Threat hunts for GitHub
52 hunts covering GitHub, each with a hypothesis, the queries that test it and what the hunt cannot see.
52 hunts
-
high Part 2 of 2Research by Sekoia
ShinyHunters Cloud Exfiltration and Ransomware
An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.
3 query1 analytic1 checkpoint1 action2 taskcollection · credential access · impact -
highResearch by Unit 42
Kubernetes Operator RBAC Abuse and Secret Theft
A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.
3 query1 analytic1 checkpoint2 taskCVE-2026-6389 -
high Part 2 of 2Research by Rapid7
Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
high Part 1 of 2Research by Rapid7
Exploitation of Web-Facing GitLab and Langflow
An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
high Part 2 of 2Research by Cisco Talos
Autonomous AI Command-and-Control and Impact
An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Socially Engineered Endpoint Infection and Evasion
An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Rapid7
Metasploit Framework Exploitation and Post-Exploitation
An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-54988 · CVE-2025-66516 -
highResearch by ESET Research
SparroWocky Backdoor and FamousSparrow APT Activity
An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · initial access -
high Part 2 of 2Research by Sekoia
ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration
An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-64446 -
high Part 2 of 2Research by Rapid7
Metasploit Lateral Movement and Native Persistence
An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 1 of 2Research by Rapid7
Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
highResearch by Sekoia
Gamaredon Modular Espionage Chain
An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-8088 -
high Part 2 of 2Research by Microsoft
Storm-3168 Web Application Probing
An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Microsoft
Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition
A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 2Research by The DFIR Report
Bissa Scanner C2 and S3 Exfiltration
An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
high Part 1 of 2Research by The DFIR Report
Bissa Scanner Mass Exploitation and Credential Harvesting
An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
highResearch by Elastic Security Labs
Rapid Phishing and Proxy-based Exfiltration
An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · exfiltration · initial access -
medium Part 2 of 2Research by Microsoft
Cloud Workload Identity and Network Triage
An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
medium Part 1 of 2Research by Microsoft
Cloud Workload Runtime and Exploitation Behavior
An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.
3 query2 analytic2 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Unit 42
Appliance Persistence and Identity Abuse
An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Collaboration Platform Phishing and Execution
An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Build-Time Execution and Secret Harvesting
An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.
3 query1 analytic1 checkpoint2 taskCVE-2024-3094 -
highResearch by Elastic Security Labs
Linux Fileless and In-Memory Execution
An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
highResearch by Microsoft
AI-Themed Social Engineering and Multi-Stage Fraud
An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
high Part 2 of 2Research by Huntress
Malicious C2 Infrastructure Polling
An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.
5 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Huntress
Cross-Platform Malware Execution and Persistence
An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Unit 42
ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation
An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Unit 42
ChainDrop: NPM Worm Endpoint and CI Runner Activity
An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Elastic Security Labs
Suspicious ingress tool transfer via native utilities
An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.
3 query1 analytic1 checkpoint1 action2 taskcommand and control -
high Part 2 of 2Research by Proofpoint
UNK_DeadDrop Credential and Crypto Wallet Theft
A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Ossprey
Flutter Supply Chain Build Execution
An adversary has compromised developer and CI environments by injecting malicious Flutter packages that execute obfuscated shell scripts during native Android or iOS builds.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Unit 42
Aeternum Decentralized C2 and Telegram Exfiltration
An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Aeternum Loader Persistence and Execution
The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · execution · exfiltration -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by Huntress
GTA 6 Hype: RAT C2 and Data Theft
An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Huntress
GTA6 Malicious Installer and Chaos Wiper Activity
An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Wiz
TeamPCP Credential Validation and Discovery
An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · exfiltration -
highResearch by Huntress
Abused Faronics Deploy and RMM Installation
An adversary has used a phishing lure to install a legitimately signed Faronics Deploy agent, then abused its remote script execution capabilities to deploy ScreenConnect and establish persistent access.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Rapid7
wp2shell: Endpoint RCE and Lateral Movement
An intruder has exploited the WordPress wp2shell vulnerability to gain shell access and is now attempting to move laterally within the network via RDP or SSH using credentials compromised from the web server.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Rapid7
WordPress Core REST API RCE (wp2shell)
An unauthenticated attacker executes code on an internet-facing WordPress server by exploiting a logic flaw in the REST API batch endpoint to perform SQL injection and upload a malicious plugin.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
highResearch by Proofpoint
TA488 OWA XSS Exploitation and OWAReaper Network Operations
An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.
5 query2 analytic1 checkpoint1 action3 taskCVE-2026-42897 -
highResearch by Sekoia
MuddyRot Custom Implant Lifecycle
An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Elastic Security Labs
Web Server Shell Execution and wp2shell Post-Exploitation
An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Elastic Security Labs
WordPress REST API Exploitation and Plugin Staging
An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030