From ScreenConnect to Hive Ransomware in 61 hours
ID: 938595cd-78d0-551d-a06b-3c8bf2f6e599
STIX ID: report--938595cd-78d0-551d-a06b-3c8bf2f6e599
Feed Name: The DFIR Report
This DFIR investigation documents a multi-stage intrusion (Oct 2022) where an initial user-executed dropper installed ScreenConnect RMM, enabling attackers to run discovery, stage Cobalt Strike and Metasploit backdoors (including trojanized ApacheBench and Powerfun shells), perform credential dumping (Mimikatz), exfiltrate large volumes with Rclone over SFTP, and deploy Hive ransomware (manual and attempted domain-wide GPO deployment), with a time-to-ransom of 61 hours and numerous IoCs and detection guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
