Hacktivists turn to other clusters to enhance attacks
Insolent Hyena obtains access to victim infrastructures from other threat actors and uses it in subsequent attacks.
Hacktivists typically target organizations to generate publicity. They publish sensitive data stolen from organizations and their customers or simply claim responsibility for the attack. To gain initial access, they can either breach a victim environment themselves or acquire data from other clusters.
During the campaign, Insolent Hyena also employed the ClickFix social engineering technique to access target environments. The attackers presumably distributed phishing emails containing a link to a fake website of a regulatory authority. After redirection, victims were prompted to complete an I am not a robot CAPTCHA and press the displayed key combination. These actions triggered subsequent lateral movement.
Beyond social engineering, Insolent Hyena relied on a wide range of tools. It used the custom‑built NightWire remote access trojan to maintain covert control of compromised systems and the Excalibur stealer to exfiltrate data. The threat actor also employed the NetSupport legitimate remote access tool to disguise its activity as genuine administrative actions, the CapDoor trojan to gain persistence, and the AdaptixC2 and Cobalt Strike post‑exploitation frameworks to orchestrate and direct the intrusion.
Building an effective cybersecurity strategy requires an understanding of the methods and tools used by adversaries. Portals such as BI.ZONE Threat Intelligence provide up‑to‑date details on current threats, attackers, tactics, techniques, and tools.