logo

Top attack vectors: December 2021

ID: fc7816b5-d87c-5dc9-9827-2f1f2ff766c6

STIX ID: report--fc7816b5-d87c-5dc9-9827-2f1f2ff766c6

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2022-01-13

Date Updated: 2026-04-27

Author: Britton Manahan

...
...

December 2021 SOC analysis found high-volume, active exploitation of the Apache Log4j zero-day alongside widespread use of Cobalt Strike beacons and a ransomware campaign pattern (BazarLoader → Cobalt Strike → Diavol); the report details incident investigations and containment, provides IOCs, and recommends urgent mitigations such as patching Log4j, validating EDR coverage, vulnerability scanning, and phishing defense.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.