Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A detailed DFIR case study of a September 2024 intrusion where a threat actor gained initial access via a trojanized EarthTime application delivering SectopRAT. The attacker deployed multiple malware families including SystemBC for proxy tunneling and the Betruger backdoor, performed extensive reconnaissance using Grixba, SharpHound, AdFind, and SoftPerfect NetScan, and exfiltrated data via unencrypted FTP using WinSCP. Key findings link the threat actor to three ransomware groups simultaneously: Play (Grixba tooling), RansomHub (Betruger backdoor), and DragonForce (prior victim netscan output left behind as an opsec failure). The actor is assessed to be a multi-group ransomware affiliate. No ransomware was deployed before eviction, but data exfiltration was successful.