Back to Intelligence

INCRANSOM: 6 New Leak-Site Listings — Healthcare and Professional Services Claims, Exposure Analysis & Detection Rules

SA
Security Arsenal Team
September 25, 2026
20 min read

Classification: TLP:CLEAR | Publication Date: 2026-09-25 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

Executive Summary

  • Security Arsenal monitoring observed six new INCRANSOM leak-site listings published between 2026-09-23 and 2026-09-25. The listings name organizations in healthcare, professional services, manufacturing, and one listing for which no sector was identified.
  • The claimed geographic distribution covers five country or region codes: MA, MO, GB, US, and BR. The US accounts for two of the six claims; each of the other codes accounts for one.
  • All six listings are currently single-source. None was independently observed by a second crawler, and none confirms that a compromise occurred.
  • The operational concern is the combination of healthcare and professional-services claims with INCRANSOM's publicly reported double-extortion model: theft or threatened theft of sensitive information, followed by encryption and publication pressure.
  • Defenders should prioritize internet-facing remote access, identity controls, Office macro execution, PsExec and WMI lateral movement, archive or cloud-sync staging, backup tampering, and the five CISA Known Exploited Vulnerabilities discussed below.
  • No evidence in the supplied data links any specific named organization to any specific CVE. The CVE analysis is a sector- and infrastructure-level exposure hypothesis only.

Sourcing & Verification

  • Second-crawler corroboration: 0 of 6 listings were independently observed by a second leak-site crawler.
  • Single-source listings: 6 of 6 currently appear only through ransomware.live monitoring.
  • Meaning of inclusion: Inclusion reflects INCRANSOM's claim. It is not confirmation of a breach, intrusion, data theft, encryption, or an active incident.
  • Meaning of corroboration: MULTI-SOURCE would mean two independent crawlers observed the gang publish the same claim. It would still not confirm the underlying breach. No corroboration tier confirms an incident; only the organization, a regulator, forensic evidence, or another authoritative disclosure can do that.
  • Disputes and silence: A named organization may dispute a listing. A denial is likewise not proof that the threat actor's claim is false. Disclosure obligations vary by jurisdiction, sector, contract, and materiality, and not every incident is reportable. Neither silence nor denial settles the question.
  • Corrections: Security Arsenal will publish corrections when warranted and welcomes contact from any named organization at security@securityarsenal.com.

Organizations Named in the Latest Claims

Organization or domain as listedClaimed sectorCountry/region codePublication dateCrawler status
pharma5.maHealthcareMA2026-09-25Single-source
bnlawmacau.com www.bn-ip.comProfessional ServicesMO2026-09-24Single-source
ukbjja.orgNot FoundGB2026-09-24Single-source
welgenone.comHealthcareUS2026-09-24Single-source
Grupo CaberjManufacturingBR2026-09-24Single-source
Lemon LawProfessional ServicesUS2026-09-23Single-source

These entries are reproduced to support defensive monitoring and verification. They are accusations by a criminal actor and should not be treated as breach notifications.

Threat Actor Profile — INCRANSOM

Names and operating model

  • Aliases and styling: The group is commonly rendered as INC Ransom or INC RANSOM. Security Arsenal is not treating minor spelling or capitalization variants as separate actor names.
  • Operating model: Public reporting generally tracks INCRANSOM as an affiliate-supported ransomware-as-a-service operation rather than a fully closed team. As with other RaaS ecosystems, the personnel, infrastructure, and execution quality can vary by affiliate.
  • Ransom demands: There is no defensible fixed or average demand. Demands vary with the claimed data, perceived ability to pay, insurance position, negotiation posture, and whether the operator claims both encryption and data theft. Organizations should not budget or make disclosure decisions from a generic demand figure.

Initial-access patterns

Public reporting and ransomware investigations associate the broader INCRANSOM ecosystem with the following access methods:

  • Phishing and malicious attachments, including macro-enabled documents and script execution.
  • Valid-account access to VPN, remote desktop, or other externally exposed services.
  • Exposed or weakly protected RDP, including access obtained through credential theft or initial-access brokers.
  • Exploitation of internet-facing applications and remote-management infrastructure.
  • Use of legitimate remote-administration tools after access is established.

