The DFIR Report Real Intrusions

Real Intrusions by Real Attackers, The Truth Behind the Intrusion.

The DFIR Report Actionable Cyber Threat Intelligence

  • From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
    by editor on June 29, 2026 at 1:07 pm

    Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs The post From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.

  • Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
    by editor on May 11, 2026 at 2:05 pm

    The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

  • Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
    by editor on April 22, 2026 at 2:51 pm

    Key Takeaways We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator’s day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. This AI-assisted workflow resulted in the modular platform Bissa scanner The post Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting appeared first on The DFIR Report.

  • Apache ActiveMQ Exploit Leads to LockBit Ransomware
    by editor on February 23, 2026 at 2:09 pm

    Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon.  This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring The post Apache ActiveMQ Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.

  • Cat’s Got Your Files: Lynx Ransomware
    by editor on December 17, 2025 at 7:07 pm

    Key Takeaways The DFIR Report Services Contact us today for pricing or a demo! The intrusion began in early March 2025 with a single successful Remote Desktop Protocol (RDP) logon to an internet-exposed system. Notably, there was no evidence of credential stuffing, brute forcing, or other failed authentication attempts from the source IP, indicating the The post Cat’s Got Your Files: Lynx Ransomware appeared first on The DFIR Report.

  • From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
    by editor on September 29, 2025 at 2:30 pm

    Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually.   Contact us today for pricing or a demo!   Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK   Case Summary The intrusion The post From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion appeared first on The DFIR Report.

  • Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
    by editor on September 8, 2025 at 2:20 pm

    Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in The post Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs appeared first on The DFIR Report.

  • Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
    by editor on August 5, 2025 at 9:30 pm

    Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May of 2025 Cyjax reported on a campaign using this method again, impersonating various IT tools. We observed a similar campaign in The post Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.

  • KongTuke FileFix Leads to New Interlock RAT Variant
    by editor on July 14, 2025 at 12:50 am

    Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.

  • Hide Your RDP: Password Spray Leads to RansomHub Deployment
    by editor on June 30, 2025 at 12:20 am

    Key Takeaways Case Summary This intrusion began in November 2024 with a password spray attack targeting an internet-facing RDP server. Over the course of several hours, the threat actor attempted logins against multiple accounts using known malicious IPs (based on OSINT). Several hours later they then logged in via RDP with one of the previously The post Hide Your RDP: Password Spray Leads to RansomHub Deployment appeared first on The DFIR Report.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.