216.73.216.226

Data Exfiltration and Threat Actor Infrastructure Exposed

· Published 13/03/2026 11:17 · Modified 16/03/2026 10:21

Export JSON

Essential information

Published
13/03/2026 11:17
Modified
16/03/2026 10:21
Tags
2026-03-13 data exfiltration inc ransomware restic vipre
Related entities
2 observables, 6 techniques (mitre), 1 malware

Description

Huntress SOC analysts have uncovered sophisticated techniques employed by threat actors. The analysis reveals the use of various tools for data staging, including WinZip, 7Zip, and Windows' native tar.exe. Exfiltration methods observed include the use of finger.exe and backup utilities like , BackBlaze, and s5cmd. A specific incident on February 25, 2026, involved deployment, with the threat actor using PSEXEC for privilege escalation and creating a scheduled task to run a malicious PowerShell script. The actor utilized the backup utility, renamed as winupdate.exe, to exfiltrate data. Similar tactics were observed in a previous incident on February 9, suggesting a pattern in the threat actor's methodology.

External references