From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
ID: a69a5c88-d5b5-5e8c-817f-c9d9885192cf
STIX ID: report--a69a5c88-d5b5-5e8c-817f-c9d9885192cf
Feed Name: The DFIR Report
A multi-stage intrusion (May 2024) attributed to Lunar Spider/Latrodectus initiated by a malicious tax-themed JavaScript dropped a MSI that installed Brute Ratel, which deployed Latrodectus and ultimately Cobalt Strike and a .NET backdoor; the actor performed host/domain enumeration, obtained plaintext domain admin credentials from an unattend.xml, used Zerologon to target domain controllers, maintained persistent BackConnect VNC access, exfiltrated data via a renamed rclone over FTP, and retained intermittent access for nearly two months with extensive IOCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
