Ransomware Initial Access Brokers Exposed
ID: e7080005-aeb3-5b5d-8374-dfc3284a2323
STIX ID: report--e7080005-aeb3-5b5d-8374-dfc3284a2323
Feed Name: Huntress Blog
Threat Score
This Huntress incident write-up describes an RDP brute-force compromise that led to discovery of a distributed infrastructure and tradecraft tied to ransomware actors and initial access brokers; the report includes forensic findings, pivots from TLS certificates to multiple malicious domains/IPs, and a table of IOCs (IPs, domains, certificate fingerprints) to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
