Nov. 20, 2023, 9:06 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Author: Alex Jessop (@ThisIsFineChief)


Summary


Tl;dr


This post will delve into a recent incident response engagement handled by NCC Group’s Cyber Incident Response Team (CIRT) involving the Ransomware-as-a-Service known as NoEscape.


Below provides a summary of findings which are presented in this blog post: 



  • Initial access gained via a publicly disclosed vulnerability in an externally facing server

  • Use of vulnerable drivers to disable security controls

  • Remote Desktop Protocol was used for Lateral Movement

  • Access persisted through tunnelling RDP over SSH …

alex as-a-service author blog caught cirt cyber cyber incident cyber incident response cyber incident response team engagement fantasy findings incident incident response incident response team life malware analysis ncc ncc group noescape ransomware real response service team

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC