logo

Data Exfiltration and Threat Actor Infrastructure Exposed

ID: cbec4a69-6fed-54be-949e-49717c120d13

STIX ID: report--cbec4a69-6fed-54be-949e-49717c120d13

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

...
...

Huntress SOC investigated an incident where threat actors used base64-encoded PowerShell to configure Restic (renamed as winupdate.exe) with S3 credentials and an exposed RESTIC_PASSWORD to stage/exfiltrate data, removed security agents (VIPRE/EDR), disabled Windows Defender, and deployed INC ransomware (c:\perflogs\win.exe), with RestartManager activity observed during file encryption; the report includes SHA256 IOCs and notes similar prior activity and external reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.