Supply-chain compromise is not established by the supplied data as a defining INCRANSOM access method. Nevertheless, developer-platform and supply-chain exposure remains relevant because the CISA KEV set includes JetBrains TeamCity and Nx Console vulnerabilities.

Extortion and operational behavior

  • Double extortion: The actor's leak-site model supports a claim of data theft or threatened publication in addition to encryption. Even where a listing does not publish a data sample, defenders should assume that staging and exfiltration may have been objectives if the claim is later substantiated.
  • Hands-on lateral movement: INCRANSOM reporting is consistent with the wider ransomware pattern of using built-in Windows administration, remote services, and legitimate tools rather than relying exclusively on custom malware.
  • Dwell time: No reliable actor-wide average dwell time is available. Reported ransomware intrusions commonly progress from days to weeks, but the distribution is broad. A short dwell time is possible when affiliates purchase ready-made access or when endpoint controls are weak.
  • Execution quality: Affiliate-driven operations can produce inconsistent tooling and timelines. Detection should therefore focus on behavior rather than actor-specific file names, hashes, or a single command line.

Current Campaign Analysis

Claimed sector mix

Sector in leak-site dataCountShare of six claims
Healthcare233.3%
Professional Services233.3%
Manufacturing116.7%
Not Found116.7%

Healthcare and professional services are the most visible sectors in this sample. Both can hold high-value personal, financial, contractual, legal, or regulated information. Manufacturing adds operational-technology and intellectual-property concerns, although the leak-site data does not state that any OT environment was affected.

The sample is too small to establish a durable sector shift. It is sufficient to justify heightened review by healthcare organizations, law firms and other professional-services providers, and regional manufacturers.

Geographic concentration

Country/region codeCount
US2
MA1
MO1
GB1
BR1

The claims are geographically dispersed rather than concentrated in one jurisdiction. The US has two listings, but two observations are not enough to characterize a US-focused campaign. Organizations in the other listed jurisdictions should not discount the claims simply because each appears only once.

Profile of organizations named

The supplied data does not provide employee counts, revenue, system inventory, or compromise details. Consequently:

  • Company size: Not reliably determinable. The mixture of named organizations and domains is consistent with a possible focus on small-to-midsized or regional organizations, but that is an inference rather than a verified profile.
  • Revenue estimate: Not available. Producing a numeric revenue range from a domain, legal-services name, or sector label would be speculative and could unfairly characterize the named organizations.
  • Data sensitivity hypothesis: Healthcare listings raise concern for patient, employee, billing, and clinical information. Professional-services listings raise concern for client files, contracts, privileged communications, credentials, and regulated personal data. The manufacturing listing raises concern for designs, supplier information, production documentation, and business records.
  • Infrastructure hypothesis: Organizations of this profile commonly operate Microsoft identity, remote access, virtualized servers, shared file services, and third-party backup or remote-management tooling. Those systems should be reviewed first, without assuming they were involved in any specific claim.

Posting frequency and escalation pattern

The six listings form a short publication burst:

  • 2026-09-23: 1 listing
  • 2026-09-24: 4 listings
  • 2026-09-25: 1 listing

Four listings in one day can indicate batch publication after separate negotiations, a deliberate visibility push, or crawler timing. The current extract does not include ransom deadlines, sample-data volume, countdown status, or prior negotiation history. It therefore does not establish a sustained increase in INCRANSOM activity or a new escalation tactic.

The supplied monitoring extract identifies six recent entries within the gang's last 100 postings. Security Arsenal will watch for republication, data-sample additions, countdown changes, duplicate claims under alternate names, and second-crawler confirmation.

CISA KEV exposure hypothesis — not victim attribution

CISA lists the following vulnerabilities as known to be exploited and confirms ransomware use in the supplied intelligence. This does not mean INCRANSOM used any of them against a named organization.

