Huntbase Hub · All hunts

Initial Access threat hunts

230 hunts covering initial access, each with a hypothesis, the queries that test it and what the hunt cannot see.

230 hunts

  1. medium
    Research by Huntress

    Shadow AI Usage and Prompt Injection Exposure

    Employees are bypassing corporate AI controls by using personal accounts to process sensitive documents, or external attackers are exploiting public-facing AI applications to extract internal data.

    4 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  2. high
    Research by Huntress

    VPN Entry and Identity Harvest

    An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · exfiltration · impact
  3. high Part 2 of 2
    Research by Huntress

    Cloud Identity Hijacking and Mailbox Persistence

    An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  4. high Part 1 of 2
    Research by Huntress

    Endpoint Social Engineering and Malicious Execution

    An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  5. high Part 2 of 2
    Research by Sekoia

    ShinyHunters Cloud Exfiltration and Ransomware

    An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · impact
  6. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  7. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  8. high
    Research by Microsoft

    Identity-Led Intrusion and Ransomware Impact

    An adversary has compromised a government identity via phishing, leveraged valid accounts to harvest credentials, and is now encrypting files for impact.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  9. critical
    Research by Cisco Talos

    NetScaler exploitation and RMM-driven ransomware

    An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  10. high
    Research by Rapid7

    Cisco SD-WAN Manager API Authentication Bypass

    An attacker is bypassing authentication on an internet-exposed Cisco Catalyst SD-WAN Manager by using URL-encoded characters in the j_security_check path, gaining administrative access through reserved system accounts.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-20127 · CVE-2026-20182
  11. high Part 2 of 2
    Research by Huntress

    Web Worker Discovery and Payment Data Harvesting

    An intruder is using a compromised IIS web worker to execute discovery tools and search for payment card data or database credentials.

    3 query2 analytic2 checkpoint1 action2 task
    collection · discovery · execution
  12. high Part 1 of 2
    Research by Huntress

    Web Shell Ingress and Platform Probing

    An intruder has exploited a file upload vulnerability to drop web shells in member-facing directories after probing the application boundary and brute-forcing credentials.

    3 query1 analytic1 checkpoint1 action2 task
    collection · discovery · execution
  13. medium
    Research by Rapid7

    Edge Exploitation and Cross-Campus Ransomware Impact

    An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.

    5 query2 analytic1 checkpoint1 action2 task
    impact · initial access · lateral movement
  14. medium
    Research by Microsoft

    Detection of Phishing and Agent-Driven Exfiltration

    An intruder has used a phishing attack to bypass multi-factor authentication and is now using compromised productivity applications to exfiltrate data over a C2 channel.

    3 query1 analytic1 checkpoint1 action2 task
    exfiltration · initial access
  15. high
    Research by Cisco Talos

    UAT-11587 Antino Backdoor Phased Infection and M365 C2

    An adversary is using Cloudflare-hosted stagers to deliver the Rust-compiled Antino backdoor, which then establishes persistence via Run keys and communicates using Microsoft 365 as a dead-drop C2 channel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  16. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  17. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  18. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  19. medium
    Research by Cisco Talos

    Detection of Targeted Executive Asset Compromise

    An adversary targets high-value executive assets using whaling and MFA bypass to access sensitive corporate roadmaps and financial data via stealthy living-off-the-land techniques.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · initial access
  20. high
    Research by Microsoft

    Star Blizzard RedFlick VHDX and SSH-based Malware Delivery

    An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  21. high
    Research by Unit 42

    Kubernetes Operator RBAC Abuse and Secret Theft

    A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-6389
  22. high Part 2 of 2
    Research by Microsoft

    Storm-3068 Build Pipeline Execution and Tunneling

    An adversary has modified build pipelines to execute malicious code on agents, deploying RMM tools and establishing tunnels to exfiltrate Kubernetes credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  23. high Part 1 of 2
    Research by Microsoft

    Cloud Identity Takeover and DevOps Enumeration

    An adversary hijacked a cloud identity using self-service password reset to perform automated discovery across Azure DevOps repositories and harvest Kubernetes configuration files.

    4 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · discovery
  24. high Part 1 of 2
    Research by Huntress

    ChatGPT Custom GPT ClickFix Lure and MSI Installer

    An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · initial access
  25. medium
    Research by Proofpoint

    AI-Enhanced Collaboration and Browser Attacks

    An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · initial access · persistence
  26. medium
    Research by ESET Research

    AI-Enhanced OSINT and Identity Abuse

    An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.

