logo

Defeating BLOCKADE SPIDER: How CrowdStrike Stops Cross-Domain Attacks

ID: 1abba9ed-3886-5ad7-8d0c-ffcbce9c4b0d

STIX ID: report--1abba9ed-3886-5ad7-8d0c-ffcbce9c4b0d

Feed Name: Crowdstrike Blog

Threat Score
75/100

Date Published: 2025-11-18

Date Updated: 2026-04-27

Author: Chris Prall

...
...

CrowdStrike OverWatch documents BLOCKADE SPIDER, an eCrime ransomware actor active since at least April 2024, executing cross-domain attacks across unmanaged endpoints, cloud, and identity systems. The actor gained access via an unmanaged VPN appliance, used DCSync to dump additional credentials, added accounts to AD groups, bypassed MFA, deployed a rogue AD agent and targeted backups and virtualized infrastructure with Embargo ransomware; OverWatch leveraged identity protection and Falcon Next‑Gen SIEM telemetry to trace, monitor, and ultimately disrupt the adversary’s access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.