Hudson Rock launched three new Cavalier threat feed modules covering infostealer C2 servers ClickFix clipboard injection infrastructure and PhaaS kits that let security teams preemptively block active attacker infrastructure before credentials get exfiltrated.

(source: Hudson Rock InfoStealers)
Imagine your security team getting an alert not after a breach notification arrives but on the exact day an infostealer command and control server goes live and begins accepting connections from infected employee machines.
That shift from reactive to preemptive defense represents exactly what Hudson Rock built when they expanded their Cavalier intelligence platform on July 21 2026 with three new threat feed modules covering infostealer C2 infrastructure ClickFix clipboard injection networks and Phishing as a Service kit tracking. For any security team that spent the last year watching infostealer logs drive breach after breach this announcement carries genuine operational weight.
Cavalier Infostealer Attack Explained
The infostealer problem in 2026 no longer needs introduction for most security professionals. Hudson Rocks own research linked a single infostealer infection at Artlist to a targeted ClickFix campaign that used stolen browser history and autofill data as reconnaissance intelligence to build individualized phishing lures.
Their FortiBleed analysis showed that 659 credential harvesting cycles ran against FortiGate firewalls over months with attackers using infostealer sourced SSH credentials as the initial entry point. The Argentine Football Association suffered a major database breach traced directly to an infostealer infection on an employee device.
The pattern across all of these incidents points toward the same fundamental gap. Organizations typically discover infostealer exposure through a breach notification or a credential appearing in a threat feed days or weeks after the stealer already ran and exfiltrated everything it targeted.
The C2 Data module inside Cavalier addresses that gap at the infrastructure layer rather than at the credential layer. Instead of waiting for stolen credentials to surface in infostealer markets the feed tracks the command and control servers that active infostealer campaigns use to receive data from infected machines and push follow on instructions to them.
Daily feed updates cover observed C2 hosts with activity trends over time malware family breakdowns including Redline Vidar Stealc and similar families top countries where infrastructure concentrates and detailed host data including infrastructure type autonomous system number AS organization ports first seen timestamps and last seen timestamps.
The feature that separates this from a standard threat intelligence IP blocklist involves correlated credential telemetry. When Cavalier surfaces a C2 host like the example domain myrtler.biz associated with Vidar the platform simultaneously shows whether any employee or user credentials from the organization appear in Hudson Rocks cybercrime intelligence database in connection with that same server.
That correlation answers the question that matters most for incident responders. Not just that the server exists and runs Vidar but whether anyone from the organization already got compromised in a way that may have given attackers initial access to that infrastructure in the first place.

(source: Hudson Rock InfoStealers)
The ClickFix module provides visibility into a threat class that grew dramatically throughout the first half of 2026. ClickFix attacks present victims with fake error messages technical instructions or verification prompts that direct them to open a command interface and paste a clipboard payload that executes silently.
The Cavalier feed tracks malicious ClickFix pages and clipboard injection infrastructure as it goes live giving defenders the ability to block these pages at the proxy or DNS filtering layer before employees encounter them rather than only investigating after someone already ran the pasted command on a company machine.
The PhaaS module covers Phishing as a Service kits targeting corporate credentials including the kind of Microsoft 365 token harvesting operations Hudson Rock documented throughout the EvilTokens and Ghost Phishing research cycles.
Commercial PhaaS platforms like Venom and Forg365 operate with subscription pricing and rotating infrastructure making static domain blocklists inadequate as a defense. A feed that tracks PhaaS kit deployments as new instances spin up gives security teams a fundamentally different advantage specifically the ability to add blocking rules against attacker infrastructure that may only sit active for 24 to 72 hours before rotating to a new domain.
Infostealer C2 Telemetry Analysis
The operational model Hudson Rock built around these feeds reflects a specific philosophy about where infostealer defense actually needs to happen. Most organizations focus their infostealer response on the credential side meaning they monitor for employee credentials appearing in leaked logs rotate passwords when exposures get confirmed and potentially add multi factor authentication requirements.
That response addresses a real risk but it consistently runs behind the attack timeline because credentials only surface in marketplaces after the stealer already ran and the exfiltrated data made its way through trading hands.
C2 infrastructure represents an earlier point in the same attack chain. A C2 server needs to spin up before any stealer can receive instructions or send stolen data anywhere. Network defenders who block communication to known C2 servers at the firewall or proxy level interrupt the exfiltration step even on machines where a stealer already executed.
An infected endpoint that cannot reach its C2 server cannot deliver stolen credentials cannot receive secondary payload instructions and cannot update its configuration. The credential theft still happened on that machine but the damage stops before it reaches the attacker’s collection infrastructure.
The REST API integration built into all three feed modules matters for organizations running security orchestration platforms or custom detection stacks. The GET endpoint at /json/v3/threat-feeds/c2 returns observed C2 hosts with granular filter support covering host identity malware family country autonomous system number feed type date range and pagination.

