logo

Malicious ISO File Leads to Domain Wide Ransomware

ID: 049eb619-7f31-5455-b525-f861decfaf50

STIX ID: report--049eb619-7f31-5455-b525-f861decfaf50

Feed Name: The DFIR Report

Threat Score
85/100

Date Published: 2023-04-03

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR report documents a late-September 2022 intrusion that began with IcedID delivered via a malicious ISO, escalated to Cobalt Strike beacons and hands-on-keyboard activity, leveraged ZeroLogon and named-pipe/Winlogon token impersonation for privilege escalation, exfiltrated backups to Mega using rclone, and culminated in deployment of Quantum ransomware that encrypted all domain-joined systems; the report provides detailed TTPs, network and file IOCs (domains, IPs, file names, and hashes), and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.