Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes
ID: 9c0ddf9b-37c6-5737-a8bc-7a261bfc2735
STIX ID: report--9c0ddf9b-37c6-5737-a8bc-7a261bfc2735
Feed Name: The Hacker News
Threat Score
Proofpoint observed TA577 phishing campaigns (Feb 26–27, 2024) that delivered ZIP attachments containing HTML files which trigger SMB connections to attacker-controlled servers to capture NTLMv2 challenge/response pairs; the technique enables credential theft and pass-the-hash lateral movement, impacted hundreds of organizations worldwide, and defenders are advised to block outbound SMB.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
