logo

Lorenz Abuses Magnet RAM Capture

ID: a28c82fe-a1c0-5fbb-932b-4eca63f981b3

STIX ID: report--a28c82fe-a1c0-5fbb-932b-4eca63f981b3

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2023-02-23

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs investigated multiple Lorenz ransomware intrusions that exploited a Mitel MiVoice vulnerability (CVE-2022-29499) and later abused compromised VPN/vendor credentials to regain access; the actors used Chisel for tunneling, exfiltrated data via FileZilla, and notably leveraged Magnet RAM Capture (and its signed kernel driver) to dump LSASS memory and bypass EDR protections. The report includes IOCs (IPs, hashes, filenames), Sigma/YARA detection guidance, MITRE ATT&CK mappings, and defensive recommendations such as enforcing secure password resets, MFA, baselining, and driver controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.