How a Brute Force Attack Unmasked a Ransomware Infrastructure Network
ID: 73e6de98-ad31-5ee6-963b-5c0b726f433e
STIX ID: report--73e6de98-ad31-5ee6-963b-5c0b726f433e
Feed Name: Bleeping Computer
Threat Score
Huntress investigators traced a successful RDP brute-force compromise that led to manual credential harvesting and domain enumeration; pivots from Windows telemetry to TLS certificate fingerprints uncovered a geo-distributed infrastructure (specialsseason.com, 1vpns.com) and VPN service tied to ransomware activity and initial access brokers, with multiple IOCs and certificate hashes provided for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
