Huntbase Hub · All hunts

Credential Access threat hunts

110 hunts covering credential access, each with a hypothesis, the queries that test it and what the hunt cannot see.

110 hunts

  1. high
    Research by Huntress

    VPN Entry and Identity Harvest

    An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · exfiltration · impact
  2. high Part 2 of 2
    Research by Huntress

    Cloud Identity Hijacking and Mailbox Persistence

    An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  3. high Part 1 of 2
    Research by Huntress

    Endpoint Social Engineering and Malicious Execution

    An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  4. high Part 2 of 2
    Research by Sekoia

    ShinyHunters Cloud Exfiltration and Ransomware

    An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · impact
  5. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  6. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  7. high
    Research by Microsoft

    Identity-Led Intrusion and Ransomware Impact

    An adversary has compromised a government identity via phishing, leveraged valid accounts to harvest credentials, and is now encrypting files for impact.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  8. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  9. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  10. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  11. high
    Research by Unit 42

    Kubernetes Operator RBAC Abuse and Secret Theft

    A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-6389
  12. high Part 2 of 2
    Research by Microsoft

    Storm-3068 Build Pipeline Execution and Tunneling

    An adversary has modified build pipelines to execute malicious code on agents, deploying RMM tools and establishing tunnels to exfiltrate Kubernetes credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  13. high Part 1 of 2
    Research by Microsoft

    Cloud Identity Takeover and DevOps Enumeration

    An adversary hijacked a cloud identity using self-service password reset to perform automated discovery across Azure DevOps repositories and harvest Kubernetes configuration files.

    4 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · discovery
  14. medium
    Research by Proofpoint

    AI-Enhanced Collaboration and Browser Attacks

    An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · initial access · persistence
  15. medium
    Research by ESET Research

    AI-Enhanced OSINT and Identity Abuse

    An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.

    5 query2 analytic1 checkpoint1 action3 task
    credential access · impact · initial access
  16. medium
    Research by ESET Research

    Exploitation of AI-Generated Vibe-Coded Applications

    An attacker is exploiting vulnerabilities in AI-generated applications—such as missing input validation or hardcoded secrets—to gain initial access, brute-force credentials, or execute code from user-writable directories.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  17. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  18. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  19. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  20. medium
    Research by Rapid7

    Executive Identity Harvesting and Dark Web Abuse

    An intruder has deployed infostealer malware on a high-profile device to harvest PII and SSNs, which are subsequently traded on dark web marketplaces and used for account impersonation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · initial access
  21. high
    Research by Rapid7

    SonicWall SMA1000 Edge Appliance Exploitation

    An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-83548 · CVE-2026-83549
  22. high
    Research by Rapid7

    GitLab Critical API Exploitation

    An adversary is exploiting unauthenticated path traversal in the GitLab repository commits API to read server configuration or using insecure deserialization in Duo Chat to extract sensitive credentials.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-85706 · CVE-2026-87719
  23. medium Part 2 of 2
    Research by ESET Research

    EDR Impairment and Ransomware Impact

    An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  24. medium Part 1 of 2
    Research by ESET Research

    AI Agent and Social Engineering Initial Access

    An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  25. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  26. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  27. high
    Research by Cisco Talos

    M365 Session Hijacking and Malware Execution

    An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  28. high Part 2 of 2
    Research by Cisco Talos

    SSO Takeover and Data Impact

    An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  29. high Part 1 of 2
    Research by Cisco Talos

    Infostealer execution and browser credential harvesting

    An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.

    5 query2 analytic2 checkpoint1 action2 task
    credential access · execution · impact
  30. high Part 2 of 2
    Research by Cisco Talos

    Autonomous AI Command-and-Control and Impact

    An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  31. high Part 1 of 2
    Research by Cisco Talos

    Socially Engineered Endpoint Infection and Evasion

    An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  32. high Part 2 of 2
    Research by Huntress

    AI-Accelerated Post-Exploitation and Extortion

    An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  33. high Part 1 of 2
    Research by Huntress

    Machine-Speed Perimeter and Identity Ingress

    An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  34. high
    Research by Rapid7

    Unauthenticated N-central Administrator Account Creation

    An intruder has exploited a routing discrepancy between Envoy and Jetty in an N-central server to bypass authentication and create a new administrative account for persistence.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-18577 · CVE-2026-86206
  35. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  36. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  37. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  38. high Part 2 of 2
    Research by Sekoia

    APT28 Edge Hijacking and AI-Driven Exfiltration

    An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  39. high Part 1 of 2
    Research by Sekoia

    APT28: Outlook and Print Spooler Exploitation

    An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  40. high Part 2 of 2
    Research by Cisco Talos

    Amatera Stealer and Follow-on Payloads

    An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  41. high Part 2 of 2
    Research by Rapid7

    DPRK CurlRAT and HAProxy Ted Interception

    An adversary has compromised the edge load balancer by installing a custom HAProxy filter and a Curl-based RAT to intercept web traffic and execute remote commands.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  42. high Part 1 of 2
    Research by Rapid7

    Linux System Daemon Trojanization and Credential Harvesting

    An adversary has established long-term persistence and credential harvesting by replacing legitimate Linux system daemons with trojanized versions that log passwords and monitor process health.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · credential access
  43. high Part 2 of 2
    Research by Cisco Talos

    CLOSEDQUORUM AI Payload Actions

    An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  44. high Part 1 of 2
    Research by Cisco Talos

    Autonomous LLM Decision Loop

    An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  45. high Part 2 of 2
    Research by Cisco Talos

    Cisco FMC Vulnerability and Blockchain C2

    Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  46. high Part 1 of 2
    Research by Cisco Talos

    UAT-10820 Multi-Stage Stealer Infection Chain

    An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  47. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  48. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  49. critical Part 3 of 3
    Research by Microsoft

    Storm-2570 Data Exfiltration and Ransomware Impact

    An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  50. high Part 1 of 3
    Research by Microsoft

    Storm-2570 Persistent Remote Access and Discovery

    An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  51. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  52. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  53. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  54. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  55. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  56. high Part 3 of 3
    Research by The DFIR Report

    Persistence and Exfiltration of Lunar Spider

    An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.

    4 query1 analytic1 checkpoint1 action2 task
    CVE-2020-1472
  57. high Part 3 of 3
    Research by The DFIR Report

    Apache ActiveMQ Lateral Movement and Ransomware Impact

    An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  58. high Part 1 of 3
    Research by The DFIR Report

    ActiveMQ Exploitation and Metasploit Staging

    An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  59. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  60. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  61. high Part 2 of 2
    Research by Huntress

    DarkMe RAT: COM Hijacking and Application Profiling

    An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-38831 · CVE-2024-21412
  62. high Part 1 of 2
    Research by Microsoft

    EvilTokens Client-Side Phishing Interaction

    An intruder has delivered an AI-tailored phishing lure that, when opened, initiates high-frequency background polling to a malicious Node.js endpoint while redirecting the user to the Microsoft device login portal.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  63. high
    Research by Elastic Security Labs

    Living off the coding agent: Tunnels and LaunchAgents

    An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  64. medium
    Research by Elastic Security Labs

    Endpoint-to-Cloud Phased Intrusion Hunt

    An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  65. medium Part 2 of 2
    Research by Microsoft

    Cloud Workload Identity and Network Triage

    An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  66. medium Part 1 of 2
    Research by Microsoft

    Cloud Workload Runtime and Exploitation Behavior

    An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.

    3 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · defense evasion
  67. medium
    Research by Microsoft

    Edge AI Artifact Integrity and Data Exfiltration

    An adversary has compromised the Edge AI supply chain to poison model artifacts, then manipulated those models via prompt injection to exfiltrate sensitive weights and credentials over high-volume network channels.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  68. high Part 1 of 2
    Research by Unit 42

    Build-Time Execution and Secret Harvesting

    An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.

    3 query1 analytic1 checkpoint2 task
    CVE-2024-3094
  69. high
    Research by Elastic Security Labs

    Kubernetes Service Account Abuse and Escape

    An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  70. high
    Research by Microsoft

    AI-Themed Social Engineering and Multi-Stage Fraud

    An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  71. high Part 2 of 2
    Research by Huntress

    Knight Office Token Theft and Device Persistence

    An adversary has stolen Microsoft 365 session tokens via a device-code phishing flow and secured persistence by enrolling an unauthorized rogue device into the Entra ID tenant.

    3 query1 analytic1 checkpoint1 action3 task
    credential access · initial access · persistence
  72. high Part 1 of 2
    Research by Huntress

    Knight Office Phishing Delivery and Redirects

    An adversary is using Monday.com redirects and .vu landing pages to deliver Knight Office phishing lures to M365 users.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access · persistence
  73. high Part 1 of 2
    Research by Sekoia

    ErrTraffic: WordPress Infrastructure and Backdoor Maintenance

    An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  74. critical
    Research by Volexity

    SonicWall Appliance Zero-Day Exploitation and Webshells

    An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2026-15410
  75. high
    Research by Unit 42

    SPIFFE/SPIRE Workload Identity Spoofing

    An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.

