Skip to content

Add: Shai-Hulud/Carnage APT IWD — breakingcircuits.com 2026-05-13#6

Open
breakingcircuits1337 wants to merge 1 commit into
mthcht:mainfrom
breakingcircuits1337:main
Open

Add: Shai-Hulud/Carnage APT IWD — breakingcircuits.com 2026-05-13#6
breakingcircuits1337 wants to merge 1 commit into
mthcht:mainfrom
breakingcircuits1337:main

Conversation

@breakingcircuits1337

Copy link
Copy Markdown

Add: Shai-Hulud / Carnage APT — Incident Worm Disclosure (breakingcircuits.com, 2026-05-13)

Independent operational analysis published while the threat was active.
Includes artifacts not present in existing indexed entries for this campaign.

Path

Intel Reports/breakingcircuits_com/2026_05_shai_hulud_iwd/
├── README.md
├── content.txt
├── iocs.txt
├── timeline.txt
└── yara/
    └── teampcp_shai_hulud.yar

Artifacts

File Content
content.txt Narrative analysis — propagation, persistence, deadman switch, detection
iocs.txt Machine-parseable IOCs: files, domains, IPs, strings, git commits, PBKDF2 salt, Session recipient ID, branch patterns, CVEs, YARA IDs, MITRE ATT&CK
timeline.txt Chronological reconstruction — campaign history (Sep 2025 → May 2026) + disclosure timeline
yara/teampcp_shai_hulud.yar 16 YARA rules — all dropper variants, persistence, exfil, Sigstore forgery

Delta vs existing Shai-Hulud entries

  • PBKDF2-SHA256 campaign salt (svksjrhjkcejg) and Session recipient ID as cryptographic IOCs
  • Dependabot-masquerade branch name patterns (dependabot/github_actions/format/sietch etc.)
  • Claude Code SessionStart hook as distinct persistence vector
  • 63-fork commit-level network forensics
  • Deadman switch handler payload with operational context
  • Full MITRE ATT&CK mapping (12 techniques)
  • Evidence provenance documented

Metadata

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant