Huntbase Hub · All hunts

Exfiltration threat hunts

62 hunts covering exfiltration, each with a hypothesis, the queries that test it and what the hunt cannot see.

62 hunts

  1. medium
    Research by Huntress

    Shadow AI Usage and Prompt Injection Exposure

    Employees are bypassing corporate AI controls by using personal accounts to process sensitive documents, or external attackers are exploiting public-facing AI applications to extract internal data.

    4 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  2. high
    Research by Huntress

    VPN Entry and Identity Harvest

    An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · exfiltration · impact
  3. medium
    Research by Microsoft

    Detection of Phishing and Agent-Driven Exfiltration

    An intruder has used a phishing attack to bypass multi-factor authentication and is now using compromised productivity applications to exfiltrate data over a C2 channel.

    3 query1 analytic1 checkpoint1 action2 task
    exfiltration · initial access
  4. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  5. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  6. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  7. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  8. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  9. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  10. medium
    Research by ESET Research

    AI-Driven Persistence and Automated Data Theft

    An adversary is using compromised AI runtimes to maintain persistence and automate the exfiltration of sensitive data to AI skill repositories.

    3 query2 analytic2 checkpoint1 action2 task
    execution · exfiltration · initial access
  11. high Part 2 of 2
    Research by Cisco Talos

    Obfuscated Phishing and Exfiltration in Node Environments

    An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  12. high Part 1 of 2
    Research by Cisco Talos

    Obfuscated JavaScript and Local Collection

    An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.

    5 query2 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  13. high
    Research by ESET Research

    SparroWocky Backdoor and FamousSparrow APT Activity

    An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · initial access
  14. high
    Research by Sekoia

    Gamaredon GammaLoad Intrusion Lifecycle

    An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · persistence
  15. high Part 2 of 2
    Research by Sekoia

    APT28 Edge Hijacking and AI-Driven Exfiltration

    An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  16. high Part 1 of 2
    Research by Sekoia

    APT28: Outlook and Print Spooler Exploitation

    An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  17. high Part 2 of 2
    Research by Sekoia

    Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration

    An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  18. high Part 1 of 2
    Research by Sekoia

    Gammasteel Fileless PowerShell Registry Staging

    An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  19. high
    Research by Sekoia

    Gamaredon Modular Espionage Chain

    An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-8088
  20. critical Part 3 of 3
    Research by Microsoft

    Storm-2570 Data Exfiltration and Ransomware Impact

    An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  21. high Part 1 of 3
    Research by Microsoft

    Storm-2570 Persistent Remote Access and Discovery

    An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  22. high
    Research by CISA

    Integrator Supply Chain Compromise and SCADA Data Exfiltration

    A malicious actor has pivoted from a compromised third-party integrator network into the ICS environment, searched for SCADA schematics using sensitive keywords, and staged them in archives for exfiltration.

    6 query2 analytic1 checkpoint1 action2 task
    collection · discovery · exfiltration
  23. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  24. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  25. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  26. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  27. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  28. high Part 3 of 3
    Research by The DFIR Report

    Persistence and Exfiltration of Lunar Spider

    An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.

    4 query1 analytic1 checkpoint1 action2 task
    CVE-2020-1472
  29. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  30. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  31. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  32. medium
    Research by Elastic Security Labs

    Rapid Identity Breakout and Exfiltration

    An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  33. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  34. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  35. medium Part 2 of 2
    Research by Unit 42

    Endpoint Data Staging and Exfiltration

    An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.

    3 query1 analytic1 checkpoint1 action2 task
    collection · exfiltration · initial access
  36. medium Part 1 of 2
    Research by Unit 42

    Identity and Cloud Pivot from Web Exploits

    An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.

    3 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  37. medium
    Research by Elastic Security Labs

    Multi-Stage Intrusion and Ransomware Triage

    An adversary has established a beachhead, moved laterally to host-314, exfiltrated data via Node.js to an AI service, and initiated ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    exfiltration · impact · lateral movement
  38. high
    Research by CISA

    Industrial-Scale AI Model Distillation and Extraction

    China-based adversaries are using fraudulent accounts and proxy transfer stations to conduct high-volume, automated extraction of proprietary AI model capabilities through systematic distillation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  39. high Part 3 of 3
    Research by The DFIR Report

    SystemBC C2 and WinSCP Exfiltration

    An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  40. high Part 2 of 3
    Research by The DFIR Report

    Identity-Based Lateral Movement and Credential Access

    An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  41. high Part 1 of 3
    Research by The DFIR Report

    EarthTime Trojan to Ransomware Reconnaissance

    An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  42. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  43. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  44. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  45. high
    Research by Red Canary

    Entra ID Assistive Agent Impersonation

    An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · exfiltration
  46. high Part 1 of 2
    Research by Mandiant

    Interactive Remote Access and Support Tool Abuse

    An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · exfiltration
  47. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  48. high
    Research by Datadog Security Labs

    Third-Party Integration OAuth Abuse and API Exfiltration

    An intruder has abused a dormant Klue integration to exfiltrate Salesforce data by leveraging compromised OAuth tokens to perform automated API harvesting.

    3 query2 analytic2 checkpoint1 action2 task
    exfiltration · initial access · persistence
  49. high Part 2 of 2
    Research by Cisco Talos

    Static Tundra: Cisco IOS Post-Exploitation

    An adversary has exploited legacy Smart Install services to enable TFTP servers for configuration theft or is using compromised SNMP community strings for lateral discovery within the network infrastructure.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2018-0171
  50. high Part 1 of 2
    Research by Cisco Talos

    Vulnerable Cisco Asset Exposure

    An adversary is identifying and exploiting end-of-life Cisco devices via the Smart Install feature on port 4786 to extract configuration files and establish persistence.

    3 query1 analytic1 checkpoint1 action3 task
    CVE-2018-0171
  51. high
    Research by Unit 42

    D2IP Malware and Obfuscated HTTP Exfiltration

    An adversary is using hard-coded IP addresses and malformed HTTP protocols to bypass DNS-based security controls, exfiltrate data, and proxy credential theft in real-time.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  52. high Part 2 of 2
    Research by Unit 42

    Aeternum Decentralized C2 and Telegram Exfiltration

    An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  53. high Part 1 of 2
    Research by Unit 42

    Aeternum Loader Persistence and Execution

    The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · exfiltration
  54. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Deployment and Credential Access

    An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  55. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Reconnaissance and Privileged Persistence

    An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  56. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee SEO Poisoning and DLL Sideloading

    An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  57. high Part 2 of 2
    Research by Microsoft

    Microsoft Graph and Cloud Application Exfiltration

    An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · exfiltration · initial access
  58. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  59. high
    Research by CISA

    NextGen Mirth Connect Exploitation and Exfiltration

    An intruder is exploiting SQL injection or XXE vulnerabilities in NextGen Mirth Connect to exfiltrate credentials or write malicious files from the service process, typically identifiable by rare API traffic and unusual file system activity.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-78224 · CVE-2026-82578
  60. high
    Research by Proofpoint

    TA488 OWA XSS Exploitation and OWAReaper Network Operations

    An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.

    5 query2 analytic1 checkpoint1 action3 task
    CVE-2026-42897
  61. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  62. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery