XHunt — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
December 15, 2025
Last Seen
December 16, 2025

XHunt is an Advanced Persistent Threat (APT) group observed in 2025 that targets Windows infrastructure by exploiting internet-facing Microsoft Exchange and IIS Web Server deployments to deploy bespoke backdoors.

Overview

XHunt is an Advanced Persistent Threat (APT) group observed in 2025 that targets Windows infrastructure by exploiting internet-facing Microsoft Exchange and IIS Web Server deployments to deploy bespoke backdoors. Their focus on Exchange and IIS and deployment of custom backdoors indicates a persistent capability to gain and maintain access within enterprise networks.

Related Threat Clusters

Recent Intelligence Reports

  • Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild — Cybersecuritynews · December 16, 2025
  • ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices — Cybersecuritynews · December 15, 2025
  • xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors — Cybersecuritynews · December 15, 2025
  • xHunt APT Exploits Microsoft Exchange and IIS to Deploy Custom Backdoors — Gbhackers · December 15, 2025

CVSS v3.1 Breakdown