A detailed DFIR case study of a November 2024 intrusion that began with a password spray attack against an internet-facing RDP server. Over six days, the threat actor compromised multiple accounts, used Mimikatz and Nirsoft CredentialsFileView for credential harvesting, performed network discovery with Advanced IP Scanner and SoftPerfect NetScan, established persistence via Atera and Splashtop RMM tools, exfiltrated 2.03 GB of data via Rclone over SFTP, and ultimately deployed RansomHub ransomware network-wide via SMB. The ransomware killed VMs, deleted shadow copies, cleared event logs, and encrypted files. Time to ransomware was approximately 118 hours across six calendar days. The report includes IOCs, Sigma rules, YARA signatures, and full MITRE ATT&CK mapping.