Disney security breach
ID: ef32afda-a715-5537-bd02-3cef26a66039
STIX ID: report--ef32afda-a715-5537-bd02-3cef26a66039
Feed Name: ThreatLocker Blog
Threat actor group "Nullbulge" reportedly compromised Disney by leveraging an insider who had exported or stored credentials and by distributing malicious packages: a malicious Beam.NG mod that executed a PowerShell payload and a trojanized ComfyUI extension that replaced OpenAI/Anthropic libraries to exfiltrate API keys and deploy a payload. ThreatLocker analysis links the intrusions to known RATs and info stealers (AsyncRAT, LockBit payloads), provides multiple SHA-256 IOCs and a hosting URL, and recommends hardening password manager usage, MFA, application allowlisting, ringfencing, and EDR detection to mitigate similar attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
