logo

How cyberattackers exploit domain controllers using ransomware

ID: c73b7bc9-832d-53e5-a9ab-5cbeda5a134a

STIX ID: report--c73b7bc9-832d-53e5-a9ab-5cbeda5a134a

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2025-04-09

Date Updated: 2026-04-28

Author: Alon Rosental

...
...

Modern human-operated ransomware campaigns increasingly target domain controllers to obtain high‑privilege accounts and access central network assets, enabling rapid, large-scale encryption; the report outlines attacker TTPs (privilege escalation, network reconnaissance, persistence), presents a case study of an attempted Akira ransomware deployment, and describes Microsoft Defender for Endpoint's automatic attack disruption and "contain high value assets" (HVA) capability that granularly contains compromised domain controllers to stop lateral movement while maintaining essential authentication services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.