<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>HuntPack: CrowdStrike CQL threat-hunting packs</title>
  <subtitle>Newest hunt packs. One self-contained CrowdStrike CQL playbook per threat.</subtitle>
  <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/"/>
  <link rel="self" type="application/atom+xml" href="https://slapopotamus.github.io/HuntPack/feed.xml"/>
  <id>https://slapopotamus.github.io/HuntPack/</id>
  <updated>2026-08-05T00:00:00Z</updated>
  <author><name>HuntPack</name></author>
  <entry>
    <title>DOUBLECUP — ClickFix Loader-as-a-Service</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/DOUBLECUP-ClickFix-LaaS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/DOUBLECUP-ClickFix-LaaS-Hunt.html</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <published>2026-08-05T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Steganographic browser-cache delivery, IP-keyed in-memory decryption, CountLoader 4.5p and the DeviceManager Python RAT</summary>
  </entry>
  <entry>
    <title>SMOKE#SCREEN — Fake Adobe and Zoom Updates Installing ScreenConnect RMM</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SmokeScreen-ScreenConnect-FakeUpdate-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SmokeScreen-ScreenConnect-FakeUpdate-Hunt.html</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <published>2026-08-05T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A multi-wave, multi-lure campaign that ends with a genuine ConnectWise-signed ScreenConnect agent beaconing to one of three attacker relays. Windows and macOS.</summary>
  </entry>
  <entry>
    <title>CaptiveCrunch — Storm-2945 / Midnight Blizzard captive-portal AiTM</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CaptiveCrunch-Storm2945-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CaptiveCrunch-Storm2945-Hunt.html</id>
    <updated>2026-08-04T00:00:00Z</updated>
    <published>2026-08-04T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Hospitality-network captive portals manipulated to deliver the CornFlake Go RAT and the ChocoShell PowerShell infostealer, then pivot to Microsoft 365 via Entra device code phishing.</summary>
  </entry>
  <entry>
    <title>STAC4749 — Microsoft Teams Vishing to Chaos Ransomware</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/STAC4749-TeamsVishing-Chaos-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/STAC4749-TeamsVishing-Chaos-Hunt.html</id>
    <updated>2026-08-04T00:00:00Z</updated>
    <published>2026-08-04T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Fake IT-helpdesk Teams calls into Quick Assist / RemSupp remote support, a PowerShell-staged Python and Golang implant chain, then Chaos ransomware in under 17 hours.</summary>
  </entry>
  <entry>
    <title>N-able N-central Authentication Bypass — RMM Takeover &amp; Cloudflare Tunnel Persistence</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/N-able-N-central-CVE-2026-18577-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/N-able-N-central-CVE-2026-18577-Hunt.html</id>
    <updated>2026-08-03T00:00:00Z</updated>
    <published>2026-08-03T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-18556 → CVE-2026-18577 (incomplete patch) · exploited in the wild · fixed in build 2026.3.1.7 (2026-08-02)</summary>
  </entry>
  <entry>
    <title>Joyfill npm Supply-Chain Compromise — Import-Time RAT on Developer Workstations</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Joyfill-npm-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Joyfill-npm-SupplyChain-Hunt.html</id>
    <updated>2026-08-02T00:00:00Z</updated>
    <published>2026-08-02T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Malicious 2773 beta builds of @joyfill/components and @joyfill/layouts ship a five-stage chain: obfuscated in-bundle loader → blockchain C2 resolver → two staged downloaders → Socket.IO RAT with worm-like self-propagation → Python credential stealer. The payload runs on import , so npm install --ignore-scripts does not stop it.</summary>
  </entry>
  <entry>
    <title>HollowFrame &amp; Matryoshka — Layered Loader and Nested Backdoors</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/HollowFrame-Matryoshka-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/HollowFrame-Matryoshka-Hunt.html</id>
    <updated>2026-08-01T00:00:00Z</updated>
    <published>2026-08-01T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Go-based modular loader framework delivering a two-variant Rust backdoor family via LNK phishing, Defender tampering and a chained DLL side-load. Reported by Blackpoint Cyber APG, 2026-07-30.</summary>
  </entry>
  <entry>
    <title>MacSync — Six-Stage macOS Infostealer + RAT Delivered by a Fake Claude Install Guide</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/MacSync-Stealer-macOS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/MacSync-Stealer-macOS-Hunt.html</id>
    <updated>2026-08-01T00:00:00Z</updated>
    <published>2026-08-01T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A malvertised Google Ads result pushes victims to a weaponised claude.ai/share conversation badged &quot;Shared by Apple Support&quot; that tells them to paste a curl -k … | zsh one-liner into Terminal. Six stages follow: a polymorphic zsh loader, a server-side AppleScript stealer, a native Mach-O RAT, a separately signed Screen Recording TCC helper, and in-place trojanisation of Ledger and Trezor wallet apps that phish the recovery seed phrase.</summary>
  </entry>
  <entry>
    <title>GitHub Actions Abuse Powers Distributed cPanel &amp; WHM Exploitation</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GitHubActions-cPanel-CVE-2026-41940-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GitHubActions-cPanel-CVE-2026-41940-Hunt.html</id>
    <updated>2026-07-31T00:00:00Z</updated>
    <published>2026-07-31T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Poisoned .github/workflows turn ephemeral GitHub-hosted runners into an internet-scale scanner for CVE-2026-41940, then harvest cloud, payment and source-control credentials from compromised hosting servers.</summary>
  </entry>
  <entry>
    <title>WebDAV Malware-Delivery Lab — search-ms → WebDAV → PureRAT 4.4.3</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/WebDAVDeliveryLab-SearchMS-PureRAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/WebDAVDeliveryLab-SearchMS-PureRAT-Hunt.html</id>
    <updated>2026-07-31T00:00:00Z</updated>
    <published>2026-07-31T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Fileless infostealer &amp; modular .NET RAT delivered through a phishing-triggered search-ms: URI that opens a remote WebDAV share. Documented by Rapid7 Labs from an exposed operator server (the &quot;Simba Panel&quot;), 2026-07-20.</summary>
  </entry>
  <entry>
    <title>Arista VeloCloud Orchestrator On-Prem — CVE-2026-16812</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Arista-VeloCloud-CVE-2026-16812-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Arista-VeloCloud-CVE-2026-16812-Hunt.html</id>
    <updated>2026-07-30T00:00:00Z</updated>
    <published>2026-07-30T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated OS command injection (CWE-78) in the VCO web tier, CVSS 10.0, exploited in the wild as a zero-day. CISA KEV due date 2026-07-30.</summary>
  </entry>
  <entry>
    <title>Certighost — CVE-2026-54121 · AD CS Domain-Controller Impersonation</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Certighost-CVE-2026-54121-ADCS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Certighost-CVE-2026-54121-ADCS-Hunt.html</id>
    <updated>2026-07-30T00:00:00Z</updated>
    <published>2026-07-30T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>A low-privileged domain user steers the AD CS enrollment &quot;chase&quot; at an attacker-controlled host, is issued a certificate for a Domain Controller, and DCSyncs the krbtgt secret. Behavioral hunt pack — public PoC, no published C2 infrastructure.</summary>
  </entry>
  <entry>
    <title>Cruciferra — Crypter-as-a-Service with EDR Blinding</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Cruciferra-Crypter-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Cruciferra-Crypter-Hunt.html</id>
    <updated>2026-07-29T00:00:00Z</updated>
    <published>2026-07-29T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Hunting the loader, not the customer: BYOVD EDR termination, indirect syscalls, API/IAT unhooking, COM Elevation Moniker UAC bypass, and a tweaked Process Ghosting chain shared across a dozen unrelated commodity-malware crews.</summary>
  </entry>
  <entry>
    <title>Nimbus Manticore: NightLedger backdoor and the BridgeHead / ArcBridge relay tunnelers</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/NimbusManticore-NightLedger-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/NimbusManticore-NightLedger-Hunt.html</id>
    <updated>2026-07-29T00:00:00Z</updated>
    <published>2026-07-29T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Iranian state-aligned espionage against aerospace, aviation, defence, telecom, government and financial targets across the Middle East and Africa. The implants invert the C2 direction and turn the victim endpoint into an operator relay.</summary>
  </entry>
  <entry>
    <title>AgentBaiting / FakeGit — SmartLoader to StealC via Fake AI Skills and MCP Servers</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AgentBaiting-SmartLoader-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AgentBaiting-SmartLoader-Hunt.html</id>
    <updated>2026-07-28T00:00:00Z</updated>
    <published>2026-07-28T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Roughly 7,600 malicious GitHub repositories, 800+ posing as AI Skills or Model Context Protocol servers, funnelling a LuaJIT-based loader and the StealC infostealer into developer and agent workflows.</summary>
  </entry>
  <entry>
    <title>LAUNDRY BEAR — Zero-Click Zimbra Webmail Espionage (CVE-2025-66376)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/LaundryBear-Zimbra-CVE-2025-66376-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/LaundryBear-Zimbra-CVE-2025-66376-Hunt.html</id>
    <updated>2026-07-28T00:00:00Z</updated>
    <published>2026-07-28T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Russian state-supported email collection via the Ulej / ZimReaper browser-resident stealer, DNS + HTTPS dual-channel exfiltration, and a “ZimbraWeb” app-specific password that survives a password reset.</summary>
  </entry>
  <entry>
    <title>APT42 — SpearSpecter Campaign &amp; the TAMECAT Backdoor</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/APT42-TAMECAT-SpearSpecter-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/APT42-TAMECAT-SpearSpecter-Hunt.html</id>
    <updated>2026-07-27T00:00:00Z</updated>
    <published>2026-07-27T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>IRGC-IO espionage against senior defense &amp; government officials: AI-assisted relationship phishing, search-ms/WebDAV delivery, and a fileless modular PowerShell implant with Telegram, Discord and Cloudflare Workers C2.</summary>
  </entry>
  <entry>
    <title>Golden Chickens / Venom Spider (TAG-195) — TinyEgg, ChonkyChicken &amp; ChromEggscalator</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GoldenChickens-TAG195-TinyEgg-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GoldenChickens-TAG195-TinyEgg-Hunt.html</id>
    <updated>2026-07-27T00:00:00Z</updated>
    <published>2026-07-27T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>ClickFix-delivered OCX implants executed via regsvr32, WinComCtl Run-key persistence, WebSocket C2, Chrome App-Bound-Encryption bypass and live CDP browser-session hijack.</summary>
  </entry>
  <entry>
    <title>SourTrade — Browser-Assembled Malware via Malvertising</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SourTrade-BrowserAssembled-Malvertising-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SourTrade-BrowserAssembled-Malvertising-Hunt.html</id>
    <updated>2026-07-26T00:00:00Z</updated>
    <published>2026-07-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Cloaked landing pages make the victim&#x27;s browser assemble a unique Windows PE in memory from a clean Bun runtime, so no finished malware ever crosses the network and every victim gets a different hash.</summary>
  </entry>
  <entry>
    <title>TELESHIM · MIXEDKEY · BINDCLOAK</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TELESHIM-MiddleEast-Gov-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TELESHIM-MiddleEast-Gov-Hunt.html</id>
    <updated>2026-07-26T00:00:00Z</updated>
