Topic: credential hunting
-
How a Brute Force Attack Exposed a Ransomware Network
A routine brute force attack on an exposed RDP server provided a critical entry point, revealing the operational patterns of initial access brokers who sell network access to ransomware gangs. Investigation of the compromised account uncovered a vast, geo-distributed criminal infrastructure, incl...
Read More » -
CPU Spike Exposed RansomHub Ransomware Attack
An employee inadvertently triggered a ransomware attack by downloading a malicious file disguised as a browser update, initiating automated reconnaissance and credential harvesting. Attackers established persistence and network access through a SOCKS proxy, exploiting Active Directory weaknesses ...
Read More »