logo

Bullseye: A Story of a Targeted Cyberattack | Huntress

ID: 256a7900-364c-5181-a999-4cf43c7db8b9

STIX ID: report--256a7900-364c-5181-a999-4cf43c7db8b9

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

This Huntress analysis describes a targeted PowerShell-based persistent backdoor that used a scheduled task to run obfuscated PowerShell which downloaded segmented Base64/GZIP payloads, reflectively loaded a .NET DLL to invoke Win32 APIs, patched AmsiScanBuffer to bypass AMSI, and attempted to establish an Empire beacon via a typosquatted vendor-like C2 domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.