CVEAffected product and issueAdded to CISA KEVDefensive relevance
CVE-2026-59310Broadcom VMware vCenter path traversal2026-08-18Compromise of the virtualization management plane can amplify impact across many workloads and complicate containment.
CVE-2026-63077JetBrains TeamCity deserialization of untrusted data2026-08-05CI/CD compromise can expose source code, build credentials, deployment secrets, and software-distribution paths.
CVE-2026-20316Cisco Secure Firewall Management Center hard-coded password issue2026-07-29Security-management-plane exposure can reveal network policy, credentials, logs, and paths for broader administrative access.
CVE-2026-50751Check Point Security Gateway improper authentication in IKEv1 key exchange2026-06-08Perimeter and VPN exposure is directly relevant to valid-account and remote-access intrusion scenarios.
CVE-2026-48027Nx Console embedded malicious code2026-05-27Developer-tool compromise can provide a supply-chain route to credentials, source repositories, build systems, and downstream environments.

Priority interpretation

  1. CVE-2026-50751 is the most obvious perimeter-access hypothesis because it affects a security gateway and authentication path.
  2. CVE-2026-59310 is the highest amplification risk because vCenter can provide broad control over virtual infrastructure.
  3. CVE-2026-20316 can expose the firewall-management plane and weaken visibility or segmentation.
  4. CVE-2026-63077 and CVE-2026-48027 create developer and supply-chain paths that may bypass conventional perimeter controls.

Treat these as exposure hypotheses to drive asset inventory and patching. Do not attribute an intrusion to a CVE without perimeter logs, application telemetry, forensic artifacts, or authoritative incident evidence.

Detection Engineering

Detection strategy

The current leak-site data contains no hashes, command-and-control domains, ransom-note names, or victim-specific forensic artifacts. Detection should therefore focus on repeatable pre-encryption behavior:

  1. Office applications launching script interpreters or command shells after a phishing lure.
  2. PsExec-style service execution or WMI-spawned remote commands.
  3. Archive utilities, cloud-sync clients, or file-transfer tools creating compressed or staged data.
  4. Unexpected administrative discovery, new services, disabled security tooling, or backup manipulation.
  5. Periodic outbound HTTPS or DNS from hosts that normally have limited Internet access. Cobalt Strike infrastructure and beacon intervals are highly configurable, so network detections should use behavior and prevalence rather than actor-specific strings.

Use these three Sigma detections as one YAML document:

YAML
---
title: INCRANSOM - Office Application Spawning Script Interpreter
id: 8c0cf8eb-fce5-4778-807e-c722dd355ef8
status: experimental
description: Detects Office applications launching command shells, script interpreters, or proxy-execution binaries after a phishing or macro-enabled lure. This is a behavioral ransomware-access pattern and is not proof of INCRANSOM activity.
author: Security Arsenal
date: 2026/09/25
modified: 2026/09/25
references:
  - https://securityarsenal.com/darkside
logsource:
  product: windows
  category: process_creation
detection:
  selection_parent:
    Image|endswith:
      - '\\winword.exe'
      - '\\excel.exe'
      - '\\powerpnt.exe'
      - '\\outlook.exe'
      - '\\msaccess.exe'
      - '\\onenote.exe'
  selection_child:
    Image|endswith:
      - '\\cmd.exe'
      - '\\powershell.exe'
      - '\\pwsh.exe'
      - '\\wscript.exe'
      - '\\cscript.exe'
      - '\\mshta.exe'
      - '\\rundll32.exe'
      - '\\regsvr32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate Office add-ins, document-conversion workflows, and enterprise software installers
level: high
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059
  - attack.t1218
---
title: INCRANSOM - PsExec or WMI Remote Process Execution
id: 1f0ebf9a-9288-46b4-a7b8-997a-b4f2ab8f4d2e
status: experimental
description: Detects PsExec-style service execution and WMI-spawned command shells associated with hands-on lateral movement. Ransomware operators frequently use these mechanisms to run commands or deploy payloads across servers and workstations.
author: Security Arsenal
date: 2026/09/25
modified: 2026/09/25
references:
  - https://attack.mitre.org/techniques/T1021/002/
  - https://attack.mitre.org/techniques/T1047/
references:
  - https://securityarsenal.com/darkside
logsource:
  product: windows
  category: process_creation
detection:
  selection_psexec_image:
    Image|endswith:
      - '\\psexec.exe'
      - '\\psexesvc.exe'
      - '\\paexec.exe'
  selection_psexec_name:
    OriginalFileName:
      - PsExec
      - PSEXESVC
      - PAExec
  selection_wmi_parent:
    ParentImage|endswith:
      - '\\wmiprvse.exe'
  selection_wmi_child:
    Image|endswith:
      - '\\cmd.exe'
      - '\\powershell.exe'
      - '\\pwsh.exe'
      - '\\rundll32.exe'
      - '\\regsvr32.exe'
  condition: 1 of selection_psexec_* or (selection_wmi_parent and selection_wmi_child)
falsepositives:
  - Enterprise software deployment
  - Legitimate administrative remote execution
level: high
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1047
---
title: INCRANSOM - Archive or Cloud Sync Data Staging
id: 5be7d0ef-9c1e-4c2d-a5be-0a8e5e462e57
status: experimental
description: Detects suspicious use of archive utilities and cloud or file-transfer tools with compression, upload, copy, move, or synchronization arguments associated with pre-ransomware staging and exfiltration.
author: Security Arsenal
date: 2026/09/25
modified: 2026/09/25
references:
  - https://securityarsenal.com/darkside
logsource:
  product: windows
  category: process_creation
detection:
  selection_archive_image:
    Image|endswith:
      - '\\7z.exe'
      - '\\7za.exe'
      - '\\rar.exe'
      - '\\winrar.exe'
  selection_archive_args:
    CommandLine|contains:
      - ' a '
      - ' -p'
      - ' -v'
      - ' -m'
  selection_exfil_image:
    Image|endswith:
      - '\\rclone.exe'
      - '\\megasync.exe'
      - '\\megacmd.exe'
      - '\\filezilla.exe'
      - '\\winscp.exe'
  selection_exfil_args:
    CommandLine|contains:
      - ' copy '
      - ' move '
      - ' sync '
      - ' put '
      - '/upload'
      - '--transfers'
  condition: (selection_archive_image and selection_archive_args) or (selection_exfil_image and selection_exfil_args)
falsepositives:
  - Approved backup jobs
  - Software distribution and user-managed file transfers
level: medium
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
  - attack.t1567

