Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
ID: 478a61a9-a1ab-5c83-bcb2-2e0d4766944f
STIX ID: report--478a61a9-a1ab-5c83-bcb2-2e0d4766944f
Feed Name: CISA Cybersecurity Advisories
**Executive summary:** CISA and MS-ISAC investigated a state government compromise where a former employee’s administrative credentials—likely obtained from a prior breach and from unsecured credentials on a virtualized SharePoint server—were used to authenticate via the organization’s VPN, run LDAP queries that enumerated domain users, hosts, and trust relationships, and produce files later posted for sale on a dark web site; no evidence was found of lateral movement into the organization’s Azure tenant. The advisory maps the actor’s TTPs to MITRE ATT&CK and recommends immediate mitigations including disabling unnecessary admin accounts, enforcing phishing-resistant MFA, securing credential storage, auditing Azure tenant permissions, and improving logging and incident readiness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
