ReadText34 Ransomware Incident | Huntress
ID: 343b754a-88a3-563f-98f0-b44cd2d4f045
STIX ID: report--343b754a-88a3-563f-98f0-b44cd2d4f045
Feed Name: Huntress Blog
Huntress investigated a ransomware incident in which an attacker used compromised Administrator credentials and RDP to deploy a vulnerable TrueSight driver (trend.exe) to crash endpoint security, ran payloads (winppx.exe, readtext34.exe) that attempted kernel driver persistence, opened a reverse shell to 94.198.50.195, and executed file-encryption and recovery-disabling actions (including use of cipher.exe); the incident produced a ransom note (How_to_back_files.html) and multiple IOCs (file SHA256s and contact emails).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
