← All hunts high TLP:CLEAR Part 1 of 2

Socially Engineered Endpoint Infection and Evasion

An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.

Based on research by Cisco Talos 2026-09-28 12 steps · 5 queries T1071 T1204 T1555 T1562.001 T1566

Brief

Why now

Talos recently detailed an campaign targeting technical professionals with fake consultancy offers in their report, Trust and the enticing consultancy offer. The adversary uses these lures to trick users into downloading trojanized software. This software eventually deploys an EDR-killing driver and a credential stealer named Rapuncel. We developed this hunt to help practitioners identify this chain across their environment, focusing on the transition from a user-initiated execution to kernel-level evasion.

The Hunt Flow

The hunt begins by scoping potentially infected hosts using the hb_process_activity surface. The first query looks for specific file hashes and names identified in the Talos dossier. This identifies the initial entry point where a user likely executed a lure binary disguised as a project sample or utility.

Once the hunt identifies a candidate host, it pivots to gather execution context. One query examines the parent processes of the suspicious binaries to see if they originated from browsers or messaging apps. Simultaneously, another query monitors hb_file_activity to find secondary payloads or scripts dropped by the lure, mapping the transition from the initial infection to the installer phase.

Next, the hunt investigates defense evasion by searching the hb_kernel_extension_activity surface. It looks for the loading of unsigned or invalidly signed kernel drivers. The adversary uses these drivers to terminate security processes. Because the presence of an unsigned driver on a standard workstation is highly anomalous, this provides a strong signal of intentional host blinding.

Finally, the hunt checks for the ultimate goal: credential theft. Using the hb_file_activity surface, the query looks for processes other than legitimate browsers—such as Chrome or Edge—accessing sensitive files like 'Login Data' or 'Cookies'. This phase connects the initial social engineering lure to the actual data exfiltration behavior.

Blind Spots

This hunt has two primary blind spots. First, internal telemetry cannot see the initial social media conversation or elicitation. We only see the technical results of the user clicking the link. Second, if the EDR-killer driver succeeds, it may terminate the security agent. A host that executes a lure and then stops sending all telemetry is a high-risk indicator that the adversary successfully blinded the endpoint.

In this series

Steps

  1. Scope potentially infected hosts

    Query · scoping

    Identify hosts that have executed binaries matching reported hashes or original filenames.

    reads hb_process_activitysql
    SELECT device_hostname, process_original_file_name, process_hash_sha256, COUNT(*) as execution_count FROM hb_process_activity WHERE (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3

    What a hit looks like. A list of hosts that executed known indicators. Silence proves that these specific lures did not run.

  2. Lure execution behavior

    Query · detection candidate

    Examine the launch context of the reported lures, including parents and command lines.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, parent_process_name, process_hash_sha256, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Execution events where parents like browser or messaging apps suggest social engineering delivery.

  3. File drops by lure processes

    Query · enrichment

    Identify secondary payloads or scripts dropped by the initial lure binary.

    reads hb_file_activitysql
    SELECT device_hostname, file_path, file_name, process_name, file_hash_sha256, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_filenames}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\', '')), '') || ',') > 0 AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Creation of new files by processes matching the lure list, indicating installer or dropper behavior.

  4. Early stage read

    Agent triage

    Confirm the initial execution of trojanised software before hunting follow-on stages.

  5. EDR killer driver loads

    Query · triage

    Find unsigned or suspicious drivers loading, characteristic of the Rapuncel payload.

    reads hb_kernel_extension_activitysql
    SELECT device_hostname, driver_path, driver_signature_status, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (driver_signed = 'false' OR driver_signature_status != 'Valid') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Loads of unsigned drivers; these are highly anomalous and used to blind security agents.

  6. Browser credential theft

    Query · triage

    Detect unauthorized access to browser data files by non-browser processes.

    reads hb_file_activitysql
    SELECT device_hostname, file_path, file_name, process_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{sensitive_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{known_browsers}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\', '')), '') || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Non-browser processes reading sensitive Login Data or Cookies files.

  7. Follow-on read

    Agent triage

    Synthesize the entire attack chain from lure to credential theft.

  8. Route on verdict

    Decision

    Determine whether to contain the host based on the confirmed attack chain.

  9. Isolate host

    Response action

    Halt the attack by isolating the infected endpoint.

  10. Analyst review

    Analyst task

    Verify the agent's findings and document the social engineering context.

  11. Close out

    Analyst task

    Document findings and negative results.

Coverage

Scenario coverage

StageCoveredHow, or why not
Consultancy and Job Lure
T1566
Not visible Initial social media messaging occurs off-network and is not captured in internal telemetry.
Execution of Trojanised Installer
T1204 · T1566
Yes scope-potential-infections, lure-execution-behavior, file-drops-by-lure
Kernel-Level Security Evasion
T1562.001
Yes edr-killer-driver-loads
Rapuncel Infostealing
T1555
Yes browser-credential-theft
Autonomous AI-Driven C2
T1071
Out of scope Belongs to another part of the 'Trust and the enticing consultancy offer' series.
Data Encryption and Impact
T1486
Out of scope Belongs to another part of the 'Trust and the enticing consultancy offer' series.

Blind spots

  • Needs Endpoint telemetry persistence. A host that reports the initial lure execution and then stops all telemetry is likely blinded, creating a critical blind spot. It would answer Did the driver successfully terminate the security agent?.
  • Needs Social media logs. Internal telemetry cannot see the conversation on social media; we only see the resulting malware execution. It would answer What was the content of the initial social engineering lure?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
known_browserslist[string]chrome.exe, msedge.exe, firefox.exe, brave.exeLegitimate browser processes to exclude from file-read monitoring.
lookback_daysnumber14Days of history to examine for lure execution and follow-on activity.
lure_filenameslist[string]sample.exe, secoh-qad.exe, f_000bc7.exe, kmsauto.exe, content.jsFilenames of lures reported in the Talos article.
malicious_hasheslist[hash]9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f, 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8, cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a, 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55Hashes of reported trojanised software from the dossier.
scope_hostslist[host]—Filter results to these hosts; leave empty to hunt across the entire estate.
sensitive_fileslist[string]login data, cookies, web data, local stateBrowser data files targeted by the Rapuncel infostealer.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple detection rule for these hashes is easily defeated by the attacker
  re-building the trojanised installer. This hunt correlates the specific lure behavior
  (parents, paths) with subsequent kernel-level evasion and credential theft patterns
  across multiple surfaces.
blind_spots:
- id: edr-blinding-gap
  question: Did the driver successfully terminate the security agent?
  requires: Endpoint telemetry persistence
  risk: A host that reports the initial lure execution and then stops all telemetry
    is likely blinded, creating a critical blind spot.
  stage: defense-evasion-edr-killer
- id: external-lure-blindness
  question: What was the content of the initial social engineering lure?
  requires: Social media logs
  risk: Internal telemetry cannot see the conversation on social media; we only see
    the resulting malware execution.
  stage: social-engineering-elicitation
coverage:
- blind_spot: external-lure-blindness
  reason: Initial social media messaging occurs off-network and is not captured in
    internal telemetry.
  stage: social-engineering-elicitation
  status: not_visible
- stage: trojanised-software-execution
  status: covered
  steps:
  - scope-potential-infections
  - lure-execution-behavior
  - file-drops-by-lure
- stage: defense-evasion-edr-killer
  status: covered
  steps:
  - edr-killer-driver-loads
- stage: credential-access-infostealer
  status: covered
  steps:
  - browser-credential-theft
- reason: Belongs to another part of the 'Trust and the enticing consultancy offer'
    series.
  stage: command-and-control-autonomous-ai
  status: out_of_scope
- reason: Belongs to another part of the 'Trust and the enticing consultancy offer'
    series.
  stage: impact-ransomware-encryption
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Professional social engineering lures are effective at bypassing
    technical perimeters; a phased hunt that connects human-initiated execution with
    advanced evasion and theft is required to protect high-access personnel.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker uses social engineering lures such as consultancy offers to
  trick users into running trojanised software that installs an EDR killer and steals
  credentials.
labels:
- hunt
- attack.t1566
- attack.t1204
- attack.t1562.001
- attack.t1555
- attack.t1071
name: Socially Engineered Endpoint Infection and Evasion
