dfir.ch
During a recent incident response engagement, we responded to a single-host infecti 2026-9-24 16:31:22 Author: dfir.ch(查看原文) 阅读量:0 收藏

During a recent incident response engagement, we responded to a single-host infection handed over to us by the SOC. The user downloaded a malicious “Remote Desktop Connection Manager”, a legitimate tool developed by Microsoft, but attackers were now misusing the brand.

After the infection, the attackers had full access to the infected device. The RAT was ChainScript, as Nicely depicted here. [1]

As soon as we took over this case, we began hunting inside the network for traces of lateral movement and/or similar techniques (TTPs, IOCs). Additionally, we found 3 additional infected computers with the same malware, with infections occurring in a short time span.

It turns out the devices belonged to employees on the same team, and one employee pasted the malicious link in a Teams Chat, encouraging the rest of the team to install the software from the same malicious site. So the sentence could not be truer: Trust, but verify.

[1] https://blackpointcyber.com/blog/chainscript-tracing-a-nodejs-rat-across-the-blockchain/


文章来源: https://dfir.ch/posts/__tweet/
如有侵权请联系:admin#unsafe.sh