Hexastrike Blog

STORESOCKS – Microsoft Store Apps Deliver a Go Backconnect Proxy

Executive Summary Hexastrike uncovered an ongoing backconnect proxy campaign distributed through trojanized Microsoft Store applications. We track this activity as STORESOCKS. Since at least October 2025, an unknown actor has published trojanized free utility applications to the Microsoft Store. The applications impersonate common desktop tools, including WinDirStat, Lightshot, screen recorders, memory cleaners, and auto-clickers. They are not broken decoys or simple launchers. Each analyzed Store package contains a working Electron-based utility interface that matches the advertised purpose of the application. In

Read More

CodeStorm – A Microsoft 365 AiTM Phishing Kit with Storm-1167 Overlap

Executive Summary Hexastrike has identified an ongoing adversary-in-the-middle (AiTM) phishing campaign targeting Microsoft 365 users that leverages a previously undocumented phishing kit, tracked by Hexastrike as CodeStorm. Analysis of the recovered server-side kit source code and associated deployment infrastructure indicates with moderate confidence that CodeStorm overlaps with infrastructure patterns previously associated with activity Microsoft tracks as Storm-1167. Based on direct code-level comparison conducted by Hexastrike, CodeStorm appears to be a distinct kit family separate from previously documented phishing frameworks such

Read More

Cloned, Loaded, and Stolen: How 109 Fake GitHub Repositories Delivered SmartLoader and StealC

Executive Summary After someone impersonated one of our recent projects, PyrsistenceSniper, on GitHub, we uncovered a broader malware distribution campaign built around cloned open source repositories. The operator copies legitimate projects, republishes them under different accounts, strips the README of its technical content, and replaces it with prominent download buttons. Those buttons point to ZIP files hidden inside the repository tree rather than to GitHub releases or tagged source packages. The source code is usually left mostly intact. That is what

Read More
Training built from real incidents. Sharpening the defenders who matter.