216.73.216.233

Ransomware Initial Access Brokers Exposed

· Published 11/04/2025 09:39 · Modified 11/04/2025 16:14

Export JSON

Essential information

Published
11/04/2025 09:39
Modified
11/04/2025 16:14
Tags
2025-04-11 blacksuit brute-force credential harvesting domain enumeration hive infrastructure initial access brokers ransomware rdp vpn
Related entities
13 techniques (mitre), 2 malware

Description

An investigation into a brute force attack on an exposed Remote Desktop server led to the discovery of a larger ecosystem, particularly . The attack began with and successful compromise of an account from multiple IP addresses. The threat actor's unusual behavior of searching for credentials in files prompted further investigation. Analysis of the IP addresses revealed connections to and . Pivoting from TLS certificates uncovered a network of geographically distributed with a pattern of domain names. The case highlights the importance of thorough analysis in incident response and provides insights into the operations and motivations of actors.

External references