CSI: Evidence Indicators for Targeted Ransomware Attacks – Part I
ID: b78f5d39-d70d-5ca7-b388-8a610de59b58
STIX ID: report--b78f5d39-d70d-5ca7-b388-8a610de59b58
Feed Name: McAfee Labs Blog
Threat Score
This article describes a two-stage attack trend where initial credential theft via info-stealers (Azorult, Dridex, Trickbot) or weak RDP access provides accounts and access that are later used in targeted ransomware campaigns (Ryuk, Bitpaymer); it details common access vectors (drive-by compromise, spear-phishing), post-compromise behaviors (credential dumping, PowerShell reconnaissance), and forensic evidence sources and order-of-volatility to aid timely detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
