logo

Fake Zoom Ends in BlackSuit Ransomware

ID: 8c2e15a2-48d7-55b3-8ae4-3fc15208d6d6

STIX ID: report--8c2e15a2-48d7-55b3-8ae4-3fc15208d6d6

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2025-03-31

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR case details a May 2024 intrusion that began with a trojanized Zoom installer (d3f@ckloader) and IDAT loader which injected SectopRAT into MSBuild.exe; after a multi-day dwell period the actor executed Brute Ratel and Cobalt Strike for discovery and lateral movement, deployed a QDoor proxy to tunnel RDP, exfiltrated archived data to Bublup, and used PsExec to distribute and run BlackSuit ransomware across Windows hosts, deleting VSS snapshots and leaving ransom notes; the report includes timelines, YARA/Sigma rules, network/detection artifacts, and extensive IOCs (hashes, IPs, domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.