Hunt.io

1.6K posts

Hunt.io banner
Hunt.io

Hunt.io

@Huntio

https://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.

United States Katılım Haziran 2023
936 Takip Edilen6.7K Takipçiler
Hunt.io
Hunt.io@Huntio·
🔍 From SQL Queries to Infrastructure Pivots With HuntSQL HuntSQL gives threat hunters direct SQL access to Hunt’s first-party infrastructure data. One query can filter confirmed C2 activity by malware family, timeframe, IP, port, and scan URI. In this example, we use it to surface recent VShell servers, turning each result into a pivot point for reviewing hosting, risk signals, open ports, domains, associations, and related infrastructure. The workflow is simple: query the data, narrow the results, open a host, and keep following the trail without losing context along the way. See how far one SQL query can take your investigation 👉 hunt.io/get-started #ThreatHunting #ThreatIntel #CyberSecurity
Hunt.io tweet mediaHunt.io tweet mediaHunt.io tweet media
English
0
0
2
264
Hunt.io
Hunt.io@Huntio·
⚠️ New Dysphoria Botnet Infects 200,000 Devices and Uses Blockchain-Based C2 bleepingcomputer.com/news/security/… Dysphoria is the name of a new botnet that so far has infected around 200,000 routers, cameras, and IoT devices worldwide. It spreads through weak Telnet and SSH credentials, along with both recent and years-old vulnerabilities. It uses Ethereum ENS and Solana SNS domains to retrieve hidden C2 addresses, making its infrastructure harder to trace. Some variants launch DDoS attacks, while others turn infected devices into network proxies. Its operators claim the service can generate attacks reaching up to 4 Tbps. #ThreatIntel #Botnet #DDoS #CyberSecurity
English
0
0
1
322
Hunt.io
Hunt.io@Huntio·
#opendir spotted by @skocherhan x.com/skocherhan/sta… → AttackCapture URL: portal.hunt.io/attackcapture/… Key findings: - trycloudflare tunnel host - 13 files across 2 subdirs, 44.2MB, captured 07/22 - kit's built around UK-themed naming, UK label shows up in four of the archive members - 7 archive members total, including 5 nested zips/tars, UkJuly20 series plus a Sep01x86_Ayoo variant Hunt.io's AI report reads it as a modular Windows staging kit with iterative builds, medium confidence, 4 findings/11 pivots
Hunt.io tweet mediaHunt.io tweet media
ܛܔܔܔܛܔܛܔܛ@skocherhan

@smica83 azealousgreat[.]duckdns[.]org azealousgroup[.]duckdns[.]org azelagroup05[.]duckdns[.]org hsab20[.]duckdns[.]org visits-fool-judicial-outer[.]trycloudflare[.]com yeja56[.]duckdns[.]org