    5 query2 analytic1 checkpoint1 action3 task
    credential access · impact · initial access
  27. medium
    Research by ESET Research

    Exploitation of AI-Generated Vibe-Coded Applications

    An attacker is exploiting vulnerabilities in AI-generated applications—such as missing input validation or hardcoded secrets—to gain initial access, brute-force credentials, or execute code from user-writable directories.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  28. high
    Research by Sekoia

    North Korean Exploitation and Destructive Impact

    An adversary is exploiting internet-facing vulnerabilities to gain initial access before encrypting user files to generate revenue or sabotage operations.

    3 query1 analytic1 checkpoint1 action2 task
    impact · initial access
  29. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  30. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  31. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  32. medium
    Research by Rapid7

    Executive Identity Harvesting and Dark Web Abuse

    An intruder has deployed infostealer malware on a high-profile device to harvest PII and SSNs, which are subsequently traded on dark web marketplaces and used for account impersonation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · initial access
  33. high
    Research by Rapid7

    SonicWall SMA1000 Edge Appliance Exploitation

    An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-83548 · CVE-2026-83549
  34. high
    Research by Rapid7

    GitLab Critical API Exploitation

    An adversary is exploiting unauthenticated path traversal in the GitLab repository commits API to read server configuration or using insecure deserialization in Duo Chat to extract sensitive credentials.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-85706 · CVE-2026-87719
  35. medium
    Research by ESET Research

    AI-Driven Persistence and Automated Data Theft

    An adversary is using compromised AI runtimes to maintain persistence and automate the exfiltration of sensitive data to AI skill repositories.

    3 query2 analytic2 checkpoint1 action2 task
    execution · exfiltration · initial access
  36. medium Part 2 of 2
    Research by ESET Research

    EDR Impairment and Ransomware Impact

    An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  37. medium Part 1 of 2
    Research by ESET Research

    AI Agent and Social Engineering Initial Access

    An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  38. medium Part 2 of 2
    Research by Sekoia

    Cloud Runtime, Lateral Movement, and Impact

    An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.

    6 query2 analytic1 checkpoint1 action2 task
    execution · impact · initial access
  39. medium Part 1 of 2
    Research by Sekoia

    Identity Access and Exposure Investigation

    An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.

    3 query2 analytic2 checkpoint1 action2 task
    execution · impact · initial access
  40. medium
    Research by Sekoia

    Remote access and persistence via scheduled tasks

    An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.

    3 query2 analytic2 checkpoint1 action2 task
    execution · initial access · persistence
  41. medium
    Research by Cisco Talos

    Legacy System Access and Segmentation Bypass

    An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · initial access · lateral movement
  42. high
    Research by CISA

    Citrix NetScaler Zero-Day Exposure

    An attacker is exploiting zero-day remote code execution vulnerabilities in Citrix NetScaler appliances, characterized by anomalous HTTP requests to management interfaces followed by the execution of unauthorized shell commands.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-88771 · CVE-2026-88772
  43. high
    Research by Rapid7

    Windows Zero-Day Privilege Escalation and Ransomware

    Adversaries are exploiting unpatched Windows ALPC or Update Stack vulnerabilities to escalate to SYSTEM integrity and deploy ransomware, leaving traces of rare process elevations and specific link-resolution artifacts.

    4 query1 analytic1 checkpoint2 task
    CVE-2026-81963 · CVE-2026-85880
  44. high
    Research by Rapid7

    Cisco Secure Email Gateway SQLi Exploitation

    An unauthenticated attacker has exploited CVE-2026-76461 by sending a crafted email to a Cisco Secure Email Gateway, resulting in root-level command execution from a database process.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-76461
  45. high Part 2 of 2
    Research by Rapid7

    Zimbra BEC: Manufactured Reality and Manipulation

    An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-27925 · CVE-2022-37042
  46. high Part 1 of 2
    Research by Rapid7

    Exploitation of Zimbra Mail Services

    An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-27925 · CVE-2022-37042
  47. medium
    Research by Sekoia

    Contextual Investigation of Phased PowerShell Intrusions

    An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  48. high Part 2 of 2
    Research by Cisco Talos

    Obfuscated Phishing and Exfiltration in Node Environments

    An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  49. high Part 1 of 2
    Research by Cisco Talos

    Obfuscated JavaScript and Local Collection

    An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.

