Lorenz Ransomware Group Cracks MiVoice
ID: c213ce7e-632e-5abf-ae3f-14078b5555b8
STIX ID: report--c213ce7e-632e-5abf-ae3f-14078b5555b8
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs analyzed a Lorenz ransomware intrusion that exploited CVE-2022-29499 in Mitel MiVoice Connect to obtain a reverse shell, deployed Chisel and ncat for tunneling and pivoting, dumped LSASS credentials via CrackMapExec/lsassy, exfiltrated data over SFTP using FileZilla to multiple attacker IPs, and triggered widespread encryption primarily using PowerShell-driven BitLocker deployment (with some ESXi ransomware); the report includes TTP mapping (ATT&CK), IOCs (IPs and hashes), detections, and remediation/recommendations including upgrading Mitel to R19.3 and enabling robust logging and segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
