logo

CSI: Evidence Indicators for Targeted Ransomware Attacks – Part I

ID: b78f5d39-d70d-5ca7-b388-8a610de59b58

STIX ID: report--b78f5d39-d70d-5ca7-b388-8a610de59b58

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2020-02-12

Date Updated: 2026-04-28

Author: Christiaan Beek

...
...

This article describes a two-stage attack trend where initial credential theft via info-stealers (Azorult, Dridex, Trickbot) or weak RDP access provides accounts and access that are later used in targeted ransomware campaigns (Ryuk, Bitpaymer); it details common access vectors (drive-by compromise, spear-phishing), post-compromise behaviors (credential dumping, PowerShell reconnaissance), and forensic evidence sources and order-of-volatility to aid timely detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.