Publication date: 2026-08-17
Intelligence cut-off: Dark web leak-site posts observed through 2026-08-16
Confidence: High on victim posting metadata; moderate on victimology inference; low-to-moderate on direct CVE attribution to this specific victim set.
Executive assessment
MEDUSALOCKER's leak site showed a concentrated burst of five new victim posts on 2026-08-16 spanning Technology, Retail & E-Commerce, Manufacturing and Transportation across GB, DE, FR and ZA. The cadence—multiple posts inside a 24-hour window across four countries—fits an affiliate-driven RaaS operation monetizing access obtained from edge-device exploitation, exposed RDP/VPN, phish-to-loader chains, or purchased access rather than a single vertically targeted intrusion.
Security teams in the affected sectors should treat the next 72 hours as an elevated pre-ransomware window: validate edge patch posture against the KEVs below, hunt for PsExec/WMI/SMB admin-share staging, verify immutable backup separation, and pre-authorize containment actions for identity and backup infrastructure.
Threat Actor Profile — MEDUSALOCKER
Known aliases / naming confusion: MedusaLocker, MedusaLocker RaaS. Do not conflate with the separate MEDUSA ransomware operation; tooling, leak branding and affiliate ecosystems differ. Track by behaviors and binaries, not name alone.
Operating model: Historically assessed as Ransomware-as-a-Service (RaaS) with a core operator maintaining payload, negotiation and leak infrastructure while affiliates handle intrusion, privilege escalation, exfiltration and detonation. Affiliate quality varies; intrusion signatures can therefore be heterogeneous across campaigns.
Typical ransom economics: Demands are commonly scaled to victim size and perceived cyber-insurance posture, frequently landing in the mid-five to seven-figure USD equivalent range for SMB-to-midmarket victims, with separate pressure applied for data non-publication. Exact demands are negotiated privately; treat any public “sample demand” as indicative only.
Initial access methods observed across the ecosystem:
- Phishing with malicious attachments/links leading to loaders or script-based execution.
- Exposed or weakly authenticated RDP, including brute force, credential stuffing and valid-account abuse.
- VPN / firewall / remote access edge exploitation; validate against current KEV items, especially perimeter auth bypass and remote-management-tool flaws.
- Remote monitoring and management (RMM) abuse and unmanaged service-provider pathways.
- Supply-chain or developer-tool compromise where trusted update channels are abused.
Extortion approach: Double extortion is standard: encrypt locally and threaten publication of stolen data on the leak site. In some intrusions, data theft is the only lever if encryption is blocked late.
Dwell time: Commonly days to a few weeks depending on affiliate discipline and environment visibility. Fast-turn cases exist where edge exploitation converts to encryption within 24–72 hours; slower cases include staging, credential harvesting, backup discovery and selective exfiltration.
Operator behaviors worth hunting:
- Discovery:
net,nltest,arp,ipconfig,wmic,quser, BloodHound/SharpHound-like collection. - Credential access: LSASS memory access,
procdump,comsvcs.dll MiniDump, DCSync against domain controllers. - Lateral movement: PsExec-style service creation, WMI process call create, SMB ADMIN$ writes, RDP from server-to-server, scheduled tasks.
- Defense evasion: clearing logs, disabling security services, deleting shadow copies via
vssadmin,wmic shadowcopy,bcdeditrecovery changes. - Impact: mass file encryption, ransom notes dropped broadly, service/database/process kill lists, occasional safe-mode execution attempts.
Current Campaign Analysis
Recent leak-site postings
| Victim | Sector | Country | Published | Notes for defenders |
|---|---|---|---|---|
| Twal Family IT Lab | Technology | ? | 2026-08-16 | Unknown geography increases likelihood of global/customer impact; verify downstream clients. |
| All Parts Dry Cleaning | Retail & E-Commerce | GB | 2026-08-16 | Likely SMB; POS/back-office and franchise data exposure possible. |
| Idex Group | Technology | DE | 2026-08-16 | Technology victims create third-party and managed-service blast-radius risk. |
| Bija Industrie | Manufacturing | FR | 2026-08-16 | OT adjacency possible; prioritize segmentation and engineering workstation telemetry. |
| Thecourierguy | Transportation | ZA | 2026-08-16 | Logistics disruption risk; monitor dispatch, TMS, customer PII and shipment data. |
Sector targeting
The current cluster is deliberately cross-sector, which is typical of affiliate-led RaaS monetization rather than a narrowly strategic campaign. Technology and transportation are notable because they create cascade risk: IT labs/technology firms may hold client access or code artifacts; transportation/logistics victims carry operational downtime pressure that increases payment likelihood.
