Malware Hunter | Huntress SOC Principal Analyst | USAF Veteran

Filter
Exclude
Time range
-
Minimum likes
Jonathan Semon retweeted
New: Attackers are abusing ChatGPT's Custom GPT feature, luring victims in w/ the legit ChatGPT domain and then directing them to a ClickFix attack that: →Installs a malicious MSI →Uses DLL sideloading →Drops a RAT More from @JSemonSecurity @the_MarkOH: huntress.com/blog/chatgpt-cu…
3
17
48
4,672
Hey @2Kgames @GearboxOfficial Looks like your domain at gearboxsoftware.com/ was compromised via some Wordpress extension... Might wanna get that cleared up.
3
2
151
Replying to @Octoberfest73
What's even worse is companies like Forbes reposting this content for the world to see, with zero fact-checking, or even a simple Google search of "Windows .lnk malware.". They might as well call sethc.exe a vulnerability and assign a CVE at this point. 🥴
2
251
Replying to @uwu_underground
Absolute love, thank you for sharing, yall are too kind. <3
1
2
81
Nowhere did I say, "no customer notification." With any managed EDR, the workflow is simple: alerts occur, SOC investigates, reports sent. Pulling browser history is not exclusive to Huntress, and it happens only when required to validate the alert and scope an incident, and all the collected data is reported to the customer in the report for transparency.
2
3
247
Huntress is a Managed EDR/MDR product built for organizations. Whether a small business or an enterprise, installing the agent grants the SOC the authority to investigate that endpoint, that’s how all AV/EDR tools work. During sign-up, on the product page, “Business” and “Enterprise” are explicitly emphasized (Over 20 times iirc). If someone installs it outside that scope, they’re still consenting to telemetry collection and investigation when malicious activity occurs. Once installed, you are consenting to an investigation of your endpoint if the tooling considers malicious activity occurring to be severe enough to need further investigation. To be clear though, no SOC is pulling browser history "for fun." That level of review only happens when an investigation requires it, which unfortunately is quite often when we are attempting to find compromised domains or phishing portals that are used to hack hundreds of millions of people daily.
1
2
226
Looks like others commented too, but to be clear, when you install a Managed EDR/AV, you are giving a company the ability to investigate your machine. Doesn't matter which company it is. We did not just see a random endpoint and go "Let's pull that one's history for giggles." Signals were generated that lead to an investigation, in this case clearly malicious activity occurring on that endpoint, and in that investigation, it was identified that downloads had occurred, and to identify where they came from and when, the browser history was pulled. In the browser history, was the download data, as well as all the shady shit the threat actor was doing.
1
4
250
"Before you make the correlation" is wrong. The end user triggered alerts on their endpoint (we have no context), we investigate the alerts (to get context), and during the investigation we see that they're actually the bad actor themselves (we have context), that's a SOCs job.
1
11
956
Replying to @mrexodia
Not quite right. The threat actor installed Huntress on their own endpoint. They triggered alerts (malicious tooling, downloads, etc.); the SOC investigated the telemetry and then pulled the history to confirm. Only after that was the hostname/data correlation made.
1
18
16,975
I swear 2025 is the year of Animal loving malware groups, that and Femboys according to Broadcom. 😔
1
3
64
Can confirm, this is the same crap, different app. The same folks who make Onestart just license out the software stack to "partners" with absolutely no vetting, and even when called out for their "partners" slipping malware into the application code they deny any wrong doing.
2
8
338
Sold! Rib cage just to feel alive for a few minutes!
1
1
50
Don't worry, I'll hold your hand through it all. ❤️😇
6
54