    5 query2 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  50. high
    Research by Cisco Talos

    AI-Integrated Malware Execution and Orchestration

    Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  51. high
    Research by Rapid7

    Citrix NetScaler Authentication Bypass and Exposure

    An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-19490
  52. high
    Research by Rapid7

    F5 BIG-IP APM OAuth RCE Exploitation

    An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-94127
  53. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  54. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  55. high
    Research by Sekoia

    Exvicy ClickFix Social Engineering and PowerShell Execution

    An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.

    4 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  56. high
    Research by Cisco Talos

    M365 Session Hijacking and Malware Execution

    An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  57. high Part 2 of 2
    Research by Cisco Talos

    SSO Takeover and Data Impact

    An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  58. high Part 1 of 2
    Research by Cisco Talos

    Infostealer execution and browser credential harvesting

    An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.

    5 query2 analytic2 checkpoint1 action2 task
    credential access · execution · impact
  59. medium Part 1 of 2
    Research by Cisco Talos

    ClickFix Browser Injection and Extension Persistence

    An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  60. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-58599 · CVE-2026-65669
  61. high Part 2 of 2
    Research by Cisco Talos

    Autonomous AI Command-and-Control and Impact

    An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  62. high Part 1 of 2
    Research by Cisco Talos

    Socially Engineered Endpoint Infection and Evasion

    An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  63. high Part 2 of 2
    Research by Huntress

    AI-Accelerated Post-Exploitation and Extortion

    An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  64. high Part 1 of 2
    Research by Huntress

    Machine-Speed Perimeter and Identity Ingress

    An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  65. high
    Research by Rapid7

    SharePoint Business Data Connectivity Service Exploitation

    An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2019-1257 · CVE-2026-55040
  66. high
    Research by Rapid7

    Unauthenticated N-central Administrator Account Creation

    An intruder has exploited a routing discrepancy between Envoy and Jetty in an N-central server to bypass authentication and create a new administrative account for persistence.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-18577 · CVE-2026-86206
  67. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  68. high
    Research by ESET Research

    SparroWocky Backdoor and FamousSparrow APT Activity

    An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · initial access
  69. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  70. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  71. high Part 2 of 2
    Research by Sekoia

    APT28 Edge Hijacking and AI-Driven Exfiltration

    An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  72. high Part 1 of 2
    Research by Sekoia

    APT28: Outlook and Print Spooler Exploitation

    An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  73. high Part 2 of 2
    Research by Cisco Talos

    Amatera Stealer and Follow-on Payloads

    An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  74. high Part 2 of 2
    Research by Cisco Talos

    Host Intrusion and Destructive Impact

    An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  75. high Part 1 of 2
    Research by Cisco Talos

    Remote access abuse and red-team implants

    An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  76. high
    Research by Rapid7

    PaperCut NG/MF Auth Bypass to RCE and Ransomware

    An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-27350 · CVE-2026-81578
  77. high Part 2 of 2
    Research by Rapid7

    DPRK CurlRAT and HAProxy Ted Interception

    An adversary has compromised the edge load balancer by installing a custom HAProxy filter and a Curl-based RAT to intercept web traffic and execute remote commands.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  78. high Part 1 of 2
    Research by Rapid7

    Linux System Daemon Trojanization and Credential Harvesting

    An adversary has established long-term persistence and credential harvesting by replacing legitimate Linux system daemons with trojanized versions that log passwords and monitor process health.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · credential access
  79. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  80. high Part 2 of 2
    Research by Rapid7

    Metasploit Lateral Movement and Native Persistence

    An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  81. high Part 1 of 2
    Research by Rapid7

    Metasploit 2026: External Recon and Web Exploitation

    An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  82. high
    Research by Sekoia

    Gamaredon Modular Espionage Chain

    An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-8088
  83. high Part 2 of 2
    Research by Cisco Talos

    Cisco FMC Vulnerability and Blockchain C2

    Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  84. high Part 1 of 2
    Research by Cisco Talos

    UAT-10820 Multi-Stage Stealer Infection Chain

    An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-20079 · CVE-2026-20316
  85. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  86. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  87. medium Part 2 of 2
    Research by Huntress

    Rogue RMM Persistence and Defense Evasion

    An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  88. medium Part 1 of 2
    Research by Huntress

    Rogue RMM Delivery via Trusted Service Phishing

    An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  89. high Part 2 of 2
    Research by Huntress

    On-Host Miner Compilation and Resource Hijacking

    An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  90. high
    Research by CISA

    Integrator Supply Chain Compromise and SCADA Data Exfiltration

    A malicious actor has pivoted from a compromised third-party integrator network into the ICS environment, searched for SCADA schematics using sensitive keywords, and staged them in archives for exfiltration.

