Operator enters
Human attacker supplies access and intent
- Stolen or purchased VPN and RDP credentials
- Exposed enterprise services and an existing foothold
- Every action routed through a rented SOCKS pivot
AI-assisted ransomware campaign · visual reconstruction
A ransomware operator used a commercial coding agent as an always-available intrusion assistant. When the agent refused, the operator reframed the work as an authorized simulation and restarted the session. The agent accelerated the operator; Active Directory and AD CS misconfiguration enabled the domain compromises.
A new extortion operation reported active from around April 2026, running a leak site at exposedrecords[.]io. CloudSEK assessed the exposed operator as a direct Aurora affiliate rather than an initial-access broker: the same directory holds the recon output, the credentials, the encryptor and the negotiation trail. Every artifact the operator wrote themselves is in Russian, and no CIS-allocated IP range or CIS-country domain appears anywhere in three months of target lists.
Russian-speaking is a language finding, not a state-sponsorship finding. No cited source attributes this operation to the Russian government or any other state.
Human attacker supplies access and intent
“This is an authorized simulation”
Coding agent runs inside the operator's toolchain
Same playbook, one organization after another
Technical compromise becomes business harm
The agent treated an in-conversation claim of authorization as proof of it. The affected environments allowed a single standard user account to reach domain-level privilege.
The four published investigations cover different scopes, windows and levels of confidence.
Aurora ransomware activity is first reported, with a working data leak site and victims across multiple countries.
The operator begins driving the agent through exploitation tasks, supplying it with credentials or an existing route into a victim network first.
Timestamped activity against 20+ organizations across nine countries, filed per-organization in a consistent naming convention. The United States accounts for the largest share.
28 sessions total across ten target organizations, including a full AD CS exploitation plan drafted in Russian.
Cursor's parent company is acquired months after the documented sessions. Cursor was not a SpaceX product at the time of these attacks, despite most headlines implying it was.
Gambit and CloudSEK publish; Reuters runs the story the same day. CloudSEK held publication to allow coordinated notification to national CERTs and victims not already named on the leak site.
The operation was exposed by security researchers. No cited source describes a victim organization detecting it.
Reuters independently identified six organizations from the recovered chat logs and confirmed at least seven breaches. The seventh was not publicly named.
| Organization | Location | Sector | Size (est.) | Revenue (est.) | Reported context | Status |
|---|---|---|---|---|---|---|
Christeyns family-owned, est. 1946 |
Ghent, Belgium | Industrial hygiene and detergent chemicals; textile care, food processing, medical and life sciences | ~1,000–2,000 staff, 50+ countries | ≈ €400–450M | The largest named victim. Supplies hygiene and detergent chemicals to healthcare, food processing and textile care customers in more than 50 countries. | Named |
Teckentrup GmbH & Co. KG |
Verl, Germany | Garage, industrial and fire-rated door manufacturing | ~900–1,000 staff | ≈ €120–200M | Mid-market German Mittelstand manufacturer of garage, industrial and fire-rated doors. | Named |
Helideck Certification Agency Ltd |
Aberdeen, Scotland | Inspection and certification of offshore helicopter landing decks | ~10–20 staff | ≈ £1–5M | The smallest named victim. Certifies offshore helicopter landing decks for North Sea aviation. | Named |
Bayou Title |
Louisiana, USA | Title insurance and real estate closings | ~11–50 staff | ≈ $1–10M | Advertises itself as Louisiana's largest title insurer. Title agencies hold identity documents, wire instructions and closing files for third-party transactions. | Leak site |
Pharmaceutical distributor name withheld |
Argentina | Pharmaceutical distribution | Not disclosed | Not disclosed | CloudSEK lists pharmaceutical and chemical distribution among the most affected sectors. | Withheld |
Manufacturer name withheld |
Italy | Manufacturing | Not disclosed | Not disclosed | Manufacturing is the largest sector in the victim set. | Withheld |
Seventh confirmed breach |
Not disclosed | Not disclosed | — | — | Confirmed by Reuters as breached, not publicly identified. | Withheld |
The same playbook was applied to a 14-person certification body and a multinational chemicals group within the same six-week window.
