⤷ Title: Questions From a Beginner Threat Hunter
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 30 Jan 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Hunt Teaming #Informational #InfoSec 101 #Beginner #On the Hunt #PROMPT# #Q&A #threat hunting
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 30 Jan 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Hunt Teaming #Informational #InfoSec 101 #Beginner #On the Hunt #PROMPT# #Q&A #threat hunting
Black Hills Information Security, Inc.
Questions From a Beginner Threat Hunter - Black Hills Information Security, Inc.
Answered by Chris Brenton of Active Countermeasures | Questions compiled from the infosec community by Shelby Perry This article was originally published in the Threat Hunting issue of our infosec […]
⤷ Title: APT36 Suspected in India Gov Spoofing Phishing with ClickFix Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT36 #ClickFix #cyberattack #Government #Hunt.io #India #Indian Ministry #Linux #Linux Malware #malware #phishing #social engineering #Threat Hunting #threat intelligence #Transparent Tribe #windows #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT36 #ClickFix #cyberattack #Government #Hunt.io #India #Indian Ministry #Linux #Linux Malware #malware #phishing #social engineering #Threat Hunting #threat intelligence #Transparent Tribe #windows #Windows malware
Daily CyberSecurity
APT36 Suspected in India Gov Spoofing Phishing with ClickFix Tactics
A sophisticated phishing campaign, possibly by APT36, spoofs Indian government sites and uses ClickFix tactics to target Windows and Linux users.
⤷ Title: Alert: Hunt.io Uncovers SpyNote Android Spyware Disguised as Popular Apps on Open Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 06:57:54 +0000
════════════════════════
⌗ Tags: #Malware #android #cybersecurity #Data Harvesting #Hunt.io #Malicious apps #malware #mobile security #SpyNote #spyware #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 06:57:54 +0000
════════════════════════
⌗ Tags: #Malware #android #cybersecurity #Data Harvesting #Hunt.io #Malicious apps #malware #mobile security #SpyNote #spyware #surveillance
Daily CyberSecurity
Alert: Hunt.io Uncovers SpyNote Android Spyware Disguised as Popular Apps on Open Servers
Hunt.io researchers uncovered dozens of malicious Android apps disguised as popular programs on open servers, which are fronts for SpyNote spyware, harvesting sensitive user data.
⤷ Title: Leaked Source Code Exposes ERMAC 3.0: A Dangerous Trojan with Flawed Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 Aug 2025 08:37:45 +0000
════════════════════════
⌗ Tags: #Malware #Android #banking trojan #cybersecurity #ERMAC #Hunt.io #Malware_as_a_Service #ThreatFabric
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 Aug 2025 08:37:45 +0000
════════════════════════
⌗ Tags: #Malware #Android #banking trojan #cybersecurity #ERMAC #Hunt.io #Malware_as_a_Service #ThreatFabric
Penetration Testing Tools
Leaked Source Code Exposes ERMAC 3.0: A Dangerous Trojan with Flawed Security
A new analysis of the leaked ERMAC 3.0 source code reveals critical vulnerabilities in the malware's infrastructure, despite its advanced features.
⤷ Title: Stop Spoofing Yourself! Disabling M365 Direct Send
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #Patterson Cake #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #Patterson Cake #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Stop Spoofing Yourself! Disabling M365 Direct Send - Black Hills Information Security, Inc.
Remember the good ‘ol days of Zip drives, Winamp, the advent of “Office 365,” and copy machines that didn’t understand email authentication? Okay, maybe they weren’t so good! For a […]
⤷ Title: Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 14:09:33 +0000
════════════════════════
⌗ Tags: #Blue Team #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 14:09:33 +0000
════════════════════════
⌗ Tags: #Blue Team #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1) - Black Hills Information Security, Inc.
In part 1 of this post, we’ll discuss how Hayabusa and “Security Operations and Forensics ELK” (SOF-ELK) can help us wrangle EVTX files (Windows Event Log files) for maximum effect during a Windows endpoint investigation!
