Makop勒索病毒攻击
#勒索病毒 #Makop #Ransomware
Makop勒索病毒攻击
Key Takeaways Case Summary The intrusion started with the exploitation of CVE-2023-22527, a critical remote code execution vulnerability in Confluence, against a Windows server. The first indication of threat actor activity was the execution of system discovery commands, including net user and whoami. Shortly after, the threat actor attempted to download AnyDesk via curl, but […]
The post Confluence Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.