logo

Attack Behaviors | Huntress

ID: 45ed162f-30a6-502c-ae5c-1d25c73d5a33

STIX ID: report--45ed162f-30a6-502c-ae5c-1d25c73d5a33

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-05-30

Date Updated: 2026-04-28

...
...

This report reviews Huntress observations of recurring ‘threat clusters’ in early 2024 where attackers exploited CVE-2023-48788 (and other vectors) to compromise endpoints, deploy RMM tools (ScreenConnect, SimpleHelp), and exfiltrate data (including via finger.exe); it emphasizes habit-driven TTPs—password reuse, repeated endpoint names, and consistent command sequences—as high-fidelity indicators defenders can track to detect and disrupt campaigns earlier.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.