# Hunt.io > Hunt.io is a threat intelligence and adversary infrastructure platform from Hunt Intelligence, Inc. We track command-and-control servers, open directories, phishing kits, and malware infrastructure used by threat actors worldwide. Core capabilities include HuntSQL (an infrastructure query engine), AttackCapture (open directory intelligence), IOC Hunter, IP and domain enrichment, a C2 feed, and a remote MCP server for AI assistants. The platform is used by SOC teams, threat hunters, CERTs, MSSPs, and security researchers who need to find malicious infrastructure before it reaches their environment. The Hunt.io blog publishes original research on APT groups, ransomware crews, phishing operators, and exposed attacker tooling. The malware families library and glossary act as a reference for analysts. Demos: https://hunt.io/get-started Free accounts: https://app-v1.hunt.io/register API and platform documentation: https://a.hunt.io Remote MCP server: https://mcp.hunt.io ## Platform - [Homepage](https://hunt.io/): Hunt.io overview and main entry point. - [About](https://hunt.io/about): Company background and team. - [Pricing](https://hunt.io/pricing): Subscription plans and tier breakdown. - [Use Cases](https://hunt.io/use-cases): How analysts, SOCs, and researchers use Hunt.io in practice. - [Reviews](https://hunt.io/reviews): Customer feedback and quotes. - [Get Started](https://hunt.io/get-started): Demo request form for the sales team. - [Contact](https://hunt.io/contact-us): Sales and general inquiries. - [Integrations](https://hunt.io/integrations): Third-party tool integrations. - [Changelog](https://hunt.io/changelog): Platform release notes and updates. - [MalOps](https://hunt.io/malops): MalOps service for managed malware tracking. - [OEM Program](https://hunt.io/oem): The Censys alternative for threat intelligence partners. - [OEM C2 Threat Feeds](https://hunt.io/oem-c2-threat-feeds): C2 feed licensing for OEM partners. ## Products - [Cyber Threat Intelligence Feeds](https://hunt.io/products/cyber-threat-intelligence-feeds): Curated feeds covering C2 servers, malware infrastructure, and other indicators. - [Cyber Threat Enrichment API](https://hunt.io/products/cyber-threat-enrichment-api): API for enriching IPs, domains, and hashes with Hunt.io context. - [Web Interface](https://hunt.io/products/web-interface): The Hunt.io web app for interactive hunting and investigation. ## Features - [Features Overview](https://hunt.io/features): Index of platform capabilities. - [HuntSQL](https://hunt.io/features/hunt-sql): SQL-style query engine over Hunt.io's infrastructure datasets. - [AttackCapture](https://hunt.io/features/attackcapture): Open directory and exposed attacker tooling intelligence. - [IOC Hunter](https://hunt.io/features/ioc-hunter): Pivot and enrichment workflow for IPs, domains, and hashes. - [JA4 Fingerprinting](https://hunt.io/features/ja4): JA4 family of fingerprints for clustering and detection. - [Phishing Infrastructure Detection](https://hunt.io/features/phishing-infrastructure-detection): Detection signals for phishing kits and operator infrastructure. - [C2 Infrastructure Tracking](https://hunt.io/features/c2-infrastructure): Tracking of command-and-control servers across known frameworks. - [Bulk Enrichment](https://hunt.io/features/bulk-enrichment): Enrich large lists of indicators in a single workflow. ## Learning Resources - [Modern Threat Hunting](https://hunt.io/learning/modern-threat-hunting): eBook on practical threat hunting techniques. - [The Threat Hunter's Report Template](https://hunt.io/learning/the-threat-hunters-report-template): Reusable template for documenting threat hunt findings. - [Threat Hunter's Query Playbook](https://hunt.io/learning/threat-hunters-query-playbook): Reference playbook for HuntSQL queries across datasets. ## Glossary Reference entries explaining threat hunting and threat intelligence concepts. - [Glossary Index](https://hunt.io/glossary): Index of all glossary entries. - [Threat Hunting](https://hunt.io/glossary/threat-hunting): Overview of threat hunting as a discipline. - [Advanced Threat Hunting](https://hunt.io/glossary/advanced-threat-hunting): Mature practices for proactive threat hunting. - [Threat Hunting Techniques](https://hunt.io/glossary/threat-hunting-techniques): Common analytical techniques used by hunters. - [Threat Hunting Process](https://hunt.io/glossary/threat-hunting-process): Workflow steps for running a hunt. - [Threat Hunting Framework](https://hunt.io/glossary/threat-hunting-framework): Frameworks that structure hunting programs. - [Best Threat Hunting Frameworks](https://hunt.io/glossary/best-threat-hunting-frameworks): Comparison of widely used frameworks. - [Threat Hunting Loop](https://hunt.io/glossary/threat-hunting-loop): The iterative loop model for threat hunting. - [Threat Hunting Maturity Model](https://hunt.io/glossary/threat-hunting-maturity-model): Maturity levels for hunting programs. - [Types of Threat Hunting](https://hunt.io/glossary/types-of-threat-hunting): Structured, unstructured, and situational hunting modes. - [Threat Hunting Examples](https://hunt.io/glossary/threat-hunting-examples): Worked examples of real hunts. - [Threat Hunting Tools](https://hunt.io/glossary/threat-hunting-tools): Tooling categories used in hunting workflows. - [Threat Hunting Playbooks](https://hunt.io/glossary/threat-hunting-playbooks): Playbook concept and use in hunting. - [Threat Hunting Program](https://hunt.io/glossary/threat-hunting-program): Building and running a hunting program. - [Threat Hunting Report Template](https://hunt.io/glossary/threat-hunting-report-template): Templating notes for hunting reports. - [Peak Threat Hunting Framework](https://hunt.io/glossary/peak-threat-hunting-framework): The PEAK framework explained. - [Sqrrl Threat Hunting Framework](https://hunt.io/glossary/sqrrl-threat-hunting-framework): Sqrrl's framework and how it is used. - [TTP Threat Hunting](https://hunt.io/glossary/ttp-threat-hunting): TTP-driven hunting approaches. - [SOC Threat Hunting](https://hunt.io/glossary/soc-threat-hunting): Hunting from inside a SOC. - [Managed Threat Hunting](https://hunt.io/glossary/managed-threat-hunting): MDR and managed hunting services. - [Threat Hunting in the Cloud](https://hunt.io/glossary/threat-hunting-in-the-cloud): Hunting across cloud workloads. - [AWS Threat Hunting](https://hunt.io/glossary/aws-threat-hunting): Hunting techniques specific to AWS environments. - [Splunk Threat Hunting](https://hunt.io/glossary/splunk-threat-hunting): Hunting workflows in Splunk. - [Linux Threat