    4 query2 analytic1 checkpoint1 action3 task
    command and control · credential access · defense evasion
  76. high Part 2 of 2
    Research by Huntress

    MacSync Binary Persistence and Application Tampering

    An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.

    5 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  77. high Part 1 of 2
    Research by Huntress

    MacSync Scripted Execution and Credential Theft

    An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.

    4 query2 analytic2 checkpoint1 action2 task
    collection · credential access · execution
  78. high Part 2 of 2
    Research by Huntress

    AI-Impersonation Driven Script Execution and Data Theft

    An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · initial access
  79. high Part 1 of 2
    Research by Huntress

    AI Platform Mediated Malvertising and Redirection

    An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · execution · initial access
  80. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  81. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  82. high Part 3 of 3
    Research by The DFIR Report

    SystemBC C2 and WinSCP Exfiltration

    An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  83. high Part 2 of 3
    Research by The DFIR Report

    Identity-Based Lateral Movement and Credential Access

    An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  84. high Part 1 of 3
    Research by The DFIR Report

    EarthTime Trojan to Ransomware Reconnaissance

    An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  85. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  86. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  87. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  88. high
    Research by Red Canary

    Entra ID Assistive Agent Impersonation

    An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · exfiltration
  89. medium
    Research by Elastic Security Labs

    Threat Intelligence Lifecycle Detection

    An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · impact
  90. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  91. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  92. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  93. high
    Research by Unit 42

    D2IP Malware and Obfuscated HTTP Exfiltration

    An adversary is using hard-coded IP addresses and malformed HTTP protocols to bypass DNS-based security controls, exfiltrate data, and proxy credential theft in real-time.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  94. high Part 2 of 2
    Research by Unit 42

    AI-Agentic Escalation and Infrastructure Hijacking

    An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  95. high Part 1 of 2
    Research by Unit 42

    Automated Service Infiltration and Data Harvesting

    An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  96. high
    Research by Unit 42

    Endpoint AI-Assisted Scripting and Credential Dumping

    An intruder is using AI-generated scripts with iterative naming conventions to facilitate credential dumping and proxy tunneling across target organizations in Latin America.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  97. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Deployment and Credential Access

    An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  98. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Reconnaissance and Privileged Persistence

    An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  99. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee SEO Poisoning and DLL Sideloading

    An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  100. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  101. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  102. high
    Research by Elastic Security Labs

    ClickFix DLL Sideloading and Infostealer Injection

    An adversary has deployed a ClickFix script to sideload a malicious library into a signed Microsoft binary, followed by hollowing a system process to run an infostealer and using a BYOVD driver to blind endpoint security.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  103. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  104. medium
    Research by Huntress

    VSS Manipulation and Lateral Movement Correlation

    An attacker has moved laterally into the environment and is abusing Volume Shadow Copy Service utilities to either steal the Active Directory database or inhibit system recovery before a ransomware event.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  105. high Part 2 of 2
    Research by Huntress

    GTA 6 Hype: RAT C2 and Data Theft

    An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  106. high Part 1 of 2
    Research by Huntress

    GTA6 Malicious Installer and Chaos Wiper Activity

    An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  107. high
    Research by Huntress

    AD RMS Master Key Extraction and Offline Decryption

    An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.

    4 query2 analytic1 checkpoint1 action2 task
    collection · credential access · discovery
  108. medium Part 2 of 2
    Research by Huntress

    Endpoint Credential Harvesting and Dumping

    An adversary is harvesting credentials from local browser stores, LSASS memory, or Registry hives to facilitate lateral movement, indicated by rare processes in user-writable paths performing sensitive file or memory access.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access
  109. medium Part 1 of 2
    Research by Huntress

    Identity Authentication and Account Abuse

    An intruder is testing passwords against identity providers to gain initial access or using stolen session tokens to bypass MFA and access internal resources.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access
  110. high Part 2 of 2
    Research by Red Canary

    Abused RMM Infrastructure and Network Patterns

    An adversary is using unauthorized remote monitoring and management (RMM) tools for command and control, detectable via rare DNS lookups to RMM domains and specific User-Agent strings.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution