Skip to content
Blog Post

Introducing Cavalier’s New Threat Feeds: Comprehensive Visibility into Attacker Infrastructure

InfoStealers
7 min read

Introducing Cavalier’s New Threat Feeds: Comprehensive Visibility into Attacker Infrastructure

We are thrilled to introduce three new Threat Feed modules in Cavalier: C2 Data, ClickFix, and PhaaS (Phishing-as-a-service). Together, they give security teams comprehensive visibility into active attacker infrastructure – from infostealer command-and-control (C2) servers to malicious ClickFix pages executing clipboard injection, to turnkey Phishing-as-a-service (PhaaS) kits targeting corporate credentials.

Overview of the Threat Feeds monitoring options
Overview of the new Threat Feeds monitoring options available inside Cavalier, including C2 Intelligence, ClickFix Monitor, and PhaaS Feed.

Deep Dive 1: Infostealers C2 Intelligence

The new C2 Data module provides unprecedented access to observed command-and-control (C2) hosts associated directly with active infostealer campaigns. This empowers security teams to transition from reactive incident response to preemptive blocking.

Overview of the infostealers C2 monitoring
A high-level overview of the Infostealers C2 monitoring dashboard, displaying active threat infrastructure.

Inside Cavalier, you can seamlessly review:

  • Daily Infostealers C2 host feeds
  • Activity trends over time
  • Top countries where C2 hosts are observed
  • Malware family breakdowns
  • Detailed host information, including infrastructure type, ASN, AS organization, ports, tags, first seen, and last seen

Uncovering Initial Access with Correlated Intelligence

One of the most powerful features of the C2 Intelligence Feed is the integration of Infostealer credential telemetry linked to the hosting platform. This shows compromised employee or user credentials that likely enabled the threat actors to gain initial access to the server in the first place.

Specific infostealers C2 examples with correlated infection data
Specific infostealer C2 examples (Redline, Vidar, Stealc, etc.) enriched with correlated infection data from Hudson Rock’s cybercrime intelligence database, revealing compromises associated with the server.

For example, you can open a host such as myrtler(.)biz and immediately see that it’s associated with the Vidar malware family, along with its DNS activity, first-seen date, and critical infrastructure details as they are actively observed.

Overview of various families sorted by 30 days volume
An overview of various infostealer families, sorted by 30-day activity volume to help prioritize defense efforts.

Seamless API Integration for C2 Defense

To truly block active command-and-control channels at the firewall or proxy level – stopping infected endpoints from exfiltrating credentials, receiving instructions, or dropping secondary payloads – automation is key.

API overview
Overview of the C2 Host Feed REST API endpoint for seamless integration.

All C2 datasets are fully accessible via REST API endpoints for seamless integration into your existing security stack. Using the GET /json/v3/threat-feeds/c2 endpoint, teams can retrieve observed infostealer C2 hosts with granular filters for host, malware family, country, ASN, feed type, date, and pagination.


Deep Dive 2: ClickFix Monitoring

The new ClickFix module provides critical visibility into malicious websites that use fake verification pages, CAPTCHA prompts, and clipboard injection techniques to trick users into executing malicious commands.

Inside Cavalier, you can seamlessly review:

  • Detected ClickFix sites
  • Clipboard injection and CAPTCHA indicators
  • Injected command payloads
  • Before-and-after interaction screenshots
  • Domain records and associated URLs
  • Date filtering and export options
Overview of recently flagged clickfix servers
A high-level overview of recently flagged ClickFix servers and domains identified within the Cavalier platform.

Analyzing Payloads and Deceptive Lures

With ClickFix lures becoming increasingly sophisticated, it is vital to understand the exact mechanisms threat actors are using to deceive employees. Cavalier allows you to investigate flagged sites, view the copied commands presented to victims, and examine visual evidence of the attack.

Details of payload and before/after captcha interaction
Detailed analysis showing a malicious clipboard payload alongside a before-and-after comparison of a fake CAPTCHA interaction hosted on solaric.com.ph.

Uncovering Initial Access: The Infostealer Connection

Perhaps the most powerful capability of the ClickFix monitor is its integration with Infostealer credential telemetry linked to the hosting platform. This pinpoints compromised employee or user credentials that enabled attackers to gain initial access to the server, explaining how a legitimate business domain became a host for malware.

Hudson Rock infostealer credentials associated with solaric.com.ph
Hudson Rock cybercrime intelligence revealing infostealer credentials associated with solaric.com.ph’s WordPress admin panel. This initial infection on a user’s computer directly led to the website being hacked and weaponized to deliver ClickFix.

Case Study: The Artlist Breach

We’ve previously documented how legitimate businesses turn into malware hosts, and a recent high-profile example perfectly illustrates this pipeline.