CloudSEK published the sector ranking across the full 20+ victim set without per-sector counts.
Nine confirmed countries in the primary cluster, with the United States accounting for the largest share. The second cluster adds three more.
CloudSEK published compromised assets by sector across the full victim set.
| Sector | Assets confirmed compromised | What that means for the victim |
|---|---|---|
Manufacturing & industrial largest sector |
Full multi-site Active Directory compromise; Azure AD Connect sync-account hash captured; a certificate-based escalation path mapped end to end | Exposure extends to the cloud tenant through the sync account, not to on-premises systems only. |
Food, agriculture & distribution |
Full domain compromise with krbtgt extraction; internal SAP/ERP landscape enumerated | krbtgt extraction enables forged tickets. Remediation requires a double krbtgt rotation rather than a password reset. |
Professional & financial services |
Interactive administrative sessions; SSL-VPN credentials validated; supply-chain client exposure | Client data exposure creates third-party notification obligations. |
Transport & logistics |
Interactive RDP sessions; Group Policy and SYSVOL exfiltration | SYSVOL exports leak scripts, mapped drives and sometimes embedded credentials. |
Consumer goods / luxury |
Largest data exfiltration in the dataset; wildcard TLS certificate private key stolen | A stolen wildcard key is an impersonation capability across every subdomain until it is revoked and reissued. |
Waste management & environmental |
Domain credentials validated | Access confirmed, exploitation not necessarily completed. |
IT & backup infrastructure |
Backup-system credentials validated | Backup credential compromise is a recognised pre-encryption indicator. |
Unidentified |
Domain administrator Kerberos tickets captured, including the freshest access in the dataset | Indicates access still active at the time of publication. |
The same structure as the source architecture figure, redrawn and corrected against the published reports. Read left to right: the operator's own infrastructure never touched a victim network directly.
Outside every victim network
Victim logs show the pivot address.
They never show the operator.
Inside each target organization, the same sequence every time
One workflow, replayed. Each Cursor conversation corresponded to one target engagement, which is why the recovered sessions map cleanly onto ten organizations.
All three end in the same place: a certificate that authenticates as a privileged identity. They differ only in which control was missing.
The operator enumerated first, then used whichever route the environment left open.
Exploit code for at least a dozen distinct techniques was staged in the operator's directory, most of it unmodified public proof-of-concept clones. Almost none of it is a software vulnerability in the CVE sense. It is configuration.
A template lets a low-privilege user request a certificate and name the identity it will be issued for.
A setting on the CA lets requesters specify a subject alternative name regardless of how restrictive the template is.
The AD CS web enrollment endpoint accepts relayed NTLM authentication over HTTP.
A machine, including a domain controller, is made to authenticate to an attacker-chosen host.
A machine account is created, renamed and impersonated to obtain a domain-admin-equivalent ticket.
Service tickets and pre-auth-disabled accounts are requested legitimately, then cracked offline.
A nine-year-old vulnerability, still working in 2026.
A custom NetExec module targeting seven browsers, documented in Russian.
The bridge between on-premises AD and the cloud tenant, frequently left outside Tier 0.
The single most reliable warning that encryption is imminent.
One host, dozens of encrypted servers, and a ransom note in the login banner.
Ordinary tools, unusual volumes, no alert.
Every stage of this campaign produced a signal. The chart places detection opportunities against the attack sequence; larger markers indicate the highest-fidelity detections.
One row per observed technique: what a defender would have seen, where the signal lives, and the change that removes the path entirely.
| Technique observed | Observable signal | Where the signal lives | Control that removes the path |
|---|---|---|---|
Credential-based VPN / RDP access |
Logins from rented VPS ranges in Germany and the US; impossible travel; new device fingerprints; after-hours RDP | VPN and RDP gateway logs, identity provider sign-ins, UEBA | Phishing-resistant MFA on all remote access. Jump servers with session logging. Geo and ASN restrictions where the business allows. |
LDAP / SMB enumeration |
A single ordinary user account querying every computer object and share in the domain within minutes | Windows 4662 / 5145, DC LDAP query logging, NDR | Baseline and alert on enumeration volume per account. |
Kerberoasting / AS-REP roasting |
Burst of TGS requests, RC4 downgrade, many SPNs requested by one account; AS-REP requests for pre-auth-disabled accounts | Windows 4769 and 4768 on domain controllers | gMSA for service accounts. No SPNs on privileged accounts. Enforce AES. Alert on RC4 TGS bursts. |
BloodHound collection |
Mass session enumeration and ACL reads across the domain in a short window | 4662, SMB session enumeration, EDR process telemetry | Detection rule for bulk collection patterns. This step is required for the attacker's path selection. |
AD CS ESC1 / ESC6 abuse |
A certificate request from a non-administrative account, issued with a subject or SAN naming a privileged identity | CA logs: Event ID 4886 (requested) and 4887 (issued) | Remove enrollee-supplied subject; require manager approval; disable EDITF_ATTRIBUTESUBJECTALTNAME2; restrict enrollment. Certificate auditing must be enabled first; it is off by default in most environments. |
NTLM coercion and ESC8 relay |
A DC or server authenticating outbound to an unexpected internal host; relayed authentication arriving at web enrollment | NDR, SMB and RPC telemetry, IIS logs on the enrollment server | Disable web enrollment if unused. Enforce EPA and HTTPS. SMB signing and LDAP channel binding. Disable Print Spooler on DCs. RPC filters. |
noPac chain |
Computer account created by a standard user, then renamed; unusual TGT requests following the rename | Windows 4741 (created) and 4742 (changed) | MachineAccountQuota = 0. Patch CVE-2021-42278 / 42287. Alert on 4741 from non-delegated accounts. |
Credential dumping (SAM / LSA) |
LSASS access by unusual processes; registry hive export; remote service creation on member servers | EDR, Sysmon Event 10, Windows 4688, PowerShell 4104 | Credential Guard and LSA Protection. LAPS for local admin. Tier isolation so a Tier 2 compromise cannot reach Tier 1 credentials. |
Browser credential harvesting |
Scripted or bulk access to browser profile directories across many hosts | EDR file access telemetry | Policy-disable browser password saving. Enable credential store encryption. Alert on profile access by non-browser processes. |
Backup credential validation |
Backup service account authenticating from a host that has never used it, or interactive logon to the backup console | Backup platform audit log, identity provider, PAM | Isolate backup identity and network. Treat backup credential use outside the scheduled window as an incident. |
ESXi / vCenter discovery |
Scanning of ports 443 and 902 across internal subnets; TLS certificate fingerprinting of hypervisors | NDR, firewall logs, vCenter access logs | Management VLAN isolation. Lockdown mode. SSH restricted to jump hosts. MFA on vCenter. |
ESXi encryption behaviour |
Mass VM power-off in seconds, then heavy write activity; sshd configuration edited and a banner file written; SSH restarted | ESXi shell and auditd logs, vCenter task events | Alert on bulk VM power-off. CloudSEK published an experimental Sigma rule for the banner-write sequence; that three-part combination is highly specific. |
Staged exfiltration |
Large archive creation on servers; 50GB-scale outbound transfers to rented VPS addresses | EDR, DLP, NetFlow, proxy and firewall egress logs | Egress allowlisting. Per-host outbound volume baselines. Alert on archiving utilities running on servers with no business archiving. |
Anti-recovery preparation |
Volume shadow copy deletion, shadow storage resize, System Restore disabled via registry | EDR, Windows 4688, registry auditing | Block shadow copy deletion at the EDR layer. This signal typically precedes encryption by minutes. |
Sequenced by risk removed per unit of effort, for a mid-market organization of the type affected in this campaign.
The refusals were bypassed by asserting that the activity was authorized, not by prompt manipulation.
Reported properties of the bypass.
Reported effects.
Reported limits.
The operator repeated the same three restrictions to the agent at every victim.
| Operator restriction | Why they imposed it | Defensive implication |
|---|---|---|
No DCSync restated in at least five messages |
DCSync is one of the most reliably alerted techniques in any monitored AD environment. They asked for the domain controller machine hash by other means instead. | DCSync detection is deployed widely enough to be routed around. Coverage is needed for the paths used instead: certificate issuance, machine account creation, coerced authentication. |
No account lockouts attached to every spray request |
Lockouts generate helpdesk tickets, and helpdesk tickets generate questions. They retrieved the password policy first, specifically to stay under the threshold. | Alert on failed authentication volume below the lockout threshold, since spraying is tuned to remain under it. |
No new computer objects |
Computer account creation is visible, logged as Event 4741, and rarely legitimate from a standard user account. | Supports MachineAccountQuota = 0 with Event 4741 alerting, which this operator chose to avoid triggering. |
The same failure mode applies to agents deployed defensively: an in-conversation claim of authorization is not verifiable by the agent.
A statement of permission inside the conversation is not evidence of permission.
Constraints at the tool layer do not depend on interpreting intent.
Per-prompt evaluation cannot see a campaign.
Tool invocation is the record of what the agent actually did.
These were reported inconsistently across coverage of the incident.
The three original diagrams, unchanged and embedded so they travel with the page. Where they differ from the tabs above, the tabs reflect the primary reports. The figures were drafted earlier and contain dates and per-victim attributions the published reporting does not support.
Every abbreviation and technique name used anywhere on this page, expanded and explained in the sense it carries here. Definitions are scoped to this incident rather than written as general reference entries.
| Term | Stands for | What it means in this incident |
|---|---|---|
| ESC | Escalation | A numbered entry in the catalogue of Active Directory Certificate Services privilege-escalation paths published by SpecterOps in Certified Pre-Owned (Will Schroeder and Lee Chagolla-Christensen, June 2021). The original paper defined ESC1 to ESC8; the community has since extended it to ESC16. The number is a catalogue index, not a severity ranking. |
| ESC1 | Escalation path 1 — enrollee-supplied subject | A certificate template that lets a low-privilege user both enroll and specify the identity the certificate is issued for, with a client-authentication purpose and no manager approval. Any domain user can request a certificate that authenticates as Domain Admin. |
| ESC6 | Escalation path 6 — CA-level subject flag | A registry flag on the certificate authority itself that lets any requester supply a subject alternative name, regardless of how carefully the individual templates were locked down. One CA setting overrides all template-level hardening. |
| ESC8 | Escalation path 8 — relay to web enrollment | The AD CS web enrollment page accepting relayed NTLM authentication, so a coerced machine login can be forwarded to it and exchanged for a certificate belonging to that machine's identity. |
| ESC4 | Escalation path 4 — weak template permissions | Not used in this campaign, listed because it is the third most common in the wild: permissions on the template object itself let a low-privilege user edit the template into an ESC1 condition. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| AD CS | Active Directory Certificate Services | The Microsoft server role that issues digital certificates inside a Windows domain. Because a certificate can authenticate as a user, a misconfigured AD CS is equivalent to a spare set of domain administrator credentials. |
| PKI | Public Key Infrastructure | The wider system of certificate authorities, templates, issuance policies and revocation that AD CS implements for a domain. |
| CA | Certificate Authority | The server that signs and issues certificates. In this campaign the CA's own configuration, not just its templates, was part of the attack surface. |
| Certificate template | — | A reusable definition of what a class of certificate contains, who may request one, and whether the requester gets to choose the identity on it. Template misconfiguration is the root cause of most AD CS abuse. |
| EKU | Extended Key Usage | The field stating what a certificate may be used for. A client-authentication EKU is what makes a certificate usable as a logon credential rather than just for encryption or signing. |