parameters:
  known_browsers:
    default:
    - chrome.exe
    - msedge.exe
    - firefox.exe
    - brave.exe
    description: Legitimate browser processes to exclude from file-read monitoring.
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine for lure execution and follow-on activity.
    type: number
  lure_filenames:
    default:
    - sample.exe
    - secoh-qad.exe
    - f_000bc7.exe
    - kmsauto.exe
    - content.js
    description: Filenames of lures reported in the Talos article.
    from:
      kind: article
      observed: '2026-09-24'
      ref: talos
    type: list[string]
  malicious_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
    - cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a
    - 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55
    description: Hashes of reported trojanised software from the dossier.
    from:
      kind: article
      observed: '2026-09-24'
      ref: talos
    type: list[hash]
  scope_hosts:
    default: []
    description: Filter results to these hosts; leave empty to hunt across the entire
      estate.
    type: list[host]
  sensitive_files:
    default:
    - login data
    - cookies
    - web data
    - local state
    description: Browser data files targeted by the Rapuncel infostealer.
    from:
      kind: manual
      observed: '2026-09-24'
      ref: common-browser-paths
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Prioritize technical staff, project leads, and personnel with external
  social media presence (e.g., speakers, researchers) who are high-value targets for
  consultancy lures.
references:
- name: "Talos \u2014 Trust and the enticing consultancy offer"
  url: https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/
related:
- hunt: autonomous-ai-malware-analysis
  reason: The dossier mentions CLOSEDQUORUM, which represents a separate autonomous
    AI C2 phase follow-on to initial infection.
  relation: follows
scenario:
  stages:
  - name: Consultancy and Job Lure
    observables:
    - Social media messages offering $300/hour for consultancy
    - Sparse consultant profiles with no employer footprint
    - Fake job offers requiring candidate software installation
    slug: social-engineering-elicitation
    tactic: initial-access
    techniques:
    - T1566
  - name: Execution of Trojanised Installer
    observables:
    - Fake LastPass Authenticator installers
    - SECOH-QAD.exe
    - KMSAuto.exe
    - sample.exe
    - f_000bc7.exe
    - content.js
    - Distribution via GitHub repositories
    slug: trojanised-software-execution
    tactic: execution
    techniques:
    - T1204
    - T1566
  - name: Kernel-Level Security Evasion
    observables:
    - Rapuncel kernel-level EDR killer payload
    - Disabling of remote access and alarms
    slug: defense-evasion-edr-killer
    tactic: defense-evasion
    techniques:
    - T1562.001
  - name: Rapuncel Infostealing
    observables:
    - Rapuncel stealer searching for credentials
    - Accessing protected systems via found credentials
    slug: credential-access-infostealer
    tactic: credential-access
    techniques:
    - T1555
  - name: Autonomous AI-Driven C2
    observables:
    - CLOSEDQUORUM malware binary
    - Delegation of actions to LLM panels via API calls
    - Autonomous C2 decision making
    slug: command-and-control-autonomous-ai
    tactic: command-and-control
    techniques:
    - T1071
  - name: Data Encryption and Impact
    observables:
    - Qilin ransomware incidents
    - The Gentlemen leak-site listings
    - Encryption of files and manipulation of pumping cycles in utility systems
    slug: impact-ransomware-encryption
    tactic: impact
    techniques:
    - T1486
  summary: This social engineering campaign targets technical professionals with fake
    consultancy and job offers to distribute trojanised software via platforms like
    GitHub. Successful infections deploy kernel-level EDR killers and 'Rapuncel' infostealers,
    while advanced variants utilize 'CLOSEDQUORUM' for autonomous AI-driven command-and-control
    before final ransomware deployment.
series:
  index: 1
  slug: trust-and-the-enticing-consultancy-offer
  title: Trust and the enticing consultancy offer
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Socially Engineered Endpoint Infection and Evasion

This hunt follows the attack chain from the initial human-targeted social engineering lure to the execution of local payloads. It identifies the execution of reported trojanised software, correlates it with the loading of unsigned kernel drivers designed to disable security software, and detects unauthorized access to browser credential stores. By using a phased approach, the hunt connects the initial lure to subsequent high-impact evasion and theft behaviors.

