Topic: credential hunting

  • How a Brute Force Attack Exposed a Ransomware Network

    How a Brute Force Attack Exposed a Ransomware Network

    A routine brute force attack on an exposed RDP server provided a critical entry point, revealing the operational patterns of initial access brokers who sell network access to ransomware gangs. Investigation of the compromised account uncovered a vast, geo-distributed criminal infrastructure, incl...

    Read More »
  • CPU Spike Exposed RansomHub Ransomware Attack

    CPU Spike Exposed RansomHub Ransomware Attack

    An employee inadvertently triggered a ransomware attack by downloading a malicious file disguised as a browser update, initiating automated reconnaissance and credential harvesting. Attackers established persistence and network access through a SOCKS proxy, exploiting Active Directory weaknesses ...

    Read More »