    6 query2 analytic1 checkpoint1 action2 task
    collection · discovery · exfiltration
  91. high Part 2 of 2
    Research by Microsoft

    Node.js Backdoor and Lateral Movement

    An intruder is using a portable Node.js runtime and an obfuscated implant staged in LocalAppData to move laterally via WinRM after initial social engineering via Microsoft Teams.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  92. high Part 1 of 2
    Research by Microsoft

    IT Support Impersonation and Remote Access

    An attacker has gained interactive access by impersonating IT support via Microsoft Teams, coaxing a user into initiating an RMM session that bypasses standard perimeter controls.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  93. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  94. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  95. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  96. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  97. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  98. high Part 3 of 3
    Research by The DFIR Report

    Persistence and Exfiltration of Lunar Spider

    An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.

    4 query1 analytic1 checkpoint1 action2 task
    CVE-2020-1472
  99. high Part 3 of 3
    Research by The DFIR Report

    Apache ActiveMQ Lateral Movement and Ransomware Impact

    An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  100. high Part 1 of 3
    Research by The DFIR Report

    ActiveMQ Exploitation and Metasploit Staging

    An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  101. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  102. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  103. critical Part 2 of 2
    Research by Huntress

    Settra Ransomware Local Impact and Recovery Inhibition

    An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  104. high Part 1 of 2
    Research by Huntress

    Settra Persistence via MeshAgent and Remote Access

    An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  105. high Part 2 of 2
    Research by Huntress

    DarkMe RAT: COM Hijacking and Application Profiling

    An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-38831 · CVE-2024-21412
  106. high Part 1 of 2
    Research by Microsoft

    EvilTokens Client-Side Phishing Interaction

    An intruder has delivered an AI-tailored phishing lure that, when opened, initiates high-frequency background polling to a malicious Node.js endpoint while redirecting the user to the Microsoft device login portal.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  107. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  108. medium
    Research by Red Canary

    Correlating Proxy-Obscured Identity and Endpoint Activity

    An adversary is using multi-hop proxy infrastructure to authenticate via Okta and subsequently execute discovery commands on an endpoint, obscured by network egress to proxy relay ports.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  109. medium
    Research by Elastic Security Labs

    Rapid Identity Breakout and Exfiltration

    An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  110. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    execution · initial access · privilege escalation
  111. medium Part 2 of 2
    Research by Microsoft

    Cloud Workload Identity and Network Triage

    An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  112. medium Part 1 of 2
    Research by Microsoft

    Cloud Workload Runtime and Exploitation Behavior

    An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.

    3 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · defense evasion
  113. medium
    Research by Microsoft

    Edge AI Artifact Integrity and Data Exfiltration

    An adversary has compromised the Edge AI supply chain to poison model artifacts, then manipulated those models via prompt injection to exfiltrate sensitive weights and credentials over high-volume network channels.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  114. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  115. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  116. high
    Research by Elastic Security Labs

    AWS Cloud Identity Takeover Chain

    An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.

    5 query2 analytic1 checkpoint1 action2 task
    initial access · persistence · privilege escalation
  117. medium Part 2 of 2
    Research by Unit 42

    Endpoint Data Staging and Exfiltration

    An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.

    3 query1 analytic1 checkpoint1 action2 task
    collection · exfiltration · initial access
  118. medium Part 1 of 2
    Research by Unit 42

    Identity and Cloud Pivot from Web Exploits

    An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.

    3 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  119. high
    Research by Elastic Security Labs

    Linux Fileless and In-Memory Execution

    An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  120. high
    Research by Microsoft

    AI-Themed Social Engineering and Multi-Stage Fraud

    An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  121. high
    Research by Unit 42

    Commodity Loader and Multi-Payload PPI Activity

    An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  122. high Part 2 of 2
    Research by Huntress

    Knight Office Token Theft and Device Persistence

    An adversary has stolen Microsoft 365 session tokens via a device-code phishing flow and secured persistence by enrolling an unauthorized rogue device into the Entra ID tenant.

