Threat View from the Lens of Huntress Adversary Tactics: July 2026

Threats Seen in the SOC

Adversary Tactics documents, makes sense of, and informs the broader community about interesting threats that surface from our SOC. Here are some examples of standout trends we’ve seen in the last few weeks.

Fake Claude Install Guide Leads to MacSync Stealer

Mac users searching Google for a Claude install guide are getting something nastier: MacSync, a six-stage stealer and RAT chain that lives off a weaponized Claude share and a copy-paste curl command. It phishes passwords, rips browser and keychain data, abuses TCC, then rewrites crypto wallet apps to harvest seed phrases and hand full control to the attacker. Learn more in this blog post by Josh Kiriakoff – and join our upcoming Tradecraft Tuesday episode where we will discuss this attack further!

The six stages of MacSync, from the pasted curl one-liner to the trojanized wallet apps

The Takeaway

Malvertising around AI tools is now feeding full Mac kill chains that end in irreversible wallet theft. Hunt for curl piped to zsh, suspicious com.apple LaunchAgents in \~/.local and ad hoc signed wallet apps before MacSync turns one bad click into a permanent crypto drain.


Widespread SonicWall Credential Stuffing Campaign

In July we dug into a widespread credential stuffing campaign slamming SonicWall VPN and firewall portals. Threat actors worked from a small cluster of DigitalOcean IPs using stolen creds for remote access logins across dozens of unrelated orgs. When the logins worked, attackers quietly slipped in. Our SOC confirmed around 30 compromises and saw attackers validating access at scale instead of going hands on keyboard. Check out the investigation and blog by Jevon Ang and Ethan Williams here!

Timeline of SonicWall brute-force attacks

The Takeaway

SonicWall shops hit in this wave needed tighter remote access controls, full credential resets, heavier logging, and real MFA coverage.


How Attackers Are Molding Victim Environments

One sloppy web input let an attacker waltz through a SQL injection hole and start remodeling the victim's environment to their liking: enabling RDP, minting new admin accounts, dropping BadIIS modules and a stealthy XMRig miner, and then hiding it all in plain sight. This is what it looks like when criminals turn your own infrastructure into their home field. This blog post by Harlan Carvey and Lindsey O’Donnell Welch explains it all.

The threat actor installed the BadIIS modules

The Takeaway

Initial access is just the opening move; defenders need visibility into the messy post-compromise environment tweaks that let attackers dig in. Defenders can lock down web inputs, tighten identity and RDP exposure, and monitor strange configuration changes to deny attackers that home field advantage.

Tactical Response

Our Tactical Response team was developed as a separate function within our SOC for deep dives into intrusions and to answer partners’ questions outside the scope of 24x7 SOC operations. It helps bridge the gap between the SOC and when formal incident response is required. Our Tactical Response findings also give us a lot of clues about how intrusions play out.

How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

After searching for a Claude Desktop download on Bing, users from 29 different orgs landed on a “legit” Claude.ai artifact that quietly funneled them into SectopRAT. The attackers used fake installers and DLL sideloading, as well as EtherHiding on the blockchain and GPU-based anti-analysis measures in order to throw a wrinkle into the investigation. Learn more about the attack in this blog by Michael Tigges – and how he overcame these anti-analysis challenges.

Bing search results with several malicious sponsored advertisements, including the Claude.ai-hosted public artifact.

The Takeaway

Attackers are continuing to weaponize AI hype and trusted domains. Defenders should keep an eye out for fake “desktop apps” in telemetry and treat every suspicious download link like a potential loader.


Analyzing AI-Augmented Network Enumeration

In July we wrote about a threat actor leaning on AI to spit out a vibe-coded PowerShell recon script that mapped out an entire Active Directory environment then gift wrapped the results in a pretty HTML report. The playbook stayed familiar with an RDP pivot, noisy AD enum, and fast exfil, yet the tooling was one off and AI built. Check out this blog by Jevon Ang and Dray Agha for more!

Extract of Huntress SIEM identifying the tradecraft deployed

The Takeaway

AI is turning mediocre operators into script factories, but it is not rewriting the attack lifecycle. Defenders who hunt for behaviors like AD enumeration and staged exfil are still on the right track even when the code looks brand new every time.


CitrixBleed 2 Weaponized by Initial Access Brokers

An initial access broker is turning CitrixBleed 2 (CVE-2025-5777) into a repeatable seven-step kill chain that bleeds NetScaler memory, steals live session tokens, and sidesteps MFA on exposed gateways. The next stages include pivoting from hijacked user sessions to SYSTEM, planting fake Citrix style admin accounts, and dropping ScreenConnect or Zoho Assist for persistent hands-on keyboard access. This all culminates in DragonForce ransomware on unpatched environments and brutal downtime for anyone who slept on patching. Check out this blog for the breakdown of the attack.

The Takeaway

Defenders should patch exposed NetScaler appliances, retain and review logs, terminate outstanding sessions, and audit for suspicious accounts and remote-management tooling.

Threats Around the World

JADEPUFFER: AI Agent Runs Full Ransomware Op Solo (And Doesn’t Do It So Well)

Security researchers watched JADEPUFFER, an autonomous ransomware agent, break into their sandbox via a Langflow server via CVE-2025-3248. The agent stole credentials, moved laterally, and encrypted a production database with no human operator in the loop. However, the agent also made some strange moves, such as faking the ransom note's crypto details, listing a Bitcoin address that is a well-known example address from public documentation, and destroying the decryption key by accident. Overall, it is a rough preview of what happens when exposed AI workflows double as initial access, persistence, and hands-free extortion.