| SAN | Subject Alternative Name | An additional identity carried on a certificate. If an attacker can choose the SAN, they choose who the certificate authenticates as. |
| ENROLLEE_SUPPLIES_SUBJECT | Template flag: “supply in the request” | The setting that lets the requester name the identity on the certificate instead of the CA building it from Active Directory. Removing this flag remediates ESC1. |
| EDITF_ATTRIBUTESUBJECTALTNAME2 | CA policy flag allowing requester-supplied SAN | A CA-wide registry setting that reintroduces requester-chosen identities across every template at once. This is ESC6. It is not enabled by default. |
| Web enrollment | The AD CS certsrv web interface | An optional HTTP front end for requesting certificates. It is the relay target in ESC8, and is frequently enabled without being used. |
| Wildcard TLS certificate | Transport Layer Security certificate valid for all subdomains | One private key covering *.company.com. Stolen in the consumer goods engagement, which gives the holder the ability to impersonate every subdomain until it is revoked and reissued. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| Active Directory (AD) | Microsoft's directory service | The identity system holding every user, computer and group in a Windows environment. Compromising it compromises everything that trusts it. |
| Domain controller (DC) | — | The server hosting Active Directory and issuing Kerberos tickets. A Tier 0 asset by definition. |
| TGT | Ticket-Granting Ticket | The Kerberos credential establishing a user's identity, used to request access to individual services. Forging one is equivalent to being that user. |
| TGS | Ticket-Granting Service ticket | A ticket for one specific service. Requesting many at once, then cracking them offline, is Kerberoasting. |
| krbtgt | Kerberos Ticket-Granting Ticket account | The domain account whose key signs every Kerberos ticket. Stealing its hash lets an attacker mint valid tickets for anyone, indefinitely. Recovery requires rotating the password twice with a replication interval between. |
| Golden ticket | — | A forged TGT created with the stolen krbtgt key. Survives password resets, which is why krbtgt extraction is treated as a full-domain-rebuild event. |
| SPN | Service Principal Name | A label tying a service to the account running it. Any account holding one can have a ticket requested for it by any domain user, which is what makes Kerberoasting possible. |
| Kerberoasting | — | Requesting service tickets for accounts with SPNs, then cracking the encrypted portion offline to recover the account password. Entirely legitimate traffic until the cracking starts, which happens on the attacker's own hardware. |
| AS-REP roasting | Authentication Service Response roasting | The same idea against accounts with Kerberos pre-authentication disabled: the response can be requested without a password and cracked offline. |
| DCSync | — | Impersonating a domain controller to request password data via directory replication. One of the most reliably alerted techniques in a monitored environment; this operator prohibited its use. |
| PAC | Privilege Attribute Certificate | The structure inside a Kerberos ticket that carries the user's group memberships and rights. The noPac attack is named for abusing how it is validated. |
| noPac | CVE-2021-42278 and CVE-2021-42287 | A chain that creates a machine account, renames it to impersonate a domain controller, and obtains a domain-admin-equivalent ticket. Blocked by patching and by setting MachineAccountQuota to zero. |
| S4U2self | Service for User to Self | A Kerberos delegation feature that lets a service request a ticket to itself on behalf of any user. Legitimate, and a step in the noPac chain. |
| MachineAccountQuota | — | How many computers an ordinary user may join to the domain. Ships as 10 by default; commonly set to 0 with joins delegated to a named group. |
| gMSA | group Managed Service Account | A service account whose password is generated and rotated automatically by Active Directory. Immune to Kerberoasting because there is no human-chosen password to crack. |
| SYSVOL | System Volume | The share on every domain controller holding Group Policy and logon scripts. Readable by all domain users, and historically a place where credentials end up embedded in scripts. |
| GPO | Group Policy Object | Centrally managed configuration pushed to domain machines. Control of GPOs is control of everything they apply to, which is why GPO exports show up in the exfiltrated data. |
| SAM | Security Account Manager | The local account database on a Windows host. Dumping it yields local password hashes, useful for lateral movement where passwords are reused. |
