Huntbase Hub · All hunts

Threat hunts for VMware

6 hunts covering VMware, each with a hypothesis, the queries that test it and what the hunt cannot see.

6 hunts

  1. high Part 2 of 2
    Research by Volexity

    VerdantBamboo Stolen Credential and Pivot Hunt

    An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  2. high Part 1 of 2
    Research by Volexity

    VERDANTBAMBOO Edge Appliance Post-Exploitation

    An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  3. high Part 2 of 2
    Research by Sekoia

    PureCrypter Loader and Mallox Ransomware Execution

    An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  4. high Part 1 of 2
    Research by Sekoia

    Mallox Ransomware MSSQL Authentication and Service Abuse

    An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  5. critical Part 2 of 2
    Research by Mandiant

    UNC6201 Network Evasion and C2

    An adversary is using iptables REDIRECT rules for Single Packet Authorization and DNS-over-HTTPS for command-and-control to hide ingress traffic and outbound beacons on compromised appliances.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-22769
  6. critical Part 1 of 2
    Research by Mandiant

    Dell RecoverPoint Appliance Intrusion and Persistence

    An adversary is exploiting hardcoded credentials (CVE-2026-22769) to deploy SLAYSTYLE web shells and persistent GRIMBOLT backdoors on Dell RecoverPoint for Virtual Machines appliances.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-22769