Curling for Data: A Dive into a Threat Actor's Malicious TTPs | Huntress
ID: 355a16ba-5991-5da9-9145-48e9291c9936
STIX ID: report--355a16ba-5991-5da9-9145-48e9291c9936
Feed Name: Huntress Blog
Threat Score
Huntress investigators observed a post-compromise intrusion where an attacker accessed an endpoint (noted via anomalous TeamViewer entry), staged and downloaded tools (Dokan and MemProcFS) via curl from 193.149.176.90, likely dumped process memory to obtain credentials, collected browser and file data with a PowerShell script, and exfiltrated an archive back to the same external host, all while using valid compromised accounts and native/GUI tools to minimize detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
