MEGAsync Forensics and Intrusion Attribution
ID: 7268959a-407a-5068-b615-a95a4a13e716
STIX ID: report--7268959a-407a-5068-b615-a95a4a13e716
Feed Name: NVISO Labs
Threat Score
This blog post describes how forensic analysis of MEGAsync's Statecache SQLite database can reveal locally-synced and remotely-available files used for exfiltration; the investigators used a custom tool (mega-statecache.py) to enumerate nodes, recover evidence of past exfiltrations, identify additional victims, and attribute the activity to a LockBit affiliate, demonstrating that ransomware actors continue to use legitimate cloud services for data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
