<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Hunting off the Red — Focused Hunts</title>
    <link>https://www.focusedhunts.com/blog/hunting</link>
    <description>Technical threat intelligence guides — public reports turned into actionable hunting guidance with detection queries.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 31 Jul 2026 14:12:02 GMT</lastBuildDate>
    <atom:link href="https://www.focusedhunts.com/blog/hunting/feed.xml" rel="self" type="application/rss+xml" />
    <image>
      <url>https://www.focusedhunts.com/img/blog/hunting-off-the-red-small.png</url>
      <title>Hunting off the Red — Focused Hunts</title>
      <link>https://www.focusedhunts.com/blog/hunting</link>
    </image>
    <item>
      <title>CyberAv3ngers: Hunting Iranian OT Attacks on U.S. Water Systems</title>
      <link>https://www.focusedhunts.com/blog/hunting/CyberAv3ngers-IOCONTROL-Water-OT-Attacks</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/CyberAv3ngers-IOCONTROL-Water-OT-Attacks</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <description>Analysis of CyberAv3ngers and IOCONTROL attacks on U.S. water and OT systems.</description>
    </item>
    <item>
      <title>UNC6508 and the INFINITERED Backdoor Targeting Medical Research</title>
      <link>https://www.focusedhunts.com/blog/hunting/INFINITERED-REDCap-Medical-Research-Backdoor</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/INFINITERED-REDCap-Medical-Research-Backdoor</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>Analysis of UNC6508&apos;s INFINITERED backdoor targeting REDCap medical research servers.</description>
    </item>
    <item>
      <title>STOCKSTAY: Detecting Turla&apos;s Multi-Component Espionage Backdoor</title>
      <link>https://www.focusedhunts.com/blog/hunting/STOCKSTAY-Turla-Espionage-Backdoor</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/STOCKSTAY-Turla-Espionage-Backdoor</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>Analysis of STOCKSTAY, a Turla espionage backdoor targeting Ukraine and government networks.</description>
    </item>
    <item>
      <title>Fox Tempest: AI-Themed Malvertising Delivers Signed Malware at Scale</title>
      <link>https://www.focusedhunts.com/blog/hunting/Fox-Tempest-AI-Malvertising-Signed-Malware</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Fox-Tempest-AI-Malvertising-Signed-Malware</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <description>Analysis of Microsoft&apos;s Fox Tempest malware-signing service and AI-themed malvertising delivering Vidar, with Splunk and KQL hunting queries and MITRE mapping.</description>
    </item>
    <item>
      <title>UNK_DeadDrop: North Korean Phishing Turns VS Code Against Developers</title>
      <link>https://www.focusedhunts.com/blog/hunting/UNK-DeadDrop-VSCode-Developer-Targeting</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/UNK-DeadDrop-VSCode-Developer-Targeting</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <description>Analysis of the UNK_DeadDrop DPRK campaign weaponizing VS Code extensions and repos against developers, with Splunk and KQL hunting queries and MITRE mapping.</description>
    </item>
    <item>
      <title>PhantomRPC: Windows RPC Privilege Escalation via Server Impersonation</title>
      <link>https://www.focusedhunts.com/blog/hunting/PhantomRPC-Windows-RPC-Privilege-Escalation</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/PhantomRPC-Windows-RPC-Privilege-Escalation</guid>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <description>Analysis of PhantomRPC Windows RPC privilege escalation with Splunk and KQL threat hunting queries.</description>
    </item>
    <item>
      <title>F5 BIG-IP CVE-2025-53521: BRICKSTORM Backdoor and Nation-State Exploitation</title>
      <link>https://www.focusedhunts.com/blog/hunting/F5-BIG-IP-BRICKSTORM-Backdoor-Detection</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/F5-BIG-IP-BRICKSTORM-Backdoor-Detection</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <description>Analysis of CVE-2025-53521 and BRICKSTORM backdoor targeting F5 BIG-IP APM with Splunk and KQL hunting queries, MITRE mappings, and behavioral indicators.</description>
    </item>
    <item>
      <title>GRIDTIDE: Detecting Google Sheets C2 in a Global Espionage Campaign</title>
      <link>https://www.focusedhunts.com/blog/hunting/GRIDTIDE-Global-Espionage-Google-Sheets-C2</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/GRIDTIDE-Global-Espionage-Google-Sheets-C2</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description>Analysis of GRIDTIDE backdoor used by UNC2814 for global espionage. Splunk and Microsoft hunting queries with MITRE ATT&amp;CK mappings and detection strategies.</description>
