A Huntress SOC investigation that began as a routine RDP brute force attack unraveled into the discovery of a suspected ransomware-as-a-service ecosystem linked to initial access brokers. Analysts found atypical tradecraft — manual file system browsing for credentials using Notepad — which prompted deeper infrastructure analysis. By pivoting on TLS certificate fingerprints from the offending IP addresses, researchers mapped a geographically distributed network of domains (specialsseason[.]com, 1vpns[.]com) tied to known ransomware groups including Hive and BlackSuit. The domain naming convention and VPN service characteristics (no-log policy) suggest a coordinated criminal infrastructure supporting big-game hunting ransomware operations. Indicators of compromise including IP addresses and certificate fingerprints are provided.