Using Shodan Images to Hunt Down Ransomware Groups
ID: 62ddfe7b-074e-5f47-ae12-109e1ed0fe59
STIX ID: report--62ddfe7b-074e-5f47-ae12-109e1ed0fe59
Feed Name: Huntress Blog
Threat Score
**Executive summary:** This blog demonstrates using Shodan to discover exposed internet-facing infrastructure abused by ransomware actors—showing numerous unauthenticated VNC instances, screenshots of attacker commands (PowerShell, bitsadmin, cmd, FTP, nslookup), and linked GandCrab/REvil indicators—while offering mapping to MITRE ATT&CK and pragmatic defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
