Brazilian educational institutions face ransomware attacks primarily from DragonForce and LockBit 3 variants, with initial access gained through valid accounts, exposed applications, and insider threats. Attackers leverage Potato variants for privilege escalation, AnyDesk and PsExec for remote access and lateral movement, and batch scripts to disable Windows Defender and enable RDP. The use of outdated Windows 10 and unpatched Windows Server 2016 systems increases the attack surface, while shared accounts on multi-user machines enable insider keylogging attacks.
keylogger
1 post
An analysis of incidents at Brazilian educational institutions