Hunting](https://hunt.io/glossary/linux-threat-hunting): Hunting techniques on Linux hosts. - [Malware Hunting](https://hunt.io/glossary/malware-hunting): Finding malware in the wild and in environments. - [Best Threat Hunting Certifications](https://hunt.io/glossary/best-threat-hunting-certifications): Certifications relevant to threat hunters. - [Threat Hunting vs Threat Intelligence](https://hunt.io/glossary/threat-hunting-vs-threat-intelligence): How the two disciplines differ. - [Top Threat Hunting Platforms](https://hunt.io/glossary/top-threat-hunting-platforms): Vendor and platform comparison. - [Threat Detection Tools](https://hunt.io/glossary/threat-detection-tools): Detection tooling categories. - [Indicators of Compromise (IOCs)](https://hunt.io/glossary/indicators-of-compromise-iocs): Definition and types of IOCs. - [Indicators of Compromise Tools](https://hunt.io/glossary/indicators-of-compromise-tools): Tools for working with IOCs. - [Best IOC Feeds](https://hunt.io/glossary/best-ioc-feeds): Comparison of IOC feed sources. - [Best Threat Intelligence Feeds](https://hunt.io/glossary/best-threat-intelligence-feeds): Comparison of intelligence feed providers. - [Best Malware Feeds](https://hunt.io/glossary/best-malware-feeds): Malware sample and tracker feeds. - [VirusTotal Alternatives for Threat Hunters](https://hunt.io/glossary/virustotal-alternatives-for-threat-hunters): Tools that complement or replace VirusTotal. - [ThreatFox Alternatives](https://hunt.io/glossary/threatfox-alternatives): Alternatives to abuse.ch ThreatFox. - [Command and Control Server (C2)](https://hunt.io/glossary/command-and-control-server-c2): C2 server fundamentals. - [C2 Channels](https://hunt.io/glossary/c2-channels): Communication channels used by C2 frameworks. - [C2 Beaconing](https://hunt.io/glossary/c2-beaconing): Beaconing patterns and detection. - [C2 Nodes](https://hunt.io/glossary/c2-nodes): Nodes in a C2 infrastructure. - [Detect C2](https://hunt.io/glossary/detect-c2): Approaches to detecting C2 traffic. - [C2 Frameworks Explained](https://hunt.io/glossary/c2-frameworks-explained): Overview of common C2 frameworks. - [C2 Tracker for C2 Hunting](https://hunt.io/glossary/c2-tracker-for-c2-hunting): Using C2 trackers in hunts. - [Cobalt Strike](https://hunt.io/glossary/cobalt-strike): Cobalt Strike framework reference. - [Open Directories](https://hunt.io/glossary/open-directories): What open directories are and why they matter. - [How to Find Open Directories](https://hunt.io/glossary/how-to-find-open-directories): Techniques for surfacing open directories. - [JA4 Fingerprinting](https://hunt.io/glossary/ja4-fingerprinting): JA4 family of network fingerprints. - [DGA Domain Generation Algorithms](https://hunt.io/glossary/dga-domain-generation-algorithms): How DGAs work and how to detect them. - [Attack Vectors](https://hunt.io/glossary/attack-vectors): Common attack vectors used by threat actors. - [Cybercrime Investigation](https://hunt.io/glossary/cybercrime-investigation): Investigative practices for cybercrime cases. - [Cost of Cyberattacks for Banks](https://hunt.io/glossary/cost-of-cyberattacks-for-banks): Financial impact of attacks on banks. - [Detecting Threats in Financial Supply Chains](https://hunt.io/glossary/detecting-threats-in-financial-supply-chains): Supply chain threat detection in finance. - [Threat Detection for Financial Institutions](https://hunt.io/glossary/threat-detection-for-financial-institutions): Detection priorities for banks and fintech. - [JARM Fingerprints: A Practical Lens for TLS-Based Threat Hunting](https://hunt.io/glossary/jarm-fingerprinting): JARM Fingerprints: Identifying Servers via TLS Handshakes. ## Malware Families Reference profiles of malware families, C2 frameworks, RATs, stealers, loaders, and offensive tooling tracked by Hunt.io. - [Malware Families Index](https://hunt.io/malware-families): Index of all malware family profiles. - [Cobalt Strike](https://hunt.io/malware-families/cobalt-strike): Cobalt Strike profile and infrastructure tracking notes. - [Sliver](https://hunt.io/malware-families/sliver): Sliver C2 framework profile. - [Havoc](https://hunt.io/malware-families/havoc): Havoc C2 framework profile. - [Metasploit](https://hunt.io/malware-families/metasploit): Metasploit framework profile. - [Metasploit Meterpreter](https://hunt.io/malware-families/metasploit-meterpreter): Meterpreter payload profile. - [Mitre Caldera](https://hunt.io/malware-families/mitre-caldera): Caldera adversary emulation profile. - [Covenant](https://hunt.io/malware-families/covenant): Covenant C2 profile. - [Nighthawk C2](https://hunt.io/malware-families/nighthawk-c2): Nighthawk C2 profile. - [Deimos C2](https://hunt.io/malware-families/deimos-c2): Deimos C2 profile. - [Pupy C2](https://hunt.io/malware-families/pupy-c2): Pupy C2 profile. - [Posh C2](https://hunt.io/malware-families/posh-c2): PoshC2 profile. - [Viper](https://hunt.io/malware-families/viper): Viper C2 profile. - [Vshell](https://hunt.io/malware-families/vshell): Vshell C2 profile. - [Supershell](https://hunt.io/malware-families/supershell): Supershell profile. - [Nimplant](https://hunt.io/malware-families/nimplant): Nimplant implant profile. - [Joker C2 (Nosviak4)](https://hunt.io/malware-families/nosviak4): Nosviak4 / Joker C2 profile. - [Nosu](https://hunt.io/malware-families/nosu): Nosu profile. - [Ares](https://hunt.io/malware-families/ares): Ares RAT profile. - [Pantegana RAT](https://hunt.io/malware-families/pantegana-rat): Pantegana RAT profile. - [Chaos RAT](https://hunt.io/malware-families/chaos-rat): Chaos RAT profile. - [Quasar](https://hunt.io/malware-families/quasar): Quasar RAT profile. - [njRAT](https://hunt.io/malware-families/njrat): njRAT profile. - [DcRAT](https://hunt.io/malware-families/dcrat): DcRAT profile. - [VenomRAT](https://hunt.io/malware-families/venomrat): VenomRAT profile. - [XenoRAT](https://hunt.io/malware-families/xenorat): XenoRAT profile. - [Orcus RAT](https://hunt.io/malware-families/orcus-rat): Orcus RAT profile. - [DarkComet](https://hunt.io/malware-families/darkcomet): DarkComet RAT profile. - [SparkRAT](https://hunt.io/malware-families/sparkrat): SparkRAT profile. - [SpyNote](https://hunt.io/malware-families/spynote): SpyNote Android RAT profile. - [SpyAgent](https://hunt.io/malware-families/spyagent): SpyAgent profile. - [BYOB](https://hunt.io/malware-families/byob): BYOB botnet framework profile. - [BlueShell Backdoor](https://hunt.io/malware-families/blueshell-backdoor): BlueShell backdoor profile. - [Oyster Backdoor](https://hunt.io/malware-families/oyster-backdoor): Oyster backdoor profile. - [KTLV