Visualização de leitura

Cat’s Got Your Files: Lynx Ransomware

Key Takeaways The DFIR Report Services Contact us today for pricing or a demo! The intrusion began in early March 2025 with a single successful Remote Desktop Protocol (RDP) logon to an internet-exposed system. Notably, there was no evidence of credential stuffing, brute forcing, or other failed authentication attempts from the source IP, indicating the […]

The post Cat’s Got Your Files: Lynx Ransomware appeared first on The DFIR Report.

Hide Your RDP: Password Spray Leads to RansomHub Deployment

Key Takeaways Case Summary This intrusion began in November 2024 with a password spray attack targeting an internet-facing RDP server. Over the course of several hours, the threat actor attempted logins against multiple accounts using known malicious IPs (based on OSINT). Several hours later they then logged in via RDP with one of the previously […]

The post Hide Your RDP: Password Spray Leads to RansomHub Deployment appeared first on The DFIR Report.

❌