Shining a Light in the Dark – How Binary Defense…
ID: 9c180518-b0f8-5ebd-a350-8235e3b75f26
STIX ID: report--9c180518-b0f8-5ebd-a350-8235e3b75f26
Feed Name: Binary Defense Blog
Binary Defense and TrustedSec describe an intrusion in which a China-nexus threat actor compromised three publicly accessible AIX servers (using default Apache AXIS admin credentials), uploaded an AxisInvoker web shell, staged FRP reverse proxy and SSH keys for persistence, conducted Active Directory reconnaissance and NTLM relay, and attempted to dump LSASS on a Windows host in August 2024; detection in the managed Windows environment prevented full credential exfiltration. The report catalogs IOCs and TTPs, highlights shadow IT and unmanaged legacy systems as attack vectors, and recommends comprehensive asset visibility and managed detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
