Huntbase Hub · All hunts

Threat hunts for Linux

54 hunts covering Linux, each with a hypothesis, the queries that test it and what the hunt cannot see.

54 hunts

  1. high Part 2 of 2
    Research by Rapid7

    BPFDoor and AVERAT Passive Network Tunneling

    An adversary has deployed a passive BPF-based backdoor that remains dormant until triggered by specially crafted SMTP or HTTPS traffic, allowing for protocol tunneling without maintaining an open listening port.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  2. high Part 1 of 2
    Research by Rapid7

    Resident Watchdog and Masquerading on Linux Edge

    An intruder has installed persistence on a Linux appliance by using a shell script to stage binaries in /sbin, then deleting the files to leave the processes running as fileless masqueraded daemons.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  3. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  4. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  5. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  6. medium Part 2 of 2
    Research by Elastic Security Labs

    Administrative AI Configuration File Tampering

    An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.

    3 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  7. medium Part 1 of 2
    Research by Elastic Security Labs

    Automated EDR Response Action Reconciliation

    An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  8. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  9. high Part 2 of 2
    Research by Rapid7

    DPRK CurlRAT and HAProxy Ted Interception

    An adversary has compromised the edge load balancer by installing a custom HAProxy filter and a Curl-based RAT to intercept web traffic and execute remote commands.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  10. high Part 1 of 2
    Research by Rapid7

    Linux System Daemon Trojanization and Credential Harvesting

    An adversary has established long-term persistence and credential harvesting by replacing legitimate Linux system daemons with trojanized versions that log passwords and monitor process health.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · credential access
  11. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  12. high Part 2 of 2
    Research by Rapid7

    Metasploit Lateral Movement and Native Persistence

    An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  13. high Part 1 of 2
    Research by Rapid7

    Metasploit 2026: External Recon and Web Exploitation

    An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  14. high Part 2 of 2
    Research by Cisco Talos

    Cisco FMC Vulnerability and Blockchain C2

    Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  15. high Part 1 of 2
    Research by Cisco Talos

    UAT-10820 Multi-Stage Stealer Infection Chain

    An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  16. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  17. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  18. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  19. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    execution · initial access · privilege escalation
  20. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  21. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  22. high
    Research by Elastic Security Labs

    Linux Fileless and In-Memory Execution

    An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  23. high
    Research by Elastic Security Labs

    Kubernetes Service Account Abuse and Escape

    An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  24. medium
    Research by Datadog Security Labs

    Linux eBPF Rootkit Execution and Manipulation

    An intruder has deployed an eBPF rootkit that hides network connections and kernel objects by manipulating syscall returns and tampering with Netlink buffers.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution
  25. high
    Research by Unit 42

    SPIFFE/SPIRE Workload Identity Spoofing

    An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.

    4 query2 analytic1 checkpoint1 action3 task
    command and control · credential access · defense evasion
  26. high
    Research by Elastic Security Labs

    Bypass of npm Cooldown and Dependency Compromise

    An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · initial access
  27. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  28. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  29. high Part 2 of 2
    Research by Unit 42

    Kimwolf Blockchain C2 and DDoS Impact

    IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  30. high Part 1 of 2
    Research by Unit 42

    Kimwolf ADB Propagation and Evasion

    An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · defense evasion · execution
  31. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  32. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  33. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  34. medium
    Research by Elastic Security Labs

    Suspicious ingress tool transfer via native utilities

    An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.

    3 query1 analytic1 checkpoint1 action2 task
    command and control
  35. medium
    Research by Elastic Security Labs

    Threat Intelligence Lifecycle Detection

    An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · impact
  36. high
    Research by Elastic Security Labs

    Linux Local Privilege Escalation Behavior

    An intruder is exploiting a kernel vulnerability or a misconfigured SUID helper to transition from a low-privilege foothold in a writable directory to root privileges.

    4 query2 analytic1 checkpoint1 action2 task
    discovery · execution · privilege escalation
  37. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  38. high Part 2 of 2
    Research by Cisco Talos

    VoidLink Lateral Scanning and Mesh C2

    An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  39. high Part 1 of 2
    Research by Cisco Talos

    VoidLink: Exploitation and Kernel-Level Implant Deployment

    An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  40. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  41. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  42. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  43. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  44. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  45. high
    Research by Datadog Security Labs

    Local Privilege Escalation via Copy-Fail Page Cache Corruption

    An unprivileged local attacker exploits CVE-2026-31431 by splicing AF_ALG crypto sockets into the page cache of sensitive system files to achieve root execution without modifying files on disk.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-31431
  46. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  47. high Part 2 of 2
    Research by Volexity

    VerdantBamboo Stolen Credential and Pivot Hunt

    An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  48. high Part 1 of 2
    Research by Volexity

    VERDANTBAMBOO Edge Appliance Post-Exploitation

    An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  49. critical Part 2 of 2
    Research by Mandiant

    UNC6201 Network Evasion and C2

    An adversary is using iptables REDIRECT rules for Single Packet Authorization and DNS-over-HTTPS for command-and-control to hide ingress traffic and outbound beacons on compromised appliances.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-22769
  50. critical Part 1 of 2
    Research by Mandiant

    Dell RecoverPoint Appliance Intrusion and Persistence

    An adversary is exploiting hardcoded credentials (CVE-2026-22769) to deploy SLAYSTYLE web shells and persistent GRIMBOLT backdoors on Dell RecoverPoint for Virtual Machines appliances.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-22769
  51. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  52. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  53. high Part 2 of 2
    Research by Elastic Security Labs

    Web Server Shell Execution and wp2shell Post-Exploitation

    An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030
  54. high Part 1 of 2
    Research by Elastic Security Labs

    WordPress REST API Exploitation and Plugin Staging

    An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030