A Huntress SOC investigation that began as a routine RDP brute force attack unraveled into the discovery of a suspected ransomware-as-a-service ecosystem linked to initial access brokers. Analysts found atypical tradecraft — manual file system browsing for credentials using Notepad — which prompted deeper infrastructure analysis. By pivoting on TLS certificate fingerprints from the offending IP addresses, researchers mapped a geographically distributed network of domains (specialsseason[.]com, 1vpns[.]com) tied to known ransomware groups including Hive and BlackSuit. The domain naming convention and VPN service characteristics (no-log policy) suggest a coordinated criminal infrastructure supporting big-game hunting ransomware operations. Indicators of compromise including IP addresses and certificate fingerprints are provided.

9m read timeFrom huntress.com
Post cover image
Table of contents
Attack narrativeUnraveling the infrastructureConclusionIndicators of Compromise