NetSupport Intrusion Results in Domain Compromise
ID: 6e86dde7-d4e3-5418-909b-d529e255eceb
STIX ID: report--6e86dde7-d4e3-5418-909b-d529e255eceb
Feed Name: The DFIR Report
This DFIR report analyzes a January 2023 intrusion where threat actors used a malicious ZIP containing JavaScript to drop an obfuscated PowerShell installer that deployed NetSupport RAT, achieved persistence (registry Run key, scheduled tasks), installed OpenSSH and a reverse SSH tunnel, and used Impacket tools, SMB/WMI/RDP and additional tooling to move laterally, dump NTDS.dit and LSASS, stage data for exfiltration, and ultimately cause a full domain compromise; the report includes network and file IOCs (domains, IPs, filenames, hashes), tactics, techniques, and recommended detection artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
