216.73.217.22

Nitrogen Campaign Drops Sliver and Ends With BlackCat Ransomware

· Published 01/10/2024 10:05 · Modified 01/10/2024 10:29

Export JSON

Essential information

Published
01/10/2024 10:05
Modified
01/10/2024 10:29
Tags
2024-10-01 alphv blackcat cobalt strike credential harvesting data exfiltration lateral movement nitrogen noberus ransomware sliver
Related entities
45 observables, 32 techniques (mitre), 6 malware

Description

A intrusion began with a malware campaign impersonating Advanced IP Scanner. The attackers used and beacons for post-exploitation, leveraging Python scripts for memory loading. They performed network enumeration using various tools and moved laterally with Impacket after . was conducted using the Restic backup tool. Eight days after initial access, the attackers modified a privileged user's password and deployed across the domain using PsExec to execute a batch script. The intrusion lasted 156 hours over 8 days, ending with file encryption and ransom notes left on affected systems.

External references