Persistence threat hunts
147 hunts covering persistence, each with a hypothesis, the queries that test it and what the hunt cannot see.
147 hunts
-
high Part 2 of 2Research by Rapid7
BPFDoor and AVERAT Passive Network Tunneling
An adversary has deployed a passive BPF-based backdoor that remains dormant until triggered by specially crafted SMTP or HTTPS traffic, allowing for protocol tunneling without maintaining an open listening port.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Rapid7
Resident Watchdog and Masquerading on Linux Edge
An intruder has installed persistence on a Linux appliance by using a shell script to stage binaries in /sbin, then deleting the files to leave the processes running as fileless masqueraded daemons.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Huntress
Cloud Identity Hijacking and Mailbox Persistence
An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Huntress
Endpoint Social Engineering and Malicious Execution
An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
medium Part 2 of 2Research by Cisco Talos
Unauthorized RMM and Ransomware Precursors
An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
medium Part 1 of 2Research by Cisco Talos
Cloud Identity and AI Agent Anomalies
An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.
3 query2 analytic2 checkpoint1 action2 taskcredential access · discovery · impact -
highResearch by Cisco Talos
UAT-11587 Antino Backdoor Phased Infection and M365 C2
An adversary is using Cloudflare-hosted stagers to deliver the Rust-compiled Antino backdoor, which then establishes persistence via Run keys and communicates using Microsoft 365 as a dead-drop C2 channel.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 3 of 3Research by Microsoft
Zimbra secrets theft and cluster propagation
An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-73570 -
high Part 2 of 3Research by Microsoft
Zimbra Privilege Escalation and Root Persistence
An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-73570 -
high Part 1 of 3Research by Microsoft
Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry
An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.
4 query2 analytic2 checkpoint1 action2 taskCVE-2026-73570 -
medium Part 2 of 2Research by Elastic Security Labs
Administrative AI Configuration File Tampering
An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.
3 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
medium Part 1 of 2Research by Elastic Security Labs
Automated EDR Response Action Reconciliation
An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.
5 query2 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
highResearch by Microsoft
Star Blizzard RedFlick VHDX and SSH-based Malware Delivery
An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
high Part 1 of 2Research by Huntress
ChatGPT Custom GPT ClickFix Lure and MSI Installer
An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · initial access -
mediumResearch by Proofpoint
AI-Enhanced Collaboration and Browser Attacks
An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.
5 query2 analytic1 checkpoint1 action2 taskcredential access · initial access · persistence -
mediumResearch by ESET Research
AI-Driven Persistence and Automated Data Theft
An adversary is using compromised AI runtimes to maintain persistence and automate the exfiltration of sensitive data to AI skill repositories.
3 query2 analytic2 checkpoint1 action2 taskexecution · exfiltration · initial access -
medium Part 2 of 2Research by Sekoia
Cloud Runtime, Lateral Movement, and Impact
An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.
6 query2 analytic1 checkpoint1 action2 taskexecution · impact · initial access -
medium Part 1 of 2Research by Sekoia
Identity Access and Exposure Investigation
An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.
3 query2 analytic2 checkpoint1 action2 taskexecution · impact · initial access -
mediumResearch by Sekoia
Remote access and persistence via scheduled tasks
An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.
3 query2 analytic2 checkpoint1 action2 taskexecution · initial access · persistence -
high Part 2 of 2Research by Rapid7
Zimbra BEC: Manufactured Reality and Manipulation
An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
high Part 1 of 2Research by Rapid7
Exploitation of Zimbra Mail Services
An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.
3 query1 analytic1 checkpoint1 action2 taskCVE-2022-27925 · CVE-2022-37042 -
mediumResearch by Sekoia
Contextual Investigation of Phased PowerShell Intrusions
An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Cisco Talos
Obfuscated Phishing and Exfiltration in Node Environments
An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · defense evasion · execution -
high Part 1 of 2Research by Cisco Talos
Obfuscated JavaScript and Local Collection
An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.