    3 query1 analytic1 checkpoint1 action3 task
    credential access · initial access · persistence
  123. high Part 1 of 2
    Research by Huntress

    Knight Office Phishing Delivery and Redirects

    An adversary is using Monday.com redirects and .vu landing pages to deliver Knight Office phishing lures to M365 users.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access · persistence
  124. high
    Research by Red Canary

    Entra ID Agent User Impersonation and Teams Abuse

    An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.

    3 query1 analytic1 checkpoint1 action2 task
    execution · initial access
  125. high
    Research by Huntress

    BiTB Phishing to Rogue RMM Persistence

    An adversary has used browser-in-the-browser phishing to deceive a user into installing a rogue ScreenConnect instance, which established service-based persistence and executed evasion tools to hide its activity.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  126. high
    Research by Elastic Security Labs

    Bulk Directory Discovery via AAD Graph API

    An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.

    3 query2 analytic2 checkpoint1 action2 task
    discovery · execution · initial access
  127. high Part 1 of 2
    Research by Sekoia

    ErrTraffic: WordPress Infrastructure and Backdoor Maintenance

    An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  128. critical
    Research by Volexity

    SonicWall Appliance Zero-Day Exploitation and Webshells

    An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2026-15410
  129. high
    Research by Unit 42

    SPIFFE/SPIRE Workload Identity Spoofing

    An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.

    4 query2 analytic1 checkpoint1 action3 task
    command and control · credential access · defense evasion
  130. high
    Research by CISA

    Industrial-Scale AI Model Distillation and Extraction

    China-based adversaries are using fraudulent accounts and proxy transfer stations to conduct high-volume, automated extraction of proprietary AI model capabilities through systematic distillation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  131. medium Part 2 of 2
    Research by Unit 42

    Anomalous Cloud Identity Behavior

    An adversary has compromised an administrative cloud identity and is accessing the environment through multi-hop proxies or Tor to perform discovery and initial access.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  132. medium Part 1 of 2
    Research by Unit 42

    Public app exploitation and cloud identity drift

    An adversary has exploited a public-facing application on a cloud instance to obtain its identity, which is now being used for activity that deviates from the host's established behavioral profile.

    5 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  133. high
    Research by Elastic Security Labs

    Bypass of npm Cooldown and Dependency Compromise

    An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · initial access
  134. high
    Research by Elastic Security Labs

    Obfuscated Identity and Host Access

    An adversary is using multi-hop proxies or tunnels to mask their origin during authentication to cloud identity providers, subsequently using that access to reach internal hosts and execute local commands.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  135. high Part 2 of 2
    Research by Huntress

    MacSync Binary Persistence and Application Tampering

    An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.

    5 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  136. high Part 1 of 2
    Research by Huntress

    MacSync Scripted Execution and Credential Theft

    An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.

    4 query2 analytic2 checkpoint1 action2 task
    collection · credential access · execution
  137. high Part 2 of 2
    Research by Huntress

    Malicious C2 Infrastructure Polling

    An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.

    5 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  138. high Part 1 of 2
    Research by Huntress

    Cross-Platform Malware Execution and Persistence

    An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  139. high Part 2 of 2
    Research by Huntress

    AI-Impersonation Driven Script Execution and Data Theft

    An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · initial access
  140. high Part 1 of 2
    Research by Huntress

    AI Platform Mediated Malvertising and Redirection

    An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · execution · initial access
  141. high Part 2 of 2
    Research by Huntress

    Tampered Exodus Wallet Persistence and C2

    An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  142. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  143. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  144. high Part 2 of 2
    Research by Unit 42

    Kimwolf Blockchain C2 and DDoS Impact

    IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  145. high Part 1 of 2
    Research by Unit 42

    Kimwolf ADB Propagation and Evasion

    An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · defense evasion · execution
  146. high Part 2 of 2
    Research by Unit 42

    Spring Ring: NTLM Relay and RAT C2

    An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  147. high Part 1 of 2
    Research by Unit 42

    Microsoft Teams Vishing and Malicious Payload Execution

    An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  148. high Part 3 of 3
    Research by The DFIR Report

    SystemBC C2 and WinSCP Exfiltration

    An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  149. high Part 2 of 3
    Research by The DFIR Report

    Identity-Based Lateral Movement and Credential Access

    An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  150. high Part 1 of 3
    Research by The DFIR Report

    EarthTime Trojan to Ransomware Reconnaissance

    An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  151. high
    Research by Microsoft

    IT Support Impersonation and WinRM Lateral Expansion

    An adversary has hijacked a remote-support session to execute PowerShell, use a portable Node.js runtime for C2, and expand laterally via WinRM to domain controllers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  152. medium
    Research by Elastic Security Labs

    Abuse of Trusted System Binaries for Payload Delivery

    An adversary is exploiting internet-facing applications to execute certutil.exe for proxying payload downloads, which are then launched via rare, encoded PowerShell script blocks.

