logo

Hide Your RDP: Password Spray Leads to RansomHub Deployment

ID: cca6f5e7-7851-5300-9428-3effa1d7d8e5

STIX ID: report--cca6f5e7-7851-5300-9428-3effa1d7d8e5

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2025-06-30

Date Updated: 2026-04-19

Author: editor

...
...

This report documents a November 2024 intrusion where attackers gained initial access via RDP password spraying, used credential harvesting tools (Mimikatz, Nirsoft) and living‑off‑the‑land discovery to escalate and move laterally to domain controllers, exfiltrated ~2.03 GB of targeted files using Rclone over SFTP, and deployed RansomHub ransomware which propagated via SMB and executed remotely; persistent access was maintained via legitimate RMM tools (Atera, Splashtop).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.