xHunt APT Targets Microsoft Exchange and IIS with Custom Backdoors
First seen 15 Dec 2025, 20:51 UTC
•
•92% similarity
•45
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The xHunt APT group is conducting targeted cyber-espionage campaigns against organizations in Kuwait, specifically focusing on the government, shipping, and transportation sectors. They exploit vulnerabilities in Microsoft Exchange and IIS web servers to deploy custom backdoors, utilizing a sophisticated and evolving toolkit since their emergence in 2018.
ThreatCluster AI
How this analysis works