A detailed forensic analysis of a nearly two-month intrusion initiated by Lunar Spider via a malicious JavaScript file disguised as a W-9 tax form. The attack chain began with Brute Ratel C4 deployed via MSI, which injected Latrodectus into explorer.exe. Within days, the threat actor discovered plaintext domain admin credentials in an unattend.xml Windows Answer file, enabling rapid privilege escalation. Multiple tools were deployed including Cobalt Strike, BackConnect VNC, a custom .NET backdoor (lsassa.exe), and Zerologon (CVE-2020-1472) exploits for lateral movement. On day 20, data was exfiltrated via Rclone over FTP. Credential harvesting targeted LSASS, browsers, Outlook, and Veeam backup software. Despite extensive access to critical infrastructure including domain controllers and backup servers, no ransomware was deployed before the threat actor was evicted.

34m read timeFrom thedfirreport.com
Post cover image
Table of contents
Key TakeawaysThe DFIR Report ServicesCase SummaryAnalystsInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCommand and ControlExfiltrationImpactTimelineDiamond ModelIndicatorsDetectionsMITRE ATT&CK
1 Impression