πNew report out today!π
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
β‘οΈ Fake tax form JS (Lunar Spider) β Brute Ratel
β‘οΈ Latrodectus β Cobalt Strike β BackConnect β .NET backdoor
β‘οΈ Cred theft: LSASS, browsers, plaintext DA creds
β‘οΈ Rclone exfil 20 days in
β‘οΈ Nearly 2 months of C2 before eviction β no ransomware, just deep persistence.
#DFIR #ThreatIntel #BruteRatel #CobaltStrike #IncidentResponse #DFIR
