My Ransomware Post-Mortem
ID: aa8bb9b2-c531-5d25-b020-2ea1c35109b1
STIX ID: report--aa8bb9b2-c531-5d25-b020-2ea1c35109b1
Feed Name: Black Hills Infosec Blog
A practitioner recounts an Osiris ransomware infection caused by a phishing email with a macro-enabled Excel attachment that encrypted files on one workstation but did not spread across the SOHO network. The impact was limited due to reliable backups and segmented network shares; the report highlights root causes (user enabled macros, insufficient user training), lessons learned, and remediation advice (test backups, restrict macros/execute-from-%Temp%, enforce least-privilege file shares, user education).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
