logo

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

ID: 68fadbe0-35ba-546e-a177-7cf6bb34e434

STIX ID: report--68fadbe0-35ba-546e-a177-7cf6bb34e434

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2025-09-08

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR Report describes a multi-stage intrusion beginning with a malicious EarthTime installer that deployed SectopRAT, established SystemBC proxy tunnels for RDP access, performed AD credential theft (including DCSync and Veeam credential extraction), executed extensive reconnaissance (Grixba/SharpHound/AdFind/Netscan), staged and archived sensitive files with WinRAR/FS64, exfiltrated data over cleartext FTP, and later dropped the Betruger backdoor — activity consistent with a ransomware affiliate preparing for a ransomware event.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.