logo

Tales From the Incident Response Cliff Face – Case Study 3

ID: 3a21f391-193d-5503-8f5b-babe5f79ea1b

STIX ID: report--3a21f391-193d-5503-8f5b-babe5f79ea1b

Feed Name: Kudelski Security

Threat Score
78/100

Date Published: 2024-07-01

Date Updated: 2026-07-24

...
...

**Executive summary:** This report describes a real-time BlackByte ransomware intrusion against a large European manufacturer where attackers abused an unmanaged VPN account (local cisco user), performed password spraying and Kerberoasting to obtain domain admin privileges, used off-the-shelf tooling (Impacket, CrackMapExec, LSASS dumping modules, BlackByteSQLManager) for lateral movement and data discovery, and established persistence (AnyDesk, local admin accounts); the incident response team chose a surgical containment approach while completing EDR deployment, disabling the obsolete VPN, removing malicious AnyDesk instances, resetting accounts, and blocking exfiltration channels to prevent encryption and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.