BlackSuit Attack Analysis
ID: 2c8eaa99-39f4-519b-b74e-8858345a2b68
STIX ID: report--2c8eaa99-39f4-519b-b74e-8858345a2b68
Feed Name: ReliaQuest Blog
ReliaQuest investigated an April 2024 BlackSuit ransomware attack that began with VPN account compromise and Kerberoasting, escalated to domain compromise (NTDS.DIT dump), exfiltration of over 100GB via FTP, and widespread encryption using PsExec and WMIC from a malicious VM; the report outlines the attack lifecycle, observed TTPs, indicators, containment/remediation actions, and recommended mitigations (MFA, EDR/logging, disabling weak Kerberos encryption, network segmentation, DLP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
