All Reports

Archive of security research, threat analysis, and intelligence reports

Browse & Filter

Showing 12 of 12 posts

EvilTokens: Device Code Phishing Goes Industrial

Free

We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped the full infrastructure architecture: a Cloudflare CDN frontend, fragmented backend hosting with DocuSign lures and Exim mail servers, a bridge cluster with Google Trust Services certificates on compromised business domains, Cobalt Strike C2 via domain fronting, and an unreported IoT proxy layer of compromised Hikvision/Dahua surveillance cameras on Chinese telecom networks.

eviltokens
phishing
device-code
+7
09/04/2026
0 comments
0 likes

Profiling the Largest Identifiable Exposed AI Infrastructure on the Internet

Free

Over 1,500 IPs from Shodan's exposed Ollama index were analyzed through ClusterHawk. After filtering 60% honeypots, 13 of 27 clusters pointed to a single operator — XRUI TECHNOLOGY LIMITED — running identical nginx/MySQL/Ollama stacks with unauthenticated qwen3-vl inference across 35+ hosts alongside a Chinese sports gambling site. This is the largest identifiable exposed AI infrastructure we've found in one operator's hands.

ollama
llmjacking
qwen
+6
13/03/2026
0 comments
0 likes

OVERCAST: Tracking 1,900 Nation-State RDP Nodes Across Cloudzy's C2P Ecosystem

Free

We received 50 validated IPs linked to a suspected Russian state-sponsored APT. We profiled them through ClusterHawk and extracted a common fingerprint — then pivoted on that profile against internet scanning data and surfaced approximately 1,900 matching assets across 15 countries. We designate this infrastructure tracking effort OVERCAST.

overcast
nation-state
rdp
+7
22/02/2026
0 comments
0 likes

The Pattern in the Noise: What 1,602 Exposed Modbus Systems Reveal About Industrial Security's Systemic Failures

Free

Analyzing 1,602 internet-visible Modbus systems revealed not scattered misconfigurations but systematic patterns—95% shared TLS fingerprints, identical certificates, same CVEs across clusters. This isn't about individual negligence; it's how the entire ICS ecosystem deploys critical infrastructure in predictable, exploitable ways.

ics
scada
modbus
+5
06/01/2026
0 comments
0 likes

When Your Router Becomes Someone Else's Weapon: Uncovering a 800+ Proxy Network via KeeneticOS Router

Free

Through infrastructure clustering analysis, we identified a proxy network containing 832 compromised KeeneticOS routers operating across Russian ISPs. This investigation reveals how consumer devices become weaponized infrastructure in the modern threat landscape.

botnet
iot
proxy-network
+4
26/11/2025
0 comments
0 likes

SideWinder's Click Once campaign - independent validation with ClusterHawk

Free

We confirm Trellix’s reporting on SideWinder’s PDF ClickOnce chain and targets, and we prove our methodology by deliberately injecting a broad VirusTotal communicated IPs pivot and then separating CDN/search noise (~85%) from a compact nginx micro-cluster (~15%) that’s worth watching. Below are ready-to-run hunts (SIEM/Sigma + Shodan/Censys) and cluster fingerprints you can use as predictive seeds.

sidewinder
apt
clickonce
+6
02/11/2025
0 comments
0 likes

ClickFix to NetSupport: Validating ClusterHawk, Cluster Profiles, and What's New

Free

Methodology first. We seeded ClusterHawk with eSentire's published NetSupport indicators and clustered/scored the infrastructure behind ClickFix delivery. We then validated our results against eSentire TRU's reporting and IoCs. Outcome: our method reproduces the delivery chain and infra families eSentire describes and adds operator-centric cluster profiles, a predictive WinRM signature (issuer + JA3S/JARM + RDP/WinRM), and anomaly-led triage that prioritizes the right IPs fast.

clickfix
netsupport-rat
esentire
+6
01/11/2025
0 comments
0 likes

Explorative Clustering of Malicious Infrastructure with ClusterHawk

Free

Over 2,700 malicious IP addresses were analyzed in an explorative clustering experiment using ClusterHawk for trying to group adversarial infrastructure. The objective: to determine whether clusters of Command-and-Control (C2) servers could be automatically grouped by operational similarity — without relying on predefined family signatures.

clustering
malware-infrastructure
c2-servers
+3
15/10/2025
0 comments
0 likes

SystemBC Infrastructure Investigation: Automated Insights in Response to Lumen's Report

Free

We independently validated and extended Lumen's SystemBC findings using Chawkr's automated clustering, producing role-based infrastructure profiles, stability metrics, and anomaly scoring.

systembc
botnet
infrastructure
+2
19/09/2025
0 comments
0 likes

This content requires premium access. Subscribe to unlock full threat intelligence reports, analysis, and exclusive insights.

Premium Content

Storm-0940: State-Sponsored Brute-Force Attacks Targeting Microsoft 365

Unlock with premium access

How to Read and Validate Platform Reports

Free

This guide teaches analysts how to read platform-generated reports, what to focus on, and how to validate claims against underlying artifacts, following the system methodology.

guide
reports
analysis
+2
15/08/2025
0 comments
0 likes

Threat Actor Profiles: Building, Tracking, and Operationalizing Intelligence

Free

Threat actor profiles are structured, data-driven portraits of adversaries' persistent behaviors—infrastructure choices, operational cadence, cryptographic habits, naming schemes, product stacks—not just ephemeral artifacts like single IPs or hashes.

threat-intelligence
profiles
analysis
+2
01/08/2025
0 comments
0 likes