Skip to content

Threat research

Blog

Investigations, infrastructure analysis, and SOC tradecraft from the Houdin team. Follow along via RSS.

5 min read

Mapping 200 still undetected Chinese AI attack platforms in the wild

We detected 280 servers running CyberStrikeAI, an open-source AI-driven attack platform with its own C2, starting from a single ThreatFox alert. Around 200 have no record in any threat intel feed.

cyberstrikeaic2netlasinfrastructure-hunting
9 min read

Detecting ClickFix infrastructure before it goes live

In this article we point out weaknesses in a live ClickFix operator's infrastructure. We showcase a method to preemptively detect threats by monitoring certain points of it.

clickfixlatrodectus/blackwidowdead-drop-resolveretherhiding