Just Another Blue Teamer · @LeeArchinal
122 followers · 185 posts · Server ioc.exchange

Good day everyone! The DFIR Report released their latest report detailing an attack that involved two different adversaries, one acted as the distributor while the other filled the role of hands on keyboard. was responsible for the phishing campaign and a ransomware affiliate was responsible for the rest! I hope you enjoy this and find it as useful as I did, and as always, !

HTML Smuggling Leads to Domain Wide Ransomware
thedfirreport.com/2023/08/28/h

Some MITRE ATT&CK TTPs (Thanks to the DFIR team):
TA0001 - Initial Access
T1566.001 - Phishing: Spearphishing Attachment

TA0002 - Execution
T1509.001 - Command and Scripting Interpreter: Powershell

TA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled Task

TA0009 - Collection
T1560 - Archon Collected Data

TA0005 - Defense Evasion
T1027.006 -Obfuscated Files or Information: HTML Smuggling

#ta551 #nokoyawa #happyhunting #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #readoftheday #mitremonday

Last updated 1 year ago