Huntbase Hub · All hunts

Collection threat hunts

33 hunts covering collection, each with a hypothesis, the queries that test it and what the hunt cannot see.

33 hunts

  1. medium
    Research by Huntress

    Shadow AI Usage and Prompt Injection Exposure

    Employees are bypassing corporate AI controls by using personal accounts to process sensitive documents, or external attackers are exploiting public-facing AI applications to extract internal data.

    4 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  2. high Part 2 of 2
    Research by Sekoia

    ShinyHunters Cloud Exfiltration and Ransomware

    An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · impact
  3. high Part 2 of 2
    Research by Huntress

    Web Worker Discovery and Payment Data Harvesting

    An intruder is using a compromised IIS web worker to execute discovery tools and search for payment card data or database credentials.

    3 query2 analytic2 checkpoint1 action2 task
    collection · discovery · execution
  4. high Part 1 of 2
    Research by Huntress

    Web Shell Ingress and Platform Probing

    An intruder has exploited a file upload vulnerability to drop web shells in member-facing directories after probing the application boundary and brute-forcing credentials.

    3 query1 analytic1 checkpoint1 action2 task
    collection · discovery · execution
  5. medium
    Research by Cisco Talos

    Detection of Targeted Executive Asset Compromise

    An adversary targets high-value executive assets using whaling and MFA bypass to access sensitive corporate roadmaps and financial data via stealthy living-off-the-land techniques.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · initial access
  6. high Part 2 of 2
    Research by Cisco Talos

    Obfuscated Phishing and Exfiltration in Node Environments

    An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  7. high Part 1 of 2
    Research by Cisco Talos

    Obfuscated JavaScript and Local Collection

    An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.

    5 query2 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  8. high
    Research by Sekoia

    Exvicy ClickFix Social Engineering and PowerShell Execution

    An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.

    4 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  9. medium Part 1 of 2
    Research by Cisco Talos

    ClickFix Browser Injection and Extension Persistence

    An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  10. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  11. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  12. high Part 2 of 2
    Research by Rapid7

    DPRK CurlRAT and HAProxy Ted Interception

    An adversary has compromised the edge load balancer by installing a custom HAProxy filter and a Curl-based RAT to intercept web traffic and execute remote commands.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  13. high Part 1 of 2
    Research by Rapid7

    Linux System Daemon Trojanization and Credential Harvesting

    An adversary has established long-term persistence and credential harvesting by replacing legitimate Linux system daemons with trojanized versions that log passwords and monitor process health.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · credential access
  14. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  15. high
    Research by CISA

    Integrator Supply Chain Compromise and SCADA Data Exfiltration

    A malicious actor has pivoted from a compromised third-party integrator network into the ICS environment, searched for SCADA schematics using sensitive keywords, and staged them in archives for exfiltration.

    6 query2 analytic1 checkpoint1 action2 task
    collection · discovery · exfiltration
  16. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  17. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  18. high Part 1 of 2
    Research by Microsoft

    EvilTokens Client-Side Phishing Interaction

    An intruder has delivered an AI-tailored phishing lure that, when opened, initiates high-frequency background polling to a malicious Node.js endpoint while redirecting the user to the Microsoft device login portal.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  19. medium Part 2 of 2
    Research by Unit 42

    Endpoint Data Staging and Exfiltration

    An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.

    3 query1 analytic1 checkpoint1 action2 task
    collection · exfiltration · initial access
  20. medium Part 1 of 2
    Research by Unit 42

    Identity and Cloud Pivot from Web Exploits

    An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.

    3 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  21. high Part 2 of 2
    Research by Huntress

    MacSync Binary Persistence and Application Tampering

    An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.

    5 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  22. high Part 1 of 2
    Research by Huntress

    MacSync Scripted Execution and Credential Theft

    An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.

    4 query2 analytic2 checkpoint1 action2 task
    collection · credential access · execution
  23. high Part 2 of 2
    Research by Huntress

    Malicious C2 Infrastructure Polling

    An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.

    5 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  24. high Part 1 of 2
    Research by Huntress

    Cross-Platform Malware Execution and Persistence

    An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  25. high Part 2 of 2
    Research by Unit 42

    AMOS Stealer C2 and Exfiltration Patterns

    An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  26. high Part 1 of 2
    Research by Unit 42

    Atomic macOS (AMOS) Stealer Activity

    An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  27. high Part 1 of 2
    Research by Mandiant

    Interactive Remote Access and Support Tool Abuse

    An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · exfiltration
  28. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  29. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  30. high
    Research by Huntress

    AD RMS Master Key Extraction and Offline Decryption

    An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.

    4 query2 analytic1 checkpoint1 action2 task
    collection · credential access · discovery
  31. high
    Research by Rapid7

    Active Storage libvips Image Processing Exploitation

    An attacker is exploiting CVE-2026-66066 by uploading a MAT/HDF5 payload disguised as an image through Rails direct-upload and replaying a variation key to trigger an unauthenticated arbitrary file read or RCE via libvips.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-66066
  32. high Part 2 of 2
    Research by Sekoia

    iClickFix: NetSupport RAT Execution and Persistence

    An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  33. high Part 1 of 2
    Research by Sekoia

    iClickFix Web Redirection and Delivery

    An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution