Huntress SOC analysts detail two incidents involving INC ransomware and data exfiltration using restic (disguised as winupdate.exe) via Wasabi S3 storage. Threat actors used base64-encoded PowerShell commands to configure restic with AWS credentials, a scheduled task named 'Recovery Diagnostics', and then disabled security tools (VIPRE Business Agent, Windows Defender) before deploying ransomware. A key operational security mistake by the threat actors — reusing identical AWS credentials across multiple victim environments — allowed analysts to link the February 9 and February 25 incidents. IOCs including SHA256 hashes for the EDR-disabling tool and ransomware executable are provided.

5m read timeFrom huntress.com
Post cover image