How One Letter Hid a Ransomware Army
ID: 27311420-0753-52c0-90dc-a735cf6cd4f9
STIX ID: report--27311420-0753-52c0-90dc-a735cf6cd4f9
Feed Name: Halcyon Blog
Threat Score
Halcyon detected and contained a targeted Qilin ransomware intrusion at a financial services firm: a malicious svchosts.exe binary bypassed Defender and Carbon Black and spread to 30 endpoints using EDR-evasion, shadow copy deletion attempts, privilege escalation and lateral movement, but behavioral detections, tenant-wide telemetry, and a coordinated war-room response stopped the attack before any encryption or data exfiltration occurred.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
