Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
ID: 68fadbe0-35ba-546e-a177-7cf6bb34e434
STIX ID: report--68fadbe0-35ba-546e-a177-7cf6bb34e434
Feed Name: The DFIR Report
This DFIR Report describes a multi-stage intrusion beginning with a malicious EarthTime installer that deployed SectopRAT, established SystemBC proxy tunnels for RDP access, performed AD credential theft (including DCSync and Veeam credential extraction), executed extensive reconnaissance (Grixba/SharpHound/AdFind/Netscan), staged and archived sensitive files with WinRAR/FS64, exfiltrated data over cleartext FTP, and later dropped the Betruger backdoor — activity consistent with a ransomware affiliate preparing for a ransomware event.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
