[Op Report] PackClient: Hands-on-Keyboard with a new C2 Framework
Over a 48-hour Deception.Pro operation, we watched a PackClient operator use a tax-themed RAT as a doorman: after hours of quiet beaconing, a hands-on-keyboard task chain suppressed UAC and silently enrolled the victim into a ManageEngine Endpoint Central server the attacker controlled. From there the intrusion looked like routine endpoint management, including AD enumeration, vulnerability scanning, and remote control, with every second-stage binary legitimately signed by Zoho.
[Op Report] From PDF Phish to XLoader: A ScreenConnect Hands-on-Keyboard Intrusion
A phishing lure drops a batch script that silently installs ScreenConnect, giving an operator hands-on-keyboard control of a Deception.Pro honeynet before XLoader/FormBook is injected into a signed Windows binary to grab banking credentials and exfiltrate to Sendspace. A full walkthrough of the kill chain, why the ScreenConnect-plus-XLoader pairing is one we hadn't seen in our collection or in public reporting.
[Op Report] From ClickFix SpaceX1337 to Hands-on-Keyboard AD Attack
ClickFix to hands-on-keyboard ActiveDirectory attack, caught live in a Deception.Pro honeynet. Full chain + defanged IOCs.
[Op Report] From Award Scam to Domain Recon & Exfiltration
A Deception.Pro honeynet captured a complete hands-on-keyboard intrusion that started with an "award receipt" phishing email linking to a GitHub-hosted download and ended with Active Directory reconnaissance and browser-credential theft. What makes it stand out is the actor's environment-aware payload logic — delivering different follow-on stages depending on whether the host was domain-joined — and the chaining of three separate C2 frameworks (Cobalt Strike, ScreenConnect, and Havoc) on a single machine for redundancy. We walk through the full attack chain and share defanged IOCs, Suricata signatures, hunting queries, and ATT&CK mappings.
[Update] New Home, Faster Backend, New Network View
Deception.Pro has a new home at app.deception.pro — old demo.deception.pro links still work and redirect automatically. A backend database migration to faster, more reliable infrastructure means filtering detections and network data is now quicker and more stable. The rebuilt network view brings per-column filtering, more detail on every connection type, visible stats and timeline, and sessions that stay authenticated for two weeks.
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
An operator took the bait on a Deception.Pro healthcare honeynet, walking through a textbook intrusion chain: a Social Security–themed phish, an RTLO-disguised dropper, certutil-staged XWorm, and two ScreenConnect relays deployed for hands-on access. A full walkthrough of the kill chain, and every defanged IOC.
[Update] File Manager, Interactive PowerShell, and Smarter Timelines
Deception.Pro now ships a full file manager on every running host—upload, download, move, rename, delete, and add files straight to your artifacts—plus an interactive PowerShell terminal for live, on-host command execution in your deception environment. We've also reworked timeline generation so every detection that fires is properly captured, giving you the complete, ordered picture of an engagement. All three updates are live now and came straight from the top of your request list.
[Update] Deception.Pro ET PRO May 2026
Deception.Pro now ships with Proofpoint's ET Pro Suricata ruleset on every sensor — adding ~50,000 commercial signatures and daily updates to the threat-family classification on every captured session.
[Update] Deception.Pro May 2026
Deception.Pro just shipped AI-generated reports for paying customers, timeline-correlated EDR and network telemetry in artifact downloads, and a deeper, more believable Active Directory environment. Backend upgrades cut environment spin-up time, randomize replica file timestamps, and auto-configure timezones based on VPN egress — all in service of higher-fidelity adversary engagement.
[Op Report] Trojanized CPU-Z Delivers STXRAT, Steals Credentials, and Exfils Data Through a Hidden QEMU VM
A trojanized CPU-Z installer dropped STXRAT via DLL side-loading, quietly deploying PureLogs Stealer to harvest browser credentials and PureHVNC for remote access — all while routing 54 hours of continuous data exfiltration through a locally-hosted QEMU Alpine Linux VM to evade detection. Deception.Pro captured the first documented full post-exploitation chain for this campaign, delivering ground-truth adversary telemetry that no sandbox or threat feed could replicate.
[Update] Deception.Pro April 2026
TLS introspection is now live on Deception.Pro — decrypted PCAPs are automatically generated and available in the Artifact section of every operation. For the first time, you have full plaintext visibility into encrypted adversary traffic, correlated alongside your EDR telemetry, Suricata EVE logs, and raw captures. This release also ships meaningful improvements to artifact delivery speed, platform stability, and internal architecture.
[Update] Deception.Pro March 2026
This release brings a new Timeline View for unified process and event history across detonations, expanded YARA detection coverage for executables in memory and on disk, and a round of frontend stability improvements. Free researcher accounts will also see a new telemetry consent flow for anonymized data used in AI model training — paid and PoV accounts are unaffected. Attackers bet heavily on encryption to blind defenders — that's about to get harder, with TLS introspection and several other major capabilities coming to the platform soon.
[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed
A recent deception operation shows Velvet Tempest leaning on a “ClickFix”-style lure to move fast from initial access into hands-on-keyboard activity consistent with Termite ransomware operations. In this post, we break down the timeline, highlight the most actionable indicators of compromise, and translate the tradecraft into practical defender takeaways—including where deception can turn attacker momentum into instant signal.
[Op Report] Hands-on-Keyboard Intrusion Abusing Multiple RMMs
Proofpoint observed a hands-on-keyboard intrusion where an operator abused multiple RMM platforms—including Bluetrait, Fleetdeck, Level, and MSP360—after initial access via a malicious PDF “missing Adobe plugin” lure. The activity underscores a growing reality: attackers are increasingly using legitimate IT tooling as a resilient intrusion framework.
[Update] Deception.Pro Jan 2026
The January 2026 Deception.Pro update introduces industry based replica browsing for Premium users, expanded and more reliable malware auto detonation across common delivery formats, improved artifact handling with VirusTotal linking, and broad stability enhancements, while laying the groundwork for dedicated KVM infrastructure, TLS inspection, and memory dump support.
[Op Report] CastleRAT Campaign leads to Hands-on-Keyboard ATO Operations
This Deception.Pro operation captured a multi-stage malware intrusion culminating in hands-on-keyboard (HoK) activity focused exclusively on account takeover (ATO): not ransomware staging or enterprise lateral movement.
[Op Report] Oyster → Vidar → Supper socks shell Campaign Leads to Hands-on-Keyboard Activity
A recent Deception.Pro operation involving a replica victim in the travel and tourism sector revealed a multi-stage infection beginning with an Oyster malware dropper masquerading as a Microsoft Teams installer.