(source: Hudson Rock InfoStealers)
Teams running Splunk Microsoft Sentinel Palo Alto XSOAR or similar platforms can pull daily C2 feed updates directly into their blocking automation creating a continuous cycle where newly observed infostealer infrastructure gets blocked at the perimeter within hours of Hudson Rock’s observation rather than waiting for manual analyst review.
The correlated intelligence dimension of the C2 feed also provides a secondary use case that pure blocklist feeds cannot replicate.
When a C2 host carries correlated credential data showing that specific employees may have already had machines compromised by that same malware family the intelligence transforms from a simple IOC into an actionable incident investigation starting point.
Security teams can prioritize which correlated employee accounts need immediate password rotation MFA enforcement and endpoint investigation rather than treating every discovered stealer log as equally urgent.
Cyber Defense & Threat Mitigation Guide
Understanding where these feeds fit inside a broader defense strategy helps security teams decide how to operationalize them rather than simply adding another threat intelligence subscription to a stack that already has more data than analysts can process.
The C2 Data feed addresses the network layer most directly and benefits organizations that can enforce DNS or proxy based blocking at scale. Adding observed infostealer C2 hosts to a protective DNS policy or a web proxy category block creates passive protection that requires no analyst time per blocked connection once the automation pipeline gets configured.
Teams using endpoint detection tools that perform outbound connection monitoring can also use the C2 feed as an alert enrichment source flagging existing connection alerts when the destination IP or domain appears in the daily C2 feed update.
The ClickFix feed addresses a social engineering delivery mechanism that behaves differently from traditional phishing. Standard email gateway rules look for suspicious links or attachments and often miss ClickFix lures because the instruction to paste malicious content into a command prompt bypasses both link reputation checks and attachment scanning.
Blocking known ClickFix page infrastructure before employees reach those pages represents the highest leverage defensive point in the ClickFix kill chain since once a user pastes and executes the clipboard payload the attack already succeeded at the delivery layer regardless of whether any individual endpoint tool catches the subsequent execution.
The PhaaS feed addresses a threat class where defenders often feel like they are blocking yesterday’s infrastructure while attackers already moved to tomorrow’s domains. Commercial PhaaS platforms designed to harvest Microsoft 365 tokens cycle through domain registrations at a rate that makes manual blocklist maintenance ineffective.
A continuously updated feed that tracks PhaaS deployments in near real time closes the window between when a new PhaaS instance goes live and when defenders can block access to it from corporate networks.
Organizations evaluating whether these feeds add value beyond existing threat intelligence should specifically consider three scenarios that existing tools consistently miss. First the credential correlation scenario where a C2 server appears in a feed alongside evidence that specific employees already encountered that malware family provides a connection that neither pure IOC feeds nor credential monitoring services typically make on their own.
Second the preemptive ClickFix blocking scenario where the page gets blocked before any employee visits it rather than responding after someone already ran the clipboard payload. Third the PhaaS rotation scenario where blocking rules stay current against infrastructure that rotates faster than manual analyst workflows can track.
The broader shift Hudson Rock built into Cavalier with these three modules reflects where infostealer defense needs to mature across the industry. Credential monitoring catches exposure after it happens. C2 infrastructure monitoring applied proactively through automated blocking pipelines represents the closest available approximation to catching infostealer campaigns before they complete the exfiltration step that turns a compromised endpoint into a compromised organization.