Impact threat hunts
69 hunts covering impact, each with a hypothesis, the queries that test it and what the hunt cannot see.
69 hunts
-
highResearch by Huntress
VPN Entry and Identity Harvest
An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.
5 query2 analytic1 checkpoint1 action2 taskcredential access · exfiltration · impact -
high Part 2 of 2Research by Sekoia
ShinyHunters Cloud Exfiltration and Ransomware
An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.
3 query1 analytic1 checkpoint1 action2 taskcollection · credential access · impact -
medium Part 2 of 2Research by Cisco Talos
Unauthorized RMM and Ransomware Precursors
An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
medium Part 1 of 2Research by Cisco Talos
Cloud Identity and AI Agent Anomalies
An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.
3 query2 analytic2 checkpoint1 action2 taskcredential access · discovery · impact -
highResearch by Microsoft
Identity-Led Intrusion and Ransomware Impact
An adversary has compromised a government identity via phishing, leveraged valid accounts to harvest credentials, and is now encrypting files for impact.
5 query2 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
criticalResearch by Cisco Talos
NetScaler exploitation and RMM-driven ransomware
An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
mediumResearch by Rapid7
Edge Exploitation and Cross-Campus Ransomware Impact
An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.
5 query2 analytic1 checkpoint1 action2 taskimpact · initial access · lateral movement -
mediumResearch by ESET Research
AI-Enhanced OSINT and Identity Abuse
An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.
5 query2 analytic1 checkpoint1 action3 taskcredential access · impact · initial access -
highResearch by Sekoia
North Korean Exploitation and Destructive Impact
An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.
3 query1 analytic1 checkpoint1 action2 taskimpact · initial access -
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Exfiltration and Impact
An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Persistence and AD Credential Harvesting
An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee Delivery and C2 Establishment
An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
medium Part 2 of 2Research by ESET Research
EDR Impairment and Ransomware Impact
An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.
3 query1 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
medium Part 1 of 2Research by ESET Research
AI Agent and Social Engineering Initial Access
An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.
5 query2 analytic1 checkpoint1 action2 taskcredential access · defense evasion · execution -
medium Part 2 of 2Research by Sekoia
Cloud Runtime, Lateral Movement, and Impact
An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.
6 query2 analytic1 checkpoint1 action2 taskexecution · impact · initial access -
medium Part 1 of 2Research by Sekoia
Identity Access and Exposure Investigation
An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.
3 query2 analytic2 checkpoint1 action2 taskexecution · impact · initial access -
highResearch by Rapid7
Windows Zero-Day Privilege Escalation and Ransomware
Adversaries are exploiting unpatched Windows ALPC or Update Stack vulnerabilities to escalate to SYSTEM integrity and deploy ransomware, leaving traces of rare process elevations and specific link-resolution artifacts.
4 query1 analytic1 checkpoint2 taskCVE-2026-81963 · CVE-2026-85880 -
high Part 2 of 2Research by Rapid7
Zimbra BEC: Manufactured Reality and Manipulation
An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
high Part 1 of 2Research by Rapid7
Exploitation of Zimbra Mail Services
An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
highResearch by Cisco Talos
M365 Session Hijacking and Malware Execution
An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
high Part 2 of 2Research by Cisco Talos
SSO Takeover and Data Impact
An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.
3 query1 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
high Part 1 of 2Research by Cisco Talos
Infostealer execution and browser credential harvesting
An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.
5 query2 analytic2 checkpoint1 action2 taskcredential access · execution · impact -
high Part 2 of 2Research by Cisco Talos
Autonomous AI Command-and-Control and Impact
An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Socially Engineered Endpoint Infection and Evasion
An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Huntress
AI-Accelerated Post-Exploitation and Extortion
An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Huntress
Machine-Speed Perimeter and Identity Ingress
An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 2 of 2Research by Cisco Talos
Host Intrusion and Destructive Impact
An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
high Part 1 of 2Research by Cisco Talos
Remote access abuse and red-team implants
An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
highResearch by Rapid7
PaperCut NG/MF Auth Bypass to RCE and Ransomware
An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.
