Defense Evasion threat hunts
81 hunts covering defense evasion, each with a hypothesis, the queries that test it and what the hunt cannot see.
81 hunts
-
high Part 2 of 2Research by Rapid7
BPFDoor and AVERAT Passive Network Tunneling
An adversary has deployed a passive BPF-based backdoor that remains dormant until triggered by specially crafted SMTP or HTTPS traffic, allowing for protocol tunneling without maintaining an open listening port.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Rapid7
Resident Watchdog and Masquerading on Linux Edge
An intruder has installed persistence on a Linux appliance by using a shell script to stage binaries in /sbin, then deleting the files to leave the processes running as fileless masqueraded daemons.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Huntress
Microsoft Defender Antivirus Exclusion Abuse
An intruder has modified Microsoft Defender exclusions to shield malicious paths from scanning and enabled stealth settings to hide these changes from local administrators.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion -
highResearch by Microsoft
Star Blizzard RedFlick VHDX and SSH-based Malware Delivery
An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
high Part 1 of 2Research by Huntress
ChatGPT Custom GPT ClickFix Lure and MSI Installer
An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · initial access -
medium Part 2 of 2Research by ESET Research
EDR Impairment and Ransomware Impact
An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.
3 query1 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
medium Part 1 of 2Research by ESET Research
AI Agent and Social Engineering Initial Access
An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.
5 query2 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
high Part 2 of 2Research by Rapid7
Zimbra BEC: Manufactured Reality and Manipulation
An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
high Part 1 of 2Research by Rapid7
Exploitation of Zimbra Mail Services
An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
high Part 2 of 2Research by Cisco Talos
Obfuscated Phishing and Exfiltration in Node Environments
An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · defense evasion · execution -
high Part 1 of 2Research by Cisco Talos
Obfuscated JavaScript and Local Collection
An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.
5 query2 analytic1 checkpoint1 action2 taskcollection · defense evasion · execution -
highResearch by Microsoft
NeedyMantis Modular Sideloading and WebSocket C2
An adversary has established long-term access by sideloading modular components into legitimate processes like Poedit or Vim, using encrypted archives staged in unusual directories to bypass detection.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Cisco Talos
AI-Integrated Malware Execution and Orchestration
Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Cisco Talos
Autonomous AI Command-and-Control and Impact
An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Socially Engineered Endpoint Infection and Evasion
An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Rapid7
Metasploit Framework Exploitation and Post-Exploitation
An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-54988 · CVE-2025-66516 -
high Part 2 of 2Research by Cisco Talos
Amatera Stealer and Follow-on Payloads
An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Rapid7
PaperCut NG/MF Auth Bypass to RCE and Ransomware
An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.
5 query2 analytic1 checkpoint1 action2 taskCVE-2023-27350 · CVE-2026-81578 -
high Part 2 of 2Research by Sekoia
Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration
An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 1 of 2Research by Sekoia
Gammasteel Fileless PowerShell Registry Staging
An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 2 of 2Research by Sekoia
ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration
An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-64446 -
high Part 2 of 2Research by Cisco Talos
CLOSEDQUORUM AI Payload Actions
An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Autonomous LLM Decision Loop
An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Cisco Talos
Cisco FMC Vulnerability and Blockchain C2
Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-20079 · CVE-2026-20316 -
high Part 1 of 2Research by Cisco Talos
UAT-10820 Multi-Stage Stealer Infection Chain
An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-20079 · CVE-2026-20316 -
medium Part 2 of 2Research by Huntress
Rogue RMM Persistence and Defense Evasion
An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
medium Part 1 of 2Research by Huntress
Rogue RMM Delivery via Trusted Service Phishing
An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
critical Part 3 of 3Research by Microsoft
Storm-2570 Data Exfiltration and Ransomware Impact
An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by Microsoft
Storm-2570 Persistent Remote Access and Discovery
An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Microsoft
Node.js Backdoor and Lateral Movement
An intruder is using a portable Node.js runtime and an obfuscated implant staged in LocalAppData to move laterally via WinRM after initial social engineering via Microsoft Teams.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Microsoft
IT Support Impersonation and Remote Access
An attacker has gained interactive access by impersonating IT support via Microsoft Teams, coaxing a user into initiating an RMM session that bypasses standard perimeter controls.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 2Research by Huntress
Sideloaded AppX OAuth Token Theft
An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.
3 query1 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
high Part 3 of 3Research by The DFIR Report
Apache ActiveMQ Lateral Movement and Ransomware Impact
An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.
3 query1 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
high Part 1 of 3Research by The DFIR Report
ActiveMQ Exploitation and Metasploit Staging
An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.
4 query2 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
critical Part 2 of 2Research by Huntress
Settra Ransomware Local Impact and Recovery Inhibition
An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 1 of 2Research by Huntress
Settra Persistence via MeshAgent and Remote Access
An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Huntress
DarkMe RAT: COM Hijacking and Application Profiling
An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.
5 query2 analytic1 checkpoint1 action2 taskCVE-2023-38831 · CVE-2024-21412 -
medium Part 2 of 2Research by Microsoft
Cloud Workload Identity and Network Triage
An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
medium Part 1 of 2Research by Microsoft
Cloud Workload Runtime and Exploitation Behavior
An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.
3 query2 analytic2 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Unit 42
Appliance Persistence and Identity Abuse
An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Collaboration Platform Phishing and Execution
An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
highResearch by Elastic Security Labs
Linux Fileless and In-Memory Execution
An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
mediumResearch by Datadog Security Labs
Linux eBPF Rootkit Execution and Manipulation
An intruder has deployed an eBPF rootkit that hides network connections and kernel objects by manipulating syscall returns and tampering with Netlink buffers.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution -
highResearch by Elastic Security Labs
Chrysalis DLL Side-Loading and Execution
An attacker has achieved code execution by placing a malicious DLL in the same directory as a legitimate Bluetooth service, exploiting the search order to side-load code and bypass standard system directory protections.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution -
highResearch by Huntress
BiTB Phishing to Rogue RMM Persistence
An adversary has used browser-in-the-browser phishing to deceive a user into installing a rogue ScreenConnect instance, which established service-based persistence and executed evasion tools to hide its activity.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
highResearch by Unit 42
SPIFFE/SPIRE Workload Identity Spoofing
An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.
4 query2 analytic1 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
highResearch by Elastic Security Labs
Bypass of npm Cooldown and Dependency Compromise
An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · initial access -
high Part 2 of 2Research by Huntress
Tampered Exodus Wallet Persistence and C2
An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Unit 42
Kimwolf Blockchain C2 and DDoS Impact
IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Unit 42
Kimwolf ADB Propagation and Evasion
An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Unit 42
Spring Ring: NTLM Relay and RAT C2
An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 2Research by Unit 42
Microsoft Teams Vishing and Malicious Payload Execution
An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 3 of 3Research by The DFIR Report
SystemBC C2 and WinSCP Exfiltration
An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 3Research by The DFIR Report
Identity-Based Lateral Movement and Credential Access
An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by The DFIR Report
EarthTime Trojan to Ransomware Reconnaissance
An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
mediumResearch by Elastic Security Labs
Abuse of Trusted System Binaries for Payload Delivery
An adversary is exploiting internet-facing applications to execute certutil.exe for proxying payload downloads, which are then launched via rare, encoded PowerShell script blocks.
3 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · initial access -
highResearch by Sekoia
OysterLoader Multi-stage Execution and C2 Discovery
An adversary has gained initial access via a signed MSI impersonating IT software and is executing in-memory shellcode to establish C2 and deploy ransomware or infostealers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Microsoft
Unicode-Smuggling Financial Phishing Evasion
An adversary is using invisible Unicode tag characters to split keywords in finance-themed phishing lures, bypassing traditional email filters and redirecting victims to disposable infrastructure.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · defense evasion · initial access -
high Part 2 of 2Research by Proofpoint
UNK_DeadDrop Credential and Crypto Wallet Theft
A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Cisco Talos
Static Tundra: Cisco IOS Post-Exploitation
An adversary has exploited legacy Smart Install services to enable TFTP servers for configuration theft or is using compromised SNMP community strings for lateral discovery within the network infrastructure.
4 query2 analytic1 checkpoint1 action2 taskCVE-2018-0171 -
high Part 1 of 2Research by Cisco Talos
Vulnerable Cisco Asset Exposure
An adversary is identifying and exploiting end-of-life Cisco devices via the Smart Install feature on port 4786 to extract configuration files and establish persistence.
3 query1 analytic1 checkpoint1 action3 taskCVE-2018-0171 -
high Part 2 of 2Research by Huntress
PaperCut NG and MF Pre-Auth RCE Exploitation
An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-81578 · CVE-2026-82078 -
highResearch by Elastic Security Labs
ClickFix DLL Sideloading and Infostealer Injection
An adversary has deployed a ClickFix script to sideload a malicious library into a signed Microsoft binary, followed by hollowing a system process to run an infostealer and using a BYOVD driver to blind endpoint security.
5 query2 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
high Part 2 of 2Research by Elastic Security Labs
REVSTEALER: Credential Theft and Follow-on Impact
An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Rapid7
Active Storage libvips Image Processing Exploitation
An attacker is exploiting CVE-2026-66066 by uploading a MAT/HDF5 payload disguised as an image through Rails direct-upload and replaying a variation key to trigger an unauthenticated arbitrary file read or RCE via libvips.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-66066 -
highResearch by Elastic Security Labs
KREMLIN Loader and Malicious Browser Extension Forgery
An adversary is using multi-stage JavaScript loaders to install a persistent Node.js task that sideloads malware via SentinelOne to forge browser integrity checks and install malicious extensions.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Sekoia
PureCrypter Loader and Mallox Ransomware Execution
An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Sekoia
Mallox Ransomware MSSQL Authentication and Service Abuse
An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 3Research by Cisco Talos
UAT-10147: Host Elevation and Evasion
An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 3Research by Cisco Talos
Web Exploit and Telemetry Theft (UAT-10147)
The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 2Research by Huntress
RMM-Driven Endpoint Lateral Movement and Masquerading
An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18556 · CVE-2026-18577 -
high Part 1 of 2Research by Huntress
N-central Web Exploitation and Persistence
An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-18556 · CVE-2026-18577 -
high Part 3 of 3Research by Microsoft
TerminalFix Asynchronous Shell and Reverse Tunnel
An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 3Research by Microsoft
TerminalFix ClickFix Delivery and Automated Reconnaissance
An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 2Research by Elastic Security Labs
Web Server Shell Execution and wp2shell Post-Exploitation
An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Elastic Security Labs
WordPress REST API Exploitation and Plugin Staging
An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030