<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>The Hunter&apos;s Ledger</title><subtitle>Threat Intelligence Reports and Hunting Resources Supported by Hunt.io.</subtitle>
  <link href="https://the-hunters-ledger.com/feed.xml" rel="self" type="application/atom+xml"/>
  <link href="https://the-hunters-ledger.com/" rel="alternate" type="text/html"/>
  <updated>2026-09-10T06:00:50+00:00</updated>
  <id>https://the-hunters-ledger.com/</id>
  <author>
    <name>The Hunter&apos;s Ledger</name>
    <uri>https://the-hunters-ledger.com</uri>
  </author>

  

  
  <entry>
    <title>Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17</title>
    <link href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" rel="alternate" type="text/html"/>
    <published>2026-09-07T00:00:00+00:00</published>
    <updated>2026-09-07T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A Sliver C2 and a separate blockchain-resolved Node.js implant, staged from one open directory, reached Domain Admin in a US organisation&apos;s Windows estate; the second implant&apos;s C2 rotation is logged permanently and publicly on an Ethereum smart contract.</summary>
    
  </entry>
  
  <entry>
    <title>Carrier Credential Harvesting Through a Customer&apos;s Router</title>
    <link href="https://the-hunters-ledger.com/reports/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817/" rel="alternate" type="text/html"/>
    <published>2026-08-18T00:00:00+00:00</published>
    <updated>2026-08-18T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">An operator reached an Ecuadorian carrier&apos;s AAA and provisioning secrets through one small business customer&apos;s carrier-managed Cisco router, making the device upload 424,946,514 bytes of its own firmware, crash dumps and configuration files.</summary>
    
  </entry>
  
  <entry>
    <title>The Middle Tier: A Non-APT Operator&apos;s Reach Into Four Southeast Asian Governments</title>
    <link href="https://the-hunters-ledger.com/reports/seasia-gov-exploitation-toolkit-144-172-106-236/" rel="alternate" type="text/html"/>
    <published>2026-08-13T00:00:00+00:00</published>
    <updated>2026-08-13T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/seasia-gov-exploitation-toolkit-144-172-106-236/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A hands-on-keyboard operator ran a four-country government exploitation campaign from an exposed open directory. This analysis names the three systems that fell, the far larger set that only got probed, the controls that held, and the hunt anchors for the confirmed activity.</summary>
    
  </entry>
  
  <entry>
    <title>CloudSync: An Assembler&apos;s Intrusion Toolkit</title>
    <link href="https://the-hunters-ledger.com/reports/cloudsync-assembler-toolkit-91-197-98-188/" rel="alternate" type="text/html"/>
    <published>2026-08-03T00:00:00+00:00</published>
    <updated>2026-08-03T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/cloudsync-assembler-toolkit-91-197-98-188/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A 22-file intrusion toolkit staged on a live open directory, built almost entirely from other people&apos;s tooling. Three named threat actors&apos; tools sit in the kit, and the operator is none of them.</summary>
    
  </entry>
  
  <entry>
    <title>GOCLOUD: A Commodity Cryptojacking Operation, Captured Whole</title>
    <link href="https://the-hunters-ledger.com/reports/gocloud-multiservice-cryptojacking-149-28-112-221/" rel="alternate" type="text/html"/>
    <published>2026-07-26T00:00:00+00:00</published>
    <updated>2026-07-26T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/gocloud-multiservice-cryptojacking-149-28-112-221/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A self-branded, single-operator commodity cryptojacking operation captured across two hosts. Its own ledgers claim roughly 7,145 successes; independent evidence covers seven hosts. The gap between the two is the finding.</summary>
    
  </entry>
  
  <entry>
    <title>Enough to Be Dangerous: The Mechanics of an LLM-Assisted Intrusion Campaign</title>
    <link href="https://the-hunters-ledger.com/reports/multivector-ecommerce-rce-toolkit-192-3-1-116/" rel="alternate" type="text/html"/>
    <published>2026-07-21T00:00:00+00:00</published>
    <updated>2026-07-21T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/multivector-ecommerce-rce-toolkit-192-3-1-116/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">An exposed staging directory shows how an ordinary operator now runs an intrusion campaign, with scores of probably-generated attack scripts, an off-the-shelf agentic-AI framework wired in as the console, and a defensive lesson in what actually stopped it.</summary>
    
