---
title: "Data Exfiltration and Threat Actor Infrastructure Exposed"
url: https://daily.dev/posts/data-exfiltration-and-threat-actor-infrastructure-exposed-rl9x6jmho
source_url: https://www.huntress.com/blog/data-exfiltration-threat-actor-infrastructure-exposed
type: article
source: "Huntress Blog"
published: 2026-05-31T07:42:51.692Z
updated: 2026-05-31T08:08:36.613Z
tags: ["ransomware", "powershell", "data-exfiltration"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Exfiltration and Threat Actor Infrastructure Exposed

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 5 min read · 0 upvotes · 0 comments

## Summary

Huntress SOC analysts detail two incidents involving INC ransomware and data exfiltration using restic (disguised as winupdate.exe) via Wasabi S3 storage. Threat actors used base64-encoded PowerShell commands to configure restic with AWS credentials, a scheduled task named 'Recovery Diagnostics', and then disabled security tools (VIPRE Business Agent, Windows Defender) before deploying ransomware. A key operational security mistake by the threat actors — reusing identical AWS credentials across multiple victim environments — allowed analysts to link the February 9 and February 25 incidents. IOCs including SHA256 hashes for the EDR-disabling tool and ransomware executable are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/data-exfiltration-threat-actor-infrastructure-exposed>

## Similar posts on daily.dev

- [Ransomware gang’s slip-up led to data recovery for 12 US firms](https://daily.dev/posts/ransomware-gang-s-slip-up-led-to-data-recovery-for-12-us-firms-ekfv0vyfb) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware), [#powershell](https://daily.dev/tags/powershell), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/data-exfiltration-and-threat-actor-infrastructure-exposed-rl9x6jmho)
