Securelist
Read post

Incident response statistics and cases at educational institutions in Brazil

Kaspersky's Global Emergency Response Team (GERT) shares incident response statistics and case studies from Brazilian educational institutions between January 2025 and June 2026. Key findings show 40% of incidents were high-severity, primarily ransomware attacks using DragonForce and LockBit 3 (via leaked builder). Most common initial access vectors were valid accounts, exposed public-facing applications, and insiders. Three detailed cases cover a LockBit attack using PsExec for lateral movement, a DragonForce deployment via AnyDesk, and a Python keylogger used by an insider to steal credentials. Recommendations include enforcing MFA, eliminating shared accounts, isolating backups, patching legacy systems (many still run Windows 10 and Server 2016), and improving forensic visibility through artifacts like Amcache, Prefetch, and USN Journal.

    #ransomware
Aug 03•10m read time•From securelist.com
Post cover image
Table of contents
IntroductionKey findings and statisticsInteresting casesConclusions and recommendationsObserved TTPs
208 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard