Between May 01-08, 2024, Blackpoint’s Active Security Operations Center (SOC) responded to 117 total incidents. These incidents included 18 on-premises MDR incidents, 2 Cloud Response for Google Workspace, and 97 Cloud Response for Microsoft 365 incidents, with confirmed or likely threat actor use of:
- RDP and net.exe for discovery and lateral movement;
- NetSupport RAT for persistence, as well as command and control (C2); and
- Vssadmin, RDP, and attempted deletion of Blackpoint canary files for lateral movement and defense evasion during Devos ransomware incident.
In this blog, we’ll dive into the details behind these select incidents, including why they’re important for partners to account for today – even if they’ve not been attacked yet! – as well as possible mitigations leveraging your current tech stack and Blackpoint Cyber.