A threat actor compromised an IIS web server via Adobe ColdFusion vulnerabilities and deployed steganographic ASPX webshells concealed within image files. The attacker then executed a comprehensive defense impairment script that disabled IIS logging, tampered with Microsoft Defender through multiple vectors, killed and deleted security tool services, used IFEO debugger injection to neutralize monitoring binaries, and extracted credentials using a Mimikatz kernel driver after enabling WDigest plaintext caching. The attacker further uninstalled the ModSecurity WAF, deleted critical COM/CLSID registry keys to cripple OS functionality, and cleared all Windows event logs to destroy forensic evidence.
Mimikatz
12 posts
Defence Impairment Olympics GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
Seven Steps to Ransomware: CitrixBleed 2 Weaponized by Initial Access Brokers An Initial Access Broker is exploiting CVE-2025-5777 (CitrixBleed 2), a pre-authentication memory overread in Citrix NetScaler ADC/Gateway, to steal session tokens and bypass MFA. The stolen sessions are used to access Citrix published desktops, followed by a consistent privilege escalation via a registry symbolic-link LPE tool that abuses the Windows AppMgmt service and Group Policy refresh to gain SYSTEM. The operator then creates backdoor admin accounts, installs rogue ScreenConnect/Zoho Assist RMM clients, moves laterally with PsExec and Impacket, and ultimately deploys DragonForce ransomware. The full kill chain from initial access to encryption was observed completing in under one hour in at least one case.
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses GodDamn ransomware, the latest rebrand of the Monster/Beast ransomware lineage by threat actor Hyadina, employs a Microsoft-signed malicious kernel driver called PoisonX to terminate endpoint security products and remove API hooks before deploying encryption. The attack chain involves AnyDesk remote access deployment in non-standard directories, a 14-tool NirSoft-based credential harvesting toolkit, PsExec-based lateral movement across enterprise hosts, and a multi-day dwell period before ransomware execution. The use of a legitimately signed malicious driver represents a significant escalation in defense evasion capability for this ransomware group.
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects Kaspersky's 2025 compromise assessment report reveals that organizations consistently fail to detect long-dwelling threats, with 30.8% of incidents persisting over 3 months and 52% of high-severity compromises going undetected for 90+ days. Key findings include widespread abuse of LoLBins and remote management tools in every incident-bearing engagement, 40% of web shells surviving in backups to be restored post-remediation, and a strong correlation between in-house forensics/reverse-engineering capability and reduced incident severity. Multiple case studies document dormant crypto-mining on domain controllers (4 years), in-memory LionTail implants on critical servers, PurpleFox rootkit infections evading EDR with disabled memory scanning, and ClipBanker persistence via registry Run keys with Defender exclusions.
From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks Arctic Wolf Labs documents Anubis ransomware affiliate tradecraft observed across multiple 2026 intrusions, featuring CitrixBleed 2 (CVE-2025-5777) exploitation and valid VPN credential abuse for initial access. Affiliates consistently deploy legitimate RMM tools for persistence, use Mimikatz and ntds.dit extraction for credential access, establish alternate egress via cloudflared and SSH SOCKS tunnels, and employ exfiltration tools like S3 Browser and rclone before deploying encryptors on Windows and Linux systems. The attack chain relies on commodity tools and living-off-the-land techniques that resemble legitimate administration in isolation but form a distinctive kill chain when correlated.
APT28, an evolution of tradecraft Sekoia's Threat Detection & Research team details the two-decade evolution of APT28's tradecraft, highlighting a strategic shift from monolithic implants to disposable, single-purpose tools and compromised edge-router infrastructure. Recent operations demonstrate a return to custom cloud-resident backdoors and novel experimentation with LLM-driven infostealers.
- 6 minUmami honeypots: deception that flavors the environment
Some honeypots don't exist to catch attackers. They exist to make the environment around them convincing enough that sophisticated actors commit real tooling to the traps that do.
DFIR: From alert to root cause using Osquery without leaving Elastic Security The article details how modern Digital Forensics and Incident Response (DFIR) leverages Osquery within Elastic Security to perform distributed, real-time endpoint investigations. By querying artifacts like Prefetch, Shimcache, and Shellbags, analysts can rapidly reconstruct attack timelines, such as tracing a phishing email to the execution of Mimikatz, without requiring full disk images.
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape In 2025, ransomware operators increasingly relied on vulnerability exploitation for initial access and heavily targeted virtualization infrastructure like ESXi. While overall ransomware profitability appears to be declining, threat actors have adapted by increasing data theft extortion, targeting smaller organizations, and utilizing cross-platform ransomware families like REDBIKE, AGENDA, and INC.
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia A suspected China-nexus threat actor tracked as CL-STA-1087 has been conducting a persistent espionage campaign against Southeast Asian military targets since 2020. The attackers utilize custom malware, including the AppleChris and MemFun backdoors, leveraging Dead Drop Resolvers (DDR) like Pastebin and Dropbox for C2 resolution alongside advanced evasion techniques like process hollowing and DLL hijacking.
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors Since 2020, a Chinese threat actor tracked as CL-UNK-1068 has targeted critical infrastructure in Asia for cyberespionage. The group utilizes a diverse, cross-platform toolkit including web shells, custom Go-based scanners, modified Fast Reverse Proxy (FRP) for tunneling, and legacy Python executables for DLL side-loading to maintain stealth, escalate privileges, and exfiltrate sensitive data.