Backdoor](https://hunt.io/malware-families/ktlv-backdoor): KTLV backdoor profile. - [Dacls](https://hunt.io/malware-families/dacls): Dacls backdoor profile. - [DoomedLoader](https://hunt.io/malware-families/doomedloader): DoomedLoader profile. - [Neptune Loader](https://hunt.io/malware-families/neptune-loader): Neptune loader profile. - [Bumblebee](https://hunt.io/malware-families/bumblebee): Bumblebee loader profile. - [JinxLoader](https://hunt.io/malware-families/jinxloader): JinxLoader profile. - [Godzilla Loader](https://hunt.io/malware-families/godzilla-loader): Godzilla loader profile. - [Matanbuchus](https://hunt.io/malware-families/matanbuchus): Matanbuchus loader profile. - [PlugX](https://hunt.io/malware-families/plugx): PlugX backdoor profile. - [PlugX C2 Profile](https://hunt.io/malware-families/plugx-c2-profile): PlugX C2 infrastructure profile. - [PlugX Malleable C2 Profile](https://hunt.io/malware-families/plugx-malleable-c2-profile): PlugX malleable C2 notes. - [KeyPlug](https://hunt.io/malware-families/keyplug): KeyPlug profile. - [ShadowPad](https://hunt.io/malware-families/shadowpad): ShadowPad profile. - [Winnti](https://hunt.io/malware-families/winnti): Winnti malware profile. - [Hodur](https://hunt.io/malware-families/hodur): Hodur profile. - [Earth Baxia](https://hunt.io/malware-families/earth-baxia): Earth Baxia activity cluster profile. - [CloudSorcerer APT](https://hunt.io/malware-families/cloudsorcerer-apt): CloudSorcerer activity profile. - [Kimsuky](https://hunt.io/malware-families/kimsuky): Kimsuky APT profile. - [APT Gamaredon](https://hunt.io/malware-families/apt-gamaredon): Gamaredon APT profile. - [Volt Typhoon APT](https://hunt.io/malware-families/volt-typhoon-apt): Volt Typhoon profile. - [MuddyWater APT](https://hunt.io/malware-families/muddywater-apt): MuddyWater APT profile. - [LightSpy](https://hunt.io/malware-families/lightspy): LightSpy surveillance malware profile. - [Lumma Stealer](https://hunt.io/malware-families/lumma-stealer): Lumma stealer profile. - [LummaC2 Stealer](https://hunt.io/malware-families/lummac2-stealer): LummaC2 stealer profile. - [RedLine Stealer](https://hunt.io/malware-families/redline-stealer): RedLine stealer profile. - [Vidar](https://hunt.io/malware-families/vidar): Vidar stealer profile. - [Stealc](https://hunt.io/malware-families/stealc): Stealc stealer profile. - [Raccoon Stealer](https://hunt.io/malware-families/raccoon-stealer): Raccoon stealer profile. - [Atomic Stealer](https://hunt.io/malware-families/atomic-stealer): AMOS / Atomic stealer profile. - [Aurora Stealer](https://hunt.io/malware-families/aurora-stealer): Aurora stealer profile. - [Mystic Stealer](https://hunt.io/malware-families/mystic-stealer): Mystic stealer profile. - [Meduza](https://hunt.io/malware-families/meduza): Meduza stealer profile. - [Misha Stealer](https://hunt.io/malware-families/misha-stealer): Misha stealer profile. - [Power Stealer](https://hunt.io/malware-families/power-stealer): Power stealer profile. - [Risepro](https://hunt.io/malware-families/risepro): Risepro stealer profile. - [Serpent Stealer](https://hunt.io/malware-families/serpent-stealer): Serpent stealer profile. - [Titan Stealer](https://hunt.io/malware-families/titan-stealer): Titan stealer profile. - [Bandit Stealer](https://hunt.io/malware-families/bandit-stealer): Bandit stealer profile. - [Ficker Stealer](https://hunt.io/malware-families/ficker-stealer): Ficker stealer profile. - [Armageddon Stealer](https://hunt.io/malware-families/armageddon-stealer): Armageddon stealer profile. - [Axile Stealer](https://hunt.io/malware-families/axile-stealer): Axile stealer profile. - [Easy Stealer](https://hunt.io/malware-families/easy-stealer): Easy stealer profile. - [Epsilon Stealer](https://hunt.io/malware-families/epsilon-stealer): Epsilon stealer profile. - [Gotham Stealer](https://hunt.io/malware-families/gotham-stealer): Gotham stealer profile. - [Imbetter](https://hunt.io/malware-families/imbetter): Imbetter stealer profile. - [XeHookStealer](https://hunt.io/malware-families/xehookstealer): XeHookStealer profile. - [AzorUlt](https://hunt.io/malware-families/azorult): AzorUlt stealer profile. - [Lokibot](https://hunt.io/malware-families/lokibot): Lokibot profile. - [Rhadamanthys](https://hunt.io/malware-families/rhadamanthys): Rhadamanthys stealer profile. - [SolarMarker](https://hunt.io/malware-families/solarmarker): SolarMarker profile. - [Pikabot](https://hunt.io/malware-families/pikabot): Pikabot loader profile. - [IcedID](https://hunt.io/malware-families/icedid): IcedID profile. - [Gozi](https://hunt.io/malware-families/gozi): Gozi banking trojan profile. - [Ursnif](https://hunt.io/malware-families/ursnif): Ursnif banking trojan profile. - [Emotet](https://hunt.io/malware-families/emotet): Emotet profile. - [Qakbot](https://hunt.io/malware-families/qakbot): Qakbot profile. - [SystemBC](https://hunt.io/malware-families/systembc): SystemBC profile. - [Diceloader](https://hunt.io/malware-families/diceloader): Diceloader profile. - [SpiceRAT](https://hunt.io/malware-families/spicerat): SpiceRAT profile. - [Hookbot](https://hunt.io/malware-families/hookbot): Hookbot Android trojan profile. - [Hookbot Fork](https://hunt.io/malware-families/hookbot-fork): Hookbot fork variant profile. - [ERMAC](https://hunt.io/malware-families/ermac): ERMAC Android banking trojan profile. - [SharkBot](https://hunt.io/malware-families/sharkbot): SharkBot Android trojan profile. - [Medusa](https://hunt.io/malware-families/medusa): Medusa malware profile. - [DAAM](https://hunt.io/malware-families/daam): DAAM profile. - [Nexus](https://hunt.io/malware-families/nexus): Nexus Android banker profile. - [PixPirate](https://hunt.io/malware-families/pixpirate): PixPirate Android trojan profile. - [L3MON](https://hunt.io/malware-families/l3mon): L3MON Android RAT profile. - [Laplas Clipper](https://hunt.io/malware-families/laplas-clipper): Laplas clipper profile. - [Ligolo-NG](https://hunt.io/malware-families/ligolo-ng): Ligolo-NG tunneling tool profile. - [ReverseSSH](https://hunt.io/malware-families/reversessh): ReverseSSH profile. - [Responder](https://hunt.io/malware-families/responder): Responder tool profile. - [Hydra](https://hunt.io/malware-families/hydra): Hydra password-cracking tool profile. - [Hajime](https://hunt.io/malware-families/hajime): Hajime IoT worm profile. - [Mozi](https://hunt.io/malware-families/mozi): Mozi botnet profile. - [Gafgyt](https://hunt.io/malware-families/gafgyt): Gafgyt IoT botnet profile. - [Kaiten](https://hunt.io/malware-families/kaiten): Kaiten profile. - [Onimai](https://hunt.io/malware-families/onimai): Onimai