All the passwords were stored in Active Directory description fields
ID: d896bc5d-91b0-5a41-b00f-5ca1b77534ca
STIX ID: report--d896bc5d-91b0-5a41-b00f-5ca1b77534ca
Feed Name: The Register (Security)
The article describes a ransomware attack enabled by insecure practices: service account passwords were stored in Active Directory description fields, which an Initial Access Broker discovered after a phishing campaign and running the Sliver tool. Attackers used the harvested credentials to obtain full domain access, delete backups, and encrypt Hyper-V hosts, taking over 2,000 users offline for months — illustrating the severe consequences of storing credentials in accessible cleartext locations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