    <published>2026-07-26T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Multi-stage DLL-sideloading intrusion set against Middle East government entities, using the Telegram Bot API as a command-and-control dead drop. East Asia-linked, unattributed.</summary>
  </entry>
  <entry>
    <title>TrickBot DNS-Tunnel Variant — Hunt Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TrickBot-DNSTunnel-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TrickBot-DNSTunnel-Hunt.html</id>
    <updated>2026-07-25T00:00:00Z</updated>
    <published>2026-07-25T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Modular Windows loader that abandons HTTP C2 for a custom DNS tunnelling transport · FortiGuard Labs, 2026-07-22</summary>
  </entry>
  <entry>
    <title>UAC-0099 — LUNCHPOKE / BURNYBEAR via Notepad++ Plugin Loading</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/UAC0099-LunchPoke-Notepad-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/UAC0099-LunchPoke-Notepad-Hunt.html</id>
    <updated>2026-07-25T00:00:00Z</updated>
    <published>2026-07-25T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A Russia-aligned cluster that has previously handed initial access to APT44 / Sandworm now ships a complete, legitimate copy of Notepad++ 8.8.3 to the victim and lets the editor&#x27;s own plugin loader run the malware. There is no exploit and no supply-chain compromise in this chain: the trust boundary being crossed is &quot;a signed application loaded a DLL that happened to be sitting in its plugins folder&quot;. Detection therefore has to live in process lineage, write location and scheduled-task shape, not in a CVE.</summary>
  </entry>
  <entry>
    <title>JadeProx — TriBack Loader, AdaptixC2 and the Beagle Backdoor</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/JadeProx-TriBack-Loader-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/JadeProx-TriBack-Loader-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-24T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>China-nexus espionage cluster running DLL-sideloading loaders against government, healthcare and education targets in South-East Asia and Latin America. Hunt, detect and harden.</summary>
  </entry>
  <entry>
    <title>wp2shell — WordPress Core Pre-Authentication RCE Chain</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/wp2shell-CVE-2026-63030-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/wp2shell-CVE-2026-63030-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-24T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-63030 (REST API batch-route confusion) chained with CVE-2026-60137 (WP_Query author__not_in SQL injection) · exploited in the wild since 2026-07-17</summary>
  </entry>
  <entry>
    <title>Chaos Ransomware · msaRAT: Living off the Browser</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ChaosMsaRAT-BrowserC2-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ChaosMsaRAT-BrowserC2-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-24T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>A Rust implant that never touches the network. It launches its own headless Chrome or Edge, drives it over the Chrome DevTools Protocol, and lets the browser carry the C2 out through Cloudflare Workers and a Twilio TURN relay.</summary>
  </entry>
  <entry>
    <title>FakeAgent — Malicious Claude Artifact → SectopRAT — Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/FakeAgent-ClaudeArtifact-SectopRAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/FakeAgent-ClaudeArtifact-SectopRAT-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-24T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Malvertising campaign documented by Huntress on 2026-07-22: a Bing sponsored ad for &quot;Claude Desktop app&quot; pointed at a malicious public Claude Artifact hosted on the legitimate claude.ai domain (7,100 views before Anthropic removed it) → redirect to a fake installer → ClaudeDesktop.exe , which is a renamed JetBrains jcef_helper.exe CEF host used purely as a DLL-sideloading vessel for a VMProtect-packed libcef.dll → second-stage IBM SPSS sslconf.exe + tempdir.dll staged in an EdgeUpdate\Install path with a GPU/DXGI anti-VM gate and a DirectX-shader AES-256-CTR decryptor → SectopRAT (ArechClient2) with EtherHiding C2 resolution off BNB Smart Chain. 29 organizations compromised 2026-07-21 to 2026-07-22. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>Interlock Ransomware — CORNFLAKE / FLUTECLICK Web-Compromise Chain</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Interlock-CORNFLAKE-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Interlock-CORNFLAKE-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-23T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>ClickFix → in-memory CORNFLAKE (Node.js persistence) → RHYSIDA-linked hands-on-keyboard → offline ntds.dit theft → Interlock ransomware &amp; extortion. GTI campaign CAMP.26.095.</summary>
  </entry>
  <entry>
    <title>Spirals Ransomware — Rapid Rust Encryptor via IIS Web Shell</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Spirals-Ransomware-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Spirals-Ransomware-Hunt.html</id>
    <updated>2026-07-23T00:00:00Z</updated>
    <published>2026-07-23T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Break-in to network-wide encryption in under 24 hours. IIS/ASP.NET web shell, redundant tunneling, PsExec-as-SYSTEM deployment.</summary>
  </entry>
  <entry>
    <title>Azure CLI ROPC Password-Spray — LSHIY Campaign (Entra ID / Microsoft 365)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AzureCLI-ROPC-PasswordSpray-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AzureCLI-ROPC-PasswordSpray-Hunt.html</id>
    <updated>2026-07-22T00:00:00Z</updated>
    <published>2026-07-22T00:00:00Z</published>
    <category term="Identity"/>
    <summary>A large-scale, automated identity password-spray campaign (reported by Huntress, surfaced 2026-07) that abuses the deprecated OAuth 2.0 Resource Owner Password Credentials (ROPC) flow via the Microsoft Azure CLI public client to validate previously-breached credential pairs against Entra ID / Microsoft 365. ROPC sends the password straight to the /token endpoint with no interactive MFA prompt , slipping past Conditional Access policies that don&#x27;t cover the ROPC / Azure-CLI path. 81M+ login attempts, 78 accounts compromised across 64 organizations. This is an identity / IdP hunt — distinct from device-code phishing. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>GoSerpent - Go-Based Espionage Backdoor &amp; Multi-Tool Chain</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GoSerpent-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GoSerpent-Hunt.html</id>
    <updated>2026-07-22T00:00:00Z</updated>
    <published>2026-07-22T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A previously undocumented Go-based backdoor and integrated toolset (GoSerpent → ThumbcacheService → Stowaway → TmcLoader/TmcPayload) used against government and diplomatic entities in Southeast Asia. Active since ~2021, evolved through 2025–2026. Disclosed by Kaspersky / Securelist on 2026-07-16; possible overlap with the TetrisPhantom actor.</summary>
  </entry>
  <entry>
    <title>Mistic Backdoor - In-Memory Windows Backdoor Masquerading as Microsoft Endpoint Security</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Mistic-Backdoor-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Mistic-Backdoor-Hunt.html</id>
    <updated>2026-07-22T00:00:00Z</updated>
    <published>2026-06-25T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Stealthy Windows backdoor masquerading as Microsoft endpoint-security tooling, deployed by ransomware initial-access broker Woodgnat / KongTuke .</summary>
  </entry>
  <entry>
    <title>Daxin + Stupig — Pre-Login SYSTEM Backdoor Hunt</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Daxin-Stupig-PreLogin-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Daxin-Stupig-PreLogin-Hunt.html</id>
    <updated>2026-07-21T00:00:00Z</updated>
    <published>2026-07-21T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>China-linked espionage resurfaces in Taiwan: a 13-year-dormant Daxin kernel rootkit alongside &quot;Stupig,&quot; a trojanized keyboard-layout DLL that runs commands as SYSTEM from the Windows logon screen — before any user signs in.</summary>
  </entry>
  <entry>
    <title>HollowGraph — Microsoft 365 Calendar as Covert C2</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/HollowGraph-M365Calendar-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/HollowGraph-M365Calendar-Hunt.html</id>
    <updated>2026-07-21T00:00:00Z</updated>
    <published>2026-07-21T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A .NET NativeAOT DLL implant that uses a compromised M365 mailbox calendar (via Graph API) as a two-way dead drop, with a DNS AAAA-record credential-refresh channel to cloudlanecdn[.]com. High-confidence code overlap with the Cavern framework; Group-IB does not confidently attribute.</summary>
  </entry>
  <entry>
    <title>GoldenEyeDog / CylindricalCanine — DigiCert EV Code-Signing Certificate Theft</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GoldenEyeDog-DigiCert-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GoldenEyeDog-DigiCert-Hunt.html</id>
    <updated>2026-07-20T00:00:00Z</updated>
    <published>2026-07-20T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Stolen DigiCert EV code-signing certificates used to sign Golden Gh0st Loader / Golden Gh0st RAT (Gh0st RAT / Farfli lineage) · disclosed 2026-07-17</summary>
  </entry>
  <entry>
    <title>UAC-0145 ClickFix Campaign — Sandworm / APT44 Sub-Cluster</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/UAC0145-ClickFix-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/UAC0145-ClickFix-Hunt.html</id>
    <updated>2026-07-20T00:00:00Z</updated>
    <published>2026-07-20T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Compromised-website fake-CAPTCHA lures delivering GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE and COWARDDUCK</summary>
  </entry>
  <entry>
    <title>Starland RAT &amp; WLDR C2 Implant — UAT-11795</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/StarlandRAT-UAT11795-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/StarlandRAT-UAT11795-Hunt.html</id>
    <updated>2026-07-19T00:00:00Z</updated>
    <published>2026-07-19T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Trojanized software installers deliver a Python RAT, a bespoke in-memory PowerShell C2 agent, CastleStealer and Remcos RAT — credential and cryptocurrency theft against US and European targets.</summary>
  </entry>
  <entry>
    <title>DEBULL — Microsoft Device-Code Phishing (Storm-2372-style Tradecraft)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/DEBULL-DeviceCodePhishing-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/DEBULL-DeviceCodePhishing-Hunt.html</id>
    <updated>2026-07-19T00:00:00Z</updated>
    <published>2026-07-19T00:00:00Z</published>
    <category term="Identity"/>
    <summary>Phishing-as-a-Service tooling that abuses the OAuth 2.0 Device Authorization Grant to take over M365 / Entra ID accounts — no password stolen, MFA bypassed.</summary>
  </entry>
  <entry>
    <title>Operation DragonReturn</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/OperationDragonReturn-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/OperationDragonReturn-Hunt.html</id>
    <updated>2026-07-19T00:00:00Z</updated>
    <published>2026-07-11T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>aka the fake Indian ITR notice / DcRAT dual-RAT campaign — Seqrite Labs named it Operation DragonReturn ; Cyderes Howler Cell and The Hacker News reported the same activity as the fake Income Tax Return notice chain. One campaign, two vendor names A signed Indian tax-utility executable side-loads nvdaHelperRemote.dll , driving a six-stage in-memory chain that injects a Gh0st/DcRAT derivative and an AsyncRAT/Quasar-family .NET implant into svchost.exe across every logged-in session, over two separate C2 channels.</summary>
  </entry>
  <entry>
    <title>ACR Stealer / Amatera — ClickFix Intrusion Chains</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ACR-Stealer-ClickFix-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ACR-Stealer-ClickFix-Hunt.html</id>
    <updated>2026-07-18T00:00:00Z</updated>
    <published>2026-07-18T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Infostealer-as-a-service delivered by ClickFix lures · WebDAV + rundll32 chain and MSHTA + steganography chain · Browser token and Microsoft 365 document theft</summary>
  </entry>
  <entry>
    <title>NadMesh Botnet — AI &amp; MCP Infrastructure Credential Hunt</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/NadMesh-Botnet-AI-Infra-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/NadMesh-Botnet-AI-Infra-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-18T00:00:00Z</published>
    <category term="Other"/>
    <summary>Go-based mesh botnet harvesting cloud keys and Kubernetes service-account tokens from exposed AI/dev services · Linux &amp; container-centric hunt pack</summary>
  </entry>
  <entry>
    <title>CVE-2026-56155 — AD FS Distributed Key Manager ACL Weakness → Golden SAML</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ADFS-CVE-2026-56155-GoldenSAML-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ADFS-CVE-2026-56155-GoldenSAML-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-17T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Over-permissive DKM container ACL lets an authorized attacker recover the AD FS token-signing key and forge SAML tokens accepted by every federated service. Actively exploited in-the-wild.</summary>
  </entry>
  <entry>
    <title>CVE-2026-58644 — Microsoft SharePoint Server Deserialization RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-58644-Deserialization-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-58644-Deserialization-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-17T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Deserialization of untrusted data (CVSS 9.8) lets a Site-Owner-authenticated attacker execute arbitrary code on on-prem SharePoint. Exploited as a zero-day; post-ex = IIS machine-key theft &amp; ViewState persistence.</summary>
  </entry>
  <entry>
    <title>MODBEACON — Silver Fox Rust In-Memory RAT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/MODBEACON-SilverFox-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/MODBEACON-SilverFox-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-16T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>China-nexus &quot;Silver Fox&quot; (SwimSnake / UTG-Q-1000 / Void Arachne). Rust, memory-resident, gRPC-over-HTTP/2 TLS C2 fronted through public CDN. Delivered by SEO-poisoned counterfeit installers.</summary>
  </entry>
  <entry>
    <title>CVE-2026-56164 — Microsoft SharePoint Server Pre-Auth Zero-Day</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-56164-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-56164-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-16T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated network privilege escalation → RCE on on-prem SharePoint. Actively exploited in-the-wild; IIS machine-key theft &amp; deserialization persistence.</summary>
  </entry>
  <entry>
    <title>Joomla iCagenda &amp; Balbooa Forms — Unauthenticated File-Upload RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Joomla-iCagenda-Balbooa-FileUpload-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Joomla-iCagenda-Balbooa-FileUpload-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-15T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-48939 (iCagenda) &amp; CVE-2026-56291 (Balbooa Forms) — two CVSS 10.0 unauthenticated file-upload zero-days exploited to drop PHP webshells on public Joomla sites. CISA KEV.</summary>
  </entry>
  <entry>
    <title>SonicWall SMA1000 Zero-Day RCE Chain — CVE-2026-15409 + CVE-2026-15410</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SonicWall-SMA1000-CVE-2026-15409-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SonicWall-SMA1000-CVE-2026-15409-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-15T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated SSRF chained to code injection for admin-level command execution on internet-facing SMA 1000 SSL-VPN appliances — exploited in the wild, CISA KEV.</summary>
  </entry>
  <entry>
    <title>LiteLLM AI Gateway — Unauthenticated Remote Code Execution</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/LiteLLM-CVE-2026-42271-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/LiteLLM-CVE-2026-42271-Hunt.html</id>
    <updated>2026-07-14T00:00:00Z</updated>
    <published>2026-07-14T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-42271 (MCP stdio test-endpoint command injection) chained with CVE-2026-48710 (Starlette &quot;BadHost&quot; host-header bypass) → pre-auth RCE on the proxy host · combined CVSS 10.0 · CISA KEV 2026-06-08</summary>
  </entry>
  <entry>
    <title>Fake Payment-SDK npm/PyPI Supply-Chain Campaign</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PaymentSDK-npm-PyPI-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PaymentSDK-npm-PyPI-SupplyChain-Hunt.html</id>
    <updated>2026-07-14T00:00:00Z</updated>
    <published>2026-07-14T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>21 malicious packages impersonating PaySafe / Skrill / Neteller SDKs harvest CI/CD and cloud secrets from developer &amp; build hosts, exfiltrating to an ngrok tunnel · published 2026-07-07 · detected by Socket within ~6 min</summary>
  </entry>
  <entry>
    <title>GodDamn Ransomware — PoisonX BYOVD Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GodDamn-Ransomware-PoisonX-BYOVD-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GodDamn-Ransomware-PoisonX-BYOVD-Hunt.html</id>
    <updated>2026-07-13T00:00:00Z</updated>
    <published>2026-07-13T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Hands-on-keyboard intrusion by the Hyadina RaaS crew (Monster 2022 → Beast 2024 → GodDamn 2026): AnyDesk staged in the user Music folder for unattended remote access → NirSoft + Mimikatz credential sweep → a Microsoft-signed malicious kernel driver (PoisonX, g11.sys ) that terminates AV/EDR and strips kernel callbacks to blind the sensor → a fake symantec.exe masquerade → PsExec lateral movement → the encrypter-windows-gui-x86.exe locker appending .God8Damn . Disclosed by Symantec 2026-07-09. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>Vidar Stealer + XMRig Malvertising — Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Vidar-XMRig-Malvertising-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Vidar-XMRig-Malvertising-Hunt.html</id>
    <updated>2026-07-13T00:00:00Z</updated>
    <published>2026-07-13T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Financially-motivated dual-payload campaign (operator &quot;X3D MINER&quot;) documented by Palo Alto Unit 42 on 2026-07-09: malvertising for cracked software → a password-protected .bin archive → a Factory-v3 (UpdateFactory) Go loader, rogue code-signed and file-inflated to ~491 MB to evade sandboxes → fake MpClient.dll sideloaded by a legitimate Windows Defender binary → AMSI patch → drops Vidar stealer ( MicrosoftUpdate.exe ) and XMRig ( MicrosoftEdgeUpdate.exe --config=mgwthmc2.dat + WinRing0x64.sys ) → persistence as SystemAgentService masquerading as NisSrv.exe . Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-48908 — SP Page Builder for Joomla: Unauthenticated File Upload → RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-48908-SPPageBuilder-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-48908-SPPageBuilder-Hunt.html</id>
    <updated>2026-07-12T00:00:00Z</updated>
    <published>2026-07-12T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVSS 10.0 · exploited as a zero-day · unauthenticated asset.uploadCustomIcon drops a PHP web shell into the web root → OS command execution &amp; hidden Super Admin. Linux web-server telemetry hunt.</summary>
  </entry>
  <entry>
    <title>JADEPUFFER — First Documented Agentic (AI-Driven) Ransomware</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/JADEPUFFER-AgenticRansomware-Langflow-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/JADEPUFFER-AgenticRansomware-Langflow-Hunt.html</id>
    <updated>2026-07-12T00:00:00Z</updated>
    <published>2026-07-12T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Autonomous LLM-agent extortion operation: Langflow RCE (CVE-2025-3248) → credential sweep → Nacos/MySQL pivot → database encryption &amp; destruction. Linux/container telemetry hunt.</summary>
  </entry>
  <entry>
    <title>Injective Labs npm Supply-Chain Compromise</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/InjectiveLabs-npm-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/InjectiveLabs-npm-SupplyChain-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-11T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>A trusted maintainer&#x27;s identity was used to publish a backdoored @injectivelabs/sdk-ts@1.20.21 (plus 17 scoped packages) that steals crypto wallet mnemonics and private keys — a ~49-minute window on 2026-07-08.</summary>
  </entry>
  <entry>
    <title>QuimaRAT — Cross-Platform Java RAT (MaaS)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/QuimaRAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/QuimaRAT-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-10T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Modular Java/JNA remote access trojan sold as malware-as-a-service ($150/mo–$1,200 lifetime); runs on Windows, Linux, and macOS with per-OS persistence, AES-256 C2, and a Pastebin-based C2-rotation channel.</summary>
  </entry>
  <entry>
    <title>TinyRCT Backdoor — CL-STA-1062 (UAT-7237)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TinyRCT-CL-STA-1062-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TinyRCT-CL-STA-1062-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-10T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Chinese-speaking espionage cluster against Southeast Asian government &amp; state-owned energy / critical infrastructure — C# RAT delivered via AppDomainManager injection, PerfWatson2.exe masquerade, and ASPX web shells.</summary>
  </entry>
  <entry>
    <title>CVE-2026-56290 — Joomla &quot;Page Builder CK&quot; Unauthenticated Upload → Webshell RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-56290-Joomla-PageBuilderCK-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-56290-Joomla-PageBuilderCK-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-09T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVSS 10.0 unauthenticated arbitrary file upload in the Joomlack Page Builder CK extension (com_pagebuilderck). Attackers drop PHP webshells into web-served folders and execute them — actively exploited, CISA KEV (due 2026-07-10).</summary>
  </entry>
  <entry>
    <title>PolinRider — North Korea-Linked Open-Source Supply-Chain Campaign</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PolinRider-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PolinRider-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-09T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>108 packages / 162 malicious release artifacts across npm, Packagist, Go modules and Chrome — JS loaders hidden in config files and VS Code folderOpen tasks pull an XOR-encrypted stage-2 from blockchain RPC dead-drops, delivering the DEV#POPPER RAT and OmniStealer.</summary>
  </entry>
  <entry>
    <title>Adobe ColdFusion CVE-2026-48282 — RDS FILEIO Path Traversal → Unauthenticated RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ColdFusion-CVE-2026-48282-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ColdFusion-CVE-2026-48282-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-08T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Maximum-severity arbitrary file write in the ColdFusion Remote Development Services (RDS) FILEIO handler, exploited in the wild within ~2 hours of disclosure. Hunt for webshell drops and ColdFusion-JVM-spawned command execution.</summary>
  </entry>
  <entry>
    <title>TeamPCP — Software Supply-Chain Compromise (FBI FLASH-20260702-01)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TeamPCP-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TeamPCP-SupplyChain-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-08T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Trojanized developer &amp; security tooling (Trivy, KICS, LiteLLM, Telnyx Python SDK) delivering credential-stealing malware — CanisterWorm, SANDCLOCK, Mini Shai-Hulud, Miasma — that harvests cloud tokens, SSH keys, and Kubernetes secrets from CI/CD and developer hosts.</summary>
  </entry>
  <entry>
    <title>Cavern Manticore — Iran-Linked Cavern (Cav3rn) Modular C2 via SysAid / WinDirStat DLL Side-Loading</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CavernManticore-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CavernManticore-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-07T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>MOIS-affiliated espionage cluster deploying a modular .NET C2 (Cavern Agent = trojanized uxtheme.dll) against Israeli government &amp; IT-services orgs · analysed by Check Point Research, July 2026</summary>
