216.73.216.10

ReadText34 Ransomware Incident

· Published 24/09/2024 14:22 · Modified 24/09/2024 14:38

Export JSON

Essential information

Published
24/09/2024 14:22
Modified
24/09/2024 14:38
Tags
2024-09-24 bianlian readtext34
Related entities
6 observables, 14 techniques (mitre), 2 malware

Description

A ransomware attack was observed in September 2024, targeting an endpoint with limited visibility. The threat actor used stolen Administrator credentials to enable RDP and deploy malicious executables. They installed a vulnerable driver, TrueSight RogueKiller Antirootkit, to disable security applications. The ransomware, named , utilized various techniques to disable system recovery and encrypt files. The attack involved the use of Go Trojan for command and control. File encryption was performed using the native Windows utility cipher.exe. A ransom note was left, threatening to release stolen data if not contacted within 72 hours. The incident highlights the importance of comprehensive endpoint monitoring, incident response planning, and attack surface reduction efforts.

External references