Trusted relationship attacks: trust, but verify
ID: bcc3b491-8576-5bfe-979f-e81e41ca9dc1
STIX ID: report--bcc3b491-8576-5bfe-979f-e81e41ca9dc1
Feed Name: Securelist by Kaspersky
This report analyzes "trusted relationship" attacks against IT service providers that enable attackers to reach client networks; it documents common initial access vectors (exploited internet-facing apps, compromised credentials, phishing), tools and persistence methods (Ngrok, AnyDesk, backdoors, scheduled tasks, Windows services), attacker post-compromise activity (discovery, credential dumping, lateral movement via RDP), and typical goals (data exfiltration and ransomware). The authors present observed timelines (often up to three months undetected), forensic artifacts (AnyDesk logs, RDP tunneling indicators), MITRE ATT&CK mappings, and practical recommendations for service providers and their clients to reduce risk and detect such intrusions earlier.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
