A Truly Graceful Wipe Out
ID: 078d9ade-5d90-55d5-adfa-e55edcf0c06f
STIX ID: report--078d9ade-5d90-55d5-adfa-e55edcf0c06f
Feed Name: The DFIR Report
A May 2023 intrusion leveraged a 404 TDS drive-by download of a Truebot executable that loaded Cobalt Strike and the FlawedGrace RAT for discovery, lateral movement (including pass-the-hash via Impacket/atexec and Cobalt Strike psexec), and credential dumping; adversaries exfiltrated gigabytes of data and, 29 hours after initial access, deployed an MBR Killer wiper that overwrote boot records and rendered systems inoperable. The report provides technical analysis of malware execution (registry- and PowerShell-based payload staging, process injection, scheduled task persistence), network and file IoCs (IPs, JA3/JARM, hashes, filenames), detection guidance (Sigma, YARA, Suricata rules), and attributes activity with high confidence to Lace Tempest and FIN11 with possible TA505 ties.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
