logo

Data Leak Detected by AhnLab EDR (vs. Ransomware Threat Actors)

ID: 0680ba1d-3dcd-54af-9dd1-41fa6e27af49

STIX ID: report--0680ba1d-3dcd-54af-9dd1-41fa6e27af49

Feed Name: ASEC

Date Published: 2024-02-07

Date Updated: 2026-04-26

Author: Sanseo

...
...

This report outlines how ransomware groups exfiltrate data prior to encryption by abusing legitimate file transfer and cloud-sync tools—WinSCP, FileZilla, MegaSync, and Rclone—and describes how AhnLab EDR detects these activities through behavior-based monitoring and signatures. It references multiple ransomware families (e.g., Hive, Akira, Maze, LockBit, Conti, BlackCat/ALPHV, Nefilim, Money Message, REvil, BlackBasta, Cactus, DarkSide, Royal) and provides guidance for administrators to identify, investigate, and respond to these data-leak TTPs using EDR telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.