## scope-potential-infections
<!-- Scope potentially infected hosts -->
Identify hosts that have executed binaries matching reported hashes or original filenames.

```sqlite target=endpoint role=scoping params=(malicious_hashes=malicious_hashes, lure_filenames=lure_filenames, lookback_days=lookback_days)
~~~yaml
expected: A list of hosts that executed known indicators. Silence proves that these
  specific lures did not run.
reads:
- device_hostname
- process_original_file_name
- process_hash_sha256
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_original_file_name, process_hash_sha256, COUNT(*) as execution_count FROM hb_process_activity WHERE (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3
```

## initial-infection-fanout
<!-- Fan-out initial infection investigation -->
parallel:
- → lure-execution-behavior
- → file-drops-by-lure
join: → early-stage-read

## lure-execution-behavior
<!-- Lure execution behavior -->
Examine the launch context of the reported lures, including parents and command lines.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, malicious_hashes=malicious_hashes, lure_filenames=lure_filenames, lookback_days=lookback_days)
~~~yaml
expected: Execution events where parents like browser or messaging apps suggest social
  engineering delivery.
reads:
- device_hostname
- process_name
- process_original_file_name
- process_cmd_line
- parent_process_name
- process_hash_sha256
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, process_hash_sha256, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## file-drops-by-lure
<!-- File drops by lure processes -->
Identify secondary payloads or scripts dropped by the initial lure binary.

```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts, lure_filenames=lure_filenames, lookback_days=lookback_days)
~~~yaml
expected: Creation of new files by processes matching the lure list, indicating installer
  or dropper behavior.
reads:
- device_hostname
- file_path
- file_name
- process_name
- file_hash_sha256
- time
- activity_id
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, file_path, file_name, process_name, file_hash_sha256, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_filenames}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\', '')), '') || ',') > 0 AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-read
<!-- Early stage read -->
```agent target=hunter
cite: required
context:
- scope-potential-infections
- lure-execution-behavior
- file-drops-by-lure
max_iterations: 3
objective: Determine if the execution of reported lures is confirmed on the scoped
  hosts.
success_criteria: A verdict citing specific process and file events.
tools:
- endpoint
```

## follow-on-activity-fanout
<!-- Fan-out follow-on detection -->
parallel:
- → edr-killer-driver-loads
- → browser-credential-theft
join: → follow-on-read

## edr-killer-driver-loads
<!-- EDR killer driver loads -->
Find unsigned or suspicious drivers loading, characteristic of the Rapuncel payload.

```sqlite target=endpoint role=triage params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Loads of unsigned drivers; these are highly anomalous and used to blind
  security agents.
reads:
- device_hostname
- driver_path
- driver_signature_status
- driver_signed
- time
silence: not_evidence_of_absence
source: hb_kernel_extension_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, driver_path, driver_signature_status, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (driver_signed = 'false' OR driver_signature_status != 'Valid') AND time >= datetime('now', '-{{lookback_days}} days')
```

## browser-credential-theft
<!-- Browser credential theft -->
Detect unauthorized access to browser data files by non-browser processes.

```sqlite target=endpoint role=triage params=(scope_hosts=scope_hosts, sensitive_files=sensitive_files, known_browsers=known_browsers, lookback_days=lookback_days)
~~~yaml
expected: Non-browser processes reading sensitive Login Data or Cookies files.
reads:
- device_hostname
- file_path
- file_name
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, file_path, file_name, process_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{sensitive_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{known_browsers}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\', '')), '') || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## follow-on-read
<!-- Follow-on read -->
```agent target=hunter
cite: required
context:
- early-stage-read
- edr-killer-driver-loads
- browser-credential-theft
max_iterations: 4
objective: Assess the relationship between initial infection (from early-stage-read)
  and the observed driver loads or credential access events.
success_criteria: A final verdict identifying compromised hosts with multiple stage
  hits.
tools:
- endpoint
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the verdict is malicious for at least one host demonstrating multiple stages of the attack chain" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: edr-blinding-gap)
else: → close-out

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and notify the user's manager of a potential social engineering incident.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the process and kernel driver evidence. Interview the user to confirm the social media lure source and timing.
```
→ end

## close-out
<!-- Close out -->
```manual target=analyst
Log the negative results and confirm if any scoped hosts failed to report telemetry during the window.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.