Cortex XSIAM
Anthropic Threat Report (Sept 2026) - Multi-GTG Threat Hunt
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.
# Snippet | Anthropic Threat Report (Sept 2026) — Multi-GTG Threat Hunt
---
> **Scenario:** Ready-to-use Cortex XQL threat hunting queries designed to extract C2 domains, malicious IP infrastructure, file hashes, and host persistence artifacts across AI-augmented campaigns.
---
### Threat Groups Covered
* **Midnight Blizzard (`GTG-20006`)** — Russian State Espionage
* **ShinyHunters (`GTG-50014`)** — Cybercrime & Cloud Extortion
* **Iranian Surveillance (`GTG-30006`)** — SECOMS64 Implant & Domestic Profiling
---
### Capability Summary
This snippet delivers production-ready **Cortex XQL queries** engineered to sweep network and endpoint telemetry for active indicators of compromise (IOCs). By targeting distinct adversary profiles—spanning nation-state cyber espionage, cloud data theft, and targeted surveillance—it empowers SOC analysts and threat hunters to rapidly detect and mitigate sophisticated, AI-enhanced attack behaviors across the enterprise.
---
**Reference:** [Anthropic Threat Intelligence Report — September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for endpoint or firewall connections matching domains identified across GTG-20006, GTG-50014, GTG-50021, and GTG-50029.
dataset = xdr_data
| filter event_type = ENUM.NETWORK
and (
action_external_hostname in (
"ms365-live.com", "teams.ms365-live.com", "m365-owa.com", "owa-ms365.com",
"ms365-device.com", "mslivetest.duckdns.org", "my-invite.org", "chamber-ua.org",
"chathamhouse.eu", "ukrinform-share.net", "statistic-ms.live", "static-ms.live",
"ad-g.org", "docs-viewer.org", "wa-connect.eu", "mygreatmarket.org",
"mygreatmarket.com", "cdncounter.net", "static.cdncounter.net", "stuseamandesilt.org",
"api.stuseamandesilt.org", "cdn.stuseamandesilt.org", "update.stuseamandesilt.org",
"itechx.tel", "pdfviewer2024.b-cdn.net", "meridian-protocol.org", "meridiangroup-corp.com",
"projectnightcrawler.dev", "metricwave.org", "mgsend.org", "wa-meeting.com",
"russianearabroad.com", "russianearabroad.org", "updatebeacon.duckdns.org", "soraki.cc",
"soraki.work", "policenationale.cc", "emailsecure.email", "mozilla.ws",
"signin-1psswoord.com", "on-pssword.com", "ari-chain.com", "arichain.network",
"bitmart-mystery.com", "defi-claim.xyz", "service-infos.info", "awstore.cloud",
"kiro.cheap", "sys-tools.cfd", "aws-us-east-3.com", "holdboost.store",
"deltaclient.xyz", "frntrs-analytics.dedyn.io", "prod-artfkt.com", "fafwatch.xyz"
)
or dns_query_name in (
"ms365-live.com", "m365-owa.com", "owa-ms365.com", "ms365-device.com",
"updatebeacon.duckdns.org", "soraki.cc", "policenationale.cc", "awstore.cloud",
"kiro.cheap", "sys-tools.cfd", "aws-us-east-3.com", "holdboost.store"
)
)
| fields _time, agent_hostname, actor_process_image_name, action_external_hostname, action_remote_ip, dns_query_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for inbound/outbound communication against known egress and C2 IP ranges used by GTG-20006, GTG-50014, GTG-50020, and GTG-50029.
dataset = xdr_data
| filter event_type = ENUM.NETWORK
and action_remote_ip in (
"104.145.210.184", "31.57.243.154", "104.194.151.133", "104.194.159.55", "144.172.114.192",
"213.145.86.112", "2.26.53.194", "148.135.195.111", "185.198.234.26", "185.198.234.101",
"149.54.42.106", "104.194.149.228", "38.146.28.132", "38.146.28.75", "162.128.129.106",
"195.178.110.131", "45.148.10.242", "92.118.39.3", "185.65.134.246", "185.65.134.199",
"193.32.249.161", "193.32.249.164", "193.32.249.170", "104.36.50.54", "104.193.135.207",
"91.171.138.169", "176.177.12.62", "141.133.125.208", "167.250.111.136", "178.16.54.141",
"37.27.103.22", "194.163.183.216", "202.66.167.230", "146.103.101.253", "146.103.97.169",
"139.59.2.243", "158.173.46.118", "146.70.116.131", "149.22.83.6", "138.199.60.29",
"138.199.6.208", "103.216.220.19", "103.124.165.199", "103.141.60.144", "34.156.199.132",
"34.156.95.176", "136.144.242.56", "163.172.157.53"
)
| fields _time, agent_hostname, actor_process_image_name, action_remote_ip, action_remote_port, action_direction
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Detects execution of GTG-20006 payloads, custom implants (WUEngine.exe, DiagHost.exe), masquerading Edge updaters, and known malware SHA-256 hashes.
dataset = xdr_data
| filter event_type = ENUM.PROCESS
and (
action_file_sha256 in (
"be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c",
"918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593"
)
or action_process_image_name in (
"msedgeupdate_v3.exe", "WUEngine.exe", "DiagHost.exe",
"client_20260507093021_4286d211_x64.exe"
)
or (
action_process_image_name = "msedgeupdate.exe"
and not action_process_image_path contains "C:\Program Files"
)
)
| fields _time, agent_hostname, actor_process_image_name, action_process_image_path, action_process_image_sha256, action_process_command_line
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Hunts for host indicators linked to GTG-30006 SECOMS64 implant execution, including suspicious path installations, run key modifications, scheduled task registration, and script droppers.
dataset = xdr_data
| filter (
(
event_type = ENUM.FILE
and action_file_path contains "fontdrivehostServicePackages"
)
or (
event_type = ENUM.PROCESS
and action_process_image_name = "schtasks.exe"
and (
action_process_image_command_line contains "SECOMS64_AdminTask"
or action_process_image_command_line contains "Calc_AdminTask"
or action_process_image_command_line contains "MyTask"
)
)
or (
event_type = ENUM.REGISTRY
and action_registry_key_name contains "CurrentVersion"
and action_registry_key_name contains "Run"
and action_registry_value_name = "Whost"
)
or (
event_type = ENUM.PROCESS
and (action_process_image_name = "wscript.exe" or action_process_image_name = "cscript.exe")
and action_process_image_command_line contains "telegram_listener_v12_2.vbs"
)
)
| fields _time, agent_hostname, event_type, actor_process_image_name, action_file_path, action_process_image_command_line, action_registry_key_name