The following Microsoft Sentinel query hunts Office-launched interpreters, remote execution, and archive or cloud-sync staging in one result set:

KQL — Microsoft Sentinel / Defender
let Lookback = 14d;
let ArchiveExfil = dynamic(['7z.exe', '7za.exe', 'rar.exe', 'winrar.exe', 'rclone.exe', 'megasync.exe', 'megacmd.exe', 'filezilla.exe', 'winscp.exe']);
let ScriptShell = dynamic(['cmd.exe', 'powershell.exe', 'pwsh.exe', 'wscript.exe', 'cscript.exe', 'mshta.exe', 'rundll32.exe', 'regsvr32.exe']);
let OfficeParents = dynamic(['winword.exe', 'excel.exe', 'powerpnt.exe', 'outlook.exe', 'msaccess.exe', 'onenote.exe']);
let RemoteExecution = dynamic(['psexec.exe', 'psexesvc.exe', 'paexec.exe']);
DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| extend ProcessName = tolower(FileName)
| extend ParentName = tolower(InitiatingProcessFileName)
| extend ToolClass = case(
    ProcessName in (ArchiveExfil), 'archive-or-cloud-sync-staging',
    ProcessName in (RemoteExecution), 'remote-execution-utility',
    ProcessName in (ScriptShell) and ParentName in (OfficeParents), 'office-spawned-script-shell',
    ProcessName in (ScriptShell) and ParentName in~ ('wmiprvse.exe', 'psexec.exe', 'psexesvc.exe', 'paexec.exe'), 'remote-parent-script-shell',
    '')
| where isnotempty(ToolClass)
| extend CommandLine = coalesce(ProcessCommandLine, '')
| extend HighSignalCommand = CommandLine has_any (' -accepteula', ' /accepteula', ' copy ', ' move ', ' sync ', ' a ', ' -p', ' --transfers', ' --progress')
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), ExecutionCount=count(), HighSignalCount=countif(HighSignalCommand), SampleCommands=make_set(strcat(ProcessName, ' | ', CommandLine), 5)
  by ToolClass, DeviceName, AccountName, ProcessName, ParentName
| order by HighSignalCount desc, ExecutionCount desc;

Tuning guidance:

  • Baseline approved administrators, deployment servers, backup accounts, and enterprise file-transfer tools before broad alerting.
  • Prioritize servers, executive endpoints, healthcare workstations, legal-file repositories, build systems, and hosts without approved cloud-sync software.
  • Pivot from a match to successful network connections, remote logon events, new services, and file-write volume over the following two hours.
  • Add command-line exclusions only after validating the business process and approving a named application path and account.

