Hackers in Aisle 5: What DragonForce Taught Us About Zero Trust
ID: bf5f2eba-7965-5cdc-9430-1babf3691dda
STIX ID: report--bf5f2eba-7965-5cdc-9430-1babf3691dda
Feed Name: Mitiga
This report describes a series of coordinated ransomware attacks by the group "DragonForce" against multiple UK retailers that relied on targeted vishing to obtain password resets from IT helpdesks, followed by privilege escalation, lateral movement using native tools, EDR/AV tampering, widespread ransomware deployment and data exfiltration; the document outlines control failures (identity, access, segmentation, monitoring) and provides detection/hunting queries for suspicious password resets, privilege changes and security-tool tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
