INC ransomware opsec fail allowed data recovery for 12 US orgs
ID: 47a04331-1f5c-513b-9640-7e3f5771cf4c
STIX ID: report--47a04331-1f5c-513b-9640-7e3f5771cf4c
Feed Name: Bleeping Computer
Threat Score
Cyber Centaurs' forensic investigation into the INC ransomware operation uncovered attacker-controlled Restic backup repositories that retained encrypted exfiltrated data from 12 unrelated U.S. organizations; artifacts including renamed binaries, PowerShell scripts with hardcoded credentials, and other tooling were recovered and used to decrypt and preserve victim data, and the researchers produced YARA/Sigma rules to help detect related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