  </entry>
  <entry>
    <title>ChocoPoC — a Python RAT Hidden in Fake GitHub PoC Exploits, with a Mapbox Dead-Drop C2</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ChocoPoC-RAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ChocoPoC-RAT-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-07T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Trojanized &quot;proof-of-concept&quot; repos for hot CVEs pull in a compiled payload (skytext → gradient.so / gradient.pyd) that steals credentials and beacons via a Mapbox dataset dead-drop · targets vulnerability researchers &amp; pentesters · YesWeHack + Sekoia, July 2026</summary>
  </entry>
  <entry>
    <title>BusySnake Stealer — Armored Likho (Eagle Werewolf) APT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/BusySnake-ArmoredLikho-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/BusySnake-ArmoredLikho-Hunt.html</id>
    <updated>2026-07-06T00:00:00Z</updated>
    <published>2026-07-06T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A Python-based information stealer (Kaspersky Securelist, July 2026) deployed by the espionage actor Armored Likho against government agencies and electric-power operators in Russia, Kazakhstan and Brazil. Spear-phishing delivers a decoy-laden NSIS EXE dropper (or a ZDI-CAN-25373 LNK variant) that injects into pnx.exe , pulls a Python 3.12 runtime + module.pyw payload from GitHub into %APPDATA%\WindowsHelper , and persists via a WindowsHelper scheduled task. BusySnake loots Chromium/Firefox credentials, cookies, Telegram tdata , crypto wallets and 2FA secrets, then opens a reverse SSH tunnel + RustDesk for hands-on access. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>RustDuck Botnet — Rust-Rebuilt IoT &amp; Server DDoS Swarm</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/RustDuck-Botnet-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/RustDuck-Botnet-Hunt.html</id>
    <updated>2026-07-06T00:00:00Z</updated>
    <published>2026-07-06T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A two-stage DDoS botnet (QiAnXin XLab, June 2026) that has been rewritten from C into Rust — a small loader decrypts and unpacks a heavier Rust core with ChaCha20-Poly1305/AES-GCM channels, Curve25519 key exchange, 10-minute key rotation, and aggressive sandbox/analysis evasion. It spreads by weak/default Telnet &amp; SSH credentials and by exploiting known bugs in routers, DVRs and Linux server software ( ThinkPHP, Jenkins, Hadoop YARN, Apache CouchDB ) to enlist routers, IP cameras, Android boxes and poorly-secured servers into a DDoS swarm. C2 rides duckdns.org dynamic DNS; 20+ delivery IPs are active, busiest at 176.65.139[.]204 . Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-8451 — Citrix NetScaler SAML IDP Memory Overread (&quot;new CitrixBleed&quot;)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-8451-NetScaler-SAML-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-8451-NetScaler-SAML-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-05T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated out-of-bounds read in the NetScaler ADC / Gateway SAML IDP path leaks appliance memory — including session material — via the NSC_TASS response cookie. Exploited in the wild within 24 hours of disclosure.</summary>
  </entry>
  <entry>
    <title>Edgecution — Malicious Microsoft Edge Extension Backdoor</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Edgecution-EdgeExtension-Backdoor-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Edgecution-EdgeExtension-Backdoor-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-05T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A ClickFix/Teams social-engineering chain sideloads an Edge extension (&quot;Edge Monitoring Agent&quot;) that abuses the Chrome Native Messaging protocol to break the browser sandbox and drive an embedded-Python backdoor. Deployed by an initial-access broker linked to the Payouts King ransomware operation.</summary>
  </entry>
  <entry>
    <title>Avalon — AI-Assisted Modular Malware Framework with CrownX Ransomware</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Avalon-CrownX-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Avalon-CrownX-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-04T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Multi-stage phishing → ISO/LNK → MSBuild loader delivering an all-in-one credential-theft + lateral-movement + ransomware framework · disclosed by The Hacker News, July 2026</summary>
  </entry>
  <entry>
    <title>ToddyCat — Umbrij .NET Backdoor &amp; the Shadow Token via Remote Debug (STRD) Technique</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ToddyCat-Umbrij-STRD-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ToddyCat-Umbrij-STRD-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-04T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Asia-nexus espionage actor stealing Gmail / Google Workspace mail by driving a headless browser&#x27;s remote-debugging port to mint OAuth tokens · analysed by Kaspersky Securelist, July 2026</summary>
  </entry>
  <entry>
    <title>ScreenConnect SEO-Poisoning → AsyncRAT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ScreenConnect-AsyncRAT-SEO-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ScreenConnect-AsyncRAT-SEO-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-03T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Fake software installers (OBS Studio, Bandicam, DS4Windows) side-load a rogue DLL, deploy a rogue ScreenConnect instance, then process-hollow RegAsm.exe with AsyncRAT.</summary>
  </entry>
  <entry>
    <title>SharePoint Server RCE — CVE-2026-45659</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-45659-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SharePoint-CVE-2026-45659-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-03T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Deserialization-of-untrusted-data RCE in on-prem SharePoint. Added to CISA KEV 2026-07-01 (federal deadline 2026-07-05). Site-Member auth is enough to run code as the SharePoint app pool.</summary>
  </entry>
  <entry>
    <title>Progress Kemp LoadMaster — Pre-Auth RCE (CVE-2026-8037)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/KempLoadMaster-CVE-2026-8037-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/KempLoadMaster-CVE-2026-8037-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-02T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Uninitialized-heap OS command injection in the LoadMaster API — unauthenticated root code execution on the load balancer appliance.</summary>
  </entry>
  <entry>
    <title>Mustang Panda — ZOHOMURK / MINIRECON / SHARDLOADER</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/MustangPanda-ZOHOMURK-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/MustangPanda-ZOHOMURK-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-02T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>China-aligned espionage: DLL side-loading through signed binaries, a Toneshell-lineage backdoor, and a Zoho WorkDrive cloud C2 that hides in normal SaaS traffic.</summary>
  </entry>
  <entry>
    <title>Scattered Spider — UNC3944 / Octo Tempest</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ScatteredSpider-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ScatteredSpider-Hunt.html</id>
    <updated>2026-07-01T00:00:00Z</updated>
    <published>2026-07-01T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Financially-motivated intrusion set that weaponizes the help desk. Initial access comes from vishing, SIM-swaps, MFA push-bombing and AiTM phishing rather than malware — so the highest-value hunt angles are identity abuse, legitimate remote-access tooling, and BYOVD EDR tampering, not signatures. Culminates in cloud/SaaS data theft and DragonForce ransomware (frequently ESXi-targeting).</summary>
  </entry>
  <entry>
    <title>Oracle E-Business Suite — CVE-2026-46817</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Oracle-EBS-CVE-2026-46817-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Oracle-EBS-CVE-2026-46817-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-01T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated RCE in the Oracle Payments File Transmission component ( /OA_HTML/ibytransmit ) via crafted iPayment XML → local file read / code execution on the EBS app tier · CVSS 9.8 · exploitation observed 2026-06-27/28</summary>
  </entry>
  <entry>
    <title>PTC Windchill &amp; FlexPLM — CVE-2026-12569</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PTC-Windchill-CVE-2026-12569-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PTC-Windchill-CVE-2026-12569-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-07-01T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated deserialization of untrusted data in the Windchill PDMLink component → remote code execution → persistent JSP web shells for command execution and data exfiltration · KEV-listed 2026-06-25</summary>
  </entry>
  <entry>
    <title>BlueHammer CVE-2026-33825 — Microsoft Defender LPE (BlueHammer / RedSun)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/BlueHammer-CVE-2026-33825-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/BlueHammer-CVE-2026-33825-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-30T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>A TOCTOU race in Defender&#x27;s threat-remediation engine, abused with oplocks + NTFS junctions to write into System32 as SYSTEM and reach the SAM database. Now used by ransomware crews for privilege escalation and credential access.</summary>
  </entry>
  <entry>
    <title>SimpleHelp CVE-2026-48558 — TaskWeaver Loader &amp; Djinn Stealer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SimpleHelp-CVE-2026-48558-Djinn-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SimpleHelp-CVE-2026-48558-Djinn-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-30T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>OIDC authentication bypass in SimpleHelp RMM (CVSS 10.0) abused to push a Node.js loader and a cross-platform credential stealer onto managed endpoints.</summary>
  </entry>
  <entry>
    <title>STOCKSTAY — Turla / Secret Blizzard Multi-Component .NET Backdoor</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/STOCKSTAY-Turla-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/STOCKSTAY-Turla-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-29T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Russia-nexus espionage implant against Ukrainian government/military and European foreign-policy targets · disclosed by Google Threat Intelligence Group (GTIG), June 2026</summary>
  </entry>
  <entry>
    <title>SharkLoader / StrikeShark — Multi-Stage Cobalt Strike Loader</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SharkLoader-StrikeShark-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SharkLoader-StrikeShark-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-29T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Espionage-oriented intrusion set exploiting internet-facing apps to side-load a stealthy loader that deploys Cobalt Strike Beacon · tracked by Kaspersky (Securelist), June 2026</summary>
  </entry>
  <entry>
    <title>Phexia Stealer — macOS ClickFix Infostealer + RAT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Phexia-Stealer-macOS-ClickFix-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Phexia-Stealer-macOS-ClickFix-Hunt.html</id>
    <updated>2026-06-29T00:00:00Z</updated>
    <published>2026-06-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Fake-CAPTCHA &quot;ClickFix&quot; lure → pasted Terminal command → dig-TXT dead-drop C2 → osascript/JXA implant with LaunchAgent persistence, credential theft, and reverse-shell tasking</summary>
  </entry>
  <entry>
    <title>CVE-2026-9862 — Fortra Core PAM (BoKS) Unauthenticated Command Injection</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-9862-Fortra-BoKS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-9862-Fortra-BoKS-Hunt.html</id>
    <updated>2026-06-28T00:00:00Z</updated>
    <published>2026-06-28T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>An unauthenticated, network-reachable OS command-injection flaw (CVSS 9.8) in the boks_autoregisterd autoregistration service on TCP 6507 . A crafted registration request injects shell commands that run with the service&#x27;s privileges on the BoKS server — the Unix/Linux access-control hub. Compromise of a PAM appliance is a keys-to-the-kingdom event. Defensive hunt &amp; harden pack — no offensive code / no exploit.</summary>
