Between July 24-31, 2024, Blackpoint’s Security Operations Center (SOC) responded to 84 total incidents. These incidents included 15 on-premises MDR incidents, 1 Cloud Response for Google Workspace, and 68 Cloud Response for Microsoft 365 incidents, with confirmed or likely threat actor use of:
- Unnamed infostealer malware for collection and exfiltration;
- Vanilla Tempest using Oyster Backdoor for persistence; and
- NetSupport RAT for persistence.
In this blog, we’ll dive into the details behind these select incidents, including why they’re important for partners to account for today – even if they’ve not been attacked yet! – as well as possible mitigations leveraging your current tech stack and Blackpoint Cyber.