    3 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · initial access
  153. medium
    Research by Microsoft

    Interaction with BEC Lookalike Infrastructure

    An employee has received a BEC email and is interacting with lookalike infrastructure to view a fake invoice or initiate a fraudulent payment.

    3 query2 analytic2 checkpoint1 action2 task
    initial access · reconnaissance · resource development
  154. high
    Research by Huntress

    Adversary Operational Workflow and AI Automation

    An adversary is operating a jump box characterized by the installation of multiple security products for research, the use of AI for phishing content generation, and high-volume session maintenance across many compromised identities.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · initial access · persistence
  155. high
    Research by Rapid7

    SharePoint Unauthenticated Remote Code Execution

    An attacker is exploiting the CVE-2026-55040 and CVE-2026-63520 chain to bypass authentication and execute arbitrary commands via the SharePoint worker process on unpatched servers.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-55040 · CVE-2026-63520
  156. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  157. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  158. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  159. medium
    Research by Huntress

    Regulated Industry Phishing and Ransomware Chain

    An adversary has breached a regulated host via a browser-delivered payload and is using multi-hop proxies to coordinate a ransomware encryption phase.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · impact · initial access
  160. medium
    Research by Red Canary

    AI-Crafted Phishing and Multi-Hop Proxies

    An adversary is using AI-generated phishing to deliver payloads that establish command-and-control via multi-hop proxy networks, disguising traffic through Tor or private relay nodes.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  161. medium
    Research by Elastic Security Labs

    Exploit and Multi-Hop Proxy C2

    An adversary has exploited a critical vulnerability on a public-facing host and is masking command-and-control traffic through a multi-hop proxy or onion routing network.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · initial access
  162. medium
    Research by Elastic Security Labs

    Phishing and Multi-hop Proxy Detection

    An adversary has gained initial access through a phishing lure and is communicating with a multi-hop proxy or ORB network to disguise command-and-control traffic.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · initial access
  163. high
    Research by Elastic Security Labs

    Automated Triage Reproduction Monitoring

    An attacker has submitted an exploit in a HackerOne report that successfully escapes the ephemeral reproduction sandbox or bypasses network egress filters during automated triage.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  164. medium
    Research by Microsoft

    Exploitation and Obfuscated C2 in the Patch Window

    An adversary has exploited a critical vulnerability in a public-facing web application during the window before patching and is using a multi-hop proxy to mask command-and-control traffic.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  165. medium
    Research by Huntress

    External Access and Proxy-Based Command and Control

    An adversary exploits unpatched internet-facing vulnerabilities or phishes users to establish multi-hop proxy C2, banking on reduced holiday staffing to delay detection and response.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · initial access
  166. high
    Research by Sekoia

    OysterLoader Multi-stage Execution and C2 Discovery

    An adversary has gained initial access via a signed MSI impersonating IT software and is executing in-memory shellcode to establish C2 and deploy ransomware or infostealers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  167. high
    Research by Red Canary

    Entra ID Assistive Agent Impersonation

    An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · exfiltration
  168. medium
    Research by Elastic Security Labs

    Threat Intelligence Lifecycle Detection

    An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · impact
  169. high
    Research by Microsoft

    Unicode-Smuggling Financial Phishing Evasion

    An adversary is using invisible Unicode tag characters to split keywords in finance-themed phishing lures, bypassing traditional email filters and redirecting victims to disposable infrastructure.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · defense evasion · initial access
  170. high Part 2 of 2
    Research by Unit 42

    AMOS Stealer C2 and Exfiltration Patterns

    An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  171. high Part 1 of 2
    Research by Unit 42

    Atomic macOS (AMOS) Stealer Activity

    An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  172. high Part 1 of 2
    Research by Mandiant

    Interactive Remote Access and Support Tool Abuse

    An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · exfiltration
  173. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  174. high
    Research by Datadog Security Labs

    Third-Party Integration OAuth Abuse and API Exfiltration

    An intruder has abused a dormant Klue integration to exfiltrate Salesforce data by leveraging compromised OAuth tokens to perform automated API harvesting.

