Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The Weaponization of Active Directory: An Inside Look at Ransomware Attacks Ryuk, Maze, and SaveTheQueen

Summary

How Ryuk, Maze and SaveTheQueen weaponized Active Directory: human-operated campaigns chain TrickBot/Emotet loaders into Cobalt Strike, then use BloodHound/SharpHound and Mimikatz for AD recon and credential theft—against the Zerologon backdrop.
Published
Collected

original ↗