Data Leak Detected by AhnLab EDR (vs. Ransomware Threat Actors)
ID: 0680ba1d-3dcd-54af-9dd1-41fa6e27af49
STIX ID: report--0680ba1d-3dcd-54af-9dd1-41fa6e27af49
Feed Name: ASEC
This report outlines how ransomware groups exfiltrate data prior to encryption by abusing legitimate file transfer and cloud-sync tools—WinSCP, FileZilla, MegaSync, and Rclone—and describes how AhnLab EDR detects these activities through behavior-based monitoring and signatures. It references multiple ransomware families (e.g., Hive, Akira, Maze, LockBit, Conti, BlackCat/ALPHV, Nefilim, Money Message, REvil, BlackBasta, Cactus, DarkSide, Royal) and provides guidance for administrators to identify, investigate, and respond to these data-leak TTPs using EDR telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