    </item>
    <item>
      <title>VEN0m Ransomware: BYOVD-Enabled File Encryption with AV/EDR Neutralization</title>
      <link>https://www.focusedhunts.com/blog/hunting/VEN0m-Ransomware-BYOVD-Detection</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/VEN0m-Ransomware-BYOVD-Detection</guid>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
      <description>Analysis of VEN0m ransomware leveraging BYOVD driver exploitation with Splunk and KQL hunting queries. Includes MITRE ATT&amp;CK mappings and behavioral detection.</description>
    </item>
    <item>
      <title>China-Nexus APT Targeting North American Critical Infrastructure</title>
      <link>https://www.focusedhunts.com/blog/hunting/UAT-8837-Critical-Infrastructure-APT</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/UAT-8837-Critical-Infrastructure-APT</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <description>Analysis of UAT-8837 China-nexus APT targeting North American critical infrastructure with Splunk and KQL detection queries. MITRE ATT&amp;CK mappings included.</description>
    </item>
    <item>
      <title>Notepad++ Update Hijacking</title>
      <link>https://www.focusedhunts.com/blog/hunting/Notepad-Plus-Plus-Update-Hijacking</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Notepad-Plus-Plus-Update-Hijacking</guid>
      <pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate>
      <description>Analysis of the Notepad++ supply chain compromise targeting telecom and finance sectors.</description>
    </item>
    <item>
      <title>VoidLink: Detecting Advanced Cloud-Native Linux Malware</title>
      <link>https://www.focusedhunts.com/blog/hunting/VoidLink-Cloud-Native-Malware</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/VoidLink-Cloud-Native-Malware</guid>
      <pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate>
      <description>A sophisticated modular malware framework called VoidLink is purpose-built for modern cloud and container environments.</description>
    </item>
    <item>
      <title>Hunting Pro-Russia Hacktivists Targeting OT VNC</title>
      <link>https://www.focusedhunts.com/blog/hunting/Hunting-Pro-Russia-Hacktivists-OT-VNC-Exploits</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Hunting-Pro-Russia-Hacktivists-OT-VNC-Exploits</guid>
      <pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate>
      <description>Technical analysis and detection guidance for pro-Russia hacktivist campaigns targeting operational technology infrastructure via VNC vulnerabilities.</description>
    </item>
    <item>
      <title>APT24 Multi-Vector BADAUDIO Campaign Analysis</title>
      <link>https://www.focusedhunts.com/blog/hunting/APT24-Multi-Vector-BADAUDIO-Campaign</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/APT24-Multi-Vector-BADAUDIO-Campaign</guid>
      <pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate>
      <description>Deep dive into the BADAUDIO malware distribution campaign used by Chinese APT24. Detection techniques and IOAs for multiple attack vectors.</description>
    </item>
    <item>
      <title>Vibe Hacking: AI Data Extortion Techniques</title>
      <link>https://www.focusedhunts.com/blog/hunting/Vibe-Hacking-AI-Data-Extortion</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Vibe-Hacking-AI-Data-Extortion</guid>
      <pubDate>Fri, 05 Dec 2025 00:00:00 GMT</pubDate>
      <description>Emerging attack techniques using AI tools for data exfiltration and extortion. Detection strategies for AI-assisted intrusions.</description>
    </item>
    <item>
      <title>Detecting SSH Tor Backdoors in Military Networks</title>
      <link>https://www.focusedhunts.com/blog/hunting/detecting-ssh-tor-backdoor-military-targeting</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/detecting-ssh-tor-backdoor-military-targeting</guid>
      <pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate>
      <description>How to identify and respond to SSH-based persistent backdoors establishing Tor connectivity in government and military systems.</description>
    </item>
    <item>
      <title>Qilin Ransomware Attack Chain Detection</title>
      <link>https://www.focusedhunts.com/blog/hunting/qilin-ransomware-attack-chain-detection</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/qilin-ransomware-attack-chain-detection</guid>
      <pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate>
      <description>Complete attack chain analysis for Qilin ransomware. How to identify reconnaissance, lateral movement, and encryption phases.</description>