English
0
6
11
2.3K
Hunt.io retweetledi
Ctrl-Alt-Intel
Ctrl-Alt-Intel@ctrlaltintel·
Hunting for C2 #OPSEC failures w. @Huntio: Sliver edition 🧵 - Sliver is an open-source C2 framework - Implants for Win/Linux/MacOS - Abused from ransomware actors to APTs Hundreds of OPSECs failures to explore on the platform, take a peek at a few below 👇
English
1
4
30
2K
Hunt.io retweetledi
Hunt.io retweetledi
NetAskari
NetAskari@NetAskari·
Together with @Huntio we worked on an investigation concerning a RAT which seems to be a SpyNote variant that was planted inside an app that mimics a "service app" of the Chinese police. 🧵1/4
NetAskari tweet media
English
1
17
36
3.9K
Hunt.io
Hunt.io@Huntio·
🚀 Hunt 3.0 Introduces New Vulnerability Intelligence We have a new Vulnerability Intelligence module in Hunt 3.0, built to connect daily trends with CVE-level investigation. Move from Daily Digest, Top Threats, or Weaponized views into dedicated CVE pages without losing context. Review threat score, CVSS, EPSS, KEV status, ransomware signals, exploits, detections, and Nuclei templates in one place. Related CVEs are linked inside descriptions, while evidence connects directly to IOC Hunter stories and primary sources. Get ready to experience less tab switching and a much smoother path from signal to investigation. Start here 👉 hunt.io/get-started #ThreatHunting #ThreatIntel #CyberSecurity
English
0
6
31
2.3K
Hunt.io
Hunt.io@Huntio·
🚩 CastleLoader Adds Crypto Theft to Its Playbook gbhackers.com/castleloader-c… CastleLoader, a modular malware loader used in multi-stage attacks, is now delivering NeedleStealer for financial theft. One payload imitates Ledger, Trezor, and Exodus wallets to steal recovery seed phrases, while another installs fake browser extensions to hijack sessions and collect credentials. The campaigns also use malware written in Rust and Golang, alongside in-memory execution, signed installers, and staged infrastructure. #ThreatIntel #Malware #CastleLoader #CyberSecurity
English
0
0
4
682
Hunt.io
Hunt.io@Huntio·
🦅 𝗙𝗹𝘆𝗶𝗻𝗴 𝗘𝗮𝗴𝗹𝗲 𝗔𝗻𝗱𝗿𝗼𝗶𝗱 𝗥𝗔𝗧: 𝗟𝗲𝗮𝗸𝗲𝗱 𝗦𝗼𝘂𝗿𝗰𝗲 𝗖𝗼𝗱𝗲, 𝟭𝟳𝟬 𝗦𝗲𝗿𝘃𝗲𝗿𝘀, 𝗮𝗻𝗱 𝗮 𝗡𝗲𝘄 𝗣𝗹𝗮𝘁𝗳𝗼𝗿𝗺 𝗖𝗮𝗹𝗹𝗲𝗱 𝗡𝗶𝗴𝗵𝘁 𝗗𝗿𝗮𝗴𝗼𝗻 In a joint investigation with @NetAskari, our research team traced a leaked Chinese Android RAT framework across 170 active servers, analyzed the APK builder internals, and uncovered a likely successor platform called Night Dragon (夜龙). Key findings: → A fake Public Security Bureau app was the starting point, confirmed in a June 2026 Chinese state media warning → Flying Eagle combines APK generation and C2 device management in one panel, with overlays for financial, adult, and government service apps → The source code was stolen in early 2026, along with nearly 200 customer databases, sending multiple variants into circulation → Two Telegram channels, SQLRCE0 and Yx科技, distribute patched versions with operational support and cash-out services at 20-50% fees → Night Dragon was introduced June 23, 2026, with version 2 already in development as of July 12 Full breakdown and IOCs here 👇 hunt.io/blog/flying-ea…
GIF
English
0
10
22
1.8K
Hunt.io
Hunt.io@Huntio·
🚀 What could your detections find with access to a much wider view of active C2 infrastructure? Hunt’s OEM C2 Feeds reveal attacker servers that are frequently absent from public OSINT sources, delivering up to 10 times more live C2 coverage. The data is checked daily to reduce noise, add useful context, and help teams act with greater confidence. Try it free for 14 days and explore the most recent seven days of high-fidelity C2 intelligence inside your existing workflow. Apply here 👉 hunt.io/oem-c2-threat-… #ThreatHunting #ThreatIntelligence
Hunt.io tweet media
English
0
1
5
479
Hunt.io
Hunt.io@Huntio·
⚠️ Operation STANDOFF Masks C2 Traffic Behind GitHub Redirects cybersecuritynews.com/standoff-hides… A Russian-speaking cybercrime campaign is hiding C2 infrastructure behind HTTP redirects to GitHub. Dubbed Operation STANDOFF, the campaign delivers multiple payloads in a single infection, including RedLine, Raccoon Stealer, Amadey, SmokeLoader, Glupteba, and XMRig. The installed malware can steal credentials, mine cryptocurrency, turn infected devices into traffic relays, and give operators a foothold for deeper network intrusions. #ThreatIntel #Malware #Github #CyberSecurity
English
0
4
16
1.3K
Hunt.io
Hunt.io@Huntio·
@NetAskari @AnthropicAI Really solid work here! Seeing our platform and data help track down campaigns like this is the whole point, so it's great to watch it in action! Keep them coming 🔥
English
0
0
3
231
Hunt.io retweetledi
NetAskari
NetAskari@NetAskari·
Chinese hackers tricking Claude into becoming a quasi autonomous multi-attack agent against websites, is something @AnthropicAI has reported on already end of 2025. Announcing better guardrails. A dataset we received via @Huntio shows that Claude is still tricked into playing "CTF" against actual live targets today in an attempt to hack into systems ( though it seems mainly old model version ) . 🧵1/6
NetAskari tweet media
English
4
40
174
16.3K
Hunt.io
Hunt.io@Huntio·
🚩 Cl0p Exploits Windchill to Deploy Webshells and Steal Data cyberpress.org/cl0p-exploits-… Cl0p is exploiting a critical PTC Windchill and FlexPLM zero-day to break into internet-facing PLM environments without authentication. The campaign chains a FlexPLM information leak with a Windchill flaw, then drops hex-named JSP webshells for persistent access. From there, attackers map files, identify CAD and engineering repositories, stage sensitive project data, and prepare it for theft. #ThreatIntel #Cl0p #Malware #FlexPLM #CyberSecurity
English
0
4
10
851
Hunt.io
Hunt.io@Huntio·
🚨 Laundry Bear Targets US and Ukraine Through Zimbra darkreading.com/cyberattacks-d… Russian state-backed group Laundry Bear is exploiting the Zimbra zero-day CVE-2025-66376 to target US and Ukrainian government, defense, and scientific organizations. The attack doesn't require victims to open an attachment or follow a link. Simply opening or previewing an email in a vulnerable Zimbra webmail client could trigger a malicious JavaScript payload. The exploit collects up to 90 days of emails and data, then sends everything to attacker-controlled infrastructure. Zimbra patched the flaw last year, but unpatched servers remain exposed. #ThreatIntel #LaundryBear #Zimbra #CyberSecurity
English
1
1
18
1.4K
Hunt.io
Hunt.io@Huntio·
🚩 TinyEgg and ChonkyChicken Join the Golden Chickens Ecosystem thehackernews.com/2026/07/golden… Golden Chickens is back with four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. This time, the operation is moving toward modular tooling. Attackers can load specific capabilities on demand, from credential theft and keylogging to screen capture, network recon, and audio collection. TinyEgg handles initial access, while ChonkyChicken takes over post-exploitation. ClickFix-style lures remain part of the delivery chain, showing the MaaS operation is still active and continuing to rely on familiar tactics. #ThreatIntelligence #GoldenChickens #Malware #CyberSecurity
English
0
4
16
1.3K
Hunt.io
Hunt.io@Huntio·
📌 Suspected Chinese Operators Integrate LLMs Into Cyberattacks In an entry published on our blog last week, we uncovered an active intrusion campaign where suspected China-based operators used Claude Code and DeepSeek-v4-pro as part of their workflow. Claude Code handled execution and persistent sessions, while DeepSeek drove attack reasoning, exploit changes, and phishing development. The exposed infrastructure revealed attacks against government systems in Afghanistan, Thailand, and Taiwan, U.S. reconnaissance, and scans of more than 5,890 government hosts across 10 countries. A single infrastructure pivot was the starting point. Check out the full article here 👉 hunt.io/blog/chinese-o… #ThreatHunting #ThreatIntelligence #CyberSecurity
English
2
18
67
5.2K