logo

Ransomware Initial Access Brokers Exposed

ID: e7080005-aeb3-5b5d-8374-dfc3284a2323

STIX ID: report--e7080005-aeb3-5b5d-8374-dfc3284a2323

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-04-10

Date Updated: 2026-04-28

...
...

This Huntress incident write-up describes an RDP brute-force compromise that led to discovery of a distributed infrastructure and tradecraft tied to ransomware actors and initial access brokers; the report includes forensic findings, pivots from TLS certificates to multiple malicious domains/IPs, and a table of IOCs (IPs, domains, certificate fingerprints) to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.