“Advanced” Intrusion Targeting Critical Marketing Research Company
ID: 2e015a87-1263-5a23-866e-549cdf218b5b
STIX ID: report--2e015a87-1263-5a23-866e-549cdf218b5b
Feed Name: Huntress Blog
In early 2025 Huntress responded to a targeted intrusion against a global market research firm suspected to be state‑aligned espionage. The attacker used living‑off‑the‑land techniques, created a service named "WebrootCheck" to run c:\temp\1.bat, executed commands that changed registry keys (HKLM\System\CurrentControlSet\Control\Lsa DisableRestrictedAdmin and HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest UseLogonCredential) to enable credential dumping, and deployed a Go-based loader and Mesh Agent RAT (web.exe) which connected to an IP associated with Kaopu Cloud (AS138915). Huntress provided Sigma rules and hunting guidance to detect Mesh Central client activity and nslookup-based mail server enumeration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
