Defeating BLOCKADE SPIDER: How CrowdStrike Stops Cross-Domain Attacks
ID: 1abba9ed-3886-5ad7-8d0c-ffcbce9c4b0d
STIX ID: report--1abba9ed-3886-5ad7-8d0c-ffcbce9c4b0d
Feed Name: Crowdstrike Blog
CrowdStrike OverWatch documents BLOCKADE SPIDER, an eCrime ransomware actor active since at least April 2024, executing cross-domain attacks across unmanaged endpoints, cloud, and identity systems. The actor gained access via an unmanaged VPN appliance, used DCSync to dump additional credentials, added accounts to AD groups, bypassed MFA, deployed a rogue AD agent and targeted backups and virtualized infrastructure with Embargo ransomware; OverWatch leveraged identity protection and Falcon Next‑Gen SIEM telemetry to trace, monitor, and ultimately disrupt the adversary’s access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