5 query2 analytic1 checkpoint1 action2 taskcollection · defense evasion · execution -
high Part 2 of 2Research by Rapid7
Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
high Part 1 of 2Research by Rapid7
Exploitation of Web-Facing GitLab and Langflow
An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
medium Part 1 of 2Research by Cisco Talos
ClickFix Browser Injection and Extension Persistence
An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
highResearch by Rapid7
Unauthenticated N-central Administrator Account Creation
An intruder has exploited a routing discrepancy between Envoy and Jetty in an N-central server to bypass authentication and create a new administrative account for persistence.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-18577 · CVE-2026-86206 -
highResearch by Rapid7
Metasploit Framework Exploitation and Post-Exploitation
An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-54988 · CVE-2025-66516 -
highResearch by ESET Research
SparroWocky Backdoor and FamousSparrow APT Activity
An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · initial access -
highResearch by Sekoia
Gamaredon GammaLoad Intrusion Lifecycle
An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · persistence -
high Part 2 of 2Research by Sekoia
ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Sekoia
ErrTraffic Infrastructure and Delivery Monitoring
An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Cisco Talos
Amatera Stealer and Follow-on Payloads
An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Cisco Talos
Host Intrusion and Destructive Impact
An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
high Part 1 of 2Research by Cisco Talos
Remote access abuse and red-team implants
An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
highResearch by Rapid7
PaperCut NG/MF Auth Bypass to RCE and Ransomware
An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.
5 query2 analytic1 checkpoint1 action2 taskCVE-2023-27350 · CVE-2026-81578 -
high Part 2 of 2Research by Rapid7
DPRK CurlRAT and HAProxy Ted Interception
An adversary has compromised the edge load balancer by installing a custom HAProxy filter and a Curl-based RAT to intercept web traffic and execute remote commands.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Rapid7
Linux System Daemon Trojanization and Credential Harvesting
An adversary has established long-term persistence and credential harvesting by replacing legitimate Linux system daemons with trojanized versions that log passwords and monitor process health.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Sekoia
Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration
An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 1 of 2Research by Sekoia
Gammasteel Fileless PowerShell Registry Staging
An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · discovery · execution -
high Part 2 of 2Research by Sekoia
ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration
An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-64446 -
high Part 2 of 2Research by Cisco Talos
CLOSEDQUORUM AI Payload Actions
An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Autonomous LLM Decision Loop
An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Rapid7
Metasploit Lateral Movement and Native Persistence
An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 1 of 2Research by Rapid7
Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
highResearch by Sekoia
Gamaredon Modular Espionage Chain
An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-8088 -
high Part 2 of 2Research by Cisco Talos
Cisco FMC Vulnerability and Blockchain C2
Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-20079 · CVE-2026-20316 -
high Part 1 of 2Research by Cisco Talos
UAT-10820 Multi-Stage Stealer Infection Chain
An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-20079 · CVE-2026-20316 -
medium Part 2 of 2Research by Huntress
Rogue RMM Persistence and Defense Evasion
An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
medium Part 1 of 2Research by Huntress
Rogue RMM Delivery via Trusted Service Phishing
An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
critical Part 3 of 3Research by Microsoft
Storm-2570 Data Exfiltration and Ransomware Impact
An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by Microsoft
Storm-2570 Persistent Remote Access and Discovery
An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Microsoft
Node.js Backdoor and Lateral Movement
An intruder is using a portable Node.js runtime and an obfuscated implant staged in LocalAppData to move laterally via WinRM after initial social engineering via Microsoft Teams.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Microsoft
IT Support Impersonation and Remote Access
An attacker has gained interactive access by impersonating IT support via Microsoft Teams, coaxing a user into initiating an RMM session that bypasses standard perimeter controls.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 2Research by The DFIR Report
Bumblebee Delivery and Persistence
An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · exfiltration -
high Part 3 of 3Research by The DFIR Report
Persistence and Exfiltration of Lunar Spider
An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.