    3 query2 analytic2 checkpoint1 action2 task
    exfiltration · initial access · persistence
  175. high Part 2 of 2
    Research by Cisco Talos

    VoidLink Lateral Scanning and Mesh C2

    An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  176. high Part 1 of 2
    Research by Cisco Talos

    VoidLink: Exploitation and Kernel-Level Implant Deployment

    An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  177. high Part 2 of 2
    Research by Cisco Talos

    Static Tundra: Cisco IOS Post-Exploitation

    An adversary has exploited legacy Smart Install services to enable TFTP servers for configuration theft or is using compromised SNMP community strings for lateral discovery within the network infrastructure.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2018-0171
  178. high Part 1 of 2
    Research by Cisco Talos

    Vulnerable Cisco Asset Exposure

    An adversary is identifying and exploiting end-of-life Cisco devices via the Smart Install feature on port 4786 to extract configuration files and establish persistence.

    3 query1 analytic1 checkpoint1 action3 task
    CVE-2018-0171
  179. high
    Research by Ossprey

    Flutter Supply Chain Build Execution

    An adversary has compromised developer and CI environments by injecting malicious Flutter packages that execute obfuscated shell scripts during native Android or iOS builds.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  180. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  181. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  182. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  183. high Part 2 of 2
    Research by Unit 42

    AI-Agentic Escalation and Infrastructure Hijacking

    An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  184. high Part 1 of 2
    Research by Unit 42

    Automated Service Infiltration and Data Harvesting

    An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  185. high
    Research by Unit 42

    Endpoint AI-Assisted Scripting and Credential Dumping

    An intruder is using AI-generated scripts with iterative naming conventions to facilitate credential dumping and proxy tunneling across target organizations in Latin America.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  186. high Part 2 of 2
    Research by The DFIR Report

    Interlock RAT C2 and RDP Lateral Movement

    An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  187. high Part 1 of 2
    Research by The DFIR Report

    Interlock RAT Endpoint Execution and Reconnaissance

    An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  188. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Deployment and Credential Access

    An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  189. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Reconnaissance and Privileged Persistence

    An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  190. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee SEO Poisoning and DLL Sideloading

    An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  191. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  192. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  193. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  194. high Part 2 of 2
    Research by Huntress

    GTA 6 Hype: RAT C2 and Data Theft

    An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  195. high Part 1 of 2
    Research by Huntress

    GTA6 Malicious Installer and Chaos Wiper Activity

    An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  196. high
    Research by Huntress

    AD RMS Master Key Extraction and Offline Decryption

    An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.

    4 query2 analytic1 checkpoint1 action2 task
    collection · credential access · discovery
  197. high Part 2 of 2
    Research by Microsoft

    Microsoft Graph and Cloud Application Exfiltration

    An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · exfiltration · initial access
  198. high
    Research by Rapid7

    Active Storage libvips Image Processing Exploitation

    An attacker is exploiting CVE-2026-66066 by uploading a MAT/HDF5 payload disguised as an image through Rails direct-upload and replaying a variation key to trigger an unauthenticated arbitrary file read or RCE via libvips.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-66066
  199. high
    Research by Datadog Security Labs

    Local Privilege Escalation via Copy-Fail Page Cache Corruption

    An unprivileged local attacker exploits CVE-2026-31431 by splicing AF_ALG crypto sockets into the page cache of sensitive system files to achieve root execution without modifying files on disk.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-31431
  200. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  201. high Part 2 of 2
    Research by Volexity

    VerdantBamboo Stolen Credential and Pivot Hunt

    An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  202. high Part 1 of 2
    Research by Volexity

    VERDANTBAMBOO Edge Appliance Post-Exploitation

    An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  203. high
    Research by Huntress

    Abused Faronics Deploy and RMM Installation

    An adversary has used a phishing lure to install a legitimately signed Faronics Deploy agent, then abused its remote script execution capabilities to deploy ScreenConnect and establish persistent access.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  204. medium Part 2 of 2
    Research by Huntress

    Endpoint Credential Harvesting and Dumping

    An adversary is harvesting credentials from local browser stores, LSASS memory, or Registry hives to facilitate lateral movement, indicated by rare processes in user-writable paths performing sensitive file or memory access.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access
  205. medium Part 1 of 2
    Research by Huntress

    Identity Authentication and Account Abuse

    An intruder is testing passwords against identity providers to gain initial access or using stolen session tokens to bypass MFA and access internal resources.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access
  206. high
    Research by CISA

