#ParsedReport #CompletenessHigh
21-09-2026
PAYLOAD Campaign: Extortion via an Active Directory Group Policy Object
https://securelist.ru/tr/payload-ransomware-via-group-policy/117100/
Report completeness: High
Threats:
Ryuk
Lockbit
Blackcat
Payload_ransomware
Password_spray_technique
Credential_harvesting_technique
Dcsync_technique
Kerberoasting_technique
Passthehash_technique
Process_hollowing_technique
Powerview_tool
Sharpgpoabuse_tool
Shadow_copies_delete_technique
Byovd_technique
Victims:
Manufacturing sector
Geo:
Middle east
TTPs:
Tactics: 8
Technics: 17
IOCs:
File: 10
Registry: 3
Hash: 2
IP: 12
Domain: 0
Url: 0
Email: 0
BrowserExtension: 0
Soft:
Active Directory, ctive Directory en, ESXi, inux se, PsExec, FortiGate, Windows Firewall, ortiGate SS, ctive Directory po, Windows Security, have more...
Algorithms:
md5
Win API:
THECOMPANY, EvtOpenChannelEnum, EvtNextChannelPath, EvtClearLog, EtwEventWrite, EtwEventWriteFull, EtwEventWriteTransfer
Languages:
powershell
Post #32644
29