Hunt.io
hunt-io · B · active
Added 2026-07-30 as this run's single new candidate, surfaced by S3. Threat-infrastructure research blog; publishes original exposed-C2 and operator-infrastructure analysis, and collaborates with independent researchers. Already cited by a published entry on 2026-07-25 (Thailand Ministry of Finance / Hermes AI agent), which is what prompted tracking it as a source rather than only as a citation. Promote to active after 3 contributing runs. | 2026-08-07: contributed indirectly, S3 traced a Zimperium 'Flying Eagle' Android-RAT post back to hunt.io as the 2026-07-28 primary and dropped the rehash in favour of it, then re-proposed hunt.io as a candidate not realising it is already tracked. Counts toward the 3-distinct-run promotion bar; already-tracked, so no new candidate was added for it.
Cited in 2 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 2).
- A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations2026-08-28
- Unattended AI agent in 'YOLO mode' automated post-exploitation against Thailand's Finance Ministry, a transferable government-network TTP2026-07-25