logo

From ScreenConnect to Hive Ransomware in 61 hours

ID: 938595cd-78d0-551d-a06b-3c8bf2f6e599

STIX ID: report--938595cd-78d0-551d-a06b-3c8bf2f6e599

Feed Name: The DFIR Report

Threat Score
75/100

Date Published: 2023-09-25

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR investigation documents a multi-stage intrusion (Oct 2022) where an initial user-executed dropper installed ScreenConnect RMM, enabling attackers to run discovery, stage Cobalt Strike and Metasploit backdoors (including trojanized ApacheBench and Powerfun shells), perform credential dumping (Mimikatz), exfiltrate large volumes with Rclone over SFTP, and deploy Hive ransomware (manual and attempted domain-wide GPO deployment), with a time-to-ransom of 61 hours and numerous IoCs and detection guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.