  </entry>
  
  <entry>
    <title>EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-Service</title>
    <link href="https://the-hunters-ledger.com/reports/evilsoul-engine-stealer-maas-144-172-103-98/" rel="alternate" type="text/html"/>
    <published>2026-07-03T00:00:00+00:00</published>
    <updated>2026-07-03T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/evilsoul-engine-stealer-maas-144-172-103-98/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Server-side teardown of the EvilSoul-Engine stealer-builder — a Brazilian Malware-as-a-Service factory that mass-produces uniquely-packed Discord, browser, and crypto-theft payloads with a working Chrome App-Bound-Encryption bypass and Microsoft Defender timing evasion.</summary>
    
  </entry>
  
  <entry>
    <title>KAIDO: A Brazilian Quasar-Fork RAT with Hidden-Desktop Session Hijacking</title>
    <link href="https://the-hunters-ledger.com/reports/kaido-quasar-rat-144-172-109-203/" rel="alternate" type="text/html"/>
    <published>2026-07-03T00:00:00+00:00</published>
    <updated>2026-07-03T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/kaido-quasar-rat-144-172-109-203/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">KAIDO is a rebranded 64-bit Quasar RAT fork operated by a named Brazilian actor. Its Hidden-VNC module clones a victim&apos;s browser profile to drive their live, authenticated session on an invisible desktop, defeating device-trust and most 2FA. The C2 was live with May-2026 samples.</summary>
    
  </entry>
  
  <entry>
    <title>Flask C2 &amp; MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host</title>
    <link href="https://the-hunters-ledger.com/reports/flaskc2-postex-toolkit-67-215-232-25/" rel="alternate" type="text/html"/>
    <published>2026-06-12T00:00:00+00:00</published>
    <updated>2026-06-12T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/flaskc2-postex-toolkit-67-215-232-25/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A live single-host IIS/MSSQL post-exploitation staging operation pairing a bespoke Flask C2 beacon API with a sandbox-evading custom MSSQL CLR reverse-shell backdoor and a public SeImpersonate-to-Active-Directory escalation kit.</summary>
    
  </entry>
  
  <entry>
    <title>Multi-Actor AI-Agent Framework Abuse: 8 Operators Integrating AI CLIs into Offensive Workflows</title>
    <link href="https://the-hunters-ledger.com/reports/ai-agent-frameworks-2026-05-23/" rel="alternate" type="text/html"/>
    <published>2026-06-04T00:00:00+00:00</published>
    <updated>2026-06-04T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/ai-agent-frameworks-2026-05-23/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Parent report of a six-report series documenting 8 independent threat operators integrating AI-agent CLIs (Gemini CLI, Claude Code, Atlassian Rovodev, OpenClaw, Cursor IDE) into offensive workflows, observed through open-directory exposures. Five novel TTPs, six UTA designations, one named-actor HIGH attribution (Vova75Rus), and a GitHub Trust &amp; Safety Tier-0 disposition outcome.</summary>
    
  </entry>
  
  <entry>
    <title>Korean Claude Code + OpenClaw Operator (221.150.15.104) - Attacker-Customized AI-Agent Permission Allowlist</title>
    <link href="https://the-hunters-ledger.com/reports/korean-claude-openclaw-221.150.15.104/" rel="alternate" type="text/html"/>
    <published>2026-05-27T00:00:00+00:00</published>
    <updated>2026-05-27T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/korean-claude-openclaw-221.150.15.104/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Capsule sub-report (Case 4 of the AI-Agent-Frameworks investigation): a Korean-language operator&apos;s attacker-customized ~/.claude/settings.local.json permission allowlist that pre-approves the OpenClaw install-and-run chain, recovered from an open-directory exposure (221.150.15.104, Korea Telecom). UTA-2026-015.</summary>
    
  </entry>
  
  <entry>
    <title>Rovodev AI Co-Authored Mirai Variant + Matrix C2 Framework — UTA-2026-014 (Pandora 11-Arch IoT Botnet + DDoS-as-a-Service)</title>
    <link href="https://the-hunters-ledger.com/reports/rovodev-mirai-matrix-c2-87.106.143.220/" rel="alternate" type="text/html"/>
    <published>2026-05-26T00:00:00+00:00</published>
    <updated>2026-05-26T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/rovodev-mirai-matrix-c2-87.106.143.220/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Technical analysis of an English-speaking Hybrid AI-augmented operator who combined Atlassian Rovodev AI co-authoring with a downstream Pandora-Mirai 11-architecture IoT botnet and a 13-attack-method Matrix C2 framework, productized as a Discord-fronted DDoS-as-a-Service. First publicly documented Rovodev offensive-use case; AI-Generated Offensive Code Structural Signature confirmed DEFINITE for its universal subset via cross-3-operator validation. UTA-2026-014 — first public attribution.</summary>
    
  </entry>
  
  <entry>
    <title>GHOST Cryptojacker Kit Family — Vova75Rus Kit-Author Supply Chain</title>
    <link href="https://the-hunters-ledger.com/reports/ghost-cryptojacker-vova75rus-77.110.96.200/" rel="alternate" type="text/html"/>
    <published>2026-05-25T00:00:00+00:00</published>
    <updated>2026-05-25T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/ghost-cryptojacker-vova75rus-77.110.96.200/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">End-to-end technical analysis of the GHOST cryptojacker kit, a 4-tier supply chain operation authored by Vova75Rus targeting exposed ComfyUI/GPU-cloud hosts with a userland LD_PRELOAD rootkit, dual-Telegram supply-chain monitoring, and a GitHub Trust &amp; Safety Tier-0 disposition outcome.</summary>
    
  </entry>
  
  <entry>
    <title>Turkish ARPA Operator — AI-Augmented State-Insurer Observability Compromise + Insider Recruitment Artifact (UTA-2026-013)</title>
    <link href="https://the-hunters-ledger.com/reports/turkish-arpa-openclaw-state-insurer-209.38.205.158/" rel="alternate" type="text/html"/>
    <published>2026-05-25T00:00:00+00:00</published>
    <updated>2026-05-25T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/turkish-arpa-openclaw-state-insurer-209.38.205.158/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Technical analysis of an active compromise of a state-affiliated Turkish financial-sector organization: a Turkish-speaking operator weaponizes the OpenClaw AI agent platform into a custom analytics platform (ARPA) to harvest the victim&apos;s enterprise observability stack across four stolen sources (IBM Instana + SolarWinds Orion + Zabbix + VMware Aria), and authors Turkish-language insider-recruitment documentation to an in-network Windows AD user. UTA-2026-013, first public attribution.</summary>
    
  </entry>
  
  <entry>
    <title>Russian Gemini CLI Credential Mill — UTA-2026-012 / US Healthcare Provider Compromise</title>
    <link href="https://the-hunters-ledger.com/reports/russian-gemini-credential-mill-213.165.51.115/" rel="alternate" type="text/html"/>
    <published>2026-05-25T00:00:00+00:00</published>
    <updated>2026-05-25T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/russian-gemini-credential-mill-213.165.51.115/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">End-to-end technical analysis of a Russian-native AI-augmented cybercrime operator (UTA-2026-012 / Trend Micro &apos;bandcampro&apos;) running a Gemini-CLI-orchestrated credential mill against a US healthcare victim, with three novel TTP anchors: AI Operator Handoff Documents, LLM-Personalized Credential Mutation, and an operator-built unauthenticated Python-stdlib C2.</summary>
    
  </entry>
  
  <entry>
    <title>CVE-2026-41940 cPanel Harvester Toolkit — 216.126.227.49</title>
    <link href="https://the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/" rel="alternate" type="text/html"/>
    <published>2026-05-17T00:00:00+00:00</published>
    <updated>2026-05-17T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Detailed profile of a financially-motivated operator weaponizing CVE-2026-41940 (cPanel CRLF auth bypass, CVSS 9.8) with a 45-file custom Python/Bash credential-harvesting toolkit, a live Flask C2 dashboard, and a Parklogic TDS monetization layer spanning 17+ operator-controlled domains.</summary>
    
  </entry>
  
  <entry>
    <title>BellaMain — Turkish Phishing-as-a-Service Panel with USOM Self-Monitor, Four-Bot Telegram C2, On-Demand TRUNCATE Anti-Forensics, and Wadanz Code-Author Signature</title>
    <link href="https://the-hunters-ledger.com/reports/bellamain-turkish-phaas-79-137-192-3-20260516/" rel="alternate" type="text/html"/>
    <published>2026-05-16T00:00:00+00:00</published>
    <updated>2026-05-16T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/bellamain-turkish-phaas-79-137-192-3-20260516/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">BellaMain is an operator-developed Turkish Phishing-as-a-Service panel and matched seven-kit brand-impersonation bundle, recovered in full PHP source from an open directory on Aeza Group OFAC-sanctioned hosting. The panel ships first-class operator tradecraft rarely visible at the source layer — USOM (Turkey CERT) blocklist self-monitoring, four-bot Telegram C2 with identity-vs-card role separation, three Telegram-triggered TRUNCATE evidence-destruction commands, mysqldump-to-Telegram backup-as-exfil, a 70/30 TRX/TRON revenue split via live Binance TRXTRY rate conversion, invite-only operator gating with one-time-consume referral codes, and a code-level Wadanz developer signature. First public source-code disclosure for this PhaaS family. Tracked under UTA-2026-008.</summary>
    
  </entry>
  
  <entry>
    <title>Inkognito — Russian-Speaking Multi-Product Fraud Operator (INK VPN, INK Lens 467+ Brand-Impersonation Phishing Library, BEC Burn Domains, CryptOne Fake Exchange)</title>
    <link href="https://the-hunters-ledger.com/reports/inkognito-russian-vpn-phishing-185-221-196-118-20260516/" rel="alternate" type="text/html"/>
    <published>2026-05-16T00:00:00+00:00</published>
    <updated>2026-05-16T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/inkognito-russian-vpn-phishing-185-221-196-118-20260516/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Inkognito is a Russian-speaking multi-product fraud operator that has run continuously for nearly three years. The operator pairs a real commercially-billed VPN service with a 467+ brand-impersonation phishing subdomain library targeting US banking, enterprise SaaS, Chinese internet giants, and Russian telecom. Apex chameleon-decoy tradecraft, an 11-minute domain-to-live deployment pipeline, and infrastructure spanning two sanctioned bulletproof hosters (Aeza, Stark/Worktitans) define the operator footprint. This is the first public cross-brand documentation of the Inkognito portfolio.</summary>
    
  </entry>
  
  <entry>
    <title>Multi-Cluster Open-Directory Tenancy on 79.137.192.3 — Rhadamanthys MaaS Customer Loader, BellaMain Turkish PhaaS, and Inkognito VPN/Phishing</title>
    <link href="https://the-hunters-ledger.com/reports/opendirectory-79-137-192-3-20260515/" rel="alternate" type="text/html"/>
    <published>2026-05-15T00:00:00+00:00</published>
    <updated>2026-05-15T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/opendirectory-79-137-192-3-20260515/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">Three operationally separate threat actors share one Aeza bulletproof staging IP. Cluster C is a Rhadamanthys MaaS customer with a custom VS2019 loader, EAX-redirect hollowing into InstallUtil.exe, and a 34-month-stable Hostkey NL C2 that survived Operation Endgame Phase 3.</summary>
    
  </entry>
  
  <entry>
    <title>HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign</title>
    <link href="https://the-hunters-ledger.com/reports/opendirectory-62-60-237-100-20260506/" rel="alternate" type="text/html"/>
    <published>2026-05-06T00:00:00+00:00</published>
    <updated>2026-05-06T00:00:00+00:00</updated>
    <id>https://the-hunters-ledger.com/reports/opendirectory-62-60-237-100-20260506/</id>
    <author>
      <name>The Hunter&apos;s Ledger</name>
      <uri>https://the-hunters-ledger.com</uri>
    </author>
    
    <summary type="text">A Russian-speaking commodity-malware operator runs a live 15-month multi-vector phishing campaign delivering HijackLoader / Penguish / Rugmi into an AsyncRAT-class .NET RAT, staged from OFAC-sanctioned AS210644 infrastructure and beaconing to Spamhaus DROP-listed AS210558.</summary>
    
  </entry>
  
</feed>