4 query1 analytic1 checkpoint1 action2 taskCVE-2020-1472 -
critical Part 2 of 2Research by Huntress
Settra Ransomware Local Impact and Recovery Inhibition
An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 1 of 2Research by Huntress
Settra Persistence via MeshAgent and Remote Access
An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Huntress
DarkMe RAT: COM Hijacking and Application Profiling
An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.
5 query2 analytic1 checkpoint1 action2 taskCVE-2023-38831 · CVE-2024-21412 -
high Part 1 of 2Research by Microsoft
EvilTokens Client-Side Phishing Interaction
An intruder has delivered an AI-tailored phishing lure that, when opened, initiates high-frequency background polling to a malicious Node.js endpoint while redirecting the user to the Microsoft device login portal.
3 query1 analytic1 checkpoint1 action2 taskcollection · credential access · execution -
highResearch by Elastic Security Labs
Living off the coding agent: Tunnels and LaunchAgents
An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
highResearch by Sekoia
Gamaredon GammaLoad Multi-stage Persistence and Execution
An intruder has established persistent access using GammaLoad VBScripts that manage C2 configuration via registry keys in HKCU\Console and execute via a high-frequency task invoking an Alternate Data Stream.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
mediumResearch by Microsoft
Managed Access and Tenant Integrity
An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · persistence -
high Part 2 of 2Research by Unit 42
Appliance Persistence and Identity Abuse
An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Collaboration Platform Phishing and Execution
An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Build-Time Execution and Secret Harvesting
An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.
3 query1 analytic1 checkpoint2 taskCVE-2024-3094 -
highResearch by Elastic Security Labs
AWS Cloud Identity Takeover Chain
An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.
5 query2 analytic1 checkpoint1 action2 taskinitial access · persistence · privilege escalation -
medium Part 2 of 2Research by Unit 42
Endpoint Data Staging and Exfiltration
An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.
3 query1 analytic1 checkpoint1 action2 taskcollection · exfiltration · initial access -
medium Part 1 of 2Research by Unit 42
Identity and Cloud Pivot from Web Exploits
An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.
3 query2 analytic2 checkpoint1 action2 taskcollection · exfiltration · initial access -
highResearch by Elastic Security Labs
Linux Fileless and In-Memory Execution
An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
high Part 2 of 2Research by Huntress
Knight Office Token Theft and Device Persistence
An adversary has stolen Microsoft 365 session tokens via a device-code phishing flow and secured persistence by enrolling an unauthorized rogue device into the Entra ID tenant.
3 query1 analytic1 checkpoint1 action3 taskcredential access · initial access · persistence -
high Part 1 of 2Research by Huntress
Knight Office Phishing Delivery and Redirects
An adversary is using Monday.com redirects and .vu landing pages to deliver Knight Office phishing lures to M365 users.
3 query1 analytic1 checkpoint1 action2 taskcredential access · initial access · persistence -
highResearch by Huntress
BiTB Phishing to Rogue RMM Persistence
An adversary has used browser-in-the-browser phishing to deceive a user into installing a rogue ScreenConnect instance, which established service-based persistence and executed evasion tools to hide its activity.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
high Part 1 of 2Research by Sekoia
ErrTraffic: WordPress Infrastructure and Backdoor Maintenance
An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
criticalResearch by Volexity
SonicWall Appliance Zero-Day Exploitation and Webshells
An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.
6 query2 analytic1 checkpoint1 action2 taskCVE-2026-15410 -
high Part 2 of 2Research by Huntress
MacSync Binary Persistence and Application Tampering
An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.
5 query1 analytic1 checkpoint1 action2 taskcollection · credential access · execution -
high Part 1 of 2Research by Huntress
MacSync Scripted Execution and Credential Theft
An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.
4 query2 analytic2 checkpoint1 action2 taskcollection · credential access · execution -
high Part 2 of 2Research by Huntress
Malicious C2 Infrastructure Polling
An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.
