logo

Huntress Blog

ID: e1b4d979-e6a5-5eef-9f0d-273f751e82e1

STIX ID: identity--e1b4d979-e6a5-5eef-9f0d-273f751e82e1

Feed Type: rss

Earliest post: 2016-04-06

Latest post: 2026-05-26

Threat research, incident response insights, and practical defensive guidance from the Huntress team — focused on real-world attacks, persistence mechanisms, and strategies to protect SMBs and enterprises.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
From Cookies to Keys: The Threat of Session Hijacking2026-05-26TrueTrue
The Gentleman Ransomware | Defense Evasion TTPs Uncovered | Huntress2026-05-21TrueTrue
Inside the RaaS Ecosystem: Operators, Affiliates & Attack Tradecraft | Huntress2026-05-20TrueTrue
Exposed RDP: The Misconfiguration Attackers Keep Exploiting2026-05-19TrueTrue
Threat Actor Defense Evasion: How Attackers Disable AV & EDR 2026-05-18TrueTrue
Panic at the Distro2026-05-14TrueTrue
How EvilTokens Turbocharges Old School Phishing with AI2026-05-11TrueTrue
Threat Actors Weaponize Tiflux RMMs in Malspam Attacks2026-05-07TrueTrue
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 20252026-05-04TrueTrue
Social Engineering Leveled Up. Has Your Security Program?2026-05-01TrueTrue
ClickFix Removes Your Background but Leaves the Malware2026-04-30TrueTrue
Komari Red: The Monitoring Tool with a Built-in Reverse Shell2026-04-30TrueTrue
Unified EDR + ITDR: Closing the Identity Gap Before Attacks Spread 2026-04-27TrueTrue
Attackers Didn’t Wait for AI. They Built Workflows Around It.2026-04-22TrueTrue
Untangling a Linux Incident With an OpenAI Twist (Part 2)2026-04-22TrueTrue
Tradecraft Tuesday Recap: axios npm Supply Chain Compromise2026-04-21TrueTrue
Nightmare-Eclipse Tooling Seen in Real-World Intrusion2026-04-20TrueTrue
Uptick in Bomgar RMM Exploitation 2026-04-17TrueTrue
Untangling a Linux Incident With an OpenAI Twist2026-04-17TrueTrue
Attackers Love Your VPN To-Do List2026-04-17TrueTrue
When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk2026-04-14TrueTrue
Your Staging Site Is More Important than You Think2026-04-10TrueTrue
What a Fake Claude Download Says About Security Today2026-04-09TrueTrue
The ADWS Architecture That Hides PowerShell AD Enumeration 2026-04-08TrueTrue
Why the Stryker Attack Still Matters. And Five Steps You Can Take Today2026-04-08TrueTrue
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone2026-04-07TrueTrue
OpenClaw, Rogue Agents, and Application Hygiene2026-04-01TrueTrue
The Three-Finger Test2026-04-01TrueTrue
Supply Chain Compromise of axios npm Package2026-03-31TrueTrue
That “Friendly” Prompt is ClickFix2026-03-25TrueTrue
ITDR for Google Workspace | Huntress Managed ITDR2026-03-24TrueTrue
Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure2026-03-23TrueTrue
7 Key Manufacturing Cybersecurity Trends for 2026 | Huntress2026-03-23TrueTrue
How a Tax Search Leads to Kernel-Mode AV/EDR Kill2026-03-19TrueTrue
Something Phishy in the /tmp Folder2026-03-18TrueTrue
Huntress Expands Into Proactive Security Posture Management2026-03-17TrueTrue
How the Huntress SOC Stopped a VPN-Based Ransomware Attack 2026-03-13TrueTrue
Data Exfiltration and Threat Actor Infrastructure Exposed 2026-03-12TrueTrue
How Threat Actors Abuse Remote Management Software for Initial Access2026-03-11TrueTrue
A Threat Actor Abuses Another Free Trial2026-03-06TrueTrue
Unmasking an Attack Chain of MuddyWater 2026-03-06TrueTrue
RMM Abuse: When IT Convenience Bites Back2026-03-05TrueTrue
Why BEC Is Now an Identity Problem2026-03-05TrueTrue
How Fake OpenClaw Installers Spread GhostSocks Malware2026-03-04TrueTrue
The Evolving Linux Threat Landscape2026-03-03TrueTrue
Fake Tech Support Delivers Havoc Command & Control2026-03-02TrueTrue
A Survivor’s Journey Through the Cybercrime Underground2026-02-26TrueTrue
Disrupting Attacks on Endpoints | Attack Disruption Engine2026-02-25TrueTrue
Hiding in Plain Sight with App Domain Manager Injection2026-02-19TrueTrue
A New RAT and a Hands-on-Keyboard Intrusion2026-02-16TrueTrue

1–50 of 285