profile. - [Octopus](https://hunt.io/malware-families/octopus): Octopus profile. - [Unam](https://hunt.io/malware-families/unam): Unam profile. - [RapperBot](https://hunt.io/malware-families/rapperbot): RapperBot IoT botnet profile. - [Chalubo RAT](https://hunt.io/malware-families/chalubo-rat): Chalubo profile. - [Scarab](https://hunt.io/malware-families/scarab): Scarab profile. - [Socks5Systemz](https://hunt.io/malware-families/socks5systemz): Socks5Systemz proxy malware profile. - [Nobelium SSH](https://hunt.io/malware-families/nobelium-ssh): Nobelium SSH-related infrastructure profile. - [EvilGoPhish](https://hunt.io/malware-families/evilgophish): EvilGoPhish phishing framework profile. - [GoPhish](https://hunt.io/malware-families/gophish): GoPhish framework profile. - [BeEF](https://hunt.io/malware-families/beef): BeEF browser exploitation framework profile. - [RedWarden](https://hunt.io/malware-families/redwarden): RedWarden redirector profile. - [RedGuard](https://hunt.io/malware-families/redguard): RedGuard redirector profile. - [Tactical RMM](https://hunt.io/malware-families/tactical-rmm): Tactical RMM software profile. - [Hak5 Cloud C²](https://hunt.io/malware-families/hak5-cloud-c%C2%B2): Hak5 Cloud C² profile. - [Burp Collaborator](https://hunt.io/malware-families/burp-collaborator): Burp Collaborator infrastructure profile. - [Interactsh](https://hunt.io/malware-families/interactsh): Interactsh interaction server profile. - [JS-Tap](https://hunt.io/malware-families/js-tap): JS-Tap profile. - [Prism-X](https://hunt.io/malware-families/prism-x): Prism-X profile. - [Fletchen](https://hunt.io/malware-families/fletchen): Fletchen profile. - [Yakit Security Tool](https://hunt.io/malware-families/yakit-security-tool): Yakit security tool profile. - [reNgine](https://hunt.io/malware-families/rengine): reNgine recon framework profile. - [reconFTW](https://hunt.io/malware-families/reconftw): reconFTW recon tool profile. - [OWASP ZAP API](https://hunt.io/malware-families/owasp-zap-api): OWASP ZAP API profile. - [X-Ray Vuln Scanner](https://hunt.io/malware-families/x-ray-vuln-scanner): X-Ray vulnerability scanner profile. ## Research Blog Original threat research, infrastructure analysis, and platform updates from the Hunt.io research team. - [Blog Index](https://hunt.io/blog): Main blog landing page. - [PCPJack Hijacked 230 AWS, GCP, and Azure Servers for Hidden SMTP Relay Network](https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel): PCPJack hijacked 230 AWS, GCP, and Azure servers to run a hidden SMTP relay network. - [Massive Smishing Campaign Targeting Governments, Postal, and Telecoms](https://hunt.io/blog/massive-smishing-campaign-governments-postal-telecoms): Smishing campaign analysis across government and telecom targets. - [Middle East Malicious Infrastructure Report](https://hunt.io/blog/middle-east-malicious-infrastructure-report): Regional report on malicious infrastructure in the Middle East. - [TeamPCP Python Toolkit and FIRESCALE GitHub C2 Takedown](https://hunt.io/blog/teampcp-python-toolkit-firescale-github-c2-takedown): TeamPCP toolkit and the FIRESCALE GitHub C2 takedown. - [CVE-2025-32975 Quest KACE SMA Open Directory](https://hunt.io/blog/cve-2025-32975-quest-kace-sma-open-directory-60-victims): Quest KACE SMA exposure tied to CVE-2025-32975. - [Iranian Nexus Oman Government Intrusion](https://hunt.io/blog/iranian-nexus-oman-government-intrusion): Iran-linked activity against Omani government targets. - [XLabs v1 DDoS-for-Hire Operation Exposed](https://hunt.io/blog/xlabs-v1-ddos-for-hire-operation-exposed): XLabs v1 booter operation analysis. - [DinDoor Deno Runtime Backdoor MSI Analysis](https://hunt.io/blog/dindoor-deno-runtime-backdoor-msi-analysis): DinDoor backdoor running on the Deno runtime, MSI analysis. - [Practical Guide to Uncovering Malicious Infrastructure](https://hunt.io/blog/practical-guide-unconvering-malicious-infrastructure): Practitioner guide to surfacing attacker infrastructure. - [Russian Malicious Infrastructure: C2 Servers Mapped](https://hunt.io/blog/russian-malicious-infrastructure-c2-servers-mapped): Mapping of Russia-hosted C2 infrastructure. - [Canis C2: Cross-Platform Surveillance Framework in Japan](https://hunt.io/blog/canis-c2-exposed-cross-platform-surveillance-framework-japan): Canis C2 surveillance framework analysis. - [Axios Supply Chain Attack: TA444 / BlueNoroff](https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff): TA444 / BlueNoroff supply chain operation. - [33k Exposed LiteLLM Instances: TeamPCP C2 Supply Chain](https://hunt.io/blog/33k-exposed-litellm-teampcp-c2-supply-chain-attack): Exposed LiteLLM instances tied to TeamPCP C2. - [TheGentlemen Ransomware Toolkit on Russian Proton66 Server](https://hunt.io/blog/thegentlemen-ransomware-toolkit-russian-proton66-server): TheGentlemen toolkit hosted on Proton66. - [Iran Botnet Operation: Open Directory](https://hunt.io/blog/iran-botnet-operation-open-directory): Iranian botnet exposed via open directory. - [Operation Roundish: APT28 Roundcube Exploitation](https://hunt.io/blog/operation-roundish-apt28-roundcube-exploitation): APT28 Roundcube exploitation activity. - [Iranian APT Infrastructure: State-Aligned Clusters](https://hunt.io/blog/iranian-apt-infrastructure-state-aligned-clusters): State-aligned Iranian APT infrastructure clusters. - [Hunting Cobalt Strike Part 4: C2 Feeds API](https://hunt.io/blog/guide-hunting-cobalt-strike-part-4-c2-feeds-api): Cobalt Strike hunting using the C2 Feeds API. - [Hunting Cobalt Strike Part 3: Automated Discovery](https://hunt.io/blog/guide-hunting-cobalt-strike-part-3-automated-discovery): Automated discovery techniques for Cobalt Strike. - [Hunting Cobalt Strike Part 2: HuntSQL Recipes](https://hunt.io/blog/guide-hunting-cobalt-strike-part-2-huntsql-recipes): HuntSQL recipes for Cobalt Strike hunting. - [Hunting Cobalt Strike Part 1: Open Directories](https://hunt.io/blog/guide-hunting-cobalt-strike-part-1-open-directories): Finding Cobalt Strike via open directories. - [Reimagining Hunt.io](https://hunt.io/blog/reimagining-huntio): Notes on the Hunt.io platform redesign. - [Fake Homebrew ClickFix: Cuckoo Stealer on macOS](https://hunt.io/blog/fake-homebrew-clickfix-cuckoo-stealer-macos): ClickFix lures abusing Homebrew to deliver Cuckoo Stealer. - [CVE-2026-25253 OpenClaw AI Agent Exposure](https://hunt.io/blog/cve-2026-25253-openclaw-ai-agent-exposure): OpenClaw AI agent exposure tied to CVE-2026-25253. - [Exposed BYOB C2 Infrastructure: Multi-Stage Malware Deployment](https://hunt.io/blog/exposed-byob-c2-infrastructure-multi-stage-malware-deployment): BYOB-based multi-stage