logo

Bad Habits: An ANTISOC Operation

ID: 4244ee8c-8b44-5f53-9927-88562c9f68e7

STIX ID: report--4244ee8c-8b44-5f53-9927-88562c9f68e7

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: BHIS

...
...

**Executive summary:** A BHIS ANTISOC case study describes how a helpdesk technician's reuse of a single reset password enabled attackers to password-spray that credential across an Entra ID export, compromise more than 100 accounts (some without MFA), establish SSH-based C2 and persistence inside the internal network, and access a backup web portal that could allow destructive actions; the report outlines detection gaps, attacker techniques, and post-incident remediation steps taken by the victim.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.