Retail/e-commerce and manufacturing postings suggest opportunistic conversion of accessible SMB/midmarket networks where perimeter hygiene, EDR coverage and backup immutability are inconsistent.
Geographic concentration
Posts span GB, DE, FR and ZA in one day. This is not a localized European campaign; it is an access-availability campaign. Prioritize external attack surface validation regardless of HQ location, especially organizations with multilingual phishing exposure, regional MSP dependencies, or flat inter-site connectivity.
Victim profile
Based on named-victim visibility and sector norms, the cluster skews toward SMB to midmarket organizations—roughly tens to low-thousands of employees and revenue from under $10M to low hundreds of millions—where a single successful edge or identity compromise can become enterprise-wide quickly. Larger enterprises should not dismiss this: affiliates frequently use smaller victims as access brokers into partners, customers and suppliers.
Posting frequency / escalation pattern
Five posts on 2026-08-16 after a low recent count indicates either synchronized leak publication, a backlog release after negotiation deadlines, or an affiliate push to demonstrate momentum. A 24-hour multi-victim drop often precedes additional posts within 3–10 days as negotiation timers expire. Escalation indicators to watch: repeated posts naming subsidiaries, “sample data” archives, countdown timers, and sector-jumping posts that imply purchased access inventory being cleared.
CVE connection — plausible initial access, not proven per-victim
The following CISA KEV entries are confirmed exploited and ransomware-relevant, but there is no public evidence tying each named victim to a specific CVE from the leak metadata alone. Treat these as priority patch/validation candidates for similarly exposed environments:
- CVE-2026-50751 — Check Point Security Gateway improper authentication in IKEv1 key exchange. Perimeter auth weaknesses are classic ransomware entry points. Validate gateways, remote access VPN, logs for anomalous IKEv1 negotiation, and new local/admin accounts after patch windows.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer-tool supply-chain risk can seed access through build agents, IDE extensions or poisoned packages. Audit developer workstations, CI runners and package provenance.
- CVE-2024-1708 — ConnectWise ScreenConnect path traversal / RCE. RMM exploitation remains a high-fidelity ransomware precursor. Hunt for unauthorized ScreenConnect instances, unexpected service installs, and RMM-to-server lateral movement.
- CVE-2025-60710 — Microsoft Windows link following privilege escalation. Post-compromise elevation can convert a phished user into local admin. Pair with EDR process ancestry and tamper events.
- CVE-2023-21529 — Microsoft Exchange deserialization of untrusted data. Authenticated Exchange RCE can bridge email compromise to domain foothold. Verify Exchange patch level, IIS webshell indicators and abnormal mailbox/export activity.
Analytic caveat: Do not wait for attribution. If any of these products are internet-facing or broadly deployed, assume exploit attempts are commodity and hunt as if access has already been sold to an affiliate.
Detection Engineering
The detections below target MEDUSALOCKER-style behaviors rather than a single hash: edge/remote-access misuse, phishing execution, PsExec/WMI lateral movement, pre-encryption staging and backup tampering. Tune thresholds to baseline admin tooling, RMM and service accounts.
---
title: MEDUSALOCKER - Suspicious RDP or VPN Initial Access Followed by Admin Share Staging
id: 4d6b1a2e-7c41-4a6b-9a2a-medusalocker-rdp-vpn-001
status: experimental
description: Detects remote access logon anomalies followed by SMB ADMIN$ writes or service creation consistent with ransomware affiliate staging after RDP/VPN/edge access.
references:
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://attack.mitre.org/techniques/T1133/
- https://attack.mitre.org/techniques/T1021/001/
- https://attack.mitre.org/techniques/T1021/002/
author: Security Arsenal Dark Side Intel
date: 2026/08/17
modified: 2026/08/17
logsource:
category: network_connection
product: windows
detection:
selection_remote:
EventID:
- 4624
- 4625
LogonType:
- 3
- 10
IpAddress|contains:
- 'vpn'
- 'rdp'
- 'gateway'
selection_admin:
EventID: 5145
Share_Name|contains:
- 'ADMIN$'
- 'C$'
Relative_Target_Name|endswith:
- '.exe'
- '.bat'
- '.ps1'
timeframe: 30m
condition: selection_remote and selection_admin
falsepositives:
- Legitimate administrative software distribution, patch management and RMM tools.
level: high
tags:
- attack.initial_access
- attack.lateral_movement
- attack.t1133
- attack.t1021.001
- attack.t1021.002
---
title: MEDUSALOCKER - PsExec or WMI Lateral Movement With Remote Service Creation
id: 8c9f0d22-1b7a-4f53-9d7e-medusalocker-psexec-wmi-002
status: experimental
description: Detects PsExec-like service installation, WMI remote process creation, or suspicious 7045 service events used for ransomware spread and pre-encryption staging.
references:
- https://attack.mitre.org/techniques/T1569/002/
- https://attack.mitre.org/techniques/T1047/
- https://attack.mitre.org/techniques/T1053/005/
author: Security Arsenal Dark Side Intel
date: 2026/08/17
modified: 2026/08/17
logsource:
category: process_creation
product: windows
detection:
selection_psexec:
Image|endswith:
- '\psexec.exe'
- '\psexesvc.exe'
- '\paexec.exe'
- '\remcom.exe'
selection_wmi:
ParentImage|endswith: '\wmiprvse.exe'
CommandLine|contains:
- 'cmd.exe'
- 'powershell.exe'
- 'rundll32.exe'
- 'mshta.exe'
- 'regsvr32.exe'
selection_service:
EventID: 7045
Service_Name|contains:
- 'PSEXESVC'
- 'PAExec'
- 'RemCom'
- 'tmp'
- 'svc'
Service_File_Name|contains:
- 'ADMIN$'
- '\Temp\'
- '\Users\Public\'
condition: 1 of selection_*
falsepositives:
- Enterprise systems management, software deployment and IR tooling. Allow-list by service account and management host.
level: critical
tags:
- attack.lateral_movement
- attack.execution
- attack.t1569.002
- attack.t1047
- attack.t1053.005
---
title: MEDUSALOCKER - Pre-Encryption Backup Tampering and Mass Staging Indicators
id: 2f7aa410-9d8c-4a11-b4f1-medusalocker-backup-tamper-003
status: experimental
description: Detects shadow copy deletion, recovery option tampering, security-service disabling and archive staging frequently observed before ransomware detonation.
references:
- https://attack.mitre.org/techniques/T1490/
- https://attack.mitre.org/techniques/T1562/001/
- https://attack.mitre.org/techniques/T1074/001/
- https://attack.mitre.org/techniques/T1041/
author: Security Arsenal Dark Side Intel
date: 2026/08/17
modified: 2026/08/17
logsource:
category: process_creation
product: windows
detection:
selection_shadow:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'vssadmin Delete Shadows'
- 'wmic shadowcopy delete'
- 'bcdedit /set'
- 'recoveryenabled no'
- 'bootstatuspolicy ignoreallfailures'
selection_defense:
CommandLine|contains:
- 'sc stop'
- 'sc config'
- 'net stop'
- 'taskkill /f /im'
- 'Set-MpPreference -DisableRealtimeMonitoring'
- 'Add-MpPreference -ExclusionPath'
selection_stage:
Image|endswith:
- '\7z.exe'
- '\rar.exe'
- '\winrar.exe'
- '\robocopy.exe'
- '\rclone.exe'
- '\mega.exe'
- '\filezilla.exe'
CommandLine|contains:
- ' a '
- ' archive'
- ' -r'
- ' /mir'
- ' sync'
- ' copy'
condition: selection_shadow or (selection_defense and selection_stage)
falsepositives:
- Backup administrators, legitimate archiving, endpoint migrations. Correlate with host role, user, parent process and whether activity is concentrated across servers.
level: critical
tags:
- attack.defense_evasion
- attack.impact
- attack.exfiltration
- attack.t1490
- attack.t1562.001
- attack.t1074.001
- attack.t1041
// Microsoft Sentinel — MEDUSALOCKER-style lateral movement & pre-ransomware staging hunt
// Lookback: 14d. Tune allowlists for RMM, SCCM, service accounts and management hosts.
