Full archive

All reports

All the threat intelligence reports we've published, in one place

Browse & filter

Showing 12 of 14 posts

This content requires premium access. Subscribe for full threat intelligence reports and analysis.

Premium
Premium content

SILENTLOOM: A Reused Device Pool Behind a Quiet Microsoft 365 Password Attack

Premium access required

Free
doctrinemethodologyinfrastructure-analysis+6

Find the House, Not the Doormat: A Doctrine for Reading Infrastructure Metadata After the Attack

The single-indicator pivot dies against a tier-separated operator, stopping at the access surface. This doctrine proposes four moves for reading metadata after: seed from a behavioral cohort, mine persistent fingerprints, separate attack signature from residue, confirm with an independent source.

CR

Chawkr Reports

18/06/2026

Free
eviltokensphishingdevice-code+7

EvilTokens: Device Code Phishing Goes Industrial

We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped a four-tier architecture. It spans a Cloudflare CDN frontend, DocuSign/Exim backend hosting, a bridge cluster on Google Trust Services certs, Cobalt Strike C2 via domain fronting, and an unreported IoT layer of Hikvision/Dahua cameras.

CR

Chawkr Reports

09/04/2026

Free
ollamallmjackingqwen+6

Profiling the Largest Identifiable Exposed AI Infrastructure on the Internet

Over 1,500 IPs from Shodan's exposed Ollama index were analyzed through ClusterHawk. After filtering 60% honeypots, 13 of 27 clusters pointed to one operator, XRUI TECHNOLOGY LIMITED, running identical nginx/MySQL/Ollama stacks with unauthenticated qwen3-vl inference across 35+ hosts.

CR

Chawkr Reports

13/03/2026

Free
overcastnation-staterdp+8

OVERCAST: Tracking 1,900 Nation-State RDP Nodes Across Cloudzy's C2P Ecosystem

We received 50 validated IPs linked to a suspected Russian state-sponsored APT, profiled them through ClusterHawk, and extracted a common fingerprint. Pivoting that profile against internet scanning data surfaced about 1,900 matching assets across 15 countries. We call this tracking effort OVERCAST.

CR

Chawkr Reports

22/02/2026

Free
icsscadamodbus+5

The Pattern in the Noise: What 1,602 Exposed Modbus Systems Reveal About Industrial Security's Systemic Failures

Analyzing 1,602 internet-visible Modbus systems turned up systematic patterns, not scattered misconfigurations. Ninety-five percent share TLS fingerprints, identical certificates, and the same CVEs across clusters, and the entire ICS ecosystem deploys infrastructure in predictable, exploitable ways.

CR

Chawkr Reports

06/01/2026

Free
botnetiotproxy-network+4

When Your Router Becomes Someone Else's Weapon: Uncovering a 800+ Proxy Network via KeeneticOS Router

Through infrastructure clustering analysis, we identified a proxy network of 832 compromised KeeneticOS routers operating across Russian ISPs. The investigation shows how consumer routers get turned into weaponized infrastructure for threat actors.

CR

Chawkr Reports

26/11/2025

Free
sidewinderaptclickonce+6

SideWinder's Click Once campaign - independent validation with ClusterHawk

We confirm Trellix's reporting on SideWinder's PDF ClickOnce chain and targets. Testing the method, we pivoted on VirusTotal-communicated IPs and separated CDN/search noise (about 85%) from a compact nginx micro-cluster (about 15%), then built ready-to-run SIEM/Sigma and Shodan/Censys hunts.

CR

Chawkr Reports

02/11/2025

Free
clickfixnetsupport-ratesentire+6

ClickFix to NetSupport: Validating ClusterHawk, Cluster Profiles, and What's New

We seeded ClusterHawk with eSentire's published NetSupport indicators and clustered the infrastructure behind ClickFix delivery. The results validate against eSentire TRU's reporting and IoCs, and add a predictive WinRM signature plus anomaly-led IP triage.

CR

Chawkr Reports

01/11/2025

Free
clusteringmalware-infrastructurec2-servers+3

Explorative Clustering of Malicious Infrastructure with ClusterHawk

Over 2,700 malicious IP addresses were analyzed in an explorative clustering experiment using ClusterHawk to group adversarial infrastructure. The objective: determine whether Command-and-Control (C2) servers cluster by operational similarity alone, without relying on predefined family signatures.

CR

Chawkr Reports

15/10/2025

Free
systembcbotnetinfrastructure+2

SystemBC Infrastructure Investigation: Automated Insights in Response to Black Lotus Labs' Report

We independently validated and extended Lumen's SystemBC findings with Chawkr's clustering pipeline. The result: role-based infrastructure profiles, stability metrics, and anomaly scores.

CR

Chawkr Reports

19/09/2025

This content requires premium access. Subscribe for full threat intelligence reports and analysis.

Premium
Premium content

Storm-0940: State-Sponsored Brute-Force Attacks Targeting Microsoft 365

Premium access required