< ciso
brief />
Tag Banner

All news with #lateral movement tag

64 articles

Storm-2570: Cross-ecosystem ransomware tradecraft

🔍 Microsoft details activity attributed to the Storm-2570 ransomware affiliate, showing how the actor operates across multiple RaaS ecosystems (Qilin, DragonForce, Anubis, BERT) while using consistent post-compromise tooling and techniques. The report highlights repeated use of remote management software like MeshAgent, tunneling utilities, credential theft tools, lateral movement methods, and cloud exfiltration utilities. It emphasizes analyzing actor behavior across the attack chain to detect and disrupt intrusions before payload deployment, and provides detection and defense recommendations.
read more →

Mixed Device Segments Increase Lateral Movement Risk

🔍 Forescout's analysis of 47,700 real-world network segments found many contain mixed device types—IT, OT, IoT and IoMT—broadening attack surfaces and increasing lateral movement risk. The study shows only a minority of OT or IoMT segments are isolated, with common co-location like IP cameras alongside workstations enabling single-point compromises. Forescout recommends continuous visibility, device prioritization, tighter segmentation and policy-based controls to prevent breaches spreading to critical systems.
read more →

AI agents compress ransomware intrusion timelines

🛡️ Palo Alto Networks’ Unit 42 found an attacker using AI agents to traverse an enterprise network in under 10 hours, a process that could have taken human operators about two weeks. Agents conducted automated reconnaissance, searched code repositories for credentials, accessed secrets-management systems, and leveraged stolen cloud keys to abuse the victim’s AI services. The intrusion combined familiar MITRE ATT&CK techniques with agentic orchestration, highlighting the need for faster containment and stronger controls over non-human identities.
read more →

TerminalFix campaign uses reverse-tunnel to pivot

🛡️ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
read more →

Tortoiseshell expands toolkit with backdoor, SSH tunnel

🛡️ Group-IB identified new Tortoiseshell activity, uncovering a reverse SSH tunneling utility and a C++ backdoor disguised as wtsapi32.dll. The SSH tool leverages Windows OpenSSH to create reverse tunnels into compromised networks, while the backdoor supports HTTPS C2 communications, file and shell execution, and in-memory DLL loading. Researchers also linked domains resolving to servers with regional subdomains, suggesting possible targeting across Europe and the Middle East and urging enhanced threat hunting and monitoring.
read more →

AI-assisted attacks target Siemens S7 PLCs

🚨 A joint US government advisory warns that threat actors are using AI to generate exploitation scripts and tools targeting Siemens S7 Series programmable logic controllers (PLCs), placing critical sectors such as water, energy and manufacturing at heightened risk. The agencies say attackers are leveraging public scanning services to find internet-exposed PLCs, using AI to assist lateral movement and to craft tools that mimic legitimate OT monitoring, enabling read/write access via the S7comm protocol. Operators are urged to inventory systems, patch devices, block internet access to PLCs, segregate OT/IT networks, restrict remote access with MFA, disable unused services and engage with vendors for model-specific hardening to mitigate disruption, safety incidents and data compromise.
read more →

Spirals ransomware encrypts corporate networks rapidly

🛡️Researchers report a June intrusion where the new Spirals ransomware actor moved from initial access to data theft and encryption in under 24 hours. After compromising a publicly exposed IIS server and uploading an ASP.NET web shell, the attacker bypassed UAC, enabled RDP, created local accounts, and harvested credentials. They disabled security and backup services, used multiple lateral movement and remote-access tools, and deployed a Rust-based payload named bitsadmin.exe to encrypt files and drop a ransom note.
read more →

Enterprises favor convenience, increasing lateral movement risk

🔒 Zero Networks’ 2026 report, analyzing 54 trillion activities across 312 enterprise environments, finds that most internal servers remain broadly reachable and rely on legacy protocols. The study highlights that >80% of servers are accessible from anywhere inside networks, with 87% accepting RDP/SSH and 78% reachable via SMB/WinRM, while 43% still use NTLM. Experts warn this widespread internal connectivity enables easy lateral movement for attackers and call for segmentation, identity controls, and containment strategies.
read more →

Gentlemen ransomware tests identity and recovery controls

🔍 The Gentlemen ransomware highlights challenges for CISOs in stopping attackers after an initial foothold. Researchers report the malware self-propagates using legitimate Windows management tools while attempting to disable security and recovery systems. Picus Security notes the encryptor, written in Go and obfuscated with Garble, leverages multiple lateral-movement methods and targets backups, EDR, and virtualization services to hinder recovery.
read more →

Gamaredon expands malware and exfiltration tactics

🛡️ ESET observed 35 spear-phishing campaigns by the Russian APT group Gamaredon across 2025, primarily targeting Ukrainian government and military entities. Campaigns used HTML smuggling, archive attachments and a patched WinRAR flaw (CVE-2025-8088) to deploy HTA downloaders that drop payloads like PteroSand. The group enhanced persistence and lateral movement via PteroLNK, PteroPaste and PteroSetup while increasingly abusing tunnel and serverless services to hide infrastructure.
read more →

