VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
ID: 38e55a1b-792d-5a1c-a0ab-97363b2e2834
STIX ID: report--38e55a1b-792d-5a1c-a0ab-97363b2e2834
Feed Name: ThreatCluster
VerdantBamboo carried out an 18-month supply-chain campaign against a managed service provider and its clients by exploiting a misconfigured Egnyte Storage Sync appliance and stolen credentials to deploy backdoors (BRICKSTORM, AGENTPSD, PLENET), compromise pfSense firewalls, access Microsoft 365 and NAS resources, and persist through multiple re-entry attempts; Volexity’s analysis documents the technical TTPs, impacted assets, and remediation recommendations (patch Egnyte v13.13, harden VPN/firewalls, monitor TLS/DoH and cron jobs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