    </item>
    <item>
      <title>Talos Overview: Static Tundra Threat Analysis</title>
      <link>https://www.focusedhunts.com/blog/hunting/talos-overview-static-tundra</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/talos-overview-static-tundra</guid>
      <pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate>
      <description>Technical indicators for Static Tundra threat group. APT tactics, techniques, and detection methods from Talos research.</description>
    </item>
    <item>
      <title>Hunting Microsoft Teams Threats - Detection Guide</title>
      <link>https://www.focusedhunts.com/blog/hunting/Hunting-Microsoft-Teams-Threats-Detection-Guide</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Hunting-Microsoft-Teams-Threats-Detection-Guide</guid>
      <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
      <description>How attackers abuse Microsoft Teams for command and control, data exfiltration. Hunting techniques and defensive measures.</description>
    </item>
    <item>
      <title>The Rise of Malware-Free Identity-Focused Intrusions</title>
      <link>https://www.focusedhunts.com/blog/hunting/The-Rise-of-Malware-Free-Identity-Focused-Intrusions</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/The-Rise-of-Malware-Free-Identity-Focused-Intrusions</guid>
      <pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate>
      <description>Modern attack techniques bypassing malware detection through credential theft and identity abuse.</description>
    </item>
    <item>
      <title>Hunting EtherHiding: UNC5342 Analysis</title>
      <link>https://www.focusedhunts.com/blog/hunting/Hunting-EtherHiding-UNC5342</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Hunting-EtherHiding-UNC5342</guid>
      <pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate>
      <description>Technical deep dive into the EtherHiding stealth malware used by UNC5342. Detection techniques for network-level evasion.</description>
    </item>
    <item>
      <title>Flax Typhoon ArcGIS Server Web Shell Compromise</title>
      <link>https://www.focusedhunts.com/blog/hunting/Flax-Typhoon-ArcGIS-Server-Object-Extension-Web-Shell-Compromise</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Flax-Typhoon-ArcGIS-Server-Object-Extension-Web-Shell-Compromise</guid>
      <pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate>
      <description>How Flax Typhoon exploits ArcGIS Server vulnerabilities to establish persistent web shells.</description>
    </item>
    <item>
      <title>TrendMicro: Unmasking the Gentlemen Ransomware</title>
      <link>https://www.focusedhunts.com/blog/hunting/TrendMicro-unmasking-the-gentlemen-ransomware</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/TrendMicro-unmasking-the-gentlemen-ransomware</guid>
      <pubDate>Sun, 12 Oct 2025 00:00:00 GMT</pubDate>
      <description>Complete analysis of Gentlemen ransomware operations. Targeted industries, delivery mechanisms, and detection strategies.</description>
    </item>
    <item>
      <title>Exposing the Espionage Tactics of China-Aligned TA415</title>
      <link>https://www.focusedhunts.com/blog/hunting/Exposing-the-Espionage-Tactics-of-China-aligned-Threat-Actor-TA415</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Exposing-the-Espionage-Tactics-of-China-aligned-Threat-Actor-TA415</guid>
      <pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate>
      <description>Detailed exposure of TA415 intelligence gathering operations. Tools, techniques, and indicators for detecting espionage campaigns.</description>
    </item>
    <item>
      <title>Detecting Premier Pass as a Service APT Collaboration</title>
      <link>https://www.focusedhunts.com/blog/hunting/Detecting-Premier-Pass-as-a-Service-APT-Collaboration</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Detecting-Premier-Pass-as-a-Service-APT-Collaboration</guid>
      <pubDate>Sun, 28 Sep 2025 00:00:00 GMT</pubDate>
      <description>Analysis of Premier Pass abuse in APT collaboration networks. How to identify shared infrastructure and coordinated campaigns.</description>
    </item>
    <item>
      <title>Analyzing Fake CAPTCHA Phishing Attacks</title>
      <link>https://www.focusedhunts.com/blog/hunting/Analyzing-Fake-CAPTCHA-Phishing</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/hunting/Analyzing-Fake-CAPTCHA-Phishing</guid>
      <pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate>
      <description>How attackers abuse CAPTCHA mechanisms in phishing campaigns. Detection techniques for fake verification pages and credential harvesting.</description>
    </item>
  </channel>
</rss>