Three real-world incident case studies from GERT

🔍 Over the past year, Kaspersky’s Global Emergency Response Team and MDR service investigated diverse security incidents that informed the Anatomy of a Cyber World Global Report 2026. The post presents three real case studies illustrating how adversaries use credential theft, known vulnerabilities, and lateral movement to achieve persistence, escalate privileges, and deploy ransomware or wipers. It highlights recurring misconfigurations, delayed patching, and blind spots in monitoring as root causes of successful attacks.
read more →

Stealthy Mistic backdoor tied to KongTuke broker

🛡️ Symantec and Zscaler have detected a new backdoor named Mistic (tracked as MTLBackdoor) used in financially motivated intrusions since April, linked to the initial access broker KongTuke/Woodgnat. The malware was observed in attacks against insurance, education, IT, and professional services organizations and was sometimes deployed after ModeloRAT via social-engineering on Microsoft Teams. Mistic is designed for long-term stealth, side-loading as version.dll from a legitimate executable and running payloads in memory while offering file management, remote command execution, configurable C2 check intervals, and a self-deletion kill switch.
read more →

One intrusion, two attackers: uncovering parallel threats

🔍 Microsoft DART describes a complex multi-stage intrusion where two unrelated threat actors operated simultaneously, blending ransomware tactics with stealthy reconnaissance and persistence. Investigators observed exploitation attempts against on-premises SharePoint, use of legitimate tools like Velociraptor, cloud tunneling, credential misuse, and DLL sideloading to maintain access and evade detection. Coordinated telemetry correlation and threat intelligence enabled containment and targeted remediation guidance.
read more →

Silent Ransom Group Escalates Law Firm Attacks

🔒 The FBI warns that the Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, has increasingly targeted US law firms since 2023 using advanced social engineering. SRG has shifted from phishing and callback tactics to impersonating IT staff via phone and in-person visits to gain remote or physical access. Once inside, actors use legitimate tools like WinSCP or renamed Rclone to exfiltrate data without encrypting systems. The FBI recommends stronger cyber hygiene, phishing-resistant MFA, visitor verification, and limiting remote access and external drive installation on sensitive endpoints.
read more →

KongTuke Uses Microsoft Teams to Gain Corporate Access

🔒 Threat actor KongTuke has begun using Microsoft Teams to socially engineer employees and quickly gain persistent network access. Attackers impersonate IT staff, trick victims into running a malicious PowerShell command, and deploy ModeloRAT via a Dropbox-hosted ZIP containing a portable WinPython runtime. ReliaQuest observed the campaign active since April 2026, with attackers rotating Microsoft 365 tenants and employing Unicode tricks to appear legitimate. The malware includes resilient C2, multiple access paths, and persistence methods that can survive standard cleanup.
read more →

Chinese-Linked Group Repeatedly Hits Azerbaijani Energy

🔒 Bitdefender links a multi-wave intrusion against an Azerbaijani oil and gas company to the China-affiliated group FamousSparrow, observed between December 2025 and February 2026. The adversary repeatedly exploited a Microsoft Exchange Server ProxyNotShell chain to deploy alternating backdoors — Deed RAT and TernDoor — across three waves. Attackers used evolved DLL side-loading via the legitimate LogMeIn Hamachi binary, attempted web shell persistence and lateral movement, and re-entered the environment despite remediation efforts.
read more →

Stealthy Intrusion via Trusted Third-Party Compromise

🔍 Microsoft Incident Response details a stealthy intrusion in which a compromised third‑party IT services provider abused trusted operational tooling to gain durable access. The actor executed VBScripts and web shells via HPE Operations Agent and HPOM, enabling credential theft, lateral movement, and persistent footholds while blending into normal administration. Malicious modules (mslogon.dll, passms.dll, msupdate.dll) captured and staged credentials for exfiltration over SMB and SMTP. The report outlines timeline, analysis, and Microsoft Defender detection and mitigation guidance.
read more →

ClickFix and PySoxy Combined to Maintain Persistence

🔐 ReliaQuest researchers describe a campaign where social-engineering ClickFix techniques were paired with the decade-old Python SOCKS5 proxy PySoxy to maintain persistent access on compromised hosts. Attackers staged the proxy after reconnaissance and used a scheduled task for re-execution, so blocking the initial ClickFix vector did not fully remove access. Analysts advise treating these incidents as active compromises and hunting for Python proxy artifacts, scheduled tasks, and staged components rather than assuming a blocked C2 equals containment.
read more →

Webinar: Stopping Patient Zero — One Click Defense

🔒This webinar delivers a practical, technical playbook for identifying and neutralizing a corporate 'Patient Zero'—the first compromised device that enables rapid lateral movement. Speakers will unpack how generative AI enables stealthy phishing, the critical five-minute window, and how Zero Trust isolation halts spread. Attendees gain an actionable Recovery Blueprint to contain, remediate, and restore systems.
read more →

UAT-8302: China-Nexus APT Targeting Government Networks

🔒 Cisco Talos discloses UAT-8302, a China-nexus APT targeting government entities in South America and southeastern Europe since late 2024 into 2025. Post-compromise activity includes reconnaissance, credential theft, and lateral movement using tools like Impacket, plus deployment of multiple custom backdoors such as NetDraft, CloudSorcerer v3, and VSHELL with stagers SNOWLIGHT and SNOWRUST. Talos links these artifacts to other China-nexus clusters and publishes IOCs, ClamAV signatures, and Snort rules to assist defenders.
read more →