# Threat Hunting & Intel

Published articles for Threat Hunting & Intel.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

DevFeed: [PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting](<https://devfeed.tech/articles/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting-30904.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/>)

Author: Maddie Stewart

Published: 2026-09-16T13:36:43.658349Z

Content type: news

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [threat-hunting-intel](<https://devfeed.tech/tags/threat-hunting-intel.md>)

### AI overview

CrowdStrike reports that a financially motivated bug bounty hunter developed and distributed PhantomRaven, a JavaScript-based information stealer through npm. The company assesses with high confidence that a large language model was used to write the malware and says the operator likely used it to identify bug bounty opportunities.

### Source excerpt

CrowdStrike identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript-based information stealer PhantomRaven.

## Peer Pressure: Inside the Sality Botnet Disruption Operation

DevFeed: [Peer Pressure: Inside the Sality Botnet Disruption Operation](<https://devfeed.tech/articles/peer-pressure-inside-the-sality-botnet-disruption-operation-8308.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/>)

Author: CrowdStrike Counter Adversary Operations

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [P2P](<https://devfeed.tech/topics/p2p.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [industry](<https://devfeed.tech/tags/industry.md>), [operations](<https://devfeed.tech/tags/operations.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [support](<https://devfeed.tech/tags/support.md>), [threat-hunting-intel](<https://devfeed.tech/tags/threat-hunting-intel.md>)

### AI overview

CrowdStrike describes a coordinated operation that disrupted the Sality peer-to-peer botnet, which had distributed malicious payloads to more than 33,000 infected machines worldwide. The operation used peer-to-peer sinkholing to isolate infected machines and disable the criminal command channel, with support from international law enforcement and industry partners.

### Source excerpt

CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet.