logo

Curling for Data: A Dive into a Threat Actor's Malicious TTPs | Huntress

ID: 355a16ba-5991-5da9-9145-48e9291c9936

STIX ID: report--355a16ba-5991-5da9-9145-48e9291c9936

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress investigators observed a post-compromise intrusion where an attacker accessed an endpoint (noted via anomalous TeamViewer entry), staged and downloaded tools (Dokan and MemProcFS) via curl from 193.149.176.90, likely dumped process memory to obtain credentials, collected browser and file data with a PowerShell script, and exfiltrated an archive back to the same external host, all while using valid compromised accounts and native/GUI tools to minimize detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.