Full archive
All reports
All the threat intelligence reports we've published, in one place
Browse & filter
Showing 12 of 14 posts
This content requires premium access. Subscribe for full threat intelligence reports and analysis.
Premium content
SILENTLOOM: A Reused Device Pool Behind a Quiet Microsoft 365 Password Attack
Premium access required
Find the House, Not the Doormat: A Doctrine for Reading Infrastructure Metadata After the Attack
The single-indicator pivot dies against a tier-separated operator, stopping at the access surface. This doctrine proposes four moves for reading metadata after: seed from a behavioral cohort, mine persistent fingerprints, separate attack signature from residue, confirm with an independent source.
Chawkr Reports
18/06/2026
EvilTokens: Device Code Phishing Goes Industrial
We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped a four-tier architecture. It spans a Cloudflare CDN frontend, DocuSign/Exim backend hosting, a bridge cluster on Google Trust Services certs, Cobalt Strike C2 via domain fronting, and an unreported IoT layer of Hikvision/Dahua cameras.
Chawkr Reports
09/04/2026
Profiling the Largest Identifiable Exposed AI Infrastructure on the Internet
Over 1,500 IPs from Shodan's exposed Ollama index were analyzed through ClusterHawk. After filtering 60% honeypots, 13 of 27 clusters pointed to one operator, XRUI TECHNOLOGY LIMITED, running identical nginx/MySQL/Ollama stacks with unauthenticated qwen3-vl inference across 35+ hosts.
Chawkr Reports
13/03/2026
OVERCAST: Tracking 1,900 Nation-State RDP Nodes Across Cloudzy's C2P Ecosystem
We received 50 validated IPs linked to a suspected Russian state-sponsored APT, profiled them through ClusterHawk, and extracted a common fingerprint. Pivoting that profile against internet scanning data surfaced about 1,900 matching assets across 15 countries. We call this tracking effort OVERCAST.
Chawkr Reports
22/02/2026
The Pattern in the Noise: What 1,602 Exposed Modbus Systems Reveal About Industrial Security's Systemic Failures
Analyzing 1,602 internet-visible Modbus systems turned up systematic patterns, not scattered misconfigurations. Ninety-five percent share TLS fingerprints, identical certificates, and the same CVEs across clusters, and the entire ICS ecosystem deploys infrastructure in predictable, exploitable ways.
Chawkr Reports
06/01/2026
When Your Router Becomes Someone Else's Weapon: Uncovering a 800+ Proxy Network via KeeneticOS Router
Through infrastructure clustering analysis, we identified a proxy network of 832 compromised KeeneticOS routers operating across Russian ISPs. The investigation shows how consumer routers get turned into weaponized infrastructure for threat actors.
Chawkr Reports
26/11/2025
SideWinder's Click Once campaign - independent validation with ClusterHawk
We confirm Trellix's reporting on SideWinder's PDF ClickOnce chain and targets. Testing the method, we pivoted on VirusTotal-communicated IPs and separated CDN/search noise (about 85%) from a compact nginx micro-cluster (about 15%), then built ready-to-run SIEM/Sigma and Shodan/Censys hunts.
Chawkr Reports
02/11/2025
ClickFix to NetSupport: Validating ClusterHawk, Cluster Profiles, and What's New
We seeded ClusterHawk with eSentire's published NetSupport indicators and clustered the infrastructure behind ClickFix delivery. The results validate against eSentire TRU's reporting and IoCs, and add a predictive WinRM signature plus anomaly-led IP triage.
Chawkr Reports
01/11/2025
Explorative Clustering of Malicious Infrastructure with ClusterHawk
Over 2,700 malicious IP addresses were analyzed in an explorative clustering experiment using ClusterHawk to group adversarial infrastructure. The objective: determine whether Command-and-Control (C2) servers cluster by operational similarity alone, without relying on predefined family signatures.
Chawkr Reports
15/10/2025
SystemBC Infrastructure Investigation: Automated Insights in Response to Black Lotus Labs' Report
We independently validated and extended Lumen's SystemBC findings with Chawkr's clustering pipeline. The result: role-based infrastructure profiles, stability metrics, and anomaly scores.
Chawkr Reports
19/09/2025
This content requires premium access. Subscribe for full threat intelligence reports and analysis.
Premium content
Storm-0940: State-Sponsored Brute-Force Attacks Targeting Microsoft 365
Premium access required
