Suivre

UNC2596 observed leveraging vulnerabilities to deploy . Beyond commonplace tools, like Cobalt Strike BEACON and NetSupport, UNC2596 has used novel , including BURNTCIGAR to disable endpoint protection, WEDGECUT to enumerate active hosts, and the BUGHATCH custom downloader. COLDDRAW ransomware operations have impacted dozens of organizations across more than ten countries, including those within critical infrastructure. Wedgecut, Bughatch, Burntcigar

mandiant.com/resources/unc2596

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.