APT KQL

APT28: DNS Hijacking and AitM Detections for SOHO Router Compromise

April 8, 2026 15 min read

APT28 is conducting DNS hijacking campaigns against SOHO routers to perform adversary-in-the-middle attacks, intercepting credentials and communications at the network layer. This post covers 8 KQL detections across network telemetry, DNS, authentication, and device vulnerability data.

Read more →
Weekly

Weekly Threat Intel Highlights: w/b 6th April

April 7, 2026 3 min read

This week's highlights: BRICKSTORM defender guide from Google Threat Intelligence, Storm-1175 Medusa ransomware operations from Microsoft, UNC6783 social engineering via lookalike domains, Fortinet and Cisco CVE exploitation in the wild, and the BlueHammer zero-day disclosure.

Read more →
Ransomware KQL Windows

STORM-1175: KQL Detections for Medusa Ransomware Operations

April 6, 2026 12 min read

Storm-1175 is a financially motivated actor operating high-velocity Medusa ransomware campaigns, weaponising N-day vulnerabilities within days of disclosure. The group has targeted healthcare, education, finance, and professional services across Australia, the UK, and the US, moving from initial exploitation to full ransomware deployment in under 24 hours. This post covers 8 KQL detections across the full attack chain.

Read more →