Run the following elevated PowerShell response script to check local RDP exposure, recently created or modified scheduled tasks, shadow-copy state, and suspicious process-audit events:

PowerShell
# Run elevated on a Windows endpoint or server. Read-only triage script.
$Start = (Get-Date).AddDays(-7)
$Root = Join-Path $env:TEMP ('INCRANSOM-RapidCheck-' + (Get-Date -Format 'yyyyMMdd-HHmmss'))
New-Item -Path $Root -ItemType Directory -Force | Out-Null

$RdpListeners = @(Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue)
$TermService = Get-Service -Name TermService -ErrorAction SilentlyContinue
$TsRegistry = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -ErrorAction SilentlyContinue
$NlaRegistry = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue
$EnabledRdpRules = @(Get-NetFirewallRule -ErrorAction SilentlyContinue | Where-Object {
    $_.Enabled -eq 'True' -and ($_.DisplayName -match 'Remote Desktop' -or $_.Name -match 'RemoteDesktop')
})

$RdpSummary = [pscustomobject]@{
    HostName = $env:COMPUTERNAME
    ListeningOn3389 = [bool]$RdpListeners
    TermServiceStatus = if ($TermService) { $TermService.Status } else { 'Not found' }
    RdpEnabled = if ($null -ne $TsRegistry.fDenyTSConnections) { $TsRegistry.fDenyTSConnections -eq 0 } else { $null }
    NetworkLevelAuthentication = if ($null -ne $NlaRegistry.UserAuthentication) { [bool]$NlaRegistry.UserAuthentication } else { $null }
    EnabledRemoteDesktopFirewallRules = $EnabledRdpRules.Count
    Note = 'A local listener does not prove Internet exposure. Correlate with perimeter NAT, VPN, and firewall policy.'
}
$RdpSummary | Export-Csv -NoTypeInformation -Path (Join-Path $Root 'rdp-exposure.csv')

$RecentTaskFiles = Get-ChildItem -Path 'C:\Windows\System32\Tasks' -File -Recurse -ErrorAction SilentlyContinue |
    Where-Object { $_.CreationTime -ge $Start -or $_.LastWriteTime -ge $Start } |
    Select-Object FullName, CreationTime, LastWriteTime, Length
$RecentTaskFiles | Export-Csv -NoTypeInformation -Path (Join-Path $Root 'scheduled-task-files-last-7-days.csv')

$ShadowCopies = Get-CimInstance -ClassName Win32_ShadowCopy -ErrorAction SilentlyContinue |
    Select-Object DeviceObject, VolumeName, InstallDate, @{
        Name = 'CreatedInLast7Days'
        Expression = { $_.InstallDate -ge $Start }
    }
$ShadowCopies | Export-Csv -NoTypeInformation -Path (Join-Path $Root 'volume-shadow-copies.csv')

$SuspiciousEvents = @()
try {
    $SuspiciousEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Security'; Id = 4688; StartTime = $Start } -ErrorAction Stop |
        Where-Object {
            $_.Message -match 'vssadmin|wbadmin|bcdedit|shadowcopy|delete shadows|psexec|rclone|megasync|7z\.exe|rar\.exe'
        } |
        Select-Object TimeCreated, Id, Message
} catch {
    Write-Warning 'Security event 4688 was unavailable. Enable process auditing and command-line capture for stronger results.'
}
$SuspiciousEvents | Export-Csv -NoTypeInformation -Path (Join-Path $Root 'suspicious-process-events-last-7-days.csv')

[pscustomobject]@{
    OutputDirectory = $Root
    RdpListening = $RdpSummary.ListeningOn3389
    RecentTaskFiles = @($RecentTaskFiles).Count
    ShadowCopiesFound = @($ShadowCopies).Count
    SuspiciousProcessEvents = @($SuspiciousEvents).Count
} | Format-List

Operational cautions:

  • The script is read-only and does not disable services or delete artifacts.
  • A public IP cannot be inferred from a local listener alone. Review NAT, VPN, firewall, cloud security-group, and remote-access gateway configuration.
  • Scheduled-task XML files record useful creation and modification times, but Security event 4698 and command-line process auditing provide stronger attribution.
  • Absence of a shadow copy does not prove deletion. Compare endpoint state with backup-platform and storage-snapshot telemetry.

