logo

From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion

ID: a69a5c88-d5b5-5e8c-817f-c9d9885192cf

STIX ID: report--a69a5c88-d5b5-5e8c-817f-c9d9885192cf

Feed Name: The DFIR Report

Threat Score
88/100

Date Published: 2025-09-29

Date Updated: 2026-04-19

Author: editor

...
...

A multi-stage intrusion (May 2024) attributed to Lunar Spider/Latrodectus initiated by a malicious tax-themed JavaScript dropped a MSI that installed Brute Ratel, which deployed Latrodectus and ultimately Cobalt Strike and a .NET backdoor; the actor performed host/domain enumeration, obtained plaintext domain admin credentials from an unattend.xml, used Zerologon to target domain controllers, maintained persistent BackConnect VNC access, exfiltrated data via a renamed rclone over FTP, and retained intermittent access for nearly two months with extensive IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.