xHunt is a Kuwait-focused cyber-espionage threat actor active since at least 2018. The group is known for persistent, multi-year intrusions against Kuwaiti government, shipping, and transportation organizations, and for operating a custom malware ecosystem whose components are frequently named after characters from the anime Hunter x Hunter. Reported aliases include SectorD01, Hive0081, Cobalt Katana, and Hunter Serpens. The actor has used a diverse toolset that includes Sakabota, Hisoka, Killua, Gon, EYE, CASHY200, Snugy, TriFive, Netero, and the BumbleBee web shell. Its malware supports multiple covert command-and-control channels, including HTTP, DNS tunneling, and abuse of Microsoft Exchange Web Services to exchange commands and results through draft messages in compromised mailboxes. Hisoka and TriFive are notable for mailbox-draft-based C2, while CASHY200 and its Snugy variant use DNS tunneling. xHunt has demonstrated several initial access and credential collection approaches. These include targeted delivery of malicious documents, compromise of web-facing Microsoft Exchange and IIS infrastructure, and a watering-hole operation on a Kuwaiti government website that attempted to coerce visiting Windows systems into NTLM authentication to attacker-controlled SMB resources in order to capture account information and password hashes. The group has also shown interest in email credential theft through DNS redirect activity affecting mail-related services. Post-compromise, xHunt has deployed custom backdoors and web shells, executed remote commands, performed internal network discovery and port scanning, transferred tools over SMB, and established persistence through scheduled tasks designed to resemble legitimate Windows tasks. Associated tooling has supported screenshot capture, file upload and download, remote command execution, and creation of RDP sessions. Reporting also links the actor to credential theft from LSASS, changes intended to enable WDigest plaintext credential storage, and use of SSH tunneling for access to internal services and lateral movement. The group consistently emphasizes stealth and defense evasion. Observed tradecraft includes scheduled-task masquerading, use of trusted directories and legitimate accounts, covert C2 over enterprise email and DNS, cleanup tooling to remove attacker artifacts, and operational measures intended to complicate attribution and tracking. Overall, xHunt is best characterized as a sophisticated, narrowly focused espionage actor centered on long-term access and intelligence collection in Kuwait.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
107 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
xHunt is conducting cyber-espionage campaigns targeting government, shipping, and transportation sectors in Kuwait, using custom malware and advanced techniques to infiltrate critical infrastructure and harvest sensitive intelligence.
Persistent cyber-espionage activity focused on Kuwaiti organizations, including watering-hole credential harvesting (NTLM hash capture), direct compromise of Microsoft Exchange/IIS servers, and long-term access via custom PowerShell backdoors and webshells. Uses mailbox-based C2 via Exchange Web Services (EWS) by reading/writing email drafts, and employs SSH tunneling for lateral movement to internal services.
Conducting intrusions against organizations in Kuwait, including government and shipping/transportation entities, using compromised Microsoft Exchange servers, web shells, PowerShell backdoors, DNS tunneling, and email-draft-based command and control.
Credential-harvesting and watering-hole activity targeting Kuwait government and private-sector organizations, including injected HTML to capture NTLM hashes and DNS redirect activity likely aimed at stealing mail credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.