let Lookback = 14d;
let SuspiciousTools = dynamic(["psexec.exe","psexesvc.exe","paexec.exe","remcom.exe","rclone.exe","7z.exe","rar.exe","robocopy.exe","procdump.exe","comsvcs.dll","sharphound.exe","bloodhound.exe"]);
let TamperCmd = dynamic(["vssadmin delete shadows","wmic shadowcopy delete","recoveryenabled no","bootstatuspolicy ignoreallfailures","Set-MpPreference -DisableRealtimeMonitoring","Add-MpPreference -ExclusionPath"]);
let AdminHosts = dynamic(["mgmt-01","sccm-01","jump-01"]); // replace with approved management hosts
let ServiceAccounts = dynamic(["svc_sccm","svc_rmm","svc_backup"]); // replace with approved accounts
union isfuzzy=true
(
DeviceProcessEvents
| where Timestamp >= ago(Lookback)
| extend FileLower = tolower(FileName), CmdLower = tolower(ProcessCommandLine), InitLower = tolower(InitiatingProcessFileName)
| where FileLower in~ (SuspiciousTools)
or InitLower in~ (SuspiciousTools)
or CmdLower has_any (TamperCmd)
or (InitLower == "wmiprvse.exe" and FileLower in~ dynamic(["cmd.exe","powershell.exe","rundll32.exe","mshta.exe","regsvr32.exe"]))
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteDeviceName, SHA256
)
,
(
DeviceEvents
| where Timestamp >= ago(Lookback)
| where ActionType has_any ("ServiceInstalled","ScheduledTaskCreated","LogonFailed","LogonSucceeded","RemoteConnection")
| extend Addl = tostring(parse_json(AdditionalFields))
| where Addl has_any ("PSEXESVC","PAExec","RemCom","ADMIN$","C$","RDP","TermService","ScreenConnect")
| project Timestamp, DeviceName, ActionType, AccountName, RemoteDeviceName, AdditionalFields
)
,
(
DeviceNetworkEvents
| where Timestamp >= ago(Lookback)
| where RemotePort in (3389,445,135,5985,5986,22) or LocalPort in (3389,445,135,5985,5986)
| extend FileLower = tolower(InitiatingProcessFileName)
| where FileLower !in~ dynamic(["lsass.exe","svchost.exe","system","msiexec.exe"])
or InitiatingProcessAccountName !in~ ServiceAccounts
| summarize Connections=count(), UniqueTargets=dcount(RemoteIP), Ports=make_set(RemotePort) by DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName, bin(Timestamp, 1h)
| where UniqueTargets >= 5
)
| where DeviceName !in~ AdminHosts and AccountName !in~ ServiceAccounts
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Hits=count(), Devices=make_set(DeviceName), Accounts=make_set(AccountName), Files=make_set(FileName), CmdSample=make_set(ProcessCommandLine, 5)
by FileName, InitiatingProcessFileName
| order by Hits desc;
# Rapid MEDUSALOCKER pre-ransomware triage — run elevated on suspected servers/DCs/backup hosts.
# Outputs artifacts to C:\IR\MedusaLocker-Triage-<host>-<timestamp> for SOC handoff.
$Out = Join-Path "C:\IR" ("MedusaLocker-Triage-{0}-{1}" -f $env:COMPUTERNAME, (Get-Date -Format yyyyMMdd-HHmmss))
New-Item -ItemType Directory -Path $Out -Force | Out-Null
Write-Host "[1/7] RDP exposure & recent interactive/network logons" -ForegroundColor Cyan
Get-NetTCPConnection -State Listen -ErrorAction SilentlyContinue | Where-Object LocalPort -in 3389,5985,5986,445,135 | Select-Object LocalAddress,LocalPort,OwningProcess | Export-Csv "$Out\listeners.csv" -NoTypeInformation
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624,4625; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Where-Object {$_.Message -match 'Logon Type:\s+(3|10)'} | Select-Object TimeCreated,Id,Message | Export-Csv "$Out\rdp_network_logons_7d.csv" -NoTypeInformation
Write-Host "[2/7] New services, scheduled tasks, Run keys (last 7 days)" -ForegroundColor Cyan
Get-CimInstance Win32_Service | Where-Object {$_.InstallDate -and $_.InstallDate -gt (Get-Date).AddDays(-7)} | Select-Object Name,PathName,StartName,State,InstallDate | Export-Csv "$Out\new_services_7d.csv" -NoTypeInformation
Get-ScheduledTask | Where-Object {$_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7)} | ForEach-Object { [pscustomobject]@{TaskName=$_.TaskName; TaskPath=$_.TaskPath; Date=$_.Date; Author=$_.Author; Actions=($_.Actions | Out-String); Triggers=($_.Triggers | Out-String)} } | Export-Csv "$Out\new_tasks_7d.csv" -NoTypeInformation
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' | ForEach-Object { Get-ItemProperty $_ -ErrorAction SilentlyContinue } | Export-Csv "$Out\run_keys.csv" -NoTypeInformation
Write-Host "[3/7] Shadow copies and recovery tamper signals" -ForegroundColor Cyan
(& vssadmin list shadows) 2>$null | Out-File "$Out\vss_shadows.txt"
(& bcdedit /enum) 2>$null | Out-File "$Out\bcdedit.txt"
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7036,7045,7040; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue | Select-Object TimeCreated,Id,ProviderName,Message | Export-Csv "$Out\service_events_7d.csv" -NoTypeInformation
Write-Host "[4/7] Suspicious tool execution & staging paths" -ForegroundColor Cyan
$Tools = 'psexec|psexesvc|paexec|remcom|rclone|7z\.exe|rar\.exe|robocopy|procdump|sharphound|bloodhound|megacmd|filezilla'
Get-CimInstance Win32_Process | Where-Object {$_.Name -match $Tools -or $_.CommandLine -match $Tools} | Select-Object ProcessId,Name,CommandLine,CreationDate,ParentProcessId | Export-Csv "$Out\suspicious_processes_now.csv" -NoTypeInformation
Get-ChildItem "$env:PUBLIC","$env:TEMP","C:\ProgramData" -Recurse -ErrorAction SilentlyContinue -Include *.zip,*.7z,*.rar,*.exe,*.ps1,*.bat | Where-Object {$_.LastWriteTime -gt (Get-Date).AddDays(-3)} | Select-Object FullName,Length,LastWriteTime | Export-Csv "$Out\recent_staging_files.csv" -NoTypeInformation
Write-Host "[5/7] LSASS protection & credential-theft risk" -ForegroundColor Cyan
Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -ErrorAction SilentlyContinue | Select-Object RunAsPPL,RunAsPPLBoot,AuditLevel | Export-Csv "$Out\lsa_protection.csv" -NoTypeInformation
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=10; StartTime=(Get-Date).AddDays(-3)} -ErrorAction SilentlyContinue | Where-Object {$_.Message -match 'lsass.exe'} | Select-Object TimeCreated,Message | Export-Csv "$Out\sysmon_lsass_access.csv" -NoTypeInformation
Write-Host "[6/7] Defender/EDR tamper indicators" -ForegroundColor Cyan
Get-MpPreference -ErrorAction SilentlyContinue | Select-Object DisableRealtimeMonitoring,ExclusionPath,ExclusionProcess,DisableBehaviorMonitoring,DisableIOAVProtection | Export-Csv "$Out\defender_pref.csv" -NoTypeInformation
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Windows Defender/Operational'; Id=5007,5001,5004; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue | Select-Object TimeCreated,Id,Message | Export-Csv "$Out\defender_tamper_7d.csv" -NoTypeInformation
Write-Host "[7/7] Edge/RMM artifacts to verify against approved inventory" -ForegroundColor Cyan
Get-CimInstance Win32_Product -ErrorAction SilentlyContinue | Where-Object {$_.Name -match 'ScreenConnect|ConnectWise|AnyDesk|TeamViewer|Splashtop|Atera|Ninja|Check Point|Nx Console|Exchange'} | Select-Object Name,Vendor,Version,InstallDate | Export-Csv "$Out\edge_rmm_inventory.csv" -NoTypeInformation
Get-ChildItem 'C:\Program Files','C:\Program Files (x86)' -Directory -ErrorAction SilentlyContinue | Where-Object Name -match 'ScreenConnect|ConnectWise|AnyDesk|TeamViewer|Splashtop|Atera|Ninja' | Select-Object FullName,CreationTime,LastWriteTime | Export-Csv "$Out\rmm_dirs.csv" -NoTypeInformation
Compress-Archive -Path "$Out\*" -DestinationPath "$Out.zip" -Force
Write-Host "Done. Collect $Out.zip and escalate if new services/tasks, shadow deletion, LSASS access, or mass ADMIN$ writes are present." -ForegroundColor Green
Incident Response Priorities
T-minus detection checklist — before encryption fires
- Perimeter conversion: New VPN/firewall local admin, IKE/IPSec anomalies, RMM install outside change window, Exchange IIS worker process spawning
cmd/powershell, developer tool update outside approved channel. - Identity pivot: DCSync (directory replication) from non-DC, abnormal Kerberos ticket volume, protected-users group changes, sudden privileged group additions, failed logons spraying multiple hosts followed by one success.
- Lateral movement concentration: One workstation/server initiating SMB/RDP/WinRM to many hosts; service creation events clustered by source; ADMIN$ writes outside deployment windows;
wmiprvse.exespawning shells on servers. - Staging and exfil: Compression tools in user profiles/Public/ProgramData,
rclone/MEGA/FileZilla on servers, large outbound transfers to rare ASNs, archive names referencing finance/HR/legal/backups. - Backup targeting: Shadow copy deletion, recovery disabled, backup catalog queries, backup admin credential use from unusual hosts, NAS/iSCSI immutable snapshot deletions.
- Tamper surge: Defender exclusions added, EDR service stops, log clearing, Sysmon config change, safe-boot modification, service kill lists touching databases and backup agents.
Critical assets this gang historically pressures
- Domain controllers, identity providers and privileged access management.
- Backup servers, snapshots, NAS/object storage and recovery keys.
- File shares with finance, HR, legal, customer PII, contracts and payroll.
- Databases and line-of-business systems whose downtime forces payment.
- Email/Exchange archives for negotiation leverage and proof-of-theft.
- Technology/logistics victims: client lists, code, dispatch/TMS data, shipment manifests and partner credentials.
Containment actions ordered by urgency
- Isolate identity and backup control planes: Disable suspicious privileged sessions, reset exposed credentials in staged order, protect DCs/backup consoles from non-management hosts, freeze new GPO/service-account creation.
- Cut lateral movement: Temporarily restrict SMB/WinRM/RDP server-to-server, block PsExec-like service creation via EDR policy, quarantine hosts with multi-target connection bursts.
- Preserve encryption-prevention evidence: Capture memory on high-value suspects before reboot, export Security/System/Sysmon/Defender logs, snapshot volatile network connections and process trees.
- Protect recoverability: Verify offline/immutable copies are intact, rotate backup credentials, pause vulnerable replication jobs that could propagate encrypted data, test a restore of one critical system.
- External path closure: Patch or mitigate listed KEVs, disable exposed RDP, enforce VPN MFA and device posture, remove unauthorized RMM, review Exchange/IIS and developer toolchain integrity.
- Exfiltration throttling: Egress filtering by process/destination, block consumer file-transfer domains on servers, alert on large outbound flows from non-proxy hosts.
- Communications decision: Prepare legal, insurance, regulator and customer notification paths; assume leak-site publication is time-boxed and do not rely on negotiation delay as containment.
Hardening Recommendations
Immediate — next 24 hours
- Patch or apply vendor mitigations for CVE-2026-50751, CVE-2026-48027, CVE-2024-1708, CVE-2025-60710, CVE-2023-21529; if patching is blocked, restrict exposure, add virtual patching/WAF/VPN ACLs and increase logging.
- Disable internet-facing RDP; require VPN + MFA + device compliance; enable account lockout and geo/impossible-travel alerts.
- Remove or inventory all RMM tooling; block unauthorized RMM binaries by hash/signature/path and alert on ScreenConnect artifacts.
- Enforce LSASS protection (RunAsPPL), Credential Guard where supported, and block
procdump/unsigned access to LSASS. - Lock down PsExec/WMI: restrict service creation to approved management accounts/hosts, enable Windows Firewall rules for server-to-server SMB/RPC, deploy the Sigma/KQL above.
- Protect backups: verify immutability, separate credentials, disable interactive logon on backup servers, alert on shadow copy deletion and
bcdeditrecovery changes. - Add pre-detonation tripwires: canary shares/files, decoy credentials, alerts on archive creation in Public/ProgramData, and egress thresholds on servers.
Short-term — next 2 weeks
- Segment by identity and data criticality: tiered admin model, PAWs, just-in-time admin, DC isolation, backup network with deny-all except brokered jobs.
- Move from perimeter trust to explicit allow paths: ZTNA/app-proxy for admin access, certificate-based device trust, continuous evaluation for VPN sessions.
- Implement application control for servers (WDAC/AppLocker) with managed installer rules for RMM/deployment tools; block script interpreters from email and browser ancestry where feasible.
- Harden email-to-execution: strip/rewrite active content, block macros by default, detonate attachments, alert on Office spawning
powershell,mshta,rundll32. - Establish immutable recovery and rehearsal: offline copy, object-lock snapshots, restore runbooks, quarterly ransomware game-day, backup control-plane break-glass account stored securely.
- Improve supply-chain assurance for developer tools and RMM: signed package verification, private registry/proxy, SBOM monitoring, CI runner isolation and egress controls.
- Operationalize leak-site monitoring for your brands, subsidiaries and key suppliers; trigger IR tabletop if posted even before encryption telemetry confirms scope.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.