deployment infrastructure. - [ClickFix Facebook Session Hijacking](https://hunt.io/blog/clickfix-facebook-session-hijacking): ClickFix lures used to hijack Facebook sessions. - [China Hosting: Malware and C2 Infrastructure](https://hunt.io/blog/china-hosting-malware-c2-infrastructure): Malware and C2 hosted from Chinese providers. - [2025 Year in Review](https://hunt.io/blog/2025-year-in-review): Hunt.io 2025 research and platform recap. - [Announcing Hunt 2.8](https://hunt.io/blog/announcing-hunt-2-8): Release notes for Hunt 2.8. - [DPRK Lazarus and Kimsuky Infrastructure Uncovered](https://hunt.io/blog/dprk-lazarus-kimsuky-infrastructure-uncovered): DPRK Lazarus and Kimsuky infrastructure tracking. - [React2Shell: CVE-2025-55182 Next.js Node.js RCE](https://hunt.io/blog/react2shell-cve-2025-55182-nextjs-nodejs-rce): Next.js / Node.js RCE tied to CVE-2025-55182. - [Malicious VSCode Extension: Anivia OctoRAT Attack Chain](https://hunt.io/blog/malicious-vscode-extension-anivia-octorat-attack-chain): Malicious VSCode extension delivering OctoRAT. - [Announcing Hunt 2.7](https://hunt.io/blog/announcing-hunt-2-7): Release notes for Hunt 2.7. - [Multilingual ZIP Phishing Campaigns: Asian Financial and Government Targets](https://hunt.io/blog/multilingual-zip-phishing-campaigns-asia-financial-government): ZIP-delivered phishing campaigns across Asia. - [Interview: Joseph Harrison on Threat Detection](https://hunt.io/blog/interview-joseph-harrison-threat-detection): Interview with Joseph Harrison. - [Introducing Hunt 2.6](https://hunt.io/blog/introducing-hunt-2-6): Release notes for Hunt 2.6. - [macOS Odyssey / AMOS Malware Campaign](https://hunt.io/blog/macos-odyssey-amos-malware-campaign): AMOS / Odyssey campaign analysis on macOS. - [AdaptixC2: Capabilities, Tactics, and Hunting](https://hunt.io/blog/adaptixc2-uncovered-capabilities-tactics-hunting): AdaptixC2 framework analysis. - [Operation SouthNet: SideWinder South Asia Maritime Phishing](https://hunt.io/blog/operation-southnet-sidewinder-south-asia-maritime-phishing): SideWinder maritime phishing in South Asia. - [Hunting C2 Panels: Beginner's Guide](https://hunt.io/blog/hunting-c2-panels-beginners-guide): Introductory guide to hunting C2 panels. - [AsyncRAT and ScreenConnect Open Directory Campaigns](https://hunt.io/blog/asyncrat-screenconnect-open-directory-campaigns): AsyncRAT and ScreenConnect campaigns surfaced from open directories. - [US Energy Phishing Wave Report](https://hunt.io/blog/us-energy-phishing-wave-report): Phishing wave against US energy sector targets. - [Interview: Daniel Plohmann on Malpedia and Malware Analysis](https://hunt.io/blog/interview-daniel-plohmann-malpedia-malware-analysis): Interview with Malpedia maintainer Daniel Plohmann. - [TinyLoader: Cryptocurrency Theft Infrastructure](https://hunt.io/blog/tinyloader-malware-cryptocurrency-theft-infrastructure): TinyLoader and its crypto-theft infrastructure. - [Announcing Hunt 2.5](https://hunt.io/blog/announcing-hunt-2-5): Release notes for Hunt 2.5. - [APT MuddyWater: Multi-Stage Phishing Targeting CFOs](https://hunt.io/blog/apt-muddywater-deploys-multi-stage-phishing-to-target-cfos): MuddyWater multi-stage phishing aimed at finance executives. - [ERMAC v3 Banking Trojan Source Code Leak](https://hunt.io/blog/ermac-v3-banking-trojan-source-code-leak): ERMAC v3 banking trojan source code leak. - [APT SideWinder: Netlify Government Phishing](https://hunt.io/blog/apt-sidewinder-netlify-government-phishing): SideWinder phishing using Netlify-hosted lures. - [APT36 India Infrastructure Attacks](https://hunt.io/blog/apt36-india-infrastructure-attacks): APT36 infrastructure operations against India. - [macOS ClickFix: AppleScript Terminal Phishing](https://hunt.io/blog/macos-clickfix-applescript-terminal-phishing): macOS ClickFix abusing AppleScript and Terminal. - [Gov.br Subdomain SEO Poisoning: 630k URLs](https://hunt.io/blog/gov-br-subdomain-seo-poisoning-630k-urls): Mass SEO poisoning of gov.br subdomains. - [Announcing Hunt 2.4](https://hunt.io/blog/announcing-hunt-2-4): Release notes for Hunt 2.4. - [Splunk Interview: Jose Hernandez](https://hunt.io/blog/splunk-interview-jose-hernandez): Interview with Jose Hernandez from Splunk. - [Threat Hunting with URLx](https://hunt.io/blog/threat-hunting-with-urlx): Using URLx as a threat hunting input. - [Announcing Hunt 2.3](https://hunt.io/blog/announcing-hunt-2-3): Release notes for Hunt 2.3. - [Cobalt Strike PowerShell Loader: Chinese and Russian Infrastructure](https://hunt.io/blog/cobaltstrike-powershell-loader-chinese-russian-infrastructure): Cobalt Strike PowerShell loader served from Chinese and Russian hosts. - [TrustedSec CTO Interview: Justin Elze](https://hunt.io/blog/trustedsec-cto-interview-justin-elze): Interview with Justin Elze, CTO at TrustedSec. - [Introducing Hunt 2.2](https://hunt.io/blog/introducing-hunt-2-2): Release notes for Hunt 2.2. - [Paste.ee XWorm and AsyncRAT Infrastructure](https://hunt.io/blog/pasteee-xworm-asyncrat-infrastructure): Paste.ee abused to host XWorm and AsyncRAT. - [Threat Actor Intelligence with Enhanced IOC Pivoting](https://hunt.io/blog/threat-actor-intelligence-with-enhanced-ioc-pivoting): IOC pivoting workflow update. - [Introducing Hunt 2.1](https://hunt.io/blog/introducing-hunt-2-1): Release notes for Hunt 2.1. - [Phishing Campaign in Kuwait: Shared SSH Keys](https://hunt.io/blog/phishing-campaign-kuwait-shared-ssh-keys): Kuwait phishing campaign with shared SSH keys across infrastructure. - [Detect IOX, FRP, Rakshasa Proxies](https://hunt.io/blog/detect-iox-frp-rakshasa-proxies): Detection notes for IOX, FRP, and Rakshasa proxies. - [APT36 ClickFix Campaign: Indian Ministry of Defence](https://hunt.io/blog/apt36-clickfix-campaign-indian-ministry-of-defence): APT36 ClickFix campaign targeting Indian MoD. - [Track APT34-like Infrastructure Before It Strikes](https://hunt.io/blog/track-apt34-like-infrastructure-before-it-strikes): Proactive tracking of APT34-like infrastructure. - [KeyPlug Server Exposes Fortinet Exploits and Webshells](https://hunt.io/blog/keyplug-server-exposes-fortinet-exploits-webshells): Exposed KeyPlug server hosting Fortinet exploits and webshells. - [Server-Side Phishing Evasion in Employee Portals](https://hunt.io/blog/server-side-phishing-evasion-employee-portals): Server-side evasion in employee portal phishing. - [GoPhish Targets Polish Energy and Government](https://hunt.io/blog/gophish-targets-polish-energy-government): GoPhish operations against Polish energy and government targets. - [State-Sponsored Activity: Gamaredon and ShadowPad](https://hunt.io/blog/state-sponsored-activity-gamaredon-shadowpad): Gamaredon