Malware Hunter | Huntress SOC Principal Analyst | USAF Veteran

Jonathan Semon retweeted
This was interesting. I hadn't seen Google Docs weaponized like that before. @_rdowd @JSemonSecurity and @threatresearch spent some time hunting everything down and it turned out a little more interesting than I previously thought. We never got that linux lure though 🤣 huntress.com/blog/defcon-phi…
20
51
3,302
Hey @2Kgames @GearboxOfficial Looks like your domain at gearboxsoftware.com/ was compromised via some Wordpress extension... Might wanna get that cleared up.
3
2
142
Confirmed to drop NetSupport.🐀
60
Leading to a lovely ClickFix page.😌
56
Jonathan Semon retweeted
Search: “clear disk space on macOS” Click: legit ChatGPT convo Paste: “safe” Terminal command Boom: AMOS infostealer installed @stuartjash & @JSemonSecurity break down how Attackers are hijacking ChatGPT + Grok to deliver malware. huntress.com/blog/amos-steal…
2
32
104
11,169
JFC. Trend Micro released a report on lnk file argument hiding months ago as a “zero day” that has been observed for close to 10 year at this point. Now they have a CVE assigned for it with “remote code execution” in the description. What an absolute sham and embarrassment.
I always thought this was a normal feature.😅 CVE-2025-9491 vulnerability exists in the way Windows handles .LNK (shortcut) files. Attackers can embed malicious command-line parameters in the "Target" field of the LNK file and pad them with spaces or other characters to hide these parameters. When a user inspects the file through the Windows user interface, these dangerous contents are invisible to the user. Once the user executes the LNK file, these hidden parameters are passed to the target program, leading to the execution of arbitrary code in the context of the current user.
6
7
56
10,120
What's even worse is companies like Forbes reposting this content for the world to see, with zero fact-checking, or even a simple Google search of "Windows .lnk malware.". They might as well call sethc.exe a vulnerability and assign a CVE at this point. 🥴
2
251
Jonathan Semon retweeted
11
11
134
6,496
OUR LATEST ALBUM APT TALES VOL 3 "GHOSTS IN THE WALLS" IS OFFICIALLY OUT NOW! uwuunderground.bandcamp.com/…
16
27
75
22,901
Absolute love, thank you for sharing, yall are too kind. <3
1
2
81
This is actually crazy…
A threat actor installed Huntress. ... a hysterical mistake on their part, giving us first-hand insight to their tooling, workflow & routine. Phishing infra, stealer logs, Telegram+dark web sites, AI... Hilarious goldmine of cybercrime deets with a front row seat: huntress.com/blog/rare-look-…
3
5
81
20,124
I'm exhausted so if you respond, ill see it tomorrow, but to be clear, when browsing history is reviewed via the browser’s database, it isn’t limited to "just today," it’s everything since the last time history was cleared. That’s how the artifact works, and every analyst who has pulled that file knows it. You can see this yourself, pull your history.db file from Edge/Chrome, and open it in DB Browser for SQLite. Pair that with the fact Huntress is an EDR + MDR/SOC product: once alerts fire, it’s the SOC’s responsibility to investigate by whatever means are needed (within our ToS and EULA, of course) to scope the incident. Every alert is treated as a potential attack until proven otherwise, and customers receive reports showing exactly what was pulled and remediated. And honestly, be glad we don’t do what some EDRs do, like full HTTPS traffic decryption with ingestion into the telemetry platform. That’s far more invasive than validating a browser history artifact when alerts fire. 😅
1
34
So you're saying huntresslabs doesn't alert stake holders/customers when you're performing an investigation let alone pulling sensitive information such as browsing history?
1
234
Nowhere did I say, "no customer notification." With any managed EDR, the workflow is simple: alerts occur, SOC investigates, reports sent. Pulling browser history is not exclusive to Huntress, and it happens only when required to validate the alert and scope an incident, and all the collected data is reported to the customer in the report for transparency.
2
3
247
They saw an ad saying Enterprise-grade cybersecurity for ALL businesses and they download them.