⤷ Title: Beyond Trust: A New Campaign Is Using a Legitimate Tool to Deliver RATs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:10:48 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #ConnectWise ScreenConnect #cybersecurity #Hunt Intelligence #malware #phishing #Remote Access Trojan #RMM tool abuse #supply chain risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:10:48 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #ConnectWise ScreenConnect #cybersecurity #Hunt Intelligence #malware #phishing #Remote Access Trojan #RMM tool abuse #supply chain risk
Daily CyberSecurity
Beyond Trust: A New Campaign Is Using a Legitimate Tool to Deliver RATs
A new report reveals attackers are abusing ScreenConnect to deliver AsyncRAT and custom malware payloads, a serious supply chain risk for enterprises and MSPs.
⤷ Title: Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) - Black Hills Information Security, Inc.
But what if we need to wrangle Windows Event Logs for more than one system? In part 2, we’ll wrangle EVTX logs at scale by incorporating Hayabusa and SOF-ELK into my rapid endpoint investigation workflow (“REIW”)!
⤷ Title: Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
Daily CyberSecurity
Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
A joint Hunt.io and Acronis report exposes the shared infrastructure behind Lazarus and Kimsuky, revealing the unified web of North Korean hacking.
⤷ Title: Shared Shadows: Hunt.io Uncovers the Unified Staging Grounds of Lazarus and Kimsuky
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Badcall #BLINDINGCAN #Cyber Espionage #DPRK #Fast Reverse Proxy (FRP) #HttpTroy #Hunt.io #Kimsuky #Lazarus Group #Malware Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Badcall #BLINDINGCAN #Cyber Espionage #DPRK #Fast Reverse Proxy (FRP) #HttpTroy #Hunt.io #Kimsuky #Lazarus Group #Malware Infrastructure
Penetration Testing Tools
Shared Shadows: Hunt.io Uncovers the Unified Staging Grounds of Lazarus and Kimsuky
Groups operating in the interests of the DPRK continue to aggressively expand their infrastructure for cyber espionage, financial
⤷ Title: Inside the Arsenal: Exposed Server Reveals APT28’s ‘Roundish’ Toolkit and Advanced Cyber Espionage Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
Daily CyberSecurity
Inside the Arsenal: Exposed Server Reveals APT28's 'Roundish' Toolkit and Advanced Cyber Espionage Tactics
Hunt Intelligence unmasks APT28's 'Roundish' toolkit from an exposed server, revealing advanced CSS side-channel attacks and stealthy Linux implants.
⤷ Title: Inside Canis C2: The ‘Wide Open’ Surveillance Engine Targeting Every Major OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:00:53 +0000
════════════════════════
⌗ Tags: #Malware #AI_assisted development #AiTM #Android APK #Canis C2 #cyber_espionage #Hunt.io #iOS Malware #malware #Paidy #phishing #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:00:53 +0000
════════════════════════
⌗ Tags: #Malware #AI_assisted development #AiTM #Android APK #Canis C2 #cyber_espionage #Hunt.io #iOS Malware #malware #Paidy #phishing #surveillance
Daily CyberSecurity
Inside Canis C2: The 'Wide Open' Surveillance Engine Targeting Every Major OS
Hunt.io discovers Canis C2, an AI-assisted surveillance framework targeting all major OSs. An exposed API revealed payloads and source code. Read more here.
⤷ Title: The Tadashi Files: Inside the xlabs_v1 Botnet Targeting 4 Million Android Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 03 May 2026 02:17:23 +0000
════════════════════════
⌗ Tags: #Malware #ADB Exploit #Android Malware #cybersecurity #DDoS_for_hire #Hunt Intelligence #IoT security #Mirai botnet #Port 5555 #RakNet Flood #Tadashi #xlabs_v1
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 03 May 2026 02:17:23 +0000
════════════════════════
⌗ Tags: #Malware #ADB Exploit #Android Malware #cybersecurity #DDoS_for_hire #Hunt Intelligence #IoT security #Mirai botnet #Port 5555 #RakNet Flood #Tadashi #xlabs_v1
Daily CyberSecurity
The Tadashi Files: Inside the xlabs_v1 Botnet Targeting 4 Million Android Devices
Hunt Intelligence dismantles xlabs_v1, a Mirai-derived botnet targeting 4M Android devices via port 5555. See how an exposed server leaked the entire toolkit.