BlackCat Ransomware Affiliate TTPs | Huntress Blog
ID: cabb3990-0e37-5bac-9921-4e9c20ea46c4
STIX ID: report--cabb3990-0e37-5bac-9921-4e9c20ea46c4
Feed Name: Huntress Blog
Huntress investigated a February 22, 2024 incident where a compromised ScreenConnect instance (outdated/unauthorized install) was used to download and execute an ALPHV/BlackCat ransomware binary on a healthcare-associated endpoint; the attacker disabled Windows Defender, executed commands to delete volume shadow copies and inhibit recovery, and used psexec for lateral propagation attempts. The report provides IOCs (94.131.109.54:6531, iw0pjCKEzADKTMA5Xkv8ZxS6.exe, observed command strings), maps actions to MITRE ATT&CK, and emphasizes patching, asset inventory, and attack-surface reduction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
