logo

MEGAsync Forensics and Intrusion Attribution

ID: 7268959a-407a-5068-b615-a95a4a13e716

STIX ID: report--7268959a-407a-5068-b615-a95a4a13e716

Feed Name: NVISO Labs

Threat Score
75/100

Date Published: 2024-09-04

Date Updated: 2026-04-28

Author: Maxime Thiebaut

...
...

This blog post describes how forensic analysis of MEGAsync's Statecache SQLite database can reveal locally-synced and remotely-available files used for exfiltration; the investigators used a custom tool (mega-statecache.py) to enumerate nodes, recover evidence of past exfiltrations, identify additional victims, and attribute the activity to a LockBit affiliate, demonstrating that ransomware actors continue to use legitimate cloud services for data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.