logo

From IcedID to Dagon Locker Ransomware in 29 Days

ID: 29cd3782-7a78-55b1-b461-b67d08d5d8f6

STIX ID: report--29cd3782-7a78-55b1-b461-b67d08d5d8f6

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2024-04-29

Date Updated: 2026-04-19

Author: editor

...
...

In August 2023 an intrusion began via a PrometheusTDS phishing campaign delivering IcedID, which established persistence, downloaded and executed Cobalt Strike beacons, performed extensive discovery and lateral movement (SMB, WMIC, AdFind, Sharefinder), exfiltrated data (Rclone and a custom AWSCollector to S3), and after ~29 days deployed Dagon Locker ransomware across the domain; the report includes detailed IoCs, memory and file artifacts, YARA and Sigma detection rules, and analysis of attacker tooling and procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.