Sign in

Huntress

@huntress.com
413 followers 15 following 71 posts

Managed endpoint protection, detection and response designed to help the 99% fight back against today’s cybercriminals.

PostsRepliesMedia
Huntress @huntress.com · 13/02/2026
#Goals #HoldMyBeer #Bet 😉
010
Huntress @huntress.com · 13/02/2026
We’re running nearly 1 billion Sidekiq background jobs a day to power all of the telemetry processing and detections. Can Redis scale with your workload? Here are the receipts. @mike.contribsys.com where does that rank in your experience?
Screenshot of the Sidekiq dashboard showing nearly 1 billion jobs a day
020
Huntress @huntress.com · 13/05/2025
🛡️ Defensive Actions: 👉 Deploy a SIEM and detect on it– Catch brute force attempts before successful access. 👉 Enable MFA on VPN – Stop compromised credentials from granting access.
000
Huntress @huntress.com · 13/05/2025
Key Takeaways: 👉 SIEM Would Have Stopped This Early – brute force detections are only in the SIEM, not the EDR. 👉 EDR Detected the threat actor on their Windows-based attack phase – The 18 -minute gap gave attackers time to act.
100
Huntress @huntress.com · 13/05/2025
🕐 01:03:29 UTC – EDR detects Credential theft ➡️ reg save hklm\system system ➡️ C:\Users\<redacted>\AppData\Local\Temp\lazagne.exe all 🕐 01:11:10 UTC – Huntress neutralises the intrusion
100
Huntress @huntress.com · 13/05/2025
Timeline of the Attack: 🕛 00:45:43 UTC – VPN Compromise ➡️ A brute-force attack led to initial access. This was discovered through retrospective forensic analysis ➡️ Huntress' SIEM would have caught this had it of been deployed in the network
100
Huntress @huntress.com · 13/05/2025
A construction company recently suffered a VPN brute-force attack, but didn't have SIEM monitoring! The absence of a SIEM led to a 18-minute gap, giving the attacker enough time to attempt to steal credentials - but fortunately the Huntress EDR shut it down.
110
Huntress @huntress.com · 08/05/2025
These behaviours echo Makop ransomware, and they're often paired with attempts to gain long-term footholds via remote access tools. We have observed these tactics in previous incidents and were able to catch and neutralize the threat to this IT org before it could wreak havoc.
000
Huntress @huntress.com · 08/05/2025
🔥 RDP Enabled for Further Access: Modified the firewall to reopen RDP using CLI commands. If you see renamed remote access binaries or odd PsExec usage, you may be facing more than a nuisance script kiddie.
100
Huntress @huntress.com · 08/05/2025
🔑 Followed up with brute-force credential attacks tied to known Makop tooling. 🚀 Lateral Movement & Persistence: Deployed a renamed Mesh Agent via PsExec. 🔍 Attempted to disguise their remote access tool as a benign binary (wvspbind.exe).
100
Huntress @huntress.com · 08/05/2025
Our SOC tackled an attempted ransomware intrusion tied to Makop ransomware tactics. Here’s what went down 👇 🎯 Initial Entry Point: Brute-forced an exposed RDP service (don’t skip reviewing your external perimeters!). 🗺️ Enumeration & Credential Targeting: Ran a network scan using netscan.exe.
100
Huntress @huntress.com · 07/05/2025
🚨Samsung MagicINFO 9 Server (v21.1050.0) is still vulnerable to a publicly available PoC. We’ve observed active exploitation in the wild. Ensure your server is not internet-facing until a proper fix is available. Full details + mitigation steps ➡️ bit.ly/44nkzhL
021
Huntress @huntress.com · 06/05/2025
💡 Key lessons for IT pros: 🎯 Always place exposed RDP behind a VPN and enable MFA 🎯 Enforce strong passwords across all user accounts 🎯 Disable unused accounts that haven’t been touched for 30+ days
000
Huntress @huntress.com · 06/05/2025
At this point, Defender triggered alerts for ransomware deployment and Managed EDR powered by our expert SOC, swiftly isolated the network to stop lateral movement and prevent further encryption.
100
Huntress @huntress.com · 06/05/2025
The bad guys authenticated using a suspicious IP and workstation name. But as you check out below, they began to stage files in the “Music” directory on the host. Moving quickly, they pivoted to deleting shadow copies to prevent recovery after encryption.
100
Huntress @huntress.com · 06/05/2025
We’ve shared many stories about exposed RDP without MFA. Why? Because it’s a common AF, threat actors waste no time exploiting it. What makes this SOC Story from a dental facility stand out: in under 30 minutes, the attack went from initial access to attempted ransomware deployment.
100
Huntress @huntress.com · 05/05/2025
When notorious infostealer “Celestial Stealer” spots specific names, it shuts down, and one of those belongs to one of our own - @jaiminton.com. Wanna use Celestial Stealer to hack a business protected by Huntress? You're a daisy if you do.
000
Huntress @huntress.com · 05/05/2025
.@jaiminton.com is a modern-day Doc Holliday. A lawman so feared that threat actors flee at the mere mention of his name… Introducing Celestial Stealer, a notorious infostealer with a surprising connection to Huntress.
100
Huntress @huntress.com · 30/04/2025
How can you avoid incidents like these? 🔽 ➡️ Enable MFA on all VPN logins (no exceptions). ➡️ Use IP restrictions to block unused locations. ➡️ Monitor and centralize VPN telemetry. ➡️ Commit to strong password policies.
000
Huntress @huntress.com · 30/04/2025
With SIEM and EDR in place, our SOC acted fast. By combining Active Directory and VPN telemetry, we tracked the compromised account and launched network-wide isolation, shutting down lateral movement and blocking potential ransomware.
100
Huntress @huntress.com · 30/04/2025
✅ The attacker used a compromised VPN account (no MFA) to log in with a malicious device. ✅ Explored the network, hid findings in a shady folder, & dug through browser cookies for auth info. ✅ Files were staged on the network file server, ready for exfiltration or encryption.
100
Huntress @huntress.com · 30/04/2025
🐶 A vulnerability left an animal care facility wide open, and an attacker didn’t hesitate to pounce. Here’s how it unfolded 👇
100
Reposted by Huntress
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 23/04/2025
Some good takeaways from @huntress.com’s recent Tradecraft Tuesday ft. Patrick Wardle: -The impact of Apple bringing TCC events to Endpoint Security -#Mac malware persistence techniques vs BTM -Security alert inundation for #macOS users Catch up here⤵️ www.huntress.com/blog/say-hel...
huntress.com
Say Hello to Mac Malware | Huntress
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
023
Huntress @huntress.com · 22/04/2025
➕Threat actors continue to target this flaw with 24 different orgs now compromised ➕We observed several organizations targeted on April 21 in attacks that used several overlapping ping commands We’ll continue giving updates on this exploit as we gather more details: www.huntress.com/blog/cve-202...
huntress.com
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild | Huntress
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
000
Huntress @huntress.com · 22/04/2025
Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
112
Huntress @huntress.com · 17/04/2025
But our SOC swooped in and booted them out before more damage was done. Don’t slack on security hygiene: ➡️ Enable MFA for all externally facing services ➡️ Require strong passwords and enforce time-of-day restrictions—all it takes is one compromised account to gain access
000
Huntress @huntress.com · 17/04/2025
A threat actor brute forced a manufacturer's VPN appliance 🏭 Here’s what happened👇 📌 Successfully compromised one account for initial access 📌 Enumerated the domain, focusing on trust relationships and domain controllers 📌 Modified the registry and local firewall to enable lateral RDP movement
100
Huntress @huntress.com · 16/04/2025
Make sure to reinforce your security stack against ransomware👇 ✅ Secure RDP: disable exposed RDP services & enforce MFA ✅ Check Windows Defender modifications: unauthorized changes may be a red flag ✅ Tune into threat intel: stay ahead of TTPs so you disrupt threats quicker
000
Huntress @huntress.com · 16/04/2025
➡️ The payload and IPv4 are possible BianLian activity, a ransomware group known for raking in payments with data exfiltration and extortion over encryption. Fortunately, our SOC sent them packing before any serious damage was done.
111
Huntress @huntress.com · 16/04/2025
➡️ A suspected ransomware group impaired Windows Defender using registry modifications to exclude *.DLL ➡️ Then with Windows Defender on the fritz they dropped a malicious GoLang DLL payload: rundll32.exe C:\\ProgramData\\HP\\Installer\\Temp\filter.dll,Entry
100
Huntress @huntress.com · 16/04/2025
Exposed RDP can lead to anything—even attempted ransomware attacks. Here’s what went down at this manufacturing business👇
122
Huntress @huntress.com · 14/04/2025
Our new blog details in-the-wild exploitation and post-exploitation activity observed for CVE-2025-30406. This critical vulnerability impacts both Gladinet CentreStack and Triofox—orgs running vulnerable versions should patch ASAP: bit.ly/3E9knIl
bit.ly
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild | Huntress
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
000
Huntress @huntress.com · 14/04/2025
🚨If a Gladinet CentreStack server is exposed to the Internet with these hardcoded keys, it is in immediate danger and needs to be patched or have the machineKey values changed ASAP.