5 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Huntress
Cross-Platform Malware Execution and Persistence
An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Huntress
AI-Impersonation Driven Script Execution and Data Theft
An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 1 of 2Research by Huntress
AI Platform Mediated Malvertising and Redirection
An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.
4 query1 analytic1 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 2 of 2Research by Huntress
Tampered Exodus Wallet Persistence and C2
An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Unit 42
ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation
An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Unit 42
ChainDrop: NPM Worm Endpoint and CI Runner Activity
An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by Unit 42
Spring Ring: NTLM Relay and RAT C2
An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 2Research by Unit 42
Microsoft Teams Vishing and Malicious Payload Execution
An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 3 of 3Research by The DFIR Report
SystemBC C2 and WinSCP Exfiltration
An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 3Research by The DFIR Report
Identity-Based Lateral Movement and Credential Access
An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by The DFIR Report
EarthTime Trojan to Ransomware Reconnaissance
An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Huntress
Adversary Operational Workflow and AI Automation
An adversary is operating a jump box characterized by the installation of multiple security products for research, the use of AI for phishing content generation, and high-volume session maintenance across many compromised identities.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · initial access · persistence -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by Unit 42
AMOS Stealer C2 and Exfiltration Patterns
An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Unit 42
Atomic macOS (AMOS) Stealer Activity
An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Proofpoint
UNK_DeadDrop Credential and Crypto Wallet Theft
A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
highResearch by Datadog Security Labs
Third-Party Integration OAuth Abuse and API Exfiltration
An intruder has abused a dormant Klue integration to exfiltrate Salesforce data by leveraging compromised OAuth tokens to perform automated API harvesting.
3 query2 analytic2 checkpoint1 action2 taskexfiltration · initial access · persistence -
high Part 2 of 2Research by Cisco Talos
VoidLink Lateral Scanning and Mesh C2
An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Cisco Talos
VoidLink: Exploitation and Kernel-Level Implant Deployment
An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 2 of 2Research by Cisco Talos
Static Tundra: Cisco IOS Post-Exploitation
An adversary has exploited legacy Smart Install services to enable TFTP servers for configuration theft or is using compromised SNMP community strings for lateral discovery within the network infrastructure.
4 query2 analytic1 checkpoint1 action2 taskCVE-2018-0171 -
high Part 1 of 2Research by Cisco Talos
Vulnerable Cisco Asset Exposure
An adversary is identifying and exploiting end-of-life Cisco devices via the Smart Install feature on port 4786 to extract configuration files and establish persistence.
3 query1 analytic1 checkpoint1 action3 taskCVE-2018-0171 -
high Part 2 of 2Research by Microsoft
AI Infrastructure Host Monetization and Persistence
An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.
6 query2 analytic1 checkpoint1 action2 taskCVE-2025-68700 · CVE-2026-24770 -
high Part 1 of 2Research by Microsoft
AI Gateway Exploitation and Data Theft
An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-68700 · CVE-2026-24770 -
high Part 2 of 2Research by Unit 42
Aeternum Decentralized C2 and Telegram Exfiltration
An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Aeternum Loader Persistence and Execution
The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · execution · exfiltration -
high Part 2 of 2Research by Unit 42
AI-Agentic Escalation and Infrastructure Hijacking
An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.
4 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
high Part 1 of 2Research by Unit 42
Automated Service Infiltration and Data Harvesting
An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.
