The Weaponization of Active Directory: An Inside Look at Ransomware Attacks Ryuk, Maze, and SaveTheQueen
semperis.com | incident | #active-directory | #ransomware | #bloodhound | #zerologon | #maze | #ryuk
Summary
How Ryuk, Maze and SaveTheQueen weaponized Active Directory: human-operated campaigns chain TrickBot/Emotet loaders into Cobalt Strike, then use BloodHound/SharpHound and Mimikatz for AD recon and credential theft—against the Zerologon backdrop.
- Published
- Collected
Skip to content