// ThreatHuntingLabs  ·  writeup

NightShade C2 Multi-Stage Infection — Threat Hunt (Case Lab 1/2)

ThreatHuntingLabs EDR TelemetryKQL

Case Context

Part of a 2-lab Flash Hunt case on Threat Hunting Labs: NightShade C2 Multi-Stage Infection. This lab is the Threat Hunt angle (1 of 2) — hunting the multi-stage installer chain end-to-end from raw EDR telemetry.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

A user-executed MSI installer chains through several script interpreters before landing on a legitimate, signed portable runtime — repurposed as a fetch-and-eval command-and-control client rather than for anything it ships to do. The intrusion establishes persistence at both user and SYSTEM scope through different mechanisms, and later escalates privilege via a UAC-bypass technique, all using signed, trusted binaries throughout — no unsigned artifacts anywhere in the chain.

Techniques Encountered

Nine MITRE ATT&CK techniques surfaced across the hunt, spanning user-driven initial execution, layered scripting interpreters, dual persistence mechanisms (user Startup + SYSTEM scheduled task), UAC-bypass privilege escalation, tool transfer, web-based C2, and masquerading:

T1204.002 T1059.001 T1059.005 T1547.001 T1053.005 T1548.002 T1105 T1071.001 T1036.005

Prioritising Findings — Pyramid of Pain

Eighteen findings came out of the hunt, weighted by how costly each is for the attacker to change:

Pyramid of Pain breakdown of findings from the hunt

What I Practiced

Credential

Earned a Distinction (100% score) on this Flash Hunt case.

Flash Hunt Distinction badge

Verify: https://www.threathuntinglabs.com/badges/eb22ce0d-fca8-4dc0-8d71-20394cef79ff