logo

HTML Smuggling Leads to Domain Wide Ransomware

ID: dca7b5e1-de6e-5616-9e2f-f355a78b400f

STIX ID: report--dca7b5e1-de6e-5616-9e2f-f355a78b400f

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2023-08-28

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR report documents a Nokoyawa ransomware campaign in which an email-delivered HTML smuggling lure installed a password-protected ZIP/ISO that executed a LNK to run IcedID (via a renamed rundll32), leading to Cobalt Strike deployment, credential theft and lateral movement to domain controllers and backup infrastructure, and full network encryption via PsExec/WMIC within ~12 hours; the report includes extensive IOCs (IPs, domains, JA3s, SSL cert data, filenames and hashes), persistence artifacts (scheduled task), discovery commands, and attribution to TA551 (distributor) and Microsoft-tracked Storm-0390.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.