Incident Response Priorities

T-minus checklist: before encryption fires

Use this checklist when a claim concerns your organization or when telemetry shows a plausible ransomware precursor.

  1. Validate the claim without contacting the actor. Preserve the listing URL, screenshot, publication timestamp, crawler record, page hash where available, and any sample-file metadata. Do not download claimed data to a production system.
  2. Review perimeter authentication. Look for impossible travel, new MFA methods, repeated failures followed by success, logons from unusual autonomous systems, dormant account use, and administrative VPN access outside maintenance windows.
  3. Check the KEV inventory. Determine whether vCenter, TeamCity, Cisco Secure FMC, Check Point gateways, or developer endpoints with Nx Console are present, reachable, patched, and logging centrally.
  4. Hunt the phishing path. Search for Office-to-script process chains, recently opened archives, downloaded macro-enabled documents, and browser downloads from low-prevalence domains.
  5. Review privileged identity activity. Identify new administrators, changed group memberships, password resets, service-account interactive logons, and recently issued cloud or VPN sessions.
  6. Look for discovery. Investigate rapid queries for domain controllers, administrators, network shares, installed backup software, virtualization inventory, and accessible remote systems.
  7. Detect lateral movement. Alert on PsExec, PAExec, unexpected Windows services, WMI-spawned shells, remote scheduled tasks, and administrative tools launched from systems that do not normally manage other hosts.
  8. Find data staging. Review large archives, encrypted archives, cloud-sync tools, unusual FTP or SFTP activity, and concentrated reads from file shares, legal repositories, HR systems, clinical applications, or source-code platforms.
  9. Inspect backup and recovery controls. Investigate shadow-copy deletion, backup-job changes, retention reduction, credential changes, snapshot deletion, and attempts to access backup consoles.
  10. Watch for control tampering. Review EDR sensor isolation, exclusions, stopped logging, disabled antivirus, deleted system logs, and unauthorized remote-management software.
  11. Correlate beacon behavior. Look for periodic outbound HTTPS or DNS, low-prevalence destinations, long-lived sessions, and outbound traffic from servers or build systems that normally have no direct Internet access.

Critical assets to prioritize for exfiltration review

The six claims do not identify what information, if any, was taken. Given INCRANSOM's double-extortion model and the claimed sector mix, prioritize:

  • Patient, clinical, insurance, billing, and employee records.
  • Legal files, privileged communications, contracts, litigation material, and client credentials.
  • Finance, payroll, HR, tax, and identity documents.
  • Intellectual property, product designs, manufacturing documentation, and supplier records.
  • Email mailboxes, executive communications, document-management systems, and collaboration platforms.
  • Source code, build secrets, deployment keys, CI/CD artifacts, and package repositories.
  • Active Directory exports, password vaults, backup catalogs, and network diagrams.
  • Virtualization inventories, snapshots, and administrative credentials.

