Lorenz Abuses Magnet RAM Capture
ID: a28c82fe-a1c0-5fbb-932b-4eca63f981b3
STIX ID: report--a28c82fe-a1c0-5fbb-932b-4eca63f981b3
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs investigated multiple Lorenz ransomware intrusions that exploited a Mitel MiVoice vulnerability (CVE-2022-29499) and later abused compromised VPN/vendor credentials to regain access; the actors used Chisel for tunneling, exfiltrated data via FileZilla, and notably leveraged Magnet RAM Capture (and its signed kernel driver) to dump LSASS memory and bypass EDR protections. The report includes IOCs (IPs, hashes, filenames), Sigma/YARA detection guidance, MITRE ATT&CK mappings, and defensive recommendations such as enforcing secure password resets, MFA, baselining, and driver controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
