#AdvancedIPScanner

2025-07-01

Hide Your RDP: Password Spray Leads to RansomHub Deployment

This report details a cyberattack where threat actors gained initial access through a password spray attack on an exposed RDP server. They used Mimikatz and Nirsoft for credential harvesting, and employed living-off-the-land techniques along with tools like Advanced IP Scanner for network discovery. The attackers utilized Rclone for data exfiltration via SFTP and deployed RansomHub ransomware across the network using SMB and remote services. The intrusion lasted six days, culminating in widespread encryption and ransom demands. Key phases included initial access, lateral movement, credential theft, data exfiltration, and ransomware deployment, demonstrating a sophisticated and multi-staged attack methodology.

Pulse ID: 6862dc349ae605bef0998ced
Pulse Link: otx.alienvault.com/pulse/6862d
Pulse Author: AlienVault
Created: 2025-06-30 18:49:24

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AdvancedIPScanner #CredentialHarvesting #CyberAttack #CyberSecurity #Encryption #InfoSec #OTX #OpenThreatExchange #Password #RAT #RDP #RansomWare #Rclone #SMB #Word #bot #AlienVault

2024-04-01

Huntress takes us on a step-by-step adventure to redownload a malicious file purporting to be Advanced IP Scanner from Google Ad malvertising. Other than the initial malicious website, no other IOC. 🔗 huntress.com/blog/analyzing-a-

#AdvancedIPScanner #malvertising #threatintel

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst