logo

“Advanced” Intrusion Targeting Critical Marketing Research Company

ID: 2e015a87-1263-5a23-866e-549cdf218b5b

STIX ID: report--2e015a87-1263-5a23-866e-549cdf218b5b

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2025-05-27

Date Updated: 2026-04-28

...
...

In early 2025 Huntress responded to a targeted intrusion against a global market research firm suspected to be state‑aligned espionage. The attacker used living‑off‑the‑land techniques, created a service named "WebrootCheck" to run c:\temp\1.bat, executed commands that changed registry keys (HKLM\System\CurrentControlSet\Control\Lsa DisableRestrictedAdmin and HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest UseLogonCredential) to enable credential dumping, and deployed a Go-based loader and Mesh Agent RAT (web.exe) which connected to an IP associated with Kaopu Cloud (AS138915). Huntress provided Sigma rules and hunting guidance to detect Mesh Central client activity and nslookup-based mail server enumeration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.