xHunt Campaign Use Organization’s Webpage as Watering Hole to Steal Customer Login Details

xHunt campaign knows to be active since July 2018 and they target the transportation and shipping organizations based in Kuwait.

The attack campaign named xHunt, because they used the name of the tools from the character names of the series Hunter x Hunter.

xHunt Campaign Activities

Unit42 researchers spotted a new XHunt attack campaign that compromises Kuwaiti organization’s webpage and used it as a watering hole.

The attackers stored hidden image files on the website between June and December 2019. Earlier the referenced microsofte-update[.]com and later changed to learn-service[.]com.

The attack was aimed to harvest the account credentials in the form of NTLM hashes from the webpage’s visitors.

By having the NTLM handshake and other information they could crack the hashes and obtain the username and password or launch a relay attack.

To test further researchers set up the Responder tool on a server and configured the environment to have the domain microsofte-update[.]com resolve to the server.

“We then visited the website from another system in our lab that had the HTML code injected and observed the Responder tool gathering the domain name, user name, IP address and NTLM hashes from the system on which we visited the website.”

Further DNS analysis on the Kuwaiti organization’s webpage reveals that another organization within Kuwait began resolving to infrastructure utilized by the xHunt operators.

Sakabota and Hisoka DNS Timeline

Here is the DNS activity timeline of Sakabota and Hisoka DNS.

  • Top row – targeted organizations
  • Middle row – Infrastructure
  • Bottom row – xHunt domains

Attackers also obtained Let’s Encrypt SSL certificates that contained the name of the redirected domain.

Researchers believe the same threat actor group behind bot the Hisoka attack campaign and xHunt attack Campaign.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago