LOLBins, or “Living Off the Land Binaries,” are legitimate tools within operating systems like Windows and macOS that can be exploited by cyberattackers for malicious purposes. They pose a significant threat due to their stealthy nature, making detection challenging. Understanding their usage can help in identifying and mitigating potential attacks.…
Read More
Author: Huntress
In 2024, cybercriminals remained relentless, prompting analysts to enhance defenses and provide vital insights. Key events included critical vulnerabilities in ScreenConnect, the emergence of new ransomware variants, and targeted attacks on human rights activists. As we move into 2025, the focus will be on staying one step ahead of evolving threats.…
Read More
Background
Read More
Huntress analysts have previously observed INC ransomware being deployed, and recently observed this specific ransomware variant being deployed in a customer environment. The ransomware variant was identified, in part, through the threat actor’s efforts to verify that their deployment was effective, as illustrated through the following command line:
[.highlight]”C:windowssystem32NOTEPAD.EXE”[.highlight]…
Background
Read More
Given a diverse customer base, Huntress sees a wide range of activity even when it comes to persistent threat actors. When such a threat actor makes attempts to compromise a customer with both managed EDR and managed anti-virus (MAV) services, it’s often very interesting to observe their playbook.…