A few months back we identified Drone Swarm related decoys on a malware delivery campaign delivering a Rust RAT & stealer:
Staging: 5.252.177.210:8090
C2: 5.252.177.215:8080
Found via @Huntio. Read more 👇
Our first “Bulletin” published to the blog by two handsome @ctrlaltintel contributors 👏
An open-dir found on @Huntio revealed:
- JS ClickFix lure payloads
- Rust droppers
- Stealers
- Miners
Check out link below 👇👇👇
🕵️♂️ 🏴 𝗨𝗞 𝗰𝗼𝘂𝗻𝗰𝗶𝗹 𝗯𝗿𝗲𝗮𝗰𝗵 𝘁𝗿𝗮𝗰𝗲𝘀 𝘁𝗼 𝗺𝗮𝘀𝘀 𝗦𝗼𝗻𝗶𝗰𝗪𝗮𝗹𝗹 𝗦𝗠𝗔𝟭𝟬𝟬𝟬 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻
On 17 July, King's Lynn and West Norfolk Borough Council went public with a cyberattack on its services. The @BBC covered it. We assess with moderate confidence it connects to something much larger.
Two days after @SonicWall disclosed CVE-2026-15409, an operator was already scanning and exploiting SMA1000 appliances at scale. We found the whole operation in an open directory, captured by AttackCapture the same day it was still in use.
The interesting part is what they did with the appliances. Instead of pivoting to a Windows host, they dropped a standalone Linux build of Impacket's secretsdump straight onto the SonicWall box and ran credential theft from there. Most orgs watch their EDR-covered endpoints closely and their firewall and VPN appliances barely at all. That gap is the whole point.
What the recovered data showed:
- 250 targets identified as exploitable, LDAP config pulled from 168 of them
- 534 config records covering 160 unique AD domains and 255 internal LDAP servers
- SAM and LSA secrets recovered from at least 9 Active Directory domains
- Full DCSync against 7 domain controllers across 5 environments
- Confirmed credential theft spanning France, India, Italy and the US
Targeting was opportunistic, not sector-specific. Local government, healthcare, universities, finance and manufacturing all showed up in the target list, they picked victims because the appliance was vulnerable.
Full writeup, IOCs and MITRE mapping here 👇
hunt.io/blog/sonicwall…
TA leveraged modified POCs to automate intrusions & credential theft
🇨🇳 comments seen across the toolkit
Check out the write up of the campaign by @Huntio:
hunt.io/blog/sonicwall…
On July 17th, a UK council faced a cyber attack on election day
A actor compromised 150+ Sonicwall devices via CVE-2026-15409, including the council, the same day.
- Impacket binaries deployed to Sonicwall
- Automated cred theft & DCSync from firewall
@Huntio 👇
@Huntio In in the below case, @Huntio observed a custom MCP for writing, deploying and managing webshells
hunt.io/blog/chinese-o…
In separate case, we saw MCPs for running VShell leveraged by TAs
(3/3)
In the past 6 months there has been a huge increase in full intrusions conducted by AI agents
@Huntio recently reported on one of these campaigns targeting entities in Asia (2/3)
Very interesting campaign reported by @GreyNoiseIO on recent AI-orchestrated PaperCut intrusions. Linked open-dir found on @Huntio
Interestingly a previous Devman victim from UK healthcare sector was seen targeted separately in this PaperCut campaign 😟 (1/3)
@ImposeCost AI agents being abused for semi-autonomous intrusions is happening a scary amount right now (and past few months).
However, the agents do lack OPSEC, often leaving open-directories up that expose the whole operation, so it's easy to find.
🚨 𝗥𝗲𝗱𝗶𝘀 𝗖𝗿𝘆𝗽𝘁𝗼𝗺𝗶𝗻𝗶𝗻𝗴 𝗕𝗼𝘁𝗻𝗲𝘁: 𝟯,𝟱𝟲𝟮 𝗦𝗲𝗿𝘃𝗲𝗿𝘀 𝗖𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲𝗱, 𝗘𝘅𝗽𝗼𝘀𝗲𝗱 𝗯𝘆 𝘁𝗵𝗲 𝗢𝗽𝗲𝗿𝗮𝘁𝗼𝗿'𝘀 𝗢𝘄𝗻 𝗙𝗶𝗹𝗲𝘀
An open directory on a Hetzner box left the whole operation sitting in plain view. Not just a payload, the operator's entire working toolkit: exploit source, campaign logs, a bundled Python runtime, even two exported Windows registry hives.