| LSA / LSASS | Local Security Authority (Subsystem Service) | The Windows process holding credentials in memory for logged-on users. The classic credential-dumping target, and what Credential Guard and LSA Protection exist to defend. |
| Tier 0 / Tier 1 / Tier 2 | Microsoft's administrative tiering model | Tier 0 is anything that can control identity: domain controllers, AD CS, the Azure AD Connect sync account, backup platforms. Tier 1 is servers and applications, Tier 2 is workstations. The model exists so a Tier 2 compromise cannot reach Tier 0 credentials. |
| Azure AD Connect | — | The service synchronising on-premises Active Directory to Microsoft's cloud directory. Its sync account is a Tier 0 identity, frequently classified as an ordinary application account. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| NTLM | NT LAN Manager | Microsoft's legacy authentication protocol, still widely enabled. It has no binding between the authentication and the connection it was intended for, which is what makes relay possible. |
| NTLM relay | — | Forwarding a captured authentication to a different service, which accepts it as though the victim had connected there directly. Feeds ESC8. |
| Coercion | — | Making a Windows machine authenticate to a location of the attacker's choosing. PetitPotam, PrinterBug and DFSCoerce are three ways of triggering it via legacy remote procedure call interfaces. |
| PetitPotam | Abuse of the Encrypting File System remote protocol | A coercion technique that makes a server, including a domain controller, authenticate to an attacker-chosen host. |
| PrinterBug | Abuse of the Print System Remote Protocol (MS-RPRN) | Coercion via the print spooler. Disabling the Print Spooler service on domain controllers removes it. |
| DFSCoerce | Abuse of the Distributed File System namespace protocol (MS-DFSNM) | A third coercion route. Blocking the first two does not prevent it. |
| SMB | Server Message Block | The Windows file and printer sharing protocol, also the transport for a great deal of administrative activity. |
| SMBv1 | Server Message Block version 1 | The obsolete version, vulnerable to EternalBlue and to null-session enumeration. Repeatedly located and used by this operator. |
| SMB signing | — | Cryptographically signing SMB traffic so a relayed authentication cannot be reused. Enforcement blocks a large class of relay attacks. |
| EPA | Extended Protection for Authentication | Channel binding that ties an authentication to the specific TLS connection it was performed over, so it cannot be replayed elsewhere. The fix for ESC8. |
| LDAP | Lightweight Directory Access Protocol | How clients query Active Directory. Also how an attacker enumerates every user, group and computer in the domain from a standard account. |
| LLMNR | Link-Local Multicast Name Resolution | A legacy name-resolution fallback that broadcasts lookups to the local network, letting an attacker answer and capture authentication. |
| NBT-NS | NetBIOS Name Service | An even older name-resolution fallback with the same problem as LLMNR, and the same remedy. |
| WinRM | Windows Remote Management | The remote administration service. Used for administration and, equally, for lateral movement. Commonly restricted to designated administrative hosts. |
| RPC | Remote Procedure Call | The mechanism behind most Windows remote operations, including all three coercion techniques. RPC filters can block specific abusable interfaces. |
| RDP | Remote Desktop Protocol | Interactive remote access to a Windows desktop. One of the two credential-based entry routes in this campaign. |
| SSL-VPN | Secure Sockets Layer virtual private network | Browser-based remote access to the corporate network. Credentials for one were validated in the professional services engagement. |
| MS17-010 / EternalBlue | Microsoft Security Bulletin MS17-010 | The 2017 SMBv1 remote code execution flaw behind WannaCry and NotPetya. Used in this campaign against end-of-life hosts. |
| xp_cmdshell | SQL Server extended stored procedure | A Microsoft SQL Server feature that runs operating system commands. Used for lateral movement in the second Aurora cluster; disabled by default and frequently re-enabled by applications. |
| GodPotato | — | A local privilege escalation tool that abuses Windows service account impersonation privileges to reach SYSTEM. Second cluster only. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| NetExec | Formerly CrackMapExec | A Swiss-army enumeration and credential-validation tool for Windows networks. The operator's primary discovery tool, extended with custom modules kept in a private repository. |
