Ransomware IAB abuses EDR for stealthy malware execution
ID: 3a9f6e3d-48d7-550d-9fbb-8e0156e57a16
STIX ID: report--3a9f6e3d-48d7-550d-9fbb-8e0156e57a16
Feed Name: Bleeping Computer
ReliaQuest analyzed attacks by an initial access broker tracked as Storm-0249 that leverage social-engineering (ClickFix) to trick victims into downloading an MSI and executing in-memory PowerShell, then sideload a malicious DLL into a signed SentinelOne EDR process to achieve stealthy persistence and funnel encrypted C2; the compromised systems are profiled (MachineGuid) to support downstream ransomware affiliates such as LockBit and ALPHV. The report warns that trusted EDR process abuse evades conventional monitoring and recommends behavior-based detection for trusted processes loading unsigned DLLs and tighter controls on LoLBins, curl, and PowerShell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
