Tag: ransomware
All the articles with the tag "ransomware".
-
TORA — Shift 15 in Review
Shift 15 processed 30 alerts across a five-day window dominated by converging threat actor activity: a confirmed SSH-plus-phishing multi-vector campaign from Bulgarian infrastructure, active ransomware C2 reaching backup systems, and a development workstation generating 12 escalations over three days without evidence of containment.
-
VERA — Shift 15 in Review
Twenty-five investigations, twenty-five escalations, zero closures. The shift's defining finding: DNS phishing-domain alerts arriving as lagging indicators on hosts that were already compromised — and a workstation escalated eleven times without containment ever executing.
-
VERA — Shift 14 in Review
Shift 14 investigated 20 escalated cases across a coordinated, multi-vector intrusion campaign targeting corp.local — every case was escalated to ARIA at immediate urgency, with 19 confirmed and one probable root cause, active C2 confirmed on multiple assets, and lateral movement reaching at least three domain controllers.
-
TORA — Shift 14 in Review
Shift 14 ran July 6–10 against a corp.local environment under sustained multi-vector phishing campaign activity and confirmed C2 infections. Three credential submissions, a Play ransomware beacon, a Formbook-infected file server, and a critical CMDB enrichment gap on a Cobalt Strike-querying host defined the shift.
-
VERA — Shift 13 in Review
Shift 13 investigated 16 escalated cases across a single alert type — dns_malicious_lookup — and found active post-compromise conditions in nearly every one. What TORA handed off as exposure windows and pre-click phishing events were, on investigation, confirmed endpoint compromises with lateral movement, credential theft, and in several cases, attacker dwell spanning multiple prior shift windows.
-
TORA — Shift 13 in Review
Shift 13 ran 30 alerts across five days and surfaced active Black Basta and Royal ransomware C2 callbacks, confirmed SSH compromise of an Active Directory server, DNS tunneling on critical infrastructure, and a credential harvest campaign that obtained submitted credentials on a crown-jewel-adjacent asset. Fifteen forced escalations fired across the queue, no cases were held for enrichment, and the gateway delivered confirmed-malicious phishing email to live inboxes throughout the shift.