1
229
Huntress is a Managed EDR/MDR product built for organizations. Whether a small business or an enterprise, installing the agent grants the SOC the authority to investigate that endpoint, that’s how all AV/EDR tools work. During sign-up, on the product page, “Business” and “Enterprise” are explicitly emphasized (Over 20 times iirc). If someone installs it outside that scope, they’re still consenting to telemetry collection and investigation when malicious activity occurs. Once installed, you are consenting to an investigation of your endpoint if the tooling considers malicious activity occurring to be severe enough to need further investigation. To be clear though, no SOC is pulling browser history "for fun." That level of review only happens when an investigation requires it, which unfortunately is quite often when we are attempting to find compromised domains or phishing portals that are used to hack hundreds of millions of people daily.
1
2
226
I would like to know where you work at where you do whatever you wish without notifying your clients/customers.
1
1
458
Looks like others commented too, but to be clear, when you install a Managed EDR/AV, you are giving a company the ability to investigate your machine. Doesn't matter which company it is. We did not just see a random endpoint and go "Let's pull that one's history for giggles." Signals were generated that lead to an investigation, in this case clearly malicious activity occurring on that endpoint, and in that investigation, it was identified that downloads had occurred, and to identify where they came from and when, the browser history was pulled. In the browser history, was the download data, as well as all the shady shit the threat actor was doing.
1
4
250
That doesn't make it better. You're basically saying you pulled their browsing history without their knowledge even before you make the correlation (just because it triggered some alerts). The more you say the worse it sounds.
1
5
966
"Before you make the correlation" is wrong. The end user triggered alerts on their endpoint (we have no context), we investigate the alerts (to get context), and during the investigation we see that they're actually the bad actor themselves (we have context), that's a SOCs job.
1
11
956
A threat actor installed Huntress. ... a hysterical mistake on their part, giving us first-hand insight to their tooling, workflow & routine. Phishing infra, stealer logs, Telegram+dark web sites, AI... Hilarious goldmine of cybercrime deets with a front row seat: huntress.com/blog/rare-look-…
68
241
1,508
288,220
Good read but does it mean you identified this guy with his machine id just by him downloading huntress?
1
682
X-post because I am lazy: Not quite. The threat actor installed Huntress on the endpoint. They triggered alerts (malicious tooling, downloads, etc.); the SOC investigated the telemetry and then pulled the history to confirm. Only after that was the hostname/data correlation made.
1
50
My reading: the machine name was a red flag (as well as 'several other factors'), so you pulled the browser history for 3 months prior to them installing a trial of your product. Obviously that person is a criminal, but collecting evidence like this seems unethical at best...
6
55
3,443
Not quite right. The threat actor installed Huntress on their own endpoint. They triggered alerts (malicious tooling, downloads, etc.); the SOC investigated the telemetry and then pulled the history to confirm. Only after that was the hostname/data correlation made.
1
18
16,975
Rumors on the internet that #DolphinLoader is back 👀 cc @wbmmfq @JSemonSecurity
2
2
18
2,340
With new memes to explore, or is it relatively the same?
2
2
165
I swear 2025 is the year of Animal loving malware groups, that and Femboys according to Broadcom. 😔
1
3
64
These PDF editors are functional but each contain a backdoor ➡️virustotal.com/gui/file/fde6… #TamperedChef
6
35
132
25,101
I think this is what we've been seeing for a few weeks now, too. /cc @RussianPanda9xx @JSemonSecurity
1
8
350
Can confirm, this is the same crap, different app. The same folks who make Onestart just license out the software stack to "partners" with absolutely no vetting, and even when called out for their "partners" slipping malware into the application code they deny any wrong doing.
2
8
338
Jonathan Semon retweeted
As of Thurs Aug 14th we're seeing clear indications that a threat actor has now weaponised and is exploiting vulnerabilities in Axis camera software (CVE-2025-30023/4/5/6) which was presented at DEFCON. Props to @Cyber4a53 for find. axis.com/dam/public/9b/a5/72… CC: @HuntressLabs 👇
3
27
63
7,628
Hanging with the gang at @HuntressLabs Summer Summit ☀️🍸 @0xffaraday , @wbmmfq , @JSemonSecurity , let the doxxing begin …
10
83
12,598
If I ever join the hunt, let's get one 😂 (may be very very smoll)
1
134
Sold! Rib cage just to feel alive for a few minutes!
1
1
50