3 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
high Part 2 of 2Research by The DFIR Report
Interlock RAT C2 and RDP Lateral Movement
An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by The DFIR Report
Interlock RAT Endpoint Execution and Reconnaissance
An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Deployment and Credential Access
An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Reconnaissance and Privileged Persistence
An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee SEO Poisoning and DLL Sideloading
An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by Microsoft
Microsoft Graph and Cloud Application Exfiltration
An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · exfiltration · initial access -
high Part 1 of 2Research by Wiz
TeamPCP Credential Validation and Discovery
An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · exfiltration -
high Part 2 of 2Research by Volexity
VerdantBamboo Stolen Credential and Pivot Hunt
An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 1 of 2Research by Volexity
VERDANTBAMBOO Edge Appliance Post-Exploitation
An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
highResearch by Huntress
Abused Faronics Deploy and RMM Installation
An adversary has used a phishing lure to install a legitimately signed Faronics Deploy agent, then abused its remote script execution capabilities to deploy ScreenConnect and establish persistent access.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
highResearch by Elastic Security Labs
KREMLIN Loader and Malicious Browser Extension Forgery
An adversary is using multi-stage JavaScript loaders to install a persistent Node.js task that sideloads malware via SentinelOne to forge browser integrity checks and install malicious extensions.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 2 of 2Research by Rapid7
wp2shell: Endpoint RCE and Lateral Movement
An intruder has exploited the WordPress wp2shell vulnerability to gain shell access and is now attempting to move laterally within the network via RDP or SSH using credentials compromised from the web server.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Rapid7
WordPress Core REST API RCE (wp2shell)
An unauthenticated attacker executes code on an internet-facing WordPress server by exploiting a logic flaw in the REST API batch endpoint to perform SQL injection and upload a malicious plugin.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
highResearch by Proofpoint
TA488 OWA XSS Exploitation and OWAReaper Network Operations
An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.
5 query2 analytic1 checkpoint1 action3 taskCVE-2026-42897 -
high Part 2 of 2Research by Sekoia
iClickFix: NetSupport RAT Execution and Persistence
An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Sekoia
iClickFix Web Redirection and Delivery
An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Red Canary
Abused RMM Infrastructure and Network Patterns
An adversary is using unauthorized remote monitoring and management (RMM) tools for command and control, detectable via rare DNS lookups to RMM domains and specific User-Agent strings.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
critical Part 2 of 2Research by Mandiant
UNC6201 Network Evasion and C2
An adversary is using iptables REDIRECT rules for Single Packet Authorization and DNS-over-HTTPS for command-and-control to hide ingress traffic and outbound beacons on compromised appliances.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-22769 -
critical Part 1 of 2Research by Mandiant
Dell RecoverPoint Appliance Intrusion and Persistence
An adversary is exploiting hardcoded credentials (CVE-2026-22769) to deploy SLAYSTYLE web shells and persistent GRIMBOLT backdoors on Dell RecoverPoint for Virtual Machines appliances.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-22769 -
high Part 2 of 3Research by Cisco Talos
UAT-10147: Host Elevation and Evasion
An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 3Research by Cisco Talos
Web Exploit and Telemetry Theft (UAT-10147)
The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
highResearch by Sekoia
MuddyRot Custom Implant Lifecycle
An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Huntress
RMM Command and Control and Redundancy
An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Huntress
Rogue ScreenConnect Host Execution and Persistence
An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 2 of 2Research by Huntress
RMM-Driven Endpoint Lateral Movement and Masquerading
An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18556 · CVE-2026-18577 -
high Part 1 of 2Research by Huntress
N-central Web Exploitation and Persistence
An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-18556 · CVE-2026-18577 -
high Part 3 of 3Research by Microsoft
TerminalFix Asynchronous Shell and Reverse Tunnel
An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 3Research by Microsoft
TerminalFix ClickFix Delivery and Automated Reconnaissance
An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 2Research by Microsoft
Persistent implant using repurposed update utilities
An attacker has established persistence through a scheduled task that executes a randomized binary from a world-writable path, which then uses a legitimate update utility to communicate with Alibaba OSS infrastructure.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 1 of 2Research by Microsoft
Counterfeit software delivery and randomized execution
An intruder has established initial access by tricking a user into downloading a polymorphic installer from a spoofed vendor site, which then launches a masqueraded payload from a randomized directory.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Elastic Security Labs
Web Server Shell Execution and wp2shell Post-Exploitation
An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Elastic Security Labs
WordPress REST API Exploitation and Plugin Staging
An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030