In our recent shared research on how an infostealer infection led to a sophisticated ClickFix campaign at Artlist, we traced the root cause of a compromised Artlist subdomain back to an infostealer infection from August 2023. A freelance developer unwittingly downloaded a pirated copy of Adobe Acrobat PRO DC, infecting their machine. This breach exposed highly privileged WordPress credentials belonging to a Senior Content Executive. Armed with valid, high-privilege access, threat actors were able to inject an advanced EtherHiding script into the blog, which dynamically routed visitors to a ClickFix payload.

Artlist delivering captcha and associated credentials
Visual evidence showing the compromised Artlist domain delivering a fake CAPTCHA payload, alongside the specific infostealer credentials that led to the initial breach.

With Cavalier’s new Threat Feeds, security teams can now instantly monitor these high-value, trusted domains that have been repurposed by threat actors. This capability pinpoints exactly where they are serving ClickFix prompts and simultaneously reveals the compromised credentials that facilitated the takeover.

Artlist in the ClickFix threat feeds feature
The compromised Artlist domain accurately flagged and detailed within Cavalier’s new ClickFix Threat Feeds feature.

Seamless API Integration for Proactive Defense

By feeding these surfaced ClickFix domains and indicators directly into your perimeter controls, firewalls, and DNS sinks, organizations can prevent social engineering attacks and block fake verification pages before employees can interact with or execute copied command payloads.

All datasets are fully accessible via REST API endpoints. Teams can utilize the GET /json/v3/threat-feeds/clickfix endpoint to retrieve detected sites, including domains, URLs, malicious indicators, clipboard activity, CAPTCHA detection, and screenshot evidence, or use the GET /json/v3/threat-feeds/clickfix/{domain} endpoint for specific record lookups.


Deep Dive 3: Phishing-as-a-Service (PhaaS) Intelligence

As Phishing-as-a-Service (PhaaS) platforms become extremely prominent in high-profile corporate hacks, giving lower-tier actors turnkey access to advanced credential harvesting tools, preemptive visibility is more critical than ever. The new PhaaS Threat Feed is unique to Hudson Rock, providing an unparalleled view into active phishing host networks before they are deployed in targeted spear-phishing campaigns against your workforce.

Overview of the PhaaS feed in Cavalier
A high-level overview of the Phishing-as-a-Service (PhaaS) intelligence feed within Cavalier, enabling security teams to monitor active phishing host networks and operational statuses.

Inside Cavalier, security teams can seamlessly review:

  • Active phishing host networks and root domains
  • Specific kit tags and deployment platforms
  • Resolved IP nodes and server infrastructure
  • Infostealer credential telemetry linked to the hosting platform

Tracking the Most Dangerous Phishing Kits

Cavalier groups PhaaS hosts by their specific operational kits, allowing defenders to understand the exact tactics they are facing. Our intelligence tracks massive networks running well-known platforms like Eviltokens and Kali365, as well as exclusive, recently uncovered campaigns like SessionSerpent—intelligence you will only find surfaced through Hudson Rock.

Examples of PhaaS infrastructure kits
Detailed grouping of PhaaS hosts by kit, featuring prominent platforms like Kali365, Eviltokens, Generic PhaaS, and the recently uncovered SessionSerpent campaign, tracked exclusively by Hudson Rock.

Uncovering Infrastructure and Initial Access

The PhaaS feed allows you to go beyond the domain level and map out the entire operational footprint of an attacker. For example, you can surface surface infrastructure like garage-door-repair(.)cyou running Eviltokens, or pinpoint specific IP nodes like 43.172.6.35 tied to Kali365 operations.

Infrastructure servers and resolved IPs
Deep dive into an active PhaaS campaign, showing the underlying infrastructure servers, ASNs, and resolved IPs utilized by the threat actors to host their credential harvesting kits.

Crucially, just like our ClickFix and C2 modules, the PhaaS feed integrates directly with our infostealer telemetry. This allows you to instantly see if a host domain (e.g., webcindario(.)com) has compromised employee credentials tied to it, revealing exactly how attackers gained initial control of the server to host their phishing infrastructure.

Seamless API Integration for PhaaS Prevention

By feeding these surfaced domains, IP networks, and hosting infrastructure directly into your perimeter controls, firewalls, and DNS sinks, organizations can preemptively block turnkey phishing networks before employees receive a single malicious email.

All datasets are fully accessible via REST API endpoints for automated ingestion into your SIEM or SOAR. Teams can utilize the GET /json/v3/threat-feeds/phaas endpoint to retrieve active Phishing-as-a-Service indicators with flexible filtering, or use the GET /json/v3/threat-feeds/phaas/{host} endpoint for specific host network lookups and operational status checks.

Protect Your Organization from Imminent Intrusions

With our new Threat Feeds, cybersecurity teams can monitor live C2 infrastructure from infostealer campaigns, ClickFix networks, and PhaaS (Phishing-as-a-service) operations to proactively block malicious communications.

To learn more about how Hudson Rock protects companies from intrusions caused by info-stealer infections of employees, partners, and users, and how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:
https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:
www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!
Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Continue reading

Related articles

Free Tools Check your exposure