  </entry>
  <entry>
    <title>Prinz Eugen — Go-based Ransomware Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PrinzEugen-Ransomware-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PrinzEugen-Ransomware-Hunt.html</id>
    <updated>2026-06-28T00:00:00Z</updated>
    <published>2026-06-28T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Compromised RDP access → Chrome-staged payload in the Music folder → RemotePC RMM + PowerShell stagers from a hardcoded C2 → rogue local admin (admin/germania) → hands-on-keyboard data theft → ChaCha20-Poly1305 encryptor (servertool.exe) that hits recently-modified files first, drops no note, and self-deletes. New June-2026 Go encryptor attributed to actor ROOTBOY. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>Lantronix EDS5000 Command Injection — CVE-2025-67038</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Lantronix-EDS5000-CVE-2025-67038-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Lantronix-EDS5000-CVE-2025-67038-Hunt.html</id>
    <updated>2026-06-27T00:00:00Z</updated>
    <published>2026-06-27T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>OT serial-to-Ethernet converter — unauthenticated root command injection via LuCI JSON-RPC auth endpoint. CISA KEV, exploited in the wild.</summary>
  </entry>
  <entry>
    <title>TonRAT / &quot;Photo-ZIP&quot; Hospitality Campaign</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TonRAT-PhotoZIP-Hospitality-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TonRAT-PhotoZIP-Hospitality-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-27T00:00:00Z</published>
    <category term="Other"/>
    <summary>Microsoft-reported multi-stage intrusion delivering a Node.js implant (TonRAT) with TON-blockchain C2 resolution — targeting hotels &amp; hospitality across Europe and Asia.</summary>
  </entry>
  <entry>
    <title>macOS.Gaslight — North Korea-Aligned Rust Backdoor &amp; Infostealer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/macOS-Gaslight-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/macOS-Gaslight-Hunt.html</id>
    <updated>2026-06-27T00:00:00Z</updated>
    <published>2026-06-27T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>aarch64 ad-hoc-signed Rust implant that masquerades inside Apple&#x27;s LaunchAgent namespace, exfils over Telegram Bot API, and embeds a prompt-injection blob aimed at LLM-assisted triage. Reported ~2026-06-25.</summary>
  </entry>
  <entry>
    <title>AryStinger — Router/NAS Recon-and-Proxy Botnet</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AryStinger-Botnet-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AryStinger-Botnet-Hunt.html</id>
    <updated>2026-06-26T00:00:00Z</updated>
    <published>2026-06-26T00:00:00Z</published>
    <category term="Other"/>
    <summary>4,300+ legacy D-Link routers &amp; QNAP NAS turned into &quot;Executor&quot; proxy/recon nodes via decade-old N-day exploits · DNS hijacking, internal scanning, traffic tunneling · QiAnXin XLab</summary>
  </entry>
  <entry>
    <title>Cisco Unified CM WebDialer SSRF → Root — CVE-2026-20230</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Cisco-CUCM-CVE-2026-20230-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Cisco-CUCM-CVE-2026-20230-Hunt.html</id>
    <updated>2026-06-26T00:00:00Z</updated>
    <published>2026-06-26T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated SSRF in the WebDialer service chains to arbitrary file-write, an Apache Axis2 JSP webshell, and root on the call-control appliance · exploited in the wild</summary>
  </entry>
  <entry>
    <title>CitrixBleed 3 — CVE-2026-3055</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CitrixBleed3-CVE-2026-3055-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CitrixBleed3-CVE-2026-3055-Hunt.html</id>
    <updated>2026-06-25T00:00:00Z</updated>
    <published>2026-06-25T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Citrix NetScaler ADC / NetScaler Gateway out-of-bounds memory read (SAML IdP) → session-token disclosure → session hijacking. Companion: CVE-2026-4368.</summary>
  </entry>
  <entry>
    <title>Contagious Interview — BeaverTail / OtterCookie Developer-Workstation Hunt</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ContagiousInterview-BeaverTail-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ContagiousInterview-BeaverTail-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-25T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>DPRK recruitment-themed phishing → actor GitHub repos → cross-platform loaders → crypto-wallet &amp; credential theft. Aliases: Famous Chollima, Void Dokkaebi, HexagonalRodent (Lazarus cluster).</summary>
  </entry>
  <entry>
    <title>Dropping Elephant — Fondue.exe DLL Side-Loading Campaign</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/DroppingElephant-Fondue-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/DroppingElephant-Fondue-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-24T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>India-nexus espionage actor (APT-C-17 / Patchwork) abuses the signed Microsoft binary Fondue.exe to side-load a malicious APPWIZ.cpl and run a Donut-staged in-memory RAT, persisting via a one-minute &quot;GoogleErrorReport&quot; scheduled task.</summary>
  </entry>
  <entry>
    <title>FlutterShell — Operation FlutterBridge (macOS Backdoor)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/FlutterShell-FlutterBridge-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/FlutterShell-FlutterBridge-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-24T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>CL-CRI-1089 spreads a Flutter-built macOS backdoor through Google/YouTube malvertising fronted by Google-verified shell companies; apps masquerade as AI PDF/podcast tools, hijack Chrome traffic, and exfiltrate browser and credential data.</summary>
  </entry>
  <entry>
    <title>OXLOADER → CastleStealer — Node.js Malvertising Loader (REF8372)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/OXLOADER-CastleStealer-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/OXLOADER-CastleStealer-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-24T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Russian-speaking, financially-motivated malvertising crew loads a heavily-obfuscated Windows loader (OXLOADER) via fake Node.js installers, dropping the CastleStealer .NET infostealer.</summary>
  </entry>
  <entry>
    <title>ClickFix Multi-Loader Campaign — BabaDeda · Lorem Ipsum · Potemkin</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ClickFix-Loaders-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ClickFix-Loaders-Hunt.html</id>
    <updated>2026-06-23T00:00:00Z</updated>
    <published>2026-06-23T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A June 2026 ClickFix surge tricks users into copy-pasting attacker PowerShell from fake CAPTCHA / &quot;verify you are human&quot; / fake browser-update pages, then drops THREE distinct loaders (BabaDeda, Lorem Ipsum, Potemkin) that fan out to .NET backdoors, infostealers, RATs and Rhysida-linked ransomware. Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>LiteSpeed cPanel / WHM Plugin — CVE-2026-54420 Symlink-Following Root Privilege Escalation</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/LiteSpeed-cPanel-CVE-2026-54420-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/LiteSpeed-cPanel-CVE-2026-54420-Hunt.html</id>
    <updated>2026-06-23T00:00:00Z</updated>
    <published>2026-06-23T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>A low-privileged shared-hosting tenant (FTP or web-shell access) plants a symbolic link inside a docroot; the privileged LiteSpeed plugin process follows it and performs a file operation as root , escaping the CageFS tenant boundary and taking over the whole server. Actively exploited (CISA KEV). Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>WhatsApp VBScript Campaign → ManageEngine RMM Abuse</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/WhatsApp-VBScript-ManageEngine-RMM-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/WhatsApp-VBScript-ManageEngine-RMM-Hunt.html</id>
    <updated>2026-06-23T00:00:00Z</updated>
    <published>2026-06-23T00:00:00Z</published>
    <category term="Identity"/>
    <summary>Compromised WhatsApp accounts DM heavily-obfuscated .vbs &quot;documents&quot; → WhatsApp.Root.exe (Desktop) spawns wscript.exe → secondary VBScript payloads (UAC tamper + ZIP fetch) → a legitimate ManageEngine RMM Central agent is installed as a covert backdoor. Infrastructure overlaps prior Gh0st RAT / ValleyRAT activity. Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>AMOS Stealer (Atomic macOS Stealer) — June 2026 Keychain-Theft Campaign</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AMOS-Stealer-macOS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AMOS-Stealer-macOS-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>ClickFix-style fake-app / Terminal-paste lures deliver a curl|sh loader that copies the macOS Keychain, harvests Chrome/Edge secrets and developer keys, then exfiltrates via chunked HTTP PUT. macOS endpoints; actively distributed.</summary>
  </entry>
  <entry>
    <title>SHEET#CREEP — APT36 / Transparent Tribe Google Sheets API RAT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SHEETCREEP-TransparentTribe-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SHEETCREEP-TransparentTribe-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Diplomatic-themed ISO phishing lure delivers a ~20 KB C# RAT (vaultsvc.exe) that abuses the Google Sheets API as its C2 — one victim tab per host, Base64 traffic, XOR-obfuscated config, and PowerShell executed in-process to leave no child process. Pakistan-aligned espionage; Securonix continuation of the Zscaler-documented family.</summary>
  </entry>
  <entry>
    <title>UniFi OS Server — Unauthenticated Root RCE Chain (CVE-2026-34908 / 34909 / 34910)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/UniFi-OS-RCE-Chain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/UniFi-OS-RCE-Chain-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Three chained CVSS-10.0 flaws in the UniFi OS Server auth gateway + package-update service → unauthenticated root command execution via a single crafted HTTP request. Active exploitation reported; forged sessions persist after patching.</summary>
  </entry>
  <entry>
    <title>GentleKiller — The Gentlemen&#x27;s BYOVD EDR-Killer Framework</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/GentleKiller-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/GentleKiller-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>In-house EDR-killer suite (8+ variants) · kernel-level process termination via vulnerable drivers · pre-encryption defense teardown</summary>
  </entry>
  <entry>
    <title>TrapDoor — Cross-Ecosystem Supply-Chain Credential Stealer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TrapDoor-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TrapDoor-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>npm + PyPI + Crates.io coordinated campaign · developer-machine credential &amp; wallet theft · AI-assistant config poisoning</summary>
  </entry>
  <entry>
    <title>VoidStealer — Debugger-Based Chrome ABE Bypass</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/VoidStealer-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/VoidStealer-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>MaaS infostealer · first ITW weaponization of a debugger + hardware-breakpoint bypass of Chrome Application-Bound Encryption · no injection, no SYSTEM</summary>
  </entry>
  <entry>
    <title>FortiBleed — FortiGate Leaked-Credential &amp; Config Intrusion HuntPack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/FortiBleed-CVE-2026-24858-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/FortiBleed-CVE-2026-24858-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-21T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-24858 · FortiCloud SSO SAML authentication bypass · ~75,000 FortiGate appliances with leaked admin/SSL-VPN credentials &amp; config exports (mid-June 2026)</summary>
  </entry>
  <entry>
    <title>Miasma — Red Hat npm Supply-Chain Credential Worm</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Miasma-RedHat-npm-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Miasma-RedHat-npm-SupplyChain-Hunt.html</id>
    <updated>2026-06-21T00:00:00Z</updated>
    <published>2026-06-21T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Shai-Hulud-family self-propagating npm worm · &quot;Phantom Gyp&quot; install-time execution via weaponized binding.gyp · multi-cloud secret theft (GitHub / npm / AWS / Azure / GCP / Vault / Kubernetes)</summary>
  </entry>
  <entry>
    <title>Twill Typhoon — Updated FDMTP Backdoor</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TwillTyphoon-FDMTP-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TwillTyphoon-FDMTP-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-21T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Chinese APT espionage campaign: DLL side-loading of legitimate binaries (Sogou Pinyin, Visual Studio, ClickOnce) to launch a modular .NET RAT (FDMTP) over CDN-impersonating C2. Aliases: Earth Preta · Stately Taurus · Bronze President · Mustang Panda · TA416. APAC/Japan, late Sep 2025–Apr 2026.</summary>
  </entry>
  <entry>
    <title>CVE-2026-42897 — Microsoft Exchange Server OWA Zero-Day</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Exchange-OWA-CVE-2026-42897-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Exchange-OWA-CVE-2026-42897-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-20T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Actively exploited stored/reflected XSS in Outlook Web Access — weaponized email drives JavaScript execution in the OWA session. On-prem Exchange only.</summary>
  </entry>
  <entry>
    <title>Malicious JetBrains Marketplace AI Plugins — Supply-Chain AI Key Theft</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/JetBrains-Marketplace-AIPlugin-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/JetBrains-Marketplace-AIPlugin-SupplyChain-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-20T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>15 DeepSeek-themed IDE plugins covertly exfiltrate developer OpenAI / DeepSeek / SiliconFlow API keys to a plaintext-HTTP C2. ~70,000 installs.</summary>
  </entry>
  <entry>
    <title>Splunk Enterprise Unauthenticated RCE — CVE-2026-20253</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Splunk-CVE-2026-20253-RCE-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Splunk-CVE-2026-20253-RCE-Hunt.html</id>
    <updated>2026-06-20T00:00:00Z</updated>
    <published>2026-06-20T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>PostgreSQL sidecar unauthenticated file-write chains to remote code execution on the Splunk host · CISA KEV, exploited in the wild</summary>
  </entry>
  <entry>
    <title>CryptoBandits — Windows Crypto Clipper, Tor Backdoor &amp; USB LNK Worm</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CryptoBandits-Clipper-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CryptoBandits-Clipper-Hunt.html</id>
    <updated>2026-06-19T00:00:00Z</updated>
    <published>2026-06-19T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>A Windows cryptocurrency clipper (Trojan:Win32/CryptoBandits) that swaps attacker wallet addresses into the clipboard, harvests seed phrases / private keys, captures screenshots, and exfiltrates over a bundled portable Tor client via a local SOCKS5 proxy (127.0.0.1:9050). It self-propagates through malicious LNK shortcuts on USB media and runs an EVAL-driven backdoor. Active since February 2026; disclosed by Microsoft Threat Intelligence on 2026-06-17. This is a Falcon-side endpoint behavioral + IOC hunt pack. Defensive hunt &amp; harden pack — no malware code.</summary>
  </entry>
  <entry>
    <title>DragonForce Ransomware &amp; Backdoor.Turn — Microsoft Teams TURN-Relay C2</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/DragonForce-BackdoorTurn-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/DragonForce-BackdoorTurn-Hunt.html</id>
    <updated>2026-06-19T00:00:00Z</updated>
    <published>2026-06-19T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>DragonForce affiliates deploy a custom Go-based RAT, Backdoor.Turn, that hides its command-and-control inside legitimate Microsoft Teams/Skype infrastructure: it obtains an anonymous Teams visitor token, relays through a real Microsoft TURN server, then runs a QUIC session to the attacker C2 — so defenders see only outbound traffic to Microsoft. The RAT is injected into the legitimate Sysinternals DbgView64.exe process after ransomware is staged. First known in-the-wild abuse of TURN-relay infrastructure for C2 (technique = Praetorian &quot;Ghost Calls&quot;). Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>F5 NGINX CVE-2026-42530 / CVE-2026-42055 — Critical Unauthenticated RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/F5-NGINX-CVE-2026-42530-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/F5-NGINX-CVE-2026-42530-Hunt.html</id>
    <updated>2026-06-19T00:00:00Z</updated>
    <published>2026-06-19T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Two critical (CVSS v4 9.2) remote, unauthenticated memory-corruption flaws in NGINX. CVE-2026-42530 is a use-after-free in the HTTP/3 (QUIC) module; CVE-2026-42055 is a heap overflow in the HTTP/2 proxy &amp; gRPC modules. Both can crash NGINX workers (DoS) and yield arbitrary code execution where ASLR is disabled or bypassed. F5 shipped out-of-band patches ~17–18 Jun 2026. This is a Falcon-side endpoint hunt for post-exploitation off the NGINX worker plus a vulnerable-version inventory. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-48907 — Joomla Content Editor (JCE) Unauthenticated RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-48907-Joomla-JCE-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-48907-Joomla-JCE-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-18T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Chained authorization + file-validation failure in the JCE profile-import workflow → webshell upload → arbitrary PHP execution on Linux web servers. Actively exploited; CISA KEV.</summary>
  </entry>
  <entry>
    <title>Fortinet FortiSandbox Triple-Flaw — Active Exploitation</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Fortinet-FortiSandbox-CVE-2026-39813-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Fortinet-FortiSandbox-CVE-2026-39813-Hunt.html</id>
    <updated>2026-06-18T00:00:00Z</updated>
    <published>2026-06-18T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>CVE-2026-39813 (auth-bypass path traversal) · CVE-2026-39808 &amp; CVE-2026-25089 (OS command injection) — unauthenticated RCE on the FortiSandbox appliance management plane</summary>
  </entry>
  <entry>
    <title>Mastra npm Supply-Chain Attack — &quot;easy-day-js&quot;</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Mastra-npm-easy-day-js-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Mastra-npm-easy-day-js-SupplyChain-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-18T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>144 @mastra packages backdoored via a typosquat dependency that drops a detached crypto-stealing RAT through an obfuscated postinstall hook.</summary>
  </entry>
  <entry>
    <title>APT37 / ScarCruft — NarwhalRAT (Fake Microsoft Alert → LNK → Batch → Compiled-Python RAT)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/APT37-NarwhalRAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/APT37-NarwhalRAT-Hunt.html</id>
    <updated>2026-06-17T00:00:00Z</updated>
    <published>2026-06-17T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A DPRK-nexus espionage campaign (Genians Security Center, June 2026) that opens with spear-phishing emails impersonating Microsoft account-security / OTP-abuse alerts , designed to alarm the recipient into opening a ZIP archive disguised as a Microsoft security advisory . The ZIP carries a malicious LNK that launches a multi-stage, largely in-memory chain — env-var-obfuscated batch scripts that download and run NarwhalRAT , a compiled-Python RAT with keylogging, screen capture, audio recording and data collection. C2 is a dead-drop resolver abusing legitimate Korean websites plus pCloud storage. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>SprySOCKS Windows Variants — WIN_DRV / WIN_PLUS (FishMonger)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SprySOCKS-Windows-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SprySOCKS-Windows-Hunt.html</id>
    <updated>2026-06-17T00:00:00Z</updated>
    <published>2026-06-17T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>ESET (June 16, 2026) documented two previously unseen Windows ports of the China-nexus SprySOCKS backdoor — historically a Linux-only implant — attributed to FishMonger (linked to the I-Soon contractor). WIN_PLUS loads via the Print Spooler (a print-processor loader injecting svchost.exe ); the stealthier WIN_DRV ships a kernel-mode driver acting as a rootkit — hiding files, processes, registry keys, and network connections, and rerouting traffic from any open port to the backdoor&#x27;s hidden port when a packet marker appears (port-knocking covert channel). Both retain the Linux C2 protocol/encryption over TCP, UDP, and WebSocket, and run 30+ espionage commands. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>UNC5221 / VerdantBamboo — Brickstorm + Plenet + AgentPSD in Microsoft 365</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/UNC5221-Brickstorm-M365-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/UNC5221-Brickstorm-M365-Hunt.html</id>
    <updated>2026-06-17T00:00:00Z</updated>
    <published>2026-06-17T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A long-dwell Chinese espionage campaign (June 2026 reporting) that lived inside victim Microsoft 365 / Entra ID environments for roughly 18 months . UNC5221 plants its signature Brickstorm backdoor on internet-facing edge/appliance devices that don&#x27;t run EDR, proxies through them to defeat Conditional Access, then deploys two newer families — Plenet (.NET cross-platform backdoor) and AgentPSD (Python reverse-shell backup) — and also compromises the victim&#x27;s MSP for onward access. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>Atomic Arch — Arch Linux AUR Supply-Chain Attack (Rust Infostealer + eBPF Rootkit)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AtomicArch-AUR-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AtomicArch-AUR-SupplyChain-Hunt.html</id>
    <updated>2026-06-16T00:00:00Z</updated>
    <published>2026-06-16T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Attackers seized abandoned / maintainer Arch User Repository (AUR) packages and rewrote their PKGBUILD build scripts to deploy malware at build/install time . A Rust-compiled Linux ELF infostealer (sample &quot;deps&quot;) harvests developer secrets — SSH keys, cloud/dev tokens, browser &amp; Electron sessions — and, with root, loads an eBPF rootkit to hide. 408 packages compromised in the first wave (Jun 11), &gt;1,500 by Jun 12. Sonatype-2026-003775 · CVSS 8.7. Linux endpoint hunt &amp; harden pack — defensive only, no offensive code.</summary>
  </entry>
  <entry>
    <title>Awesome Motive CDN Supply-Chain Attack — OptinMonster / TrustPulse / PushEngage Tampered CDN Scripts</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AwesomeMotive-CDN-WordPress-SupplyChain-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AwesomeMotive-CDN-WordPress-SupplyChain-Hunt.html</id>
    <updated>2026-06-16T00:00:00Z</updated>
    <published>2026-06-16T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>A compromised Awesome Motive CDN API key let attackers inject malicious JavaScript into three popular WordPress plugins served from the vendors&#x27; official CDNs. The tampered JS runs in a logged-in administrator&#x27;s browser and abuses that authenticated session to silently create hidden rogue admin accounts ( developer_api1 / dev_* ) and install self-hiding backdoor plugins ( content-delivery-helper , database-optimizer ); new credentials are exfiltrated to the typosquat C2 domain tidio.cc . ~1.2M WordPress sites exposed. First activity 2026-06-12; PushEngage CDN nodes served the payload through 2026-06-14. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-10520 — Ivanti Sentry (MobileIron Sentry) Pre-Auth OS Command Injection</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Ivanti-Sentry-CVE-2026-10520-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Ivanti-Sentry-CVE-2026-10520-Hunt.html</id>
    <updated>2026-06-16T00:00:00Z</updated>
    <published>2026-06-16T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated OS command injection (CWE-78) in the Sentry web app&#x27;s ConfigServiceController : an unauthenticated POST to /mics/api/v2/sentry/mics-config/handleMessage reaches handleExecute() and runs attacker-supplied OS commands as root . CVSS 10.0 · CISA KEV (~2026-06-12, 3-day remediation deadline 2026-06-14) · mass-exploited within 24h of patch with a public PoC; Shadowserver observed most internet-exposed gateways backdoored. Fixed in 10.5.2 / 10.6.2 / 10.7.1 (patched 2026-06-10). Companion flaw CVE-2026-10523 disclosed alongside. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-11645 — Chromium V8 Out-of-Bounds Read/Write RCE Zero-Day</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-11645-Chromium-V8-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-11645-Chromium-V8-Hunt.html</id>
    <updated>2026-06-15T00:00:00Z</updated>
    <published>2026-06-15T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>An out-of-bounds read AND write in V8, Chrome&#x27;s JavaScript/WebAssembly engine. A crafted HTML page yields arbitrary code execution inside the browser renderer/sandbox. Exploit confirmed in the wild; CISA KEV 2026-06-09. Fixed in Chrome 149.0.7827.102/.103. This is a Falcon-side endpoint hunt for post-exploitation from a browser parent plus a vulnerable-version inventory. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-45247 — Mirasvit Full Page Cache Warmer (Magento / Adobe Commerce) Unauthenticated RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-45247-Magento-MirasvitCacheWarmer-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-45247-Magento-MirasvitCacheWarmer-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-15T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>PHP Object Injection via attacker-controlled CacheWarmer cookie → unserialize() → Monolog gadget chain → remote code execution. Hunt the web host running Falcon.</summary>
  </entry>
  <entry>
    <title>CVE-2026-7473 — Arista EOS Tunnel Decapsulation Bypass</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-7473-Arista-EOS-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-7473-Arista-EOS-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-15T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unverified tunnel protocol type lets a switch decapsulate &amp; forward unexpected tunneled packets — bypassing network segmentation. Exploited as a zero-day; no patch planned.</summary>
  </entry>
  <entry>
    <title>Cisco Catalyst SD-WAN Manager — CVE-2026-20245</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Cisco-SD-WAN-Manager-CVE-2026-20245-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Cisco-SD-WAN-Manager-CVE-2026-20245-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-14T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Authenticated netadmin → root command injection via crafted CLI file upload (vconfd) — zero-day, no patch, config pushed to edge devices · suspected UAT-8616</summary>
  </entry>
  <entry>
    <title>PAN-OS GlobalProtect Authentication Bypass — CVE-2026-0257</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PAN-OS-GlobalProtect-CVE-2026-0257-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PAN-OS-GlobalProtect-CVE-2026-0257-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-14T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated attacker bypasses portal/gateway auth to establish a VPN session — actively exploited (Unit 42)</summary>
  </entry>
  <entry>
    <title>Oracle PeopleSoft PeopleTools RCE — CVE-2026-35273</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PeopleSoft-CVE-2026-35273-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PeopleSoft-CVE-2026-35273-Hunt.html</id>
    <updated>2026-07-24T00:00:00Z</updated>
    <published>2026-06-14T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>ShinyHunters / UNC6240 unauthenticated PSEMHUB exploitation → MeshCentral RMM, SSH fan-out, data theft &amp; extortion</summary>
  </entry>
  <entry>
    <title>CVE-2026-20131 — Interlock Ransomware Exploiting Cisco Secure Firewall Management Center RCE</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-20131-Interlock-CiscoFMC-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-20131-Interlock-CiscoFMC-Hunt.html</id>
    <updated>2026-06-13T00:00:00Z</updated>
    <published>2026-06-13T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Insecure deserialization of a user-supplied Java byte stream on the Cisco Secure FMC web-management interface lets an unauthenticated attacker execute arbitrary Java code as root via crafted HTTP requests. CVSS 10.0. Exploited as a zero-day by the Interlock ransomware group since 2026-01-26 — 36 days before Cisco&#x27;s 2026-03-04 disclosure. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-50751 — Check Point Remote Access VPN / Mobile Access IKEv1 Authentication Bypass</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-50751-CheckPoint-VPN-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-50751-CheckPoint-VPN-Hunt.html</id>
    <updated>2026-06-13T00:00:00Z</updated>
    <published>2026-06-13T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Improper authentication (CWE-287) in the deprecated IKEv1 key exchange: an unauthenticated remote attacker bypasses Remote Access / Mobile Access certificate validation and establishes a VPN tunnel without a valid user password. CVSS 9.3 · CISA KEV (2026-06-08) · actively exploited since 2026-05-07 with a Qilin ransomware affiliate linked to post-compromise activity. Fixed by hotfix sk185033. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>Needle Stealer — Golang Modular Infostealer (Crypto / Browser Credential Theft)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/NeedleStealer-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/NeedleStealer-Hunt.html</id>
    <updated>2026-06-13T00:00:00Z</updated>
    <published>2026-06-13T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A modular Golang infostealer / MaaS that lands via a fake AI-trading site ( tradingclaw[.]pro ) and via Amadey / GCleaner / CountLoader. Its chain sideloads iviewers.dll and process-hollows into RegAsm.exe , installs a malicious browser extension under %LOCALAPPDATA%\Packages\Extensions that intercepts MetaMask / Phantom seed phrases, and exfiltrates browser creds, wallets, Telegram/FTP data and clipboard over HTTP C2. Documented April 2026, active build observed 2026-06-03. Defensive hunt &amp; harden pack — no malware code.</summary>
  </entry>
  <entry>
    <title>RemusStealer / AnimateClipper / SessionGate — Fake Dev-Tool Sites (SEO + TDS)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/RemusStealer-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/RemusStealer-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-12T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A large malware-distribution ecosystem (Check Point Research, June 2026) that runs 100+ SEO-poisoned sites impersonating open-source developer/security tools (Ghidra, dnSpy, SpiderFoot, ILSpy, grpcurl, mqttexplorer, mfcmapi, CrystalDiskMark…). A CloudFront-hosted JavaScript layer turns a &quot;Download&quot; click into a handoff to a gated Traffic Distribution System (TDS) that delivers RemusStealer (20+ browsers, wallets, password managers, 2FA), AnimateClipper (clipboard wallet-address swapper), and SessionGate (heavily-obfuscated multi-stage loader). Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>ConsentFix — Entra ID OAuth Phishing &amp; Token Theft</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ConsentFix-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ConsentFix-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-12T00:00:00Z</published>
    <category term="Identity"/>
    <summary>Lure → legit first-party-app sign-in → victim pastes the localhost auth-code URL → attacker redeems it for access + refresh tokens and operates from their own infra. MFA &amp; most Conditional Access bypassed. Identity-log hunt — detection lives in Entra, not the endpoint.</summary>
  </entry>
  <entry>
    <title>RoguePlanet — Microsoft Defender SYSTEM Escalation Zero-Day</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/RoguePlanet-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/RoguePlanet-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-12T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>TOCTOU race in Defender&#x27;s file-processing path → NTFS junction redirect → MsMpEng.exe (SYSTEM) writes/executes attacker content on fully-patched Windows 10/11. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>WinRAR CVE-2025-8088 — Russia-Aligned Stealer Campaigns</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/WinRAR-CVE-2025-8088-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/WinRAR-CVE-2025-8088-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-12T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Path-traversal via NTFS ADS (patched WinRAR 7.13, Jul 2025, still exploited) → Startup-folder LNK → cmd → PowerShell → GIFTEDCROOK, plus Gamaredon&#x27;s HTA→VBScript GammaLoad/GammaSteel. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>The Gentlemen — Ransomware Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TheGentlemen-Ransomware-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TheGentlemen-Ransomware-Hunt.html</id>
    <updated>2026-06-11T00:00:00Z</updated>
    <published>2026-06-11T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>FortiOS exploit (CVE-2024-55591) → AD recon → BYOVD EDR-kill → self-propagating Go encryptor ( .i8p14s ). Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>CVE-2026-41091 (RedSun) — Microsoft Defender Link-Following Elevation of Privilege</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-41091-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-41091-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-11T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Improper link resolution (CWE-59) in the Microsoft Malware Protection Engine: an unprivileged user writes a crafted file to a privileged location, MMPE follows the symlink/junction and writes it back as SYSTEM. KEV-listed, exploited in the wild (Nightmare Eclipse). Patched in MMPE v1.1.26040.8. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>INC Ransom — Rapid Extortion Against Professional-Services Firms</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/INC-Ransom-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/INC-Ransom-Hunt.html</id>
    <updated>2026-06-10T00:00:00Z</updated>
    <published>2026-06-10T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>RaaS double-extortion operation clustering attacks on legal &amp; professional-services firms in 2026. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>Salt Typhoon / UAT-9244 — TernDoor · PeerTime · BruteEntry</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Salt-Typhoon-UAT-9244-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Salt-Typhoon-UAT-9244-Hunt.html</id>
    <updated>2026-06-10T00:00:00Z</updated>
    <published>2026-06-10T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>China-nexus telecom espionage toolkit. Windows backdoor (TernDoor), cross-arch ELF P2P backdoor (PeerTime), and a GoLang edge-device brute-force ORB (BruteEntry). Defensive hunt &amp; harden pack — no offensive tradecraft.</summary>
  </entry>
  <entry>
    <title>CVE-2026-41089 — Windows Netlogon RCE (Domain Controller Takeover)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-41089-Netlogon-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/CVE-2026-41089-Netlogon-Hunt.html</id>
    <updated>2026-06-09T00:00:00Z</updated>
    <published>2026-06-09T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Unauthenticated 0-click stack overflow in netlogon.dll → SYSTEM on any Domain Controller. Defensive hunt &amp; harden pack — no exploit code.</summary>
  </entry>
  <entry>
    <title>Shai-Hulud &quot;Hades&quot; Wave — PyPI Supply-Chain Worm</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ShaiHulud-Hades-PyPI-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ShaiHulud-Hades-PyPI-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-09T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>Self-propagating credential-stealing worm trojanizing scientific &amp; developer-tooling PyPI packages. A .pth Python startup hook pulls the Bun runtime and runs an obfuscated payload that harvests cloud/CI tokens, then re-publishes via stolen credentials. Cross-ecosystem (npm + PyPI). Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>IronWorm — Rust-Built npm Supply-Chain Worm</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/IronWorm-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/IronWorm-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-05T00:00:00Z</published>
    <category term="Supply-chain"/>