Containment actions by urgency

  1. Isolate only the systems supported by evidence. Use EDR network isolation or switch-level controls. Avoid shutting down volatile systems before memory and triage data are collected when operationally safe.
  2. Disable or suspend suspected accounts. Revoke VPN, cloud, and SSO sessions; revoke refresh tokens; reset exposed credentials; and remove unauthorized MFA devices.
  3. Stop command-and-control and exfiltration. Block confirmed malicious destinations and unapproved transfer tools at the proxy, DNS, firewall, and cloud egress layers. Preserve logs before changing rules.
  4. Protect identity infrastructure. Restrict domain-admin use, disable stale service accounts, rotate high-risk secrets, and verify that no unauthorized federation or privileged-role changes occurred.
  5. Isolate virtualization and management planes. Separate vCenter, backup consoles, firewall managers, CI/CD systems, and remote-management tools from ordinary administrative access.
  6. Protect backups. Confirm offline or immutable copies, restrict deletion rights, verify retention, and test a representative restore before broad recovery.
  7. Preserve evidence. Collect process, memory, registry, scheduled-task, service, PowerShell, VPN, firewall, EDR, identity, and cloud logs. Maintain chain of custody for potentially regulated or litigated material.
  8. Activate legal, privacy, communications, and executive workflows. Do not characterize a criminal claim as a breach before investigation supports that conclusion, but preserve any deadlines that may apply if evidence later confirms reportable access or acquisition.
  9. Eradicate before reconnecting. Remove persistence and unauthorized tools, patch exploited services, rotate credentials in the correct sequence, and monitor for re-entry before restoring broad connectivity.
  10. Monitor for renewed pressure. Watch for leak-site changes, duplicate postings, contact with employees or customers, and data appearing on third-party services.

Hardening Recommendations

Immediate: next 24 hours

  • Inventory and remediate the five KEV exposures. Patch or isolate affected vCenter, TeamCity, Cisco Secure FMC, Check Point gateway, and Nx Console installations. If patching is not immediately possible, restrict management access and add compensating monitoring.
  • Disable direct Internet RDP. Require VPN or zero-trust access, MFA, device compliance, least privilege, and jump-host mediation. Block inbound 3389 at the perimeter.
  • Strengthen remote-access authentication. Enforce phishing-resistant MFA for administrators where possible, remove stale VPN accounts, disable shared credentials, and revoke long-lived sessions.
  • Restrict Office macro execution. Block Internet-marked macros, enforce attack-surface-reduction rules, and alert on Office applications spawning shells or script interpreters.
  • Control staging and transfer tools. Block or require approval for rclone, MEGA tools, unmanaged FTP clients, and nonstandard archive utilities on servers and sensitive endpoints.
  • Alert on lateral movement. Enable process command-line auditing, service-install auditing, WMI logging, PowerShell logging, and detections for PsExec-style execution.
  • Protect EDR and logging. Enable tamper protection, restrict local administrator counts, centralize logs off the endpoint, and alert when sensors or log services stop.
  • Protect backups. Verify immutable or offline copies, separate backup credentials, prevent ordinary administrators from deleting retention, and test one critical restore.
  • Monitor the leak-site claim carefully. Preserve evidence, designate a single intelligence owner, and avoid public conclusions while verification is under way.

Short term: next two weeks

  • Segment management planes. Place vCenter, backup systems, security consoles, CI/CD platforms, and firewall managers in dedicated administrative zones reachable only through monitored privileged-access workstations.
  • Implement tiered administration. Separate domain, server, workstation, cloud, and backup administration. Remove routine domain-admin use and enforce just-in-time elevation.
  • Reduce standing privileges. Deploy privileged-access management, unique local administrator passwords, short-lived administrative credentials, and approval workflows.
  • Control egress. Default-deny server Internet access where practical, require authenticated proxy access, inspect newly observed cloud-storage destinations, and alert on unusual transfer volume.
  • Harden identity. Expand conditional access, block legacy authentication, monitor token theft indicators, and protect help-desk reset and MFA-enrollment workflows.
  • Secure development infrastructure. Isolate build agents, rotate CI/CD secrets, sign artifacts, control package sources, and monitor developer tools such as TeamCity and Nx Console for unauthorized changes.
  • Create authoritative asset-to-owner mappings. Ensure every internet-facing system has an owner, patch status, business purpose, data classification, logging source, and recovery priority.
  • Validate detection content. Test the Sigma, KQL, and PowerShell controls in a lab, tune approved administrative paths, and add high-fidelity results to SOC triage playbooks.
  • Exercise double-extortion response. Include legal, privacy, communications, executive leadership, cyber-insurance contacts, and forensic providers in a scenario based on an unverified leak-site claim.
  • Measure recovery, not just prevention. Track restoration time for identity, virtualization, file services, clinical or legal repositories, and manufacturing systems under a scenario in which both encryption and publication pressure occur.

Related Resources

Security Arsenal Incident Response

Managed SOC & MDR Services

AlertMonitor Threat Detection

From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.