and ShadowPad activity overview. - [ClickFix Pages: Proactive Threat Hunting](https://hunt.io/blog/clickfix-pages-proactive-threat-hunting): Hunting for ClickFix landing pages. - [Russian Actor Cloudflare Phishing with Telegram C2](https://hunt.io/blog/russian-actor-cloudflare-phishing-telegram-c2): Cloudflare-fronted phishing tied to Telegram C2. - [URLx Product Update](https://hunt.io/blog/urlx-product-update): URLx feature update. - [IOC Hunter Feed Attribution](https://hunt.io/blog/ioc-hunter-feed-attribution): Attribution features in IOC Hunter feeds. - [Rust Beacon Cobalt Strike Cat: South Korea](https://hunt.io/blog/rust-beacon-cobalt-strike-cat-south-korea): Rust-based Cobalt Strike Cat beacon observed against South Korea. - [JspSpy and FileBroser: Custom Webshell Management](https://hunt.io/blog/jspspy-filebroser-custom-webshell-management): JspSpy and FileBroser webshell management. - [Introducing Hunt 2](https://hunt.io/blog/introducing-hunt-2): Hunt 2 platform launch notes. - [Russian-Speaking Actors Impersonate ETF and Distribute StealC via Pyramid C2](https://hunt.io/blog/russian-speaking-actors-impersonate-etf-distribute-stealc-pyramid-c2): ETF impersonation distributing StealC via Pyramid C2. - [Uncovering Joker C2 Network](https://hunt.io/blog/uncovering-joker-c2-network): Joker C2 network analysis. - [LightSpy Malware Targets Facebook and Instagram](https://hunt.io/blog/lightspy-malware-targets-facebook-instagram): LightSpy targeting Facebook and Instagram users. - [Backdoored Executables for Signal, LINE, Gmail Target Chinese Users](https://hunt.io/blog/backdoored-executables-for-signal-line-gmail-target-chinese-users): Backdoored Signal, LINE, and Gmail executables aimed at Chinese users. - [SSL Threat Hunting: Anomaly Flags](https://hunt.io/blog/ssl-threat-hunting-anomaly-flags): SSL anomaly flags for threat hunting. - [Tracking Pyramid C2: Identifying Post-Exploitation Servers](https://hunt.io/blog/tracking-pyramid-c2-identifying-post-exploitation-servers): Identifying Pyramid C2 post-exploitation servers. - [SmokeLoader in Open Directories: Ukraine Auto and Banking](https://hunt.io/blog/smokeloader-malware-found-in-open-directories-targeting-ukraine-s-auto-banking-industries): SmokeLoader campaigns targeting Ukrainian auto and banking sectors. - [GreenSpot APT: 163.com Fake Downloads and Spoofing](https://hunt.io/blog/greenspot-apt-targets-163com-fake-downloads-spoofing): GreenSpot APT spoofing 163.com downloads. - [SSL Intelligence History for Threat Hunting](https://hunt.io/blog/ssl-intelligence-history-threat-hunting): Using historical SSL data for threat hunting. - [SparkRAT Server Detection: macOS Activity](https://hunt.io/blog/sparkrat-server-detection-macos-activity-and-malicious-connections): SparkRAT server detection with macOS activity notes. - [KeyPlug Infrastructure: TLS Certificates and GhostWolf Activity](https://hunt.io/blog/keyplug-infrastructure-tls-certificates-ghostwolf-activity): KeyPlug TLS certificate pivots and GhostWolf activity. - [Malicious VSCode Extension Impersonating Zoom Steals Chrome Cookies](https://hunt.io/blog/malicious-vs-code-extension-impersonating-zoom-steals-chrome-cookies): Fake Zoom VSCode extension stealing Chrome cookies. - [JustJoin Landing Page Linked to Suspected DPRK Activity](https://hunt.io/blog/justjoin-landing-page-linked-to-suspected-dprk-activity-resurfaces): JustJoin landing page linked to suspected DPRK operations. - [Cyberhaven Extension Compromise: TLS Certificate Links](https://hunt.io/blog/cyberhaven-extension-compromise-tls-certificate-links-infrastructure): TLS certificate pivots related to the Cyberhaven extension compromise. - [Golang Beacons and VS Code Tunnels: Tracking Cobalt Strike](https://hunt.io/blog/golang-beacons-vs-code-tunnels-tracking-cobalt-strike): Tracking Cobalt Strike via Golang beacons and VS Code tunnels. - [2024 Year in Review](https://hunt.io/blog/2024-year-in-review): Hunt.io 2024 recap. - [Oyster's Trail: Resurgence in Infrastructure and Ransomware](https://hunt.io/blog/oysters-trail-resurgence-infrastructure-ransomware-cybercrime): Oyster backdoor resurgence and tied infrastructure. - [Million-OK Naver Facade: Kimsuky Tracking](https://hunt.io/blog/million-ok-naver-facade-kimsuky-tracking): Kimsuky tracking through Naver-themed facade pages. - [MoqHao: iCloud and VK Targets on Apple and Android](https://hunt.io/blog/moqhao-icloud-vk-targets-apple-android): MoqHao campaigns hitting iCloud and VK users. - [Rare Watermark Links Cobalt Strike Team Servers](https://hunt.io/blog/rare-watermark-links-cobalt-strike-team-servers-to-ongoing-suspicious-activity): Rare watermark used to cluster Cobalt Strike team servers. - [Uncovering Threat Actor Tactics: XWorm Delivery Strategies](https://hunt.io/blog/uncovering-threat-actor-tactics-xworm-delivery-strategies): XWorm delivery method analysis. - [DarkPeony Certificate Patterns](https://hunt.io/blog/darkpeony-certificate-patterns): Certificate patterns tied to DarkPeony. - [XenoRAT, Excel XLL, and ConfuserEx as Access Method](https://hunt.io/blog/xenorat-excel-xll-confuserex-as-access-method): XenoRAT delivered via XLL files protected with ConfuserEx. - [Sliver C2 and Ligolo-NG Targeting YC](https://hunt.io/blog/sliver-c2-ligolo-ng-targeting-yc): Sliver C2 and Ligolo-NG infrastructure observed against Y Combinator. - [Exposing Large-Scale Phishing Activity Abusing Cloudflare](https://hunt.io/blog/exposing-large-scale-phishing-activity-abusing-cloudflare): Cloudflare-abusing phishing operation. - [RunningRAT: From Remote Access to Crypto Mining](https://hunt.io/blog/runningrat-from-remote-access-to-crypto-mining): RunningRAT pivot from RAT to crypto miner. - [Tricks, Treats, Threats: Cobalt Strike Goblin](https://hunt.io/blog/tricks-treats-threats-cobalt-strike-the-goblin-lurking-in-plain-sight): Cobalt Strike Goblin watermark analysis. - [DPRK Phishing Targets Naver and Apple via Domain Spoofing](https://hunt.io/blog/dprk-phishing-targets-naver-apple-domain-spoofing): DPRK phishing spoofing Naver and Apple domains. - [Rekoobe Backdoor in Open Directory: Possible TradingView Targeting](https://hunt.io/blog/rekoobe-backdoor-discovered-in-open-directory-possibly-targeting-tradingview-users): Rekoobe backdoor surfaced from an open directory. - [From Warm to Burned: Updated WarmCookie Infrastructure](https://hunt.io/blog/from-warm-to-burned-shedding-light-on-updated-warmcookie-infrastructure): Updated WarmCookie infrastructure analysis. - [Introducing Code Search on AttackCapture](https://hunt.io/blog/introducing-code-search-on-attackcapture-uncover-exploit-code-reverse-shells-c2-configs-and-more): Code search feature in AttackCapture. - [Earth Baxia and PlugX Activity via Certificates and Redirects](https://hunt.io/blog/unmasking-adversary-infrastructure-how-certificates-and-redirects-exposed-earth-baxia-and-plugx-activity): Certificate and redirect pivots exposing Earth Baxia and PlugX activity. - [Inside a Cybercriminal's Server: DDoS Tools, Spyware APKs, and Phishing](https://hunt.io/blog/inside-a-cybercriminal-s-server-ddos-tools-spyware-apks-and-phishing-pages): Walkthrough of a cybercriminal server hosting multiple toolsets. - [SQL Blog Post](https://hunt.io/blog/sql): HuntSQL feature post. - [Unboxing the Threat: Python Scripts Using BoxedApp SDK](https://hunt.io/blog/unboxing-the-threat-how-malicious-python-scripts-use-the-boxedapp-sdk-to-evade-detection): Python scripts using BoxedApp SDK for evasion. - [Echoes of Stargazer Goblin: Shared TTPs from an Open Directory](https://hunt.io/blog/echoes-of-stargazer-goblin-analyzing-shared-ttps-from-an-open-directory): Shared TTPs with Stargazer Goblin found in an open directory. - [API Launch](https://hunt.io/blog/api-launch): Hunt.io API launch announcement. - [Decoy Docs and Malicious Browser Extensions](https://hunt.io/blog/decoy-docs-and-malicious-browser-extensions-a-closer-look-at-a-multi-layered-threat): Multi-layered campaign combining decoy docs and browser extensions. - [ToneShell Backdoor Targets IISS Defence Summit Attendees](https://hunt.io/blog/toneshell-backdoor-used-to-target-attendees-of-the-iiss-defence-summit): ToneShell campaign aimed at IISS Defence Summit attendees. - [Latrodectus Masquerades as AhnLab Security Software](https://hunt.io/blog/latrodectus-malware-masquerades-as-ahnlab-security-software-to-infect-victims): Latrodectus impersonating AhnLab security software. - [AttackCapture Launch](https://hunt.io/blog/attack-capture-launch): AttackCapture feature launch. - [EvilGoPhish Unhooked: Infrastructure and Notable Domains](https://hunt.io/blog/evilgophish-unhooked-insights-into-the-infrastructure-and-notable-domains): EvilGoPhish infrastructure and domains. - [Open Directory Exposes Possible Government Targeting](https://hunt.io/blog/pentester-or-threat-actor-open-directory-exposes-test-results-and-possible-targeting-of-government-organizations): Open directory with test results suggesting government targeting. - [macOS Malware Impersonates The Unarchiver App](https://hunt.io/blog/macos-malware-impersonates-the-unarchiver-app-to-steal-user-data): Fake Unarchiver app stealing macOS user data. - [Simple Approach to Discovering Oyster Backdoor Infrastructure](https://hunt.io/blog/a-simple-approach-to-discovering-oyster-backdoor-infrastructure): Discovering Oyster backdoor infrastructure. - [SEO Poisoning Campaigns: Poseidon, GhostRAT, and More](https://hunt.io/blog/seo-poisoning-campaigns-target-browser-installers-and-crypto-sites-spreading-poseidon-ghostrat-more): SEO poisoning campaigns delivering multiple malware families. - [SpiceRAT Infrastructure via HTML Response](https://hunt.io/blog/the-secret-ingredient-unearthing-suspected-spicerat-infrastructure-via-html-response): SpiceRAT infrastructure surfaced via HTML response patterns. - [ProxyLogon and ProxyShell Used Against Government Mail Servers](https://hunt.io/blog/proxylogon-and-proxyshell-used-to-target-government-mail-servers-in-asia-europe-and-south-america): ProxyLogon and ProxyShell used against government mail servers worldwide. - [Geacon and Geacon Pro: Threat to Linux and Windows](https://hunt.io/blog/geacon-and-geacon-pro-a-constant-menace-to-linux-and-windows-systems): Geacon and Geacon Pro activity on Linux and Windows. - [Xeno RAT via .gg Domains and GitHub](https://hunt.io/blog/good-game-gone-bad-xeno-rat-spread-via-gg-domains-and-github): Xeno RAT distributed via .gg domains and GitHub. - [SpyNote in Unexpected Places](https://hunt.io/blog/caught-in-the-act-uncovering-spynote-in-unexpected-places): SpyNote samples found in unusual infrastructure. - [Open Directories Expose Tools Targeting Asian Organizations](https://hunt.io/blog/open-directories-expose-publicly-available-tools-targeting-asian-organizations): Open directories with tools aimed at Asian targets. - [Gh0st and Pantegana: Two RATs That Refuse to Fade](https://hunt.io/blog/gh0st-and-pantegana-two-rats-that-refuse-to-fade-away): Continued Gh0st and Pantegana activity. - [Tracking LightSpy Certificates](https://hunt.io/blog/tracking-lightspy-certificates-as-windows-into-adversary-behavior): LightSpy certificate tracking. - [Legacy Threat: PlugX Builder and Controller in Open Directory](https://hunt.io/blog/legacy-threat-plugx-builder-controller-discovered-in-open-directory): PlugX builder and controller found in an open directory. - [SolarMarker: Hunt.io Insight and Findings](https://hunt.io/blog/solarmarker-hunt-insight-and-findings): SolarMarker tracking findings. - [Tales from the Hunt: Yakit Security Tool](https://hunt.io/blog/tales-from-the-hunt-a-look-at-yakit-security-tool): Observations on the Yakit security tool. - [Revisiting Past Threat Reports for New Infrastructure](https://hunt.io/blog/unearthing-new-infrastructure-by-revisiting-past-threat-reports): Surfacing new infrastructure from older reports. - [Into the Viper's Nest: Observations from Hunt's Scanning](https://hunt.io/blog/into-the-vipers-nest-observations-from-hunts-scanning): Viper C2 observations from scanning data. - [Spotting SparkRAT: Detection Tactics and Sandbox Findings](https://hunt.io/blog/spotting-sparkrat-detection-tactics-and-sandbox-findings): SparkRAT detection tactics and sandbox results. - [Uncovering Supershell and Cobalt Strike from an Open Directory](https://hunt.io/blog/uncovering-supershell-and-cobalt-strike-from-an-open-directory): Supershell and Cobalt Strike artifacts from an open directory. - [BlueShell Four Years On: Still a Formidable Threat](https://hunt.io/blog/blueshell-four-years-on-still-a-formidable-threat): BlueShell activity four years post-disclosure. - [Detecting RedGuard C2 Redirector](https://hunt.io/blog/detecting-redguard-c2-redirector): RedGuard detection notes. - [Coin Miner and Mozi Botnet](https://hunt.io/blog/coin-mainer-and-mozi-botnet): Coin miner activity tied to Mozi botnet. - [Treasure Trove of Trouble](https://hunt.io/blog/treasure-trove-of-trouble): Open directory finding with mixed attacker tooling. - [Phishing Kit Targets Outlook Credentials](https://hunt.io/blog/phishing-kit-targets-outlook-credentials): Phishing kit targeting Outlook accounts. - [Hunting PrismX](https://hunt.io/blog/hunting-prismx): PrismX hunting notes. - [Open Directory Exposes Phishing Campaign: Google and Naver](https://hunt.io/blog/open-directory-exposes-phishing-campaign-targeting-google-and-naver-credentials): Open directory exposing Google and Naver credential phishing. - [Suspected North Korean Hackers Target Blockchain via Telegram](https://hunt.io/blog/suspected-north-korean-hackers-target-blockchain-community-via-telegram): Suspected DPRK targeting of blockchain communities via Telegram. - [Unveiling the Power of Tag Cloud](https://hunt.io/blog/unveiling-the-power-of-tag-cloud): Tag cloud feature explainer. - [Tracking ShadowPad via Non-Standard Certificates](https://hunt.io/blog/tracking-shadowpad-infrastructure-via-non-standard-certificates): ShadowPad pivots through non-standard certificates. - [Beyond Headlines and Borders](https://hunt.io/blog/beyond-headlines-and-borders): Research notes on cross-border threat infrastructure. - [Hunting and Collecting Malware via Open Directories Part 1](https://hunt.io/blog/hunting-and-collecting-malware-via-open-directories-part-1): Methodology for collecting malware from open directories. - [Introducing Hunt Advanced Search](https://hunt.io/blog/introducing-hunt-advanced-search): Advanced search feature launch. - [How We Identify Malicious Infrastructure](https://hunt.io/blog/how-we-identify-malicious-infrastructure): Internal methodology for identifying malicious infrastructure. - [Introducing C2 Feed](https://hunt.io/blog/introducing-C2-feed): C2 feed launch announcement. - [Announcing Hunt IOC Hunter](https://hunt.io/blog/announcing-hunt-ioc-hunter): IOC Hunter feature launch. - [Gateway to Intrusion](https://hunt.io/blog/gateway-to-intrusion): Notes on initial access infrastructure. - [How Hunt Identifies Services](https://hunt.io/blog/how-hunt-identifies-services): Service identification methodology. - [Hunt Guide to GoPhish Detection](https://hunt.io/blog/hunt-guide-to-gophish-detection): Detection guide for GoPhish. - [Decoding Cyber Shadows](https://hunt.io/blog/decoding-cyber-shadows): Research note on attribution and infrastructure analysis. - [Hunt Platform Statistics](https://hunt.io/blog/hunt-platform-statistics): Platform stats and scope. - [Discovering and Disrupting Malicious Infrastructure](https://hunt.io/blog/discovering-%26-disrupting-malicious-infrastructure): Disruption case studies. - [Transparency of Attacker Tooling](https://hunt.io/blog/transparency-of-attacker-tooling): Notes on visibility into attacker tooling. - [Let's Go Hunting](https://hunt.io/blog/lets-go-hunting): Introductory post on threat hunting with Hunt.io. - [Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site To Steal Fan Logins and Card Data](https://hunt.io/blog/fifa-world-cup-2026-ticket-phishing-kit): Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site To Steal Fan Logins and Card Data. - [Inside Eastern Europe's C2 Sprawl: 3,900+ Servers and 302 Providers Mapped](https://hunt.io/blog/eastern-europe-malicious-infrastructure-report): Inside Eastern Europe's C2 Sprawl: 3,900+ Servers and 302 Providers Mapped. - [Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries](https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion): Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries. - [Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries](https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve): Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries. - [Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent): Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged. - [Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon](https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon): Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon. - [The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2](https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2): The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2. - [Inside a Russian-Speaking Operator's Toolkit for Compromising Ukrainian IP Cameras](https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit): Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit. ## Optional Secondary pages that can be skipped if a shorter context is needed. ### Support Documentation - [Support Home](https://hunt.io/support): Support landing page. - [Getting Started](https://hunt.io/support/getting-started): First-time setup walkthrough. - [Logging In](https://hunt.io/support/logging-in): Sign-in instructions. - [Two-Factor Authentication](https://hunt.io/support/two-factor-authentication): 2FA setup steps. - [Community Slack](https://hunt.io/support/community-slack): How to join the Hunt.io community Slack. - [Change Log](https://hunt.io/support/change-log): Support-side change log. - [Web Interface](https://hunt.io/support/web-interface): Web interface walkthrough. - [Light and Dark Mode](https://hunt.io/support/light-dark-mode): Theme switching. - [Bulk Enrichment](https://hunt.io/support/bulk-enrichment): Bulk enrichment usage notes. - [Open Directory](https://hunt.io/support/open-directory): Open directory feature notes. - [Open Directory Section](https://hunt.io/support/open-directory-section): Open directory section walkthrough. - [Feeds](https://hunt.io/support/feeds): Feeds overview. - [C2 Feeds](https://hunt.io/support/c2-feeds): C2 feed usage notes. - [New Certificates](https://hunt.io/support/new-certificates): New certificates feed. - [New Hostnames Found on SSL Certs](https://hunt.io/support/new-hostnames-found-on-ssl-certs): SSL hostname discovery feed. - [Custom Feeds](https://hunt.io/support/custom-feeds): Building custom feeds. - [IOC Hunter](https://hunt.io/support/ioc-hunter): IOC Hunter usage notes. - [Phishing Infrastructure](https://hunt.io/support/phishing-infrastructure): Phishing infrastructure feature notes. - [GitHub and Exploit Tags](https://hunt.io/support/github-and-exploit-tags): GitHub and exploit tag usage. - [Advanced Search](https://hunt.io/support/advanced-search): Advanced search walkthrough. - [Real-Time Stats](https://hunt.io/support/real-time-stats): Real-time platform stats. - [Search by IP](https://hunt.io/support/search-by-ip): IP search walkthrough. - [Malicious Tags](https://hunt.io/support/malicious-tags): Malicious tag usage. - [Search History](https://hunt.io/support/search-history): Reviewing your search history. - [Global Sensors](https://hunt.io/support/global-sensors): Global sensor coverage. ### Legal and Branding - [Terms of Service](https://hunt.io/terms-of-service): Terms governing use of Hunt.io. - [Privacy Policy](https://hunt.io/privacy-policy): Privacy policy. - [Logo and Branding](https://hunt.io/logo-and-branding): Brand assets for partners and media.