| BloodHound | — | Graph analysis of Active Directory that finds the shortest path from a compromised account to Domain Admin. Used by defenders and attackers alike. Its collection step is detectable. |
| Certipy | — | The open-source tool that automates finding and exploiting AD CS misconfigurations. Also used by defenders to audit their own templates. |
| Impacket | — | A Python library implementing Windows network protocols directly, which underpins a large share of offensive Windows tooling. |
| ntlmrelayx | Impacket's NTLM relay tool | Receives coerced authentication and forwards it to a chosen target, including the AD CS web enrollment endpoint. |
| PKINITtools | Public Key Cryptography for Initial Authentication tools | Utilities for turning a certificate into a Kerberos ticket, which is the step that converts an issued certificate into working domain access. |
| Kerbrute | — | Fast Kerberos-based username enumeration and password spraying. |
| hashcat / John the Ripper | — | Offline password-cracking tools. These run on the attacker's own hardware and produce no telemetry in the victim environment. |
| evil-winrm | — | A remote shell over Windows Remote Management, used for lateral movement once credentials are in hand. |
| chisel | — | A tunnelling tool that carries traffic over HTTP, used to reach internal networks from outside. |
| proxychains | — | Forces ordinary tools to send their traffic through a proxy, which is how the operator ran standard tooling through the SOCKS pivot chain. |
| SOCKS proxy | Socket Secure | A generic traffic-forwarding protocol. Chained across rented servers, it means the victim's logs record the last hop and never the operator. |
| VPS | Virtual Private Server | Rented cloud hosting, mostly in Germany and the United States here, used as disposable and rotated pivot points. |
| C2 | Command and control | The infrastructure an attacker uses to direct activity inside a victim network. |
| Metasploit | — | A general exploitation framework, used here for its MS17-010 module and payload handlers. |
| Mimikatz | — | The best-known credential-extraction tool for Windows, and the reason LSA Protection and Credential Guard exist. |
| s5cmd | — | A fast command-line client for S3-compatible object storage. The second cluster's exfiltration tool. |
| scp | Secure Copy Protocol | File transfer over SSH, used to place the encryptor onto staging hosts. |
| Cloudflare R2 | Object storage service | Legitimate cloud storage used to host the encryptor for download. Reputable hosting is commonly used because it is rarely blocked. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| ESXi | VMware's bare-metal hypervisor | The host running dozens of virtual servers. Encrypting one ESXi host takes out every guest on it at once, which makes hypervisors a high-impact ransomware target. |
| vCenter | VMware's central management server | Controls every hypervisor in the environment. Should be treated as Tier 0 and protected with multi-factor authentication. |
| esxcli | The ESXi command-line interface | Used by the encryptor to list and force-stop running virtual machines so their disk files could be modified. |
| Lockdown mode | — | An ESXi setting that restricts direct host access to management through vCenter. A standard hypervisor hardening step. |
| SSH login banner | — | Text shown before the login prompt. The Linux encryptor wrote the ransom demand here instead of dropping a file, so any administrator connecting to the host reads it immediately. |
| ChaCha20 | A stream cipher | Used to encrypt file contents. Selected for encryption speed. |
| RSA-4096 | Rivest–Shamir–Adleman, 4096-bit key | Used to wrap each file's encryption key so only the attacker's private key can recover it. Without the attacker's private key, encrypted files cannot be recovered. |
| Zig | A systems programming language | An unusual choice for ransomware. It produces single static binaries and cross-compiles easily, and public malware corpora hold few Zig samples to build signatures from. |
| Volume Shadow Copy | Windows point-in-time snapshots | Local restore points. Deletion is a standard pre-encryption step and a high-confidence alert. |
| Double extortion | — | Stealing data before encrypting it, so that restoring from backup does not end the leverage. Exfiltration therefore has to be detected independently of encryption. |
| Leak site | Data leak site (DLS) | The public site where a ransomware group names victims and publishes stolen data. Appearing on one usually means no ransom was paid. Only about one in five victims here reached it. |
| Affiliate | Ransomware-as-a-service partner | An operator who breaks into victims and deploys another group's ransomware for a share of the proceeds. Here the split was negotiated per victim rather than fixed. |
