logo

Double Extortion Attack Analysis

ID: b6d42f9e-5d11-558b-99eb-9b0dee260929

STIX ID: report--b6d42f9e-5d11-558b-99eb-9b0dee260929

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2023-12-19

Date Updated: 2026-04-29

...
...

**Executive summary:** ReliaQuest investigated a double-extortion ransomware incident that began with presumed exploitation of NetScaler CVE-2023-3519, followed by lateral movement using Impacket, staging in c:\windows\debug, DLL sideloading of a signed Palo Alto Cortex XDR binary to load a malicious DLL, in-memory C2 (Cobalt Strike), exfiltration via a renamed Rclone to Dropbox, and defense impairment via a signed but vulnerable IObit driver (BYOVD) to disable EDR; the report includes IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.