%GoCortexIO Snippets

Cortex XSIAM

Anthropic Threat Report (Sept 2026) - Multi-GTG Threat Hunt

| 30-45 minutes to implement | ~3 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet | Anthropic Threat Report (Sept 2026) — Multi-GTG Threat Hunt

---

> **Scenario:** Ready-to-use Cortex XQL threat hunting queries designed to extract C2 domains, malicious IP infrastructure, file hashes, and host persistence artifacts across AI-augmented campaigns.

---

### Threat Groups Covered

* **Midnight Blizzard (`GTG-20006`)** — Russian State Espionage
* **ShinyHunters (`GTG-50014`)** — Cybercrime & Cloud Extortion
* **Iranian Surveillance (`GTG-30006`)** — SECOMS64 Implant & Domestic Profiling

---

### Capability Summary

This snippet delivers production-ready **Cortex XQL queries** engineered to sweep network and endpoint telemetry for active indicators of compromise (IOCs). By targeting distinct adversary profiles—spanning nation-state cyber espionage, cloud data theft, and targeted surveillance—it empowers SOC analysts and threat hunters to rapidly detect and mitigate sophisticated, AI-enhanced attack behaviors across the enterprise.

---

**Reference:** [Anthropic Threat Intelligence Report — September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for endpoint or firewall connections matching domains identified across GTG-20006, GTG-50014, GTG-50021, and GTG-50029.
dataset = xdr_data
| filter event_type = ENUM.NETWORK 
    and (
        action_external_hostname in (
            "ms365-live.com", "teams.ms365-live.com", "m365-owa.com", "owa-ms365.com", 
            "ms365-device.com", "mslivetest.duckdns.org", "my-invite.org", "chamber-ua.org", 
            "chathamhouse.eu", "ukrinform-share.net", "statistic-ms.live", "static-ms.live", 
            "ad-g.org", "docs-viewer.org", "wa-connect.eu", "mygreatmarket.org", 
            "mygreatmarket.com", "cdncounter.net", "static.cdncounter.net", "stuseamandesilt.org", 
            "api.stuseamandesilt.org", "cdn.stuseamandesilt.org", "update.stuseamandesilt.org", 
            "itechx.tel", "pdfviewer2024.b-cdn.net", "meridian-protocol.org", "meridiangroup-corp.com", 
            "projectnightcrawler.dev", "metricwave.org", "mgsend.org", "wa-meeting.com", 
            "russianearabroad.com", "russianearabroad.org", "updatebeacon.duckdns.org", "soraki.cc", 
            "soraki.work", "policenationale.cc", "emailsecure.email", "mozilla.ws", 
            "signin-1psswoord.com", "on-pssword.com", "ari-chain.com", "arichain.network", 
            "bitmart-mystery.com", "defi-claim.xyz", "service-infos.info", "awstore.cloud", 
            "kiro.cheap", "sys-tools.cfd", "aws-us-east-3.com", "holdboost.store", 
            "deltaclient.xyz", "frntrs-analytics.dedyn.io", "prod-artfkt.com", "fafwatch.xyz"
        ) 
        or dns_query_name in (
            "ms365-live.com", "m365-owa.com", "owa-ms365.com", "ms365-device.com", 
            "updatebeacon.duckdns.org", "soraki.cc", "policenationale.cc", "awstore.cloud", 
            "kiro.cheap", "sys-tools.cfd", "aws-us-east-3.com", "holdboost.store"
        )
    )
| fields _time, agent_hostname, actor_process_image_name, action_external_hostname, action_remote_ip, dns_query_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for inbound/outbound communication against known egress and C2 IP ranges used by GTG-20006, GTG-50014, GTG-50020, and GTG-50029.
dataset = xdr_data
| filter event_type = ENUM.NETWORK
    and action_remote_ip in (
        "104.145.210.184", "31.57.243.154", "104.194.151.133", "104.194.159.55", "144.172.114.192", 
        "213.145.86.112", "2.26.53.194", "148.135.195.111", "185.198.234.26", "185.198.234.101", 
        "149.54.42.106", "104.194.149.228", "38.146.28.132", "38.146.28.75", "162.128.129.106", 
        "195.178.110.131", "45.148.10.242", "92.118.39.3", "185.65.134.246", "185.65.134.199", 
        "193.32.249.161", "193.32.249.164", "193.32.249.170", "104.36.50.54", "104.193.135.207", 
        "91.171.138.169", "176.177.12.62", "141.133.125.208", "167.250.111.136", "178.16.54.141", 
        "37.27.103.22", "194.163.183.216", "202.66.167.230", "146.103.101.253", "146.103.97.169", 
        "139.59.2.243", "158.173.46.118", "146.70.116.131", "149.22.83.6", "138.199.60.29", 
        "138.199.6.208", "103.216.220.19", "103.124.165.199", "103.141.60.144", "34.156.199.132", 
        "34.156.95.176", "136.144.242.56", "163.172.157.53"
    )
| fields _time, agent_hostname, actor_process_image_name, action_remote_ip, action_remote_port, action_direction
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Detects execution of GTG-20006 payloads, custom implants (WUEngine.exe, DiagHost.exe), masquerading Edge updaters, and known malware SHA-256 hashes.
dataset = xdr_data
| filter event_type = ENUM.PROCESS 
    and (
        action_file_sha256 in (
            "be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c",
            "918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593"
        )
        or action_process_image_name in (
            "msedgeupdate_v3.exe", "WUEngine.exe", "DiagHost.exe", 
            "client_20260507093021_4286d211_x64.exe"
        )
        or (
            action_process_image_name = "msedgeupdate.exe" 
            and not action_process_image_path contains "C:\Program Files"
        )
    )
| fields _time, agent_hostname, actor_process_image_name, action_process_image_path, action_process_image_sha256, action_process_command_line
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for host indicators linked to GTG-30006 SECOMS64 implant execution, including suspicious path installations, run key modifications, scheduled task registration, and script droppers.

dataset = xdr_data
| filter (
    (
        event_type = ENUM.FILE 
        and action_file_path contains "fontdrivehostServicePackages"
    )
    or (
        event_type = ENUM.PROCESS 
        and action_process_image_name = "schtasks.exe" 
        and (
            action_process_image_command_line contains "SECOMS64_AdminTask" 
            or action_process_image_command_line contains "Calc_AdminTask" 
            or action_process_image_command_line contains "MyTask"
        )
    )
    or (
        event_type = ENUM.REGISTRY 
        and action_registry_key_name contains "CurrentVersion" 
        and action_registry_key_name contains "Run" 
        and action_registry_value_name = "Whost"
    )
    or (
        event_type = ENUM.PROCESS 
        and (action_process_image_name = "wscript.exe" or action_process_image_name = "cscript.exe") 
        and action_process_image_command_line contains "telegram_listener_v12_2.vbs"
    )
)
| fields _time, agent_hostname, event_type, actor_process_image_name, action_file_path, action_process_image_command_line, action_registry_key_name
See all 21 snippets