A deep dive into the most interesting incident response cases of last year
ID: 53d064ce-7bb3-5fc9-88a6-d455e748d6db
STIX ID: report--53d064ce-7bb3-5fc9-88a6-d455e748d6db
Feed Name: Securelist by Kaspersky
Date Published: 2024-09-03
Date Updated: 2026-04-29
Author: Eduardo Ovalle, Ahmad Zaidi Said, AbdulRhman Alfaifi
Kaspersky GERT outlines several 2023 incident response cases: an insider fraud scheme that abused internal transaction services to steal millions; a long-lived Flax Typhoon-like intrusion that leveraged legitimate software (SoftEther, Zabbix) for persistence and credential theft; a targeted phishing campaign that bypassed MFA via a phishing kit leading to mailbox compromise and a successful BEC transfer; and a ToddyCat-like attack employing DLL side-loading and an ICMP backdoor for stealthy persistence and command execution. The report maps observed TTPs to MITRE ATT&CK, documents exploitation of known vulnerabilities and legitimate tooling abuse, and emphasizes enhanced monitoring, MDR deployment, and cloud/mail security controls as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
