💰💣
IronNet Security Incident
2021
1725 days ago
Resolved
Incident Overview
Situation Description
IronNet's threat research teams analyzed how their behavioral analytics detect intrusions by the REvil and Conti ransomware groups, which leveraged the IcedID trojan.
Event Types
Ransomware
Malware / Destructive Attack
Industry Sector
nanGeographic Scope
GlobalResponse Actions
Conducted Threat Hunting & Eradication
Impact Analysis
Event Types (2 identified)
Ransomware
Malware / Destructive Attack
Financial Impact
$0 USDRecords Affected
0Data Types Compromised
Credentials
Intellectual Property
Primary Impacts
Operational Disruption
Data Exposure
Key Decisions Made
IronNet replayed intrusions in their proprietary testing environment to test how IronDefense and behavioral analytics detect malicious activity by REvil and Conti.; IronNet's behavioral analytics detected REvil's network traversal, including initial compromise via malspam, IcedID execution, Cobalt Strike beaconing, lateral movement, credential dumping, and data exfiltration.; IronNet's behavioral analytics detected Conti's network traversal, including initial compromise via phishing, IcedID execution, Cobalt Strike beaconing, domain enumeration, privilege escalation, lateral movement, and ransomware deployment.
Technical Analysis
Attack Method
Phishing
Threat Actor Attribution
REvil
Conti
Vulnerability / Tool
IcedID
Cobalt Strike
Additional Information
Quick Facts
- Company:
- IronNet
- Date:
- 2021
- Status:
- Resolved
- Decision Maker:
- IronNet Threat Analysis and Research Teams
- Position:
- nan
- Published:
- 16/11/2021
Source Information
Original Query
JBS Foods ransomware incident response communication strategy analysisTimeline
Information Published
16/11/2021
Incident Occurred
2021 (1725 days ago)
Status: Resolved
Estimated resolution based on age