TTPs Associated With a New Version of the BlackCat Ransomware
ID: a987fa37-84b1-5df2-b798-0e3b81ccad26
STIX ID: report--a987fa37-84b1-5df2-b798-0e3b81ccad26
Feed Name: SecurityScorecard Blog
This DFIR report details a BlackCat/ALPHV ransomware engagement: attackers exploited vulnerable Microsoft Exchange servers to drop webshells, used credential theft (Mimikatz or LSASS dumps) and network discovery to move laterally via RDP, staged data by compressing with WinRAR/7zip, exfiltrated with rclone and MEGAsync, installed legitimate tools (MobaXterm, Process Hacker) to evade detection, and ran a new BlackCat build that supports a “--safeboot” parameter and restart/sleep behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
