Threat Intelligence

Huntress faces backlash over attacker tracking

(Adobe Stock)

The Register reports that cybersecurity firm Huntress has come under scrutiny after publishing research that documented an attacker's activities for three months, which is an unusual case sparked when the intruder inadvertently installed Huntress's endpoint detection and response trial software.

The firm revealed that the attacker, while experimenting with phishing kits, automation, and AI tools, also relied heavily on Google Translate and even installed a premium Malwarebytes browser extension, behavior Huntress described as "hilarious."

While many defenders praised the insights, others raised sharp ethical concerns. Horizon3.ai CEO Snehal Antani asked whether private firms should be allowed to monitor adversaries so extensively or whether they had a duty to alert authorities once the work shifted from incident response into intelligence collection.

Critics also called the surveillance a "complete invasion of privacy." Huntress defended its approach, stating that its visibility mirrors standard EDR practices and that publishing the findings served its dual mission of education and advancing security awareness.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds