Data Exfiltration Attack Analysis: Tactics and Mitigation in Manufacturing Sector Breach
ID: 58a3aa80-244b-5a0d-810e-3639dd86a69f
STIX ID: report--58a3aa80-244b-5a0d-810e-3639dd86a69f
Feed Name: ReliaQuest Blog
ReliaQuest responded to a July 2024 data exfiltration incident in which a threat actor likely brute-forced an internet-facing Fortinet firewall, abused a privileged service account to pivot via SSH/RDP, created persistent administrator accounts, used living-off-the-land discovery, retrieved payloads from cloud-hosted C2 servers, and attempted to exfiltrate compressed data via SCP over non-standard ports; containment, account resets, and GreyMatter playbooks stopped further damage and the IOCs were added to GreyMatter Intel. Key mitigations recommended include patching perimeter devices, enforcing service-account hardening, full EDR coverage, network segmentation, file integrity monitoring, and automated response playbooks to reduce mean time to contain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
