Unmasking a Financial Services Intrusion: REF0657
ID: a615ac95-a0fd-5877-8759-0a3e3319ccd5
STIX ID: report--a615ac95-a0fd-5877-8759-0a3e3319ccd5
Feed Name: Elastic Security Labs
Elastic Security Labs reports on REF0657, a December 2023 smash-and-grab intrusion targeting a South Asian financial services organization in which attackers abused a remotely accessible Microsoft SQL Server (xp_cmdshell) to execute commands, deploy a range of open-source tunnelers and proxies, side-load Cobalt Strike via a modified msvcp140.dll, dump credentials, disable defenses, and exfiltrate data using MEGA; the report includes IOCs, MITRE ATT&CK mappings, detection guidance, and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
