An Attacker’s Blunder Gave Us a Look Into Their Operations
ID: 1b7281a0-ca1f-5151-b6a3-fefd4a056fbf
STIX ID: report--1b7281a0-ca1f-5151-b6a3-fefd4a056fbf
Feed Name: Huntress Blog
Threat Score
This report analyzes the day-to-day operations of a threat actor observed from May to July 2025: they performed targeted recon on financial and software firms, researched and probed Evilginx instances, used residential proxies and anti-detect browsers, accessed stolen cookie files, ran scripts to harvest Microsoft Entra tokens, and investigated dark web marketplaces and stealer logs—providing detailed TTPs, tooling, and browser/EDR artifacts for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
