Initial Access Broker

Stealthy Mistic backdoor linked to ransomware access broker KongTuke News

Stealthy Mistic backdoor linked to ransomware access broker KongTuke

A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance...
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks News

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and Fa...
Hackers bypass SonicWall VPN MFA due to incomplete patching News

Hackers bypass SonicWall VPN MFA due to incomplete patching

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appl...
KongTuke hackers now use Microsoft Teams for corporate breaches News

KongTuke hackers now use Microsoft Teams for corporate breaches

Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five min...
Yanluowang ransomware access broker gets 81 months in prison News

Yanluowang ransomware access broker gets 81 months in prison

A Russian national was sentenced to nearly 7 years in prison after pleading guilty to acting as an initial access broker...
ブルートフォース攻撃でランサムウェア基盤ネットワークの正体を暴く News

ブルートフォース攻撃でランサムウェア基盤ネットワークの正体を暴く

によるハントレス・タクティカル・レスポンス・チーム ほとんどの防御者にとって、公開されたRDP上の別のブルートフォース・アラートはバックグラウンド・ノイズであり、トリアージして通り過ぎるだけのありふれた活動です。ハントレス・タクティカル・レ...
Initial access hackers switch to Tsundere Bot for ransomware attacks News

Initial access hackers switch to Tsundere Bot for ransomware attacks

A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access...
Jordanian pleads guilty to selling access to 50 corporate networks News

Jordanian pleads guilty to selling access to 50 corporate networks

A Jordanian man has pleaded guilty to operating as an "access broker" who sold access to the computer networks of at lea...
ランサムウェアIAB、EDRを悪用してマルウェアをステルス実行 News

ランサムウェアIAB、EDRを悪用してマルウェアをステルス実行

Storm-0249として追跡されている初期アクセスブローカーは、ランサムウェア攻撃の準備のために、エンドポイント検出および応答ソリューションと信頼できるMicrosoft Windowsユーティリティを悪用して、マルウェアのロード、通信の...
Yanluowangイニシャルアクセスブローカーは、ランサムウェア攻撃で有罪を認めた News

Yanluowangイニシャルアクセスブローカーは、ランサムウェア攻撃で有罪を認めた

ロシア国籍の被告が、2021年7月から2022年11月にかけて少なくとも8つの米国企業を標的としたYanluowangランサムウェア攻撃の初期アクセス・ブローカー(IAB)として活動した罪を認めることになった。 Court Watchの編集...