    <summary>An evolved Shai-Hulud-family worm (JFrog, 3 Jun 2026). A malicious npm install hook drops a ~976 KB Rust ELF that harvests ~86 env vars + 20+ credential files, steals Exodus wallet seeds, ships an eBPF kernel rootkit (process/socket hiding), beacons over Tor , and self-propagates using stolen npm Trusted-Publishing creds. Targets Web3/crypto developers. Defensive hunt &amp; harden pack.</summary>
  </entry>
  <entry>
    <title>UNC3753 (Luna Moth / Silent Ransom Group) — Vishing Data-Theft Extortion</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/UNC3753-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/UNC3753-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-05T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>A financially-motivated, ex-Conti cluster that calls employees posing as IT/help-desk, talks them into a screen-share or installing a remote-access tool , then searches, stages, and exfiltrates data — often in under an hour — and extorts (no encryption). 2026 escalations added physical office intrusions. Defensive hunt &amp; harden pack — the front line here is people + RMM governance.</summary>
  </entry>
  <entry>
    <title>MuddyWater — Iranian MOIS Espionage APT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/MuddyWater-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/MuddyWater-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-05T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>Iran&#x27;s Ministry of Intelligence &amp; Security cyber-espionage group. 2026 campaigns deliver the Rust implant RustyWater and lean on a custom PowerShell-C2 lineage (POWERSTATS → MuddyC3 → PhonyC2 → MuddyC2Go → DarkBeatC2) plus heavily-abused RMM tools (Atera, ScreenConnect, SimpleHelp, N-able). Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>SocGholish (FakeUpdates) — JavaScript Loader &amp; Access Broker</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SocGholish-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SocGholish-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-06-05T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Compromised legitimate sites serve fake browser-update prompts → ZIP with an obfuscated JS loader run by wscript.exe → system profiling, WebDAV/SCF NTLM coercion, a Python backdoor, and hand-off to RansomHub affiliates. Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>Qilin (Agenda) — Ransomware-as-a-Service Hunt &amp; Hardening Pack</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Qilin-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Qilin-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>Edge-VPN / Veeam access → AD recon → Mimikatz cred theft → defense evasion (log clearing, service kill, symlink-eval) → PsExec/vCenter self-propagation → backup destruction → Rust/C double-extortion encryptor. The most active RaaS of 2026 (~500 victims YTD). Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>LummaC2 / Lumma Stealer — Malware-as-a-Service Infostealer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/LummaC2-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/LummaC2-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>ClickFix / fake-CAPTCHA &quot;paste-and-run&quot; → mshta/PowerShell IEX → loader → process hollowing into OpenWith.exe / more.com → browser creds, cookies, 2FA, wallets &amp; CLI tokens exfiltrated to TeslaBrowser/5.5 C2. Activity dropped after the May-2025 takedown but the ClickFix delivery chain remains pervasive. Defensive hunt &amp; harden pack.</summary>
  </entry>
  <entry>
    <title>NetSupport Manager — Abused Remote-Access Tool</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/NetSupportManager-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/NetSupportManager-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A legitimate commercial RMM (NetSupport Manager) weaponized as a RAT via fake browser updates, ClickFix, malvertising, and phishing (LNK/PDF). The tell-tale signal: client32.exe + client32.ini running from %ProgramData% / %AppData% instead of Program Files. Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>Scarlet Goldfinch — Fake-Update / ClickFix → NetSupport &amp; Remcos</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/ScarletGoldfinch-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/ScarletGoldfinch-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Red Canary-tracked activity cluster: compromised sites push a fake browser-update ( updateinstaller.zip ) running malicious JavaScript — or, since 2025, a ClickFix fake-CAPTCHA paste-and-run — that installs NetSupport Manager RAT (and, since late 2025, Remcos). Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>PayoutsKing (STAC4713 / GOLD ENCOUNTER) — Hidden-QEMU Ransomware</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PayoutsKing-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PayoutsKing-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>GOLD ENCOUNTER runs the PayoutsKing ransomware operation by hiding tradecraft inside a QEMU virtual machine : a TPMProfiler scheduled task launches a hidden Alpine VM as SYSTEM (disks disguised as .db / .dll ), forwards ports over a reverse-SSH tunnel, and runs AdaptixC2 / Chisel / Rclone inside the VM to evade endpoint security. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>TamperedChef (EvilAI) — Signed Fake-Productivity-App Malvertising</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/TamperedChef-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/TamperedChef-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-26T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A global malvertising operation distributing code-signed fake productivity apps (AppSuite PDF, Calendaromatic, OneZip, CrystalPDF) via fake download sites. The Electron apps look legitimate and stay dormant — payloads (infostealers, RATs, browser hijackers) often activate ~56 days after install to evade analysis. Defensive hunt &amp; harden pack — no malicious code.</summary>
  </entry>
  <entry>
    <title>Mini Shai-Hulud — TeamPCP npm/PyPI Supply-Chain Worm (CVE-2026-45321)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Mini-Shai-Hulud-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Mini-Shai-Hulud-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-23T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>TeamPCP&#x27;s self-propagating credential-stealing worm. It hijacks GitHub OIDC tokens to re-publish across 170+ npm/PyPI packages (@tanstack/*, @mistralai/*, @uipath/*, @opensearch-project/*), forges SLSA provenance, scrapes OIDC tokens from CI-runner memory, hooks AI coding agents/IDEs, and arms a dead-man&#x27;s-switch that wipes $HOME if tokens are revoked before it&#x27;s removed. Sibling of the later &quot;Hades&quot; wave. Defensive hunt &amp; harden pack.</summary>
  </entry>
  <entry>
    <title>DriftToken — Salesloft Drift → Salesforce OAuth Data Theft (UNC6395)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/DriftToken-SalesforceOAuth-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/DriftToken-SalesforceOAuth-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-19T00:00:00Z</published>
    <category term="APT / actor"/>
    <summary>UNC6395 stole OAuth tokens from the Salesloft Drift integration and used that trusted API access to bulk-export data from 700+ orgs&#x27; Salesforce instances (Aug 8–18, 2025) — then secret-scanned the loot for AWS keys, Snowflake &amp; VPN credentials. A SaaS supply-chain breach: detection lives in Salesforce/SaaS audit logs, not the endpoint. Defensive hunt &amp; harden pack.</summary>
  </entry>
  <entry>
    <title>Amber Albatross — PUP-Bundled → PyInstaller Stealer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/AmberAlbatross-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/AmberAlbatross-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-18T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Red Canary-tracked activity cluster: installers masquerading as free utilities (PcAppStore, Bit Driver Updater, Malware Crusher) drop an InnoSetup payload that, through an obfuscated, anti-analysis chain, unpacks a Pyarmor-protected PyInstaller executable launched via cmd.exe / powershell.exe — a stealer that runs a familiar reconnaissance burst. Defensive hunt &amp; harden pack.</summary>
  </entry>
  <entry>
    <title>Medusa Ransomware — ABYSSWORKER BYOVD EDR-Killer</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/Medusa-BYOVD-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/Medusa-BYOVD-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-17T00:00:00Z</published>
    <category term="Ransomware"/>
    <summary>The Medusa RaaS operation (Spearwing / FROZEN SPIDER / Storm-1175) deploys ABYSSWORKER , a malicious kernel driver ( smuol.sys and rotating names) that mimics CrowdStrike&#x27;s CSAgent.sys and disables EDR via BYOVD before encryption. Delivered by a HEARTCRYPT -packed loader and signed with revoked, stolen certificates (POORTRY lineage). Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>APT28 PRISMEX — Operation Neusploit (CVE-2026-21509)</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/APT28-PRISMEX-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/APT28-PRISMEX-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-16T00:00:00Z</published>
    <category term="CVE / vuln"/>
    <summary>Russia&#x27;s APT28 (Fancy Bear) exploits a Microsoft Office RTF security-feature-bypass (CVE-2026-21509) in phishing against Central/Eastern European &amp; Ukrainian government targets. The RTF drops MiniDoor (an Outlook email stealer, a stripped NotDoor variant) and PixyNetLoader , which deploys a Covenant Grunt implant. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>QEMU Hidden-VM Evasion — STAC4713 / STAC3725</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/QEMU-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/QEMU-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-13T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>Threat actors (Sophos clusters STAC4713 and STAC3725 ) deploy a portable QEMU hypervisor on a compromised Windows host and run a hidden virtual machine — a lightweight Linux/backdoor guest that proxies C2 and runs tooling outside the host EDR&#x27;s visibility. The same VM-as-evasion playbook cross-links the PayoutsKing activity. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>MimiCRAT — ClickFix → Lua Loader → Meterpreter → C++ RAT</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/MimiCRAT-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/MimiCRAT-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-12T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A multi-stage intrusion chain (Elastic Security Labs) that starts with a ClickFix social-engineering lure, runs an obfuscated PowerShell downloader, bypasses ETW/AMSI, then uses a Lua-based in-memory loader to stage Meterpreter-style shellcode and a native C++ remote-access trojan, MIMICRAT (a.k.a. AstarionRAT) — with token theft, a SOCKS5 proxy, and malleable C2 over HTTPS. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>PhantomVault — PHANTOMPULSE Blockchain-C2 RAT via Obsidian</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/PhantomVault-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/PhantomVault-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-12T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>An intrusion set (Elastic REF6598 ) that abuses the legitimate Obsidian note-taking app — via DLL side-loading — to launch PHANTOMPULSE , a modular RAT whose C2 configuration is resolved from a public blockchain (smart-contract / EtherHiding-style resilient C2) rather than a fixed domain. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
  <entry>
    <title>Operation SilentCanvas — JPEG-Staged PowerShell → Trojanized ScreenConnect</title>
    <link rel="alternate" type="text/html" href="https://slapopotamus.github.io/HuntPack/hunts/SilentCanvas-Hunt.html"/>
    <id>https://slapopotamus.github.io/HuntPack/hunts/SilentCanvas-Hunt.html</id>
    <updated>2026-06-12T00:00:00Z</updated>
    <published>2026-05-12T00:00:00Z</published>
    <category term="Loader / RAT"/>
    <summary>A fileless intrusion chain that hides obfuscated PowerShell inside a fake image ( sysupdate.jpeg with no JPEG magic bytes ), compiles a custom launcher on-host via csc.exe , performs a fileless ComputerDefaults.exe UAC bypass , then installs a trojanized ConnectWise ScreenConnect client as a service masquerading as OneDriveServers for persistent remote access. Defensive hunt &amp; harden pack — no offensive code.</summary>
  </entry>
</feed>
