Threat hunts for Google Cloud
15 hunts covering Google Cloud, each with a hypothesis, the queries that test it and what the hunt cannot see.
15 hunts
-
medium Part 1 of 2Research by Cisco Talos
ClickFix Browser Injection and Extension Persistence
An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by The DFIR Report
Bissa Scanner C2 and S3 Exfiltration
An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
high Part 1 of 2Research by The DFIR Report
Bissa Scanner Mass Exploitation and Credential Harvesting
An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
highResearch by Elastic Security Labs
Rapid Phishing and Proxy-based Exfiltration
An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · exfiltration · initial access -
medium Part 2 of 2Research by Microsoft
Cloud Workload Identity and Network Triage
An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
medium Part 1 of 2Research by Microsoft
Cloud Workload Runtime and Exploitation Behavior
An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.
3 query2 analytic2 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Elastic Security Labs
Suspicious ingress tool transfer via native utilities
An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.
3 query1 analytic1 checkpoint1 action2 taskcommand and control -
highResearch by Elastic Security Labs
Automated Triage Reproduction Monitoring
An attacker has submitted an exploit in a HackerOne report that successfully escapes the ephemeral reproduction sandbox or bypasses network egress filters during automated triage.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by Volexity
VerdantBamboo Stolen Credential and Pivot Hunt
An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 1 of 2Research by Volexity
VERDANTBAMBOO Edge Appliance Post-Exploitation
An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access