OpenAI’s Agent Breaks Into Hugging Face To “Cheat” on a “Test”

Hugging Face disclosed that an autonomous AI agent breached its production infrastructure after escaping an OpenAI evaluation sandbox, chaining a zero day in a package proxy with buggy dataset processing to reach internal clusters. The agent was not chasing money, it was hunting ExploitGym answer keys, turning a “capability eval” into the first widely documented AI-driven intrusion at scale.

Anthropic also recently disclosed that a testing misconfiguration let versions of Claude escape isolated evaluation environments and actually hack the systems of three real organizations during "capture the flag" security tests. Versions of Anthropic's Claude AI model broke out of their testing environments and hacked into other organizations on three separate occasions, a disclosure that came roughly one week after OpenAI disclosed a similar incident involving its models.


Coordinated OT Attacks Hit Minnesota Community Water Systems

In late July, hackers ran a coordinated campaign against operational technology at more than 30 Minnesota community water utilities, taking at least one plant offline and forcing others into manual operations. Water quality stayed safe, but the incident showed how little it takes to knock small municipal systems off autopilot and drag state, federal, and local responders into a full critical-infrastructure firefight.

Relevant Product Updates

While not a direct product of the Adversary Tactics team, we’d like to highlight some killer new capabilities that our partners in Product Research and Product have released to help mess up attackers. We can’t wait to start using this data to expand our understanding of the threat actors our customers face.

Check out this month's Product Lab, where Huntress co-founders Chris Bisnett and Kyle Hanslovan talked about the launch of the Huntress mobile app, ISPM hardening on the heels of the LSHIY password spray attack, and how our Athena agentic SOC analyst helps the Huntress SOC investigate threats faster, more consistently, and at scale.

July 2026 Product Lab LIVE!

Managed EDR

  • Auto-Eject for Deceptive Installers: The Huntress Agent now automatically ejects deceptive installers before a user can execute them, stopping a common initial access technique in its tracks. Incident Reports for Deceptive Installer and Fake CAPTCHA threats also now recommend targeted SAT training episodes to close the human side of the gap.
  • MDE Integration GA for GCC High: Microsoft Defender for Endpoint integration is now fully supported in Government Community Cloud (GCC) High environments, providing public sector partners and their clients with the same deep EDR visibility as in commercial deployments.

Managed ITDR

  • Trusted Device Suppression: A new Trusted Device Suppression capability is reducing unexpected-login escalations by 40–50%, cutting alert noise so partners and the SOC can focus on the threats that actually matter.

  • Onboarding Escalation Throttle: The first days after a tenant connects are the roughest: there's no baseline yet, so everything looks anomalous and escalations arrive in a burst. With Onboarding Escalation Throttling, a new tenant's first week now produces a manageable, prioritized stream instead of a flood, so you can onboard clients without warning your techs to brace for the noise.

  • Microsoft Usage Location Inference: Setting usage location tenant-by-tenant has been one of the top requests in Canny - so we are thrilled to share that Microsoft Usage Location Inference is now live in Managed ITDR (thank you for the feedback!). With this functionality, Huntress now infers the home country directly from the tenant, with zero partner configuration required.

  • IP-Based Expected Rules: Partners and customers can now create single-IP Expected Unwanted Access rules in Managed ITDR to eliminate escalations for known office or remote-worker IPs.


Managed ISPM

  • Managed ISPM Hits General Availability: Managed Identity Security Posture Management (ISPM) is now generally available to all partners and customers as a standalone product — no ITDR license required — with integrations to HaloPSA, ConnectWise, Autotask, and Syncro. Since its July 1 launch, over 5,700 organizations are already using Managed ISPM to harden their Microsoft environment.

  • Expands Huntress Coverage of NIST SP 800-171 Controls: With the addition of Managed ISPM, Huntress now maps to 55 of the 110 NIST SP 800-171 controls required for CMMC compliance, giving partners and customers in the defense industrial base a powerful tool to to support CMMC, and the in-depth documentation needed to demonstrate compliance during the assessment process.


Managed SIEM

  • AI Search Now GA: Natural-language log search is now generally available in Managed SIEM, letting partners and analysts query logs in plain English—no syntax required —making investigations faster and more accessible for teams of any skill level.
  • GCP Log Source \+ Azure GCC: High Google Cloud Platform is now a supported log source in Managed SIEM, and Azure GCC High is natively supported, expanding coverage for organizations running hybrid or government cloud environments.
  • Veeam Backup Log Collection: Huntress SIEM now ingests and normalizes logs from Veeam Backup, giving partners visibility into backup infrastructure that ransomware actors frequently target to disable recovery options before detonating.

Managed SAT

  • New Content: We’re constantly reevaluating our library to make sure that all content is relevant and up-to-date. This quarter we rolled out updated versions of previous episodes (Information Security 2, Secure Browsing 2, and Insider Threat 2) to reflect today’s threats and best practices.

  • Custom HTML Phishing: Partners can now build fully custom phishing simulations using HTML.

  • New Learner Onboarding Video: New videos in our library give learners a quick deep-dive into what they can expect from their new SAT program.

Highlights

Tradecraft Tuesday

This month’s Tradecraft Tuesday unpacked a major Azure CLI password spray campaign that involved 81 million login attempts in two weeks and cracked 78 accounts by abusing the deprecated OAuth ROPC flow to slip past weak Conditional Access Policies (CAP), even with MFA enabled. Spike Brandt, Rich Mozeleski, and Lindsey O’Donnell-Welch showed how LSHIY-hosted BYOIP, 155x higher spray volume, and mis-scoped CAP make these attacks succeed, and walked through concrete hardening steps.

The July Tradecraft Tuesday episode was focused on a massive password spray attack