Data Exfiltration and Threat Actor Infrastructure Exposed
ID: cbec4a69-6fed-54be-949e-49717c120d13
STIX ID: report--cbec4a69-6fed-54be-949e-49717c120d13
Feed Name: Huntress Blog
Threat Score
Huntress SOC investigated an incident where threat actors used base64-encoded PowerShell to configure Restic (renamed as winupdate.exe) with S3 credentials and an exposed RESTIC_PASSWORD to stage/exfiltrate data, removed security agents (VIPRE/EDR), disabled Windows Defender, and deployed INC ransomware (c:\perflogs\win.exe), with RestartManager activity observed during file encryption; the report includes SHA256 IOCs and notes similar prior activity and external reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
