logo

Unmasking a Financial Services Intrusion: REF0657

ID: a615ac95-a0fd-5877-8759-0a3e3319ccd5

STIX ID: report--a615ac95-a0fd-5877-8759-0a3e3319ccd5

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2024-01-31

Date Updated: 2026-04-27

...
...

Elastic Security Labs reports on REF0657, a December 2023 smash-and-grab intrusion targeting a South Asian financial services organization in which attackers abused a remotely accessible Microsoft SQL Server (xp_cmdshell) to execute commands, deploy a range of open-source tunnelers and proxies, side-load Cobalt Strike via a modified msvcp140.dll, dump credentials, disable defenses, and exfiltrate data using MEGA; the report includes IOCs, MITRE ATT&CK mappings, detection guidance, and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.