What we know about BlackCat and the MGM hack
ID: ea33792c-c746-5a41-b9e5-bdb986fdda94
STIX ID: report--ea33792c-c746-5a41-b9e5-bdb986fdda94
Feed Name: ReversingLabs Blog
The report details a BlackCat/ALPHV ransomware campaign that disrupted MGM Resorts (and affected other hospitality firms), describing how attackers used social engineering to bypass Okta MFA and gain super-admin/Azure privileges, leveraged known vulnerabilities and tools (ProxyShell, Mimikatz, Cobalt Strike) for lateral movement and exfiltration, and highlights the RaaS affiliate model and operational impacts; recommended defenses include staff training, patching, and early detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