    NextGen Mirth Connect Exploitation and Exfiltration

    An intruder is exploiting SQL injection or XXE vulnerabilities in NextGen Mirth Connect to exfiltrate credentials or write malicious files from the service process, typically identifiable by rare API traffic and unusual file system activity.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-78224 · CVE-2026-82578
  207. high
    Research by CISA

    Orthanc DICOM Server Vulnerability Exploitation

    An intruder exploits CVE-2026-87020 by uploading a malformed image to an authenticated session on a vulnerable Orthanc server, causing a heap overflow and process crash.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-87020
  208. high Part 2 of 2
    Research by Rapid7

    wp2shell: Endpoint RCE and Lateral Movement

    An intruder has exploited the WordPress wp2shell vulnerability to gain shell access and is now attempting to move laterally within the network via RDP or SSH using credentials compromised from the web server.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-60137 · CVE-2026-63030
  209. high Part 1 of 2
    Research by Rapid7

    WordPress Core REST API RCE (wp2shell)

    An unauthenticated attacker executes code on an internet-facing WordPress server by exploiting a logic flaw in the REST API batch endpoint to perform SQL injection and upload a malicious plugin.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-60137 · CVE-2026-63030
  210. high
    Research by Proofpoint

    TA488 OWA XSS Exploitation and OWAReaper Network Operations

    An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.

    5 query2 analytic1 checkpoint1 action3 task
    CVE-2026-42897
  211. high Part 2 of 2
    Research by Sekoia

    PureCrypter Loader and Mallox Ransomware Execution

    An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  212. high Part 1 of 2
    Research by Sekoia

    Mallox Ransomware MSSQL Authentication and Service Abuse

    An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  213. high Part 2 of 2
    Research by Sekoia

    iClickFix: NetSupport RAT Execution and Persistence

    An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  214. high Part 1 of 2
    Research by Sekoia

    iClickFix Web Redirection and Delivery

    An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  215. high Part 2 of 2
    Research by Red Canary

    Abused RMM Infrastructure and Network Patterns

    An adversary is using unauthorized remote monitoring and management (RMM) tools for command and control, detectable via rare DNS lookups to RMM domains and specific User-Agent strings.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  216. critical Part 2 of 2
    Research by Mandiant

    UNC6201 Network Evasion and C2

    An adversary is using iptables REDIRECT rules for Single Packet Authorization and DNS-over-HTTPS for command-and-control to hide ingress traffic and outbound beacons on compromised appliances.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-22769
  217. critical Part 1 of 2
    Research by Mandiant

    Dell RecoverPoint Appliance Intrusion and Persistence

    An adversary is exploiting hardcoded credentials (CVE-2026-22769) to deploy SLAYSTYLE web shells and persistent GRIMBOLT backdoors on Dell RecoverPoint for Virtual Machines appliances.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-22769
  218. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  219. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  220. high
    Research by Sekoia

    MuddyRot Custom Implant Lifecycle

    An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  221. high Part 2 of 2
    Research by Huntress

    RMM Command and Control and Redundancy

    An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  222. high Part 1 of 2
    Research by Huntress

    Rogue ScreenConnect Host Execution and Persistence

    An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  223. high Part 2 of 2
    Research by Huntress

    RMM-Driven Endpoint Lateral Movement and Masquerading

    An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  224. high Part 1 of 2
    Research by Huntress

    N-central Web Exploitation and Persistence

    An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  225. high Part 3 of 3
    Research by Microsoft

    TerminalFix Asynchronous Shell and Reverse Tunnel

    An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  226. high Part 2 of 3
    Research by Microsoft

    TerminalFix ClickFix Delivery and Automated Reconnaissance

    An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  227. high Part 2 of 2
    Research by Microsoft

    Persistent implant using repurposed update utilities

    An attacker has established persistence through a scheduled task that executes a randomized binary from a world-writable path, which then uses a legitimate update utility to communicate with Alibaba OSS infrastructure.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  228. high Part 1 of 2
    Research by Microsoft

    Counterfeit software delivery and randomized execution

    An intruder has established initial access by tricking a user into downloading a polymorphic installer from a spoofed vendor site, which then launches a masqueraded payload from a randomized directory.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  229. high Part 2 of 2
    Research by Elastic Security Labs

    Web Server Shell Execution and wp2shell Post-Exploitation

    An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030
  230. high Part 1 of 2
    Research by Elastic Security Labs

    WordPress REST API Exploitation and Plugin Staging

    An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030