Tool
HuntSQL
- First Reported
- May 12, 2026
- Latest Reported
- Sep 16, 2026
Reported Context (11)
- A copy of RTX Corporation's (formerly Raytheon) homepage served as default content on SpiceRAT servers, with the page hash returning only 13 IP's in a HuntSQL query, all exclusive to the cluster. Researchers Map SpiceRAT-Linked Infrastructure Impersonating Central Asian Government and Energy Targets
- Using identifiers from the loader code including the smart contract address, we created a simple HuntSQL query to determine the prevalence of this attack across other compromised servers: Hunt.io Details Intrusions Targeting Philippine Nuclear and Naval-Linked Organizations
- pivots available on the ls.j2x8a[.]top certificate subject, returning two additional servers in HuntSQL: 108.187.7[.]66 and 108.187.7[.]71, both hosted on AS138995 (Antbox Networks Limited), also located in Flying Eagle Android RAT: Leaked Code, 170 Servers and Night Dragon
- of the certificate itself rather than its contents. Querying that hash alongside the www common name in HuntSQL returned two additional, related hosts: 118.107.222[.]232 (The Gigabit, Malaysia) and 202.181.27[.]115 Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find
- we pivoted on a HTTP header hash observed on port 1111 of the command and control nodes. Using HuntSQL, we developed a simple query to search for additional servers sharing identical header fingerprints over Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems
CVE (17)
Malware (42)
People (7)
Threat Actors (22)
MITRE ATT&CK (73)
Vendors (74)
Products (82)
Tools (40)
Industries (30)
Countries (61)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.