logo

How a CPU spike led to uncovering a RansomHub ransomware attack

ID: 4844f8e3-4659-577e-97f9-a48b6bf0717e

STIX ID: report--4844f8e3-4659-577e-97f9-a48b6bf0717e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-11-11

Date Updated: 2026-07-18

Author: Sponsored by Varonis

...
...

**Executive summary:** A targeted compromise attributed to RansomHub affiliates began with a malicious JavaScript masquerading as a browser update, which deployed packed Python-based malware (SocGhoulish) that established a SOCKS proxy, harvested credentials (including DPAPI abuses), leveraged misconfigured AD CS to escalate to Domain Admin, and exfiltrated large volumes of data via AzCopy; Varonis detected the activity (CPU spike), worked with the customer to contain and remediate, and prevented a subsequent ransomware deployment with zero business downtime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.