiltration Script Execution",
        "reads": [
          "device_hostname",
          "script_name",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_name, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%rclone%' OR instr(',' || '{{exfil_keywords}}' || ',', ',' || LOWER(script_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script logs containing rclone commands (sync, copy) or filenames specified in the exfil_keywords parameter.",
        "verified": "dry-run",
        "verified_at": "2026-09-23"
      }
    },
    {
      "id": "agent-triage",
      "type": "analytic",
      "label": "Triage Persistence and Theft Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "backdoor-process-lead",
          "persistence-tasks",
          "ftp-prevalence",
          "exfiltration-scripts"
        ],
        "objective": "Determine if any host shows evidence of both the custom backdoor persistence and data exfiltration using Rclone or FTP.",
        "description": "Weigh the presence of masqueraded binaries, scheduled tasks, rare FTP traffic, and Rclone scripts to determine the risk per host.",
        "max_iterations": 6,
        "expected_signal": "A clear verdict identifying hosts with high-confidence indicators of long-term persistence and data theft.",
        "success_criteria": "A verdict of malicious, suspicious, or benign for each host found in the queries."
      },
      "parents": [
        {
          "id": "persistence-tasks",
          "kind": "merge"
        },
        {
          "id": "ftp-prevalence",
          "kind": "merge"
        },
        {
          "id": "exfiltration-scripts",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route Based on Intrusion Risk",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-triage verdict is malicious or suspicious for at least one host",
        "condition": "the agent-triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "telemetry-retention-gap",
        "confidence": "high",
        "description": "Route the hunt to immediate containment if the agent confirms malicious activity.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage"
        }
      ]
    },
    {
      "id": "contain-threat",
      "type": "action",
      "label": "Isolate Affected Host",
      "config": {
        "target": "endpoint",
        "description": "Stop ongoing exfiltration and prevent further backdoor commands.",
        "instructions": "Isolate the host from the network. Collect the suspected lsassa.exe binary and any identified script files for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst Forensic Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the findings and prepare for complete eviction of the threat actor.",
        "instructions": "Analyze the cited script contents and network traffic. Determine the volume of data exfiltrated. Validate if the 'lsassa.exe' binary is a legitimate .NET backdoor. Pivot to earlier stages of the intrusion (Latrodectus, initial access) if a compromise is confirmed."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "contain-threat"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt Closure",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and archive the hunt result.",
        "instructions": "Record the evidence of absence if no hits were found. If suspicious activity was found but overturned, update the parameters to reduce false positives."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}