logo

A deep dive into the most interesting incident response cases of last year

ID: 53d064ce-7bb3-5fc9-88a6-d455e748d6db

STIX ID: report--53d064ce-7bb3-5fc9-88a6-d455e748d6db

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2024-09-03

Date Updated: 2026-04-29

Author: Eduardo Ovalle, Ahmad Zaidi Said, AbdulRhman Alfaifi

...
...

Kaspersky GERT outlines several 2023 incident response cases: an insider fraud scheme that abused internal transaction services to steal millions; a long-lived Flax Typhoon-like intrusion that leveraged legitimate software (SoftEther, Zabbix) for persistence and credential theft; a targeted phishing campaign that bypassed MFA via a phishing kit leading to mailbox compromise and a successful BEC transfer; and a ToddyCat-like attack employing DLL side-loading and an ICMP backdoor for stealthy persistence and command execution. The report maps observed TTPs to MITRE ATT&CK, documents exploitation of known vulnerabilities and legitimate tooling abuse, and emphasizes enhanced monitoring, MDR deployment, and cloud/mail security controls as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.