Attack Behaviors | Huntress
ID: 45ed162f-30a6-502c-ae5c-1d25c73d5a33
STIX ID: report--45ed162f-30a6-502c-ae5c-1d25c73d5a33
Feed Name: Huntress Blog
Threat Score
This report reviews Huntress observations of recurring ‘threat clusters’ in early 2024 where attackers exploited CVE-2023-48788 (and other vectors) to compromise endpoints, deploy RMM tools (ScreenConnect, SimpleHelp), and exfiltrate data (including via finger.exe); it emphasizes habit-driven TTPs—password reuse, repeated endpoint names, and consistent command sequences—as high-fidelity indicators defenders can track to detect and disrupt campaigns earlier.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