We parsed their own campaign logs instead of trusting the summaries their scripts print. Here is what the numbers actually say:
→ 3,562 distinct Redis servers compromised, out of 12,966 targeted, across two separate runs
→ Only one technique worked at scale: rogue replication (SLAVEOF/RDB) into a cron entry that pulls XMRig
→ SSH key injection and MongoDB sandbox escape returned zero across 2,810 attempts
→ Victims run everything from Redis 2.8.17 (2015) to 7.2.0 (2023), so the weakness is missing auth, not a version bug
→ The same Monero wallet links this campaign to a separate February 2026 directory in Moldova, pushing known activity back at least five months
Check out the full breakdown 👇
hunt.io/blog/redis-cry…
We recently published the first part of our investigation into a fake recruitment campaign targeting the cryptocurrency industry. We're following up with the second part of our investigation, diving into a variant of the same infostealer targeting macOS users ⬇️
🇨🇳 🤖 𝗡𝗘𝗪 𝗥𝗘𝗦𝗘𝗔𝗥𝗖𝗛: 𝗖𝗵𝗶𝗻𝗲𝘀𝗲-𝗦𝗽𝗲𝗮𝗸𝗶𝗻𝗴 𝗢𝗽𝗲𝗿𝗮𝘁𝗼𝗿 𝗨𝘀𝗲𝘀 𝗔𝗜 𝗔𝗴𝗲𝗻𝘁𝘀 𝘁𝗼 𝗧𝗮𝗿𝗴𝗲𝘁 𝗚𝗼𝘃𝗲𝗿𝗻𝗺𝗲𝗻𝘁 𝗮𝗻𝗱 𝗘𝗱𝘂𝗰𝗮𝘁𝗶𝗼𝗻 𝗦𝘆𝘀𝘁𝗲𝗺𝘀 𝗔𝗰𝗿𝗼𝘀𝘀 𝗔𝘀𝗶𝗮
Our research team identified five exposed open directories revealing a campaign that used an orchestration framework called SecFlow to coordinate Claude, Qwen, and DeepSeek AI workers across intrusions targeting government, education, consular, and healthcare systems in Asia.
Key observations:
- A shared SOCKS endpoint connected all five workspaces, confirmed through 120 code-search matches on our platform
- The deepest compromise hit a Fengtai District government OA environment: command execution, LSASS dumps, registry hives, 822 account records extracted, and a Go implant called SecBox deployed
- A Chinese education AI platform was compromised, exposing 23 agent configurations, production credentials, and student profile data across 169 conversations
- SecFlow split reconnaissance, exploitation, and reporting across specialist AI workers, with the runtime swapping between Claude, Qwen, and DeepSeek without changing the task interface
- GLUTTON webshells transported executable bytecode inside PNG image pixels using XOR encryption, loading directly into memory while the visible server file remained a generic decoder
- A fake MySQL deserialization service delivered Linux second-stage payloads to vulnerable Java clients that connected to it
- Eight CVEs in active workflows, including Shellshock, Spring4Shell, Ghostcat, Log4Shell, Shiro deserialization, Grafana and Nexus path traversals, and Nacos authentication bypass
- The AI's shared context amplified a false positive: an unsupported Shiro success claim persisted and drove 27+ follow-up tasks that produced nothing
This is the second separate campaign we've tracked where commercial AI models were used as operational components in intrusions. Different infrastructure and tooling from our July report, but the same pattern.
Read the full report here👇
hunt.io/blog/chinese-o…
Hunting for C2 #OPSEC failures w.
@Huntio: Cobalt Strike edition 🧵
- CS is commercial adversary simulation tooling, cracked versions often abused by TAs
- Uses "beacons" as a primary implant, managed by a "Team Servers"
- abused by cybercrime & APTs
(1/n)
6 Followers 441 FollowingData Architecture and Design Chronicles | GCP | AWS | Multicloud | Big Data | Open source technologies such as Iceberg, beam, DBT
9K Followers 890 FollowingBad guy chaser, writer/author, espionage & ransomware SME. Sometimes I harass my dog. He is the brains behind these projects and opinions are his.
7K Followers 956 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.