5 query2 analytic1 checkpoint1 action2 taskCVE-2023-27350 · CVE-2026-81578 -
high Part 2 of 2Research by Microsoft
Storm-3168 Web Application Probing
An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Microsoft
Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition
A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
critical Part 3 of 3Research by Microsoft
Storm-2570 Data Exfiltration and Ransomware Impact
An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by Microsoft
Storm-2570 Persistent Remote Access and Discovery
An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 2Research by The DFIR Report
Bumblebee Delivery and Persistence
An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · exfiltration -
high Part 3 of 3Research by The DFIR Report
Apache ActiveMQ Lateral Movement and Ransomware Impact
An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.
3 query1 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
high Part 1 of 3Research by The DFIR Report
ActiveMQ Exploitation and Metasploit Staging
An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.
4 query2 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
critical Part 2 of 2Research by Huntress
Settra Ransomware Local Impact and Recovery Inhibition
An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 1 of 2Research by Huntress
Settra Persistence via MeshAgent and Remote Access
An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Microsoft
AI-Themed Social Engineering and Multi-Stage Fraud
An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
mediumResearch by Elastic Security Labs
Multi-Stage Intrusion and Ransomware Triage
An adversary has established a beachhead, moved laterally to host-314, exfiltrated data via Node.js to an AI service, and initiated ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskexfiltration · impact · lateral movement -
high Part 2 of 2Research by Huntress
MacSync Binary Persistence and Application Tampering
An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.
5 query1 analytic1 checkpoint1 action2 taskcollection · credential access · execution -
high Part 1 of 2Research by Huntress
MacSync Scripted Execution and Credential Theft
An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.
4 query2 analytic2 checkpoint1 action2 taskcollection · credential access · execution -
high Part 2 of 2Research by Unit 42
Kimwolf Blockchain C2 and DDoS Impact
IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Unit 42
Kimwolf ADB Propagation and Evasion
An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Huntress
Regulated Industry Phishing and Ransomware Chain
An adversary has breached a regulated host via a browser-delivered payload and is using multi-hop proxies to coordinate a ransomware encryption phase.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · impact · initial access -
highResearch by Sekoia
OysterLoader Multi-stage Execution and C2 Discovery
An adversary has gained initial access via a signed MSI impersonating IT software and is executing in-memory shellcode to establish C2 and deploy ransomware or infostealers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
mediumResearch by Elastic Security Labs
Threat Intelligence Lifecycle Detection
An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · impact -
high Part 2 of 2Research by Microsoft
AI Infrastructure Host Monetization and Persistence
An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.
6 query2 analytic1 checkpoint1 action2 taskCVE-2025-68700 · CVE-2026-24770 -
high Part 1 of 2Research by Microsoft
AI Gateway Exploitation and Data Theft
An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-68700 · CVE-2026-24770 -
high Part 2 of 2Research by Unit 42
AI-Agentic Escalation and Infrastructure Hijacking
An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.
4 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
high Part 1 of 2Research by Unit 42
Automated Service Infiltration and Data Harvesting
An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.
3 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Deployment and Credential Access
An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Reconnaissance and Privileged Persistence
An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee SEO Poisoning and DLL Sideloading
An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by Elastic Security Labs
REVSTEALER: Credential Theft and Follow-on Impact
An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
mediumResearch by Huntress
VSS Manipulation and Lateral Movement Correlation
An attacker has moved laterally into the environment and is abusing Volume Shadow Copy Service utilities to either steal the Active Directory database or inhibit system recovery before a ransomware event.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 2 of 2Research by Huntress
GTA 6 Hype: RAT C2 and Data Theft
An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Huntress
GTA6 Malicious Installer and Chaos Wiper Activity
An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
highResearch by CISA
Orthanc DICOM Server Vulnerability Exploitation
An intruder exploits CVE-2026-87020 by uploading a malformed image to an authenticated session on a vulnerable Orthanc server, causing a heap overflow and process crash.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-87020 -
high Part 2 of 2Research by Sekoia
PureCrypter Loader and Mallox Ransomware Execution
An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Sekoia
Mallox Ransomware MSSQL Authentication and Service Abuse
An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution