Hackers Exploit Zoom Installer to Gain RDP Access and Launch BlackSuit Ransomware Attack
ID: 86accf1c-f3ad-5d22-9057-68e246394671
STIX ID: report--86accf1c-f3ad-5d22-9057-68e246394671
Feed Name: Cyber Press
Threat Score
A nine-day, multi-stage intrusion started with a cloned Zoom installer (zoommanager.com) that installed d3f@ckloader and retrieved secondary payloads, eventually leading to deployment of BlackSuit ransomware. Attackers performed credential theft and lateral movement using Cobalt Strike and Brute Ratel, used PsExec and PowerShell for propagation, exfiltrated data via WinRAR to Bublup cloud storage, and deleted Volume Shadow Copies before encrypting files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
