TaHiTI · Targeted Hunting integrating Threat Intelligence · Stop searching, start hunting · opening post of a weekly TaHiTI series · HackForLab cyber threat intelligence · hunt methodology cover
0 63
Posted in Cyber Threat

Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface

TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.

HackForLab Weekly Threat Advisory · Jul 20-26 2026 · APT Storm cover · sanitised v2 · deep charcoal + crimson + gold palette · 77,118 indicators · 155 clusters · 25 attributed APT clusters · category-based footprint chart (C2 infrastructure, malware activity, APT, botnet, phishing) · this-week defining signals (15,000 loader hashes, 3 ICS/OT anchor blocks, SVG new-delivery vector)
0 65
Posted in Threat Intelligence

Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)

77,118 unique IOCs across 155 clusters this cycle. 25 attributed APT clusters ran concurrently — the widest APT footprint observed year-to-date. Two loader families produced ~15,000 unique hashes combined (polymorphic-build-farm signal). ICS/OT threat surfaced — PLC-targeted exploitation campaign with three concentrated subnet anchors. DPRK-adjacent activity double-tracked (cryptocurrency-focus + IT-worker infiltration). Russian-aligned and Middle East regional operations active. Novel SVG-embedded script delivery vector. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per indicator type.

HackForLab Weekly Threat Advisory · Jul 13-19 2026 · Weekly Intelligence Briefing sanitised cover · deep charcoal + crimson + gold palette · 59,935 indicators · 116 clusters · 4 attributed APT clusters · 20+ ransomware families · category-based footprint chart · this-week defining signals: novel blockchain-resolved C2, attributed APT concurrent, ransomware family surge
0 350
Posted in Threat Intelligence

Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)

59,935 unique IOCs across 116 clusters this cycle. Polygon-based C2 surfaced (314 IOCs, novel blockchain-resolved command channel — following the TON pattern). Four Chinese-aligned APT clusters active in parallel (APT-C-60 with 121 IOCs full 5-type spread, UAT-11795, APT-C-35, APT-Q-27). 20+ ransomware families concurrent (RAWorld 213, Trigona 115, Qilin 56, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry + more). Package-registry supply-chain double strike (game-cheat + Go module). macOS threat layer matured (AppleScript infostealer + macOS-focused stealer + ClickFix variants). TencShell C2 operator with 4 subnet anchors (16 IPs concentrated). Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.

HackForLab Weekly Threat Advisory · Jul 6-12 2026 · Beyond Ransomware sanitised cover · deep charcoal + crimson + gold palette · 1,804 unique IOCs · 1,322 high-severity · 89 clusters · 11 RATs 7 APTs 1 wiper · category-based footprint chart · this-week defining signals: crypto-mining RAT surge, RAT economy expansion, novel wiper delivery, macOS threat maturation
0 84
Posted in Threat Intelligence

Weekly Threat Advisory: Beyond Ransomware — 11 RATs, 7 APTs, 1 WIPER, HASH Still Leads (Jul 6 – 12, 2026)

The non-ransomware threat layer of the week. 1,804 unique IOCs across 89 clusters (ransomware excluded). RuRAT cryptomining surge (244 IOCs — wallet-drainer domain cluster). 11 RAT families active (Vidar, Millenium RAT v4, GoodPersonRAT, Dcrat, AsyncRAT, EtherRAT, QuimaRAT, Banana RAT + more). 7 APT clusters (UAT-7810 port fingerprint 2222/8088/99, DPRK 5-type spread, Lazarus, Cavern Manticore, MustangPanda, PlugX, UNK_MassTraction). Novel multi-stage LNK + JS-runtime backdoor (135 IOCs). GigaWiper — destructive-class malware, 10 IOCs. macOS ClickFix — first observation. HASH still beats IP (810 vs 468) even without ransomware. Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.

HackForLab Weekly Threat Advisory · Jun 29 – Jul 5 2026 · sanitised cover · deep charcoal + crimson + gold palette · 1,524 unique IOCs · 1,129 high-severity · 64 clusters · 5 attributed APT clusters · category-based footprint chart · this-week defining signals: novel blockchain-resolved C2, trust-anchor verification-page phishing, ransomware family activity
0 78
Posted in Threat Intelligence

Weekly Threat Advisory: 5 APTs, 200 RATs, 74% High-Severity — The Week the C2 Flood Went Quiet (Jun 29 – Jul 5, 2026)

1,524 unique IOCs across 64 clusters. Extraordinary week: DOMAIN volume beat IP for the first time; 74% of records HIGH severity (usual baseline: 1-2%). 5 named APTs active (UNC1151, APT36, TeamPCP, Lazarus, BitterAPT) + CyberAv3ngers subnet anchor at 185.82.73.0/24. AsyncRAT surged to 200+ IOCs — largest RAT footprint YTD. TONResolver introduces novel blockchain-based C2 resolution. Trust-anchor phishing (Fake Google/Cloudflare verification pages, 54 IOCs, two subnet anchors). Anubis + The Gentlemen ransomware active. Steganographic ad malware (StegoAd) and AI-agent phishing surface as new attack patterns. Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, 4 production-ready Sigma rules.