Ransomware, interrupted: Sodinokibi and the supply chain
ID: 53cad30c-92f5-5839-9331-3c4c157bba56
STIX ID: report--53cad30c-92f5-5839-9331-3c4c157bba56
Feed Name: Elastic Security Labs
Elastic Security detected and prevented an attempted Sodinokibi ransomware deployment that abused a compromised MSP's ScreenConnect remote support connection to copy a batch file and execute a Base64-encoded PowerShell script which downloaded and attempted in-memory shellcode execution from Pastebin. The report details process-injection alerts, extracted indicators and strings matching known Sodinokibi samples, provides an EQL detection example and Reflex mitigation guidance, and highlights the risk of trusted third-party access and the importance of behavior-based, layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
