Once Bitten: LockBit Ransomware Case Study
ID: d5276bbf-64bc-5367-b45c-3925916598f9
STIX ID: report--d5276bbf-64bc-5367-b45c-3925916598f9
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest details a LockBit ransomware intrusion where initial access was gained through a SocGholish infection, Cobalt Strike was staged for C2 and lateral movement, and the adversary ultimately obtained administrator-level credentials to deregister EDR sensors and deploy an encryptor via GPO and PsExec, disabling defenses and deleting recovery artifacts; the report also maps observed MITRE techniques and provides detection/remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