100
Huntress @huntress.com · 14/04/2025
➕At the time of writing, Huntress has seen seven different orgs compromised ➕The flaw was recently added to CISA’s Known Exploited Vulnerabilities database and is related to hardcoded keys set by default in the CentreStack’s configuration file
110
Huntress @huntress.com · 14/04/2025
Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.
143
Huntress @huntress.com · 08/04/2025
Read the full breakdown for actionable tips and more insights to protect your systems from this sneaky tactic 👉 www.huntress.com/blog/the-unw...
huntress.com
The Unwanted Guest | Huntress
Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.
000
Huntress @huntress.com · 08/04/2025
Threat actors are crafty—this trick helps them stay persistent while evading detection. 💡 Key Recommendations: ➡️ Monitor EDR for tools like net.exe and WMI ➡️ Watch Event Logs (look for Event ID 4722 with “Guest” mentioned) ➡️ Hunt for active Guest accounts in your environment
100
Huntress @huntress.com · 08/04/2025
Here’s how they’ve been using it lately: ✅ Enabling the Guest account via command line (net user Guest /active:yes) ✅ Changing its password to something maliciously crafted ✅ Elevating privileges by adding it to Local Administrators or Remote Desktop Users ✅ Used LOLBins like WMI to change settings
100
Huntress @huntress.com · 08/04/2025
Threat actors can gain access to your network through an account that’s already on your system. The built-in Windows Guest account is often overlooked because it’s usually disabled by default—but that’s exactly what makes it a stealthy tool for attackers to exploit.
100
Huntress @huntress.com · 07/04/2025
🩹 CVE-2025-31161 is fixed in CrushFTP versions 11.3.1+ and 10.8.4+ ➡️ We recommend organizations patch immediately. Read more about the CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation 🔗 bit.ly/4jk4VYO
bit.ly
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
011
Huntress @huntress.com · 07/04/2025
✅ cmd.exe /c "C:\windows\temp\msiinstall.exe --install "C:\windows\temp\Anydesk" --silent" ✅ cmd.exe /c "echo licence_key123 | "C:\windows\temp\Anydesk\AnyDesk.exe" --register-licence" ✅ cmd.exe /c "echo Anydesk@123 | "C:\windows\temp\Anydesk\AnyDesk.exe" --set-password"
100
Huntress @huntress.com · 07/04/2025
Threat actors used CrushFTPService.exe in order to then install an AnyDesk RMM instance, using the commands below:
100
Huntress @huntress.com · 07/04/2025
Huntress researchers recently analyzed attacks involving CVE-2025-31161, a critical authentication bypass flaw in CrushFTP. 💡 We observed specific post-exploitation activity used by threat actors leveraging the flaw in the wild
100
Huntress @huntress.com · 04/04/2025
We saw specific post-exploitation activity from threat actors leveraging this vulnerability in the wild. Read on to learn more and to see how our security experts successfully recreated the authentication bypass proof-of-concept. www.huntress.com/blog/crushft...
huntress.com
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
000
Huntress @huntress.com · 04/04/2025
🚨 We strongly recommend firing up a patch ASAP to avoid affected versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.🚨
100
Huntress @huntress.com · 04/04/2025
CVE-2025-31161 is the latest example of a critical severity authentication bypass vulnerability in CrushFTP, a growing trend we’re seeing from attackers targeting managed file transfer (MFT) platforms.
110
Huntress @huntress.com · 01/04/2025
Threat actors are on every platform you are—so whatever device you’re using, keep an eye out and protect yourself.
000
Huntress @huntress.com · 01/04/2025
Things you might spot in a #smishing text ⬇️ ✅ Sketchy phone number: Pretty sure the USPS isn’t sending out texts from the Philippines ✅ Unclickable links: On the off chance it actually was the USPS, they’d send a link you can click without basically having to solve a riddle
120
Huntress @huntress.com · 24/03/2025
Want to protect your users from this kind of attack? ➡️ Enable MFA for all and use phish-resistant security keys for admins ➡️ Educate users on phishing tactics ➡️ Have a plan in place, including communication, on rotation of any compromised credentials
000
Huntress @huntress.com · 24/03/2025
✅ The telemetry gave our analysts a pivot point to trace the identity theft source ✅ They reviewed the endpoint and found evidence of the phish kit and landing page used to steal the victim’s credentials Investigations don’t always start and end at an endpoint or in the cloud.
100