Huntbase Hub · All hunts

Threat hunts for GitHub

52 hunts covering GitHub, each with a hypothesis, the queries that test it and what the hunt cannot see.

52 hunts

  1. high Part 2 of 2
    Research by Sekoia

    ShinyHunters Cloud Exfiltration and Ransomware

    An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · impact
  2. high
    Research by Unit 42

    Kubernetes Operator RBAC Abuse and Secret Theft

    A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-6389
  3. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  4. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  5. high Part 2 of 2
    Research by Cisco Talos

    Autonomous AI Command-and-Control and Impact

    An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  6. high Part 1 of 2
    Research by Cisco Talos

    Socially Engineered Endpoint Infection and Evasion

    An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  7. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  8. high
    Research by ESET Research

    SparroWocky Backdoor and FamousSparrow APT Activity

    An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · initial access
  9. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  10. high Part 2 of 2
    Research by Rapid7

    Metasploit Lateral Movement and Native Persistence

    An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  11. high Part 1 of 2
    Research by Rapid7

    Metasploit 2026: External Recon and Web Exploitation

    An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  12. high
    Research by Sekoia

    Gamaredon Modular Espionage Chain

    An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-8088
  13. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  14. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  15. high Part 2 of 2
    Research by Huntress

    On-Host Miner Compilation and Resource Hijacking

    An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  16. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  17. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  18. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  19. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  20. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  21. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  22. medium Part 2 of 2
    Research by Microsoft

    Cloud Workload Identity and Network Triage

    An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  23. medium Part 1 of 2
    Research by Microsoft

    Cloud Workload Runtime and Exploitation Behavior

    An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.

    3 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · defense evasion
  24. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  25. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  26. high Part 1 of 2
    Research by Unit 42

    Build-Time Execution and Secret Harvesting

    An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.

    3 query1 analytic1 checkpoint2 task
    CVE-2024-3094
  27. high
    Research by Elastic Security Labs

    Linux Fileless and In-Memory Execution

    An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  28. high
    Research by Microsoft

    AI-Themed Social Engineering and Multi-Stage Fraud

    An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  29. high Part 2 of 2
    Research by Huntress

    Malicious C2 Infrastructure Polling

    An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.

    5 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  30. high Part 1 of 2
    Research by Huntress

    Cross-Platform Malware Execution and Persistence

    An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  31. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  32. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  33. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  34. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  35. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  36. medium
    Research by Elastic Security Labs

    Suspicious ingress tool transfer via native utilities

    An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.

    3 query1 analytic1 checkpoint1 action2 task
    command and control
  37. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  38. high
    Research by Ossprey

    Flutter Supply Chain Build Execution

    An adversary has compromised developer and CI environments by injecting malicious Flutter packages that execute obfuscated shell scripts during native Android or iOS builds.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  39. high Part 2 of 2
    Research by Unit 42

    Aeternum Decentralized C2 and Telegram Exfiltration

    An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  40. high Part 1 of 2
    Research by Unit 42

    Aeternum Loader Persistence and Execution

    The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · exfiltration
  41. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  42. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  43. high Part 2 of 2
    Research by Huntress

    GTA 6 Hype: RAT C2 and Data Theft

    An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  44. high Part 1 of 2
    Research by Huntress

    GTA6 Malicious Installer and Chaos Wiper Activity

    An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  45. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  46. high
    Research by Huntress

    Abused Faronics Deploy and RMM Installation

    An adversary has used a phishing lure to install a legitimately signed Faronics Deploy agent, then abused its remote script execution capabilities to deploy ScreenConnect and establish persistent access.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  47. high Part 2 of 2
    Research by Rapid7

    wp2shell: Endpoint RCE and Lateral Movement

    An intruder has exploited the WordPress wp2shell vulnerability to gain shell access and is now attempting to move laterally within the network via RDP or SSH using credentials compromised from the web server.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-60137 · CVE-2026-63030
  48. high Part 1 of 2
    Research by Rapid7

    WordPress Core REST API RCE (wp2shell)

    An unauthenticated attacker executes code on an internet-facing WordPress server by exploiting a logic flaw in the REST API batch endpoint to perform SQL injection and upload a malicious plugin.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-60137 · CVE-2026-63030
  49. high
    Research by Proofpoint

    TA488 OWA XSS Exploitation and OWAReaper Network Operations

    An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.

    5 query2 analytic1 checkpoint1 action3 task
    CVE-2026-42897
  50. high
    Research by Sekoia

    MuddyRot Custom Implant Lifecycle

    An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  51. high Part 2 of 2
    Research by Elastic Security Labs

    Web Server Shell Execution and wp2shell Post-Exploitation

    An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030
  52. high Part 1 of 2
    Research by Elastic Security Labs

    WordPress REST API Exploitation and Plugin Staging

    An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030