← Back to SOC feed Coverage →

ThreatFox: Kuiper IOCs

ioc-hunt HIGH ThreatFox
DeviceFileEvents
elf-kuiperiocthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-05T23:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets adversary activity linked to the Kuiper threat campaign by correlating Azure Sentinel logs against a curated set of 24 high-fidelity Indicators of Compromise (IOCs). Proactively hunting for these specific signatures is critical to detect early-stage reconnaissance or lateral movement that may evade standard alerting, ensuring rapid containment before the threat establishes persistence within the environment.

IOC Summary

Malware Family: Kuiper Total IOCs: 24 IOC Types: sha256_hash, sha1_hash, md5_hash

TypeValueThreat TypeFirst SeenConfidence
md5_hash43e647b9d685e1e5be276026df86d7e4payload2026-07-0595%
md5_hash69ac856f989a3dc0d8bff532c6f7f331payload2026-07-0595%
sha256_hash46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327payload2026-07-0595%
sha1_hash3acbcfe403d42d59ce337403a39201cad1107ad4payload2026-07-0595%
sha256_hashccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2payload2026-07-0595%
sha1_hasha6b87c3a216ef6e26d483fa69151174b27a7c6f8payload2026-07-0595%
sha256_hash422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42payload2026-07-0595%
sha1_hash116af423f975819cd0668484d7e0fb7c83460fb8payload2026-07-0595%
md5_hash99755cc0b98e663e73aac9be9aa33c13payload2026-07-0595%
sha256_hashd9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862dpayload2026-07-0595%
sha1_hash612fb6725b2c4b8f2c0edf6a2de5b1e53c8b8a76payload2026-07-0595%
md5_hashba3544437b369bbd4687a2ce30077a3fpayload2026-07-0595%
sha1_hash114777ca06522cfb98a8c9e93fed5330e78dff56payload2026-07-0595%
md5_hash1d870228df077b8fe89d4ab2043743d4payload2026-07-0595%
sha256_hash0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8payload2026-07-0595%
sha1_hash69e258ea6cb572bdb95f031ff22de0ccf5cfed05payload2026-07-0595%
md5_hash17cd659fb2b7797352e5c33ce77d6cdcpayload2026-07-0595%
sha256_hashef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6bpayload2026-07-0595%
sha1_hasha6bb5b9f1835a0408ede5418fab2505702bc2f53payload2026-07-0595%
md5_hash5744f69e672856a6879875f6118744f5payload2026-07-0595%
sha256_hash1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906payload2026-07-0595%
md5_hashfafa05e543e97b4a881b864b5b4babb6payload2026-07-0595%
sha256_hashaff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359payload2026-07-0595%
sha1_hash243c572dde1e2562bf66e526693a4ef53d83e185payload2026-07-0595%

KQL: Hash Hunt

// Hunt for files matching known malicious hashes
// Source: ThreatFox - Kuiper
let malicious_hashes = dynamic(["43e647b9d685e1e5be276026df86d7e4", "69ac856f989a3dc0d8bff532c6f7f331", "46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327", "3acbcfe403d42d59ce337403a39201cad1107ad4", "ccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2", "a6b87c3a216ef6e26d483fa69151174b27a7c6f8", "422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42", "116af423f975819cd0668484d7e0fb7c83460fb8", "99755cc0b98e663e73aac9be9aa33c13", "d9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862d", "612fb6725b2c4b8f2c0edf6a2de5b1e53c8b8a76", "ba3544437b369bbd4687a2ce30077a3f", "114777ca06522cfb98a8c9e93fed5330e78dff56", "1d870228df077b8fe89d4ab2043743d4", "0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8", "69e258ea6cb572bdb95f031ff22de0ccf5cfed05", "17cd659fb2b7797352e5c33ce77d6cdc", "ef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6b", "a6bb5b9f1835a0408ede5418fab2505702bc2f53", "5744f69e672856a6879875f6118744f5", "1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906", "fafa05e543e97b4a881b864b5b4babb6", "aff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359", "243c572dde1e2562bf66e526693a4ef53d83e185"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
DeviceFileEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the ThreatFox: Kuiper IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:

Original source: https://threatfox.abuse.ch/browse/malware/elf.kuiper/