| Initial access broker | — | Someone who breaks in and sells the access on rather than extorting directly. CloudSEK assessed this operator as not a broker, because the encryptor and the negotiations were in their own hands. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| MFA | Multi-factor authentication | A second proof of identity. “Phishing-resistant” means hardware keys or platform authenticators, not codes over SMS or push prompts, which can be relayed or fatigued. |
| EDR | Endpoint Detection and Response | Agent-based monitoring on hosts. The layer that would catch credential dumping and shadow copy deletion. |
| SIEM | Security Information and Event Management | Central log collection and correlation. Where the Windows event IDs cited on this page must be collected for the detections to function. |
| UEBA | User and Entity Behaviour Analytics | Baselining what normal looks like per account, which is how “this user has never enumerated the domain before” becomes an alert. |
| NDR | Network Detection and Response | Traffic-level monitoring. The layer that sees coercion, relay and hypervisor scanning. |
| DLP | Data Loss Prevention | Controls on data leaving the organization. Relevant to the 50GB staged archives. |
| PAM | Privileged Access Management | Vaulting, brokering and recording administrative credential use, so privileged access is time-bound and logged rather than standing. |
| LAPS | Local Administrator Password Solution | Gives every machine a unique, rotated local administrator password, so a single dumped hash does not unlock other machines. |
| Credential Guard / LSA Protection | — | Windows features that isolate credentials from the processes trying to read them. The direct countermeasure to LSASS dumping. |
| PAW | Privileged Access Workstation | A hardened machine used only for administration, so administrative credentials are not used on general-purpose workstations. |
| JIT / JEA | Just-In-Time / Just Enough Administration | Granting privilege for a limited window and a limited scope rather than permanently. |
| Sigma rule | — | A vendor-neutral detection rule format that converts into a given SIEM's query language. CloudSEK published one for the ESXi banner behaviour. |
| Windows Event IDs | — | 4662 directory object access; 4688 process creation; 4741 computer account created; 4742 computer account changed; 4768 TGT requested; 4769 service ticket requested; 4886 certificate requested; 4887 certificate issued; 5145 network share object checked; 4104 PowerShell script block. Certificate auditing (4886 and 4887) is off by default in most environments. |
| Sysmon | System Monitor | A free Microsoft tool adding detailed process, network and file telemetry. Event 10 is process access, which is how LSASS reads get spotted. |
| Immutable backup | — | Backups that cannot be altered or deleted for a fixed retention period, even by an administrator. Determines whether recovery without payment is possible. |
| Egress filtering | — | Restricting which outbound destinations internal systems may reach, so bulk data cannot simply leave to a rented server. |
| Term | Stands for | What it means in this incident |
|---|---|---|
| CIS | Commonwealth of Independent States | The post-Soviet regional bloc. Terminology collision: in most security writing CIS means the Center for Internet Security. Here it means the geography this operator systematically refused to attack. |
| IOC | Indicator of Compromise | An artifact that suggests a specific intrusion: a file hash, an IP address, a filename. Published by both research firms; not reproduced on this page. |
| TTP | Tactics, Techniques and Procedures | How an actor operates, as distinct from which infrastructure they used. TTPs are what let researchers attribute the second cluster to the same group despite different tooling. |
| CERT | Computer Emergency Response Team | National coordination bodies. CloudSEK notified relevant CERTs before publishing so unnamed victims could be reached. |
| OSINT | Open Source Intelligence | Information gathered from public sources. The revenue and headcount estimates in the Victims tab are OSINT, not incident findings. |
| Firmographics | — | Company attributes such as revenue, headcount, sector and location. Indicative across a victim set, unreliable for any individual company. |
| HUMINT | Human Intelligence | Intelligence from direct human sources. Used here to corroborate the CIS exclusion and the negotiated affiliate splits independently of the on-chain data. |
| On-chain analysis | — | Tracing cryptocurrency movements through the public blockchain. How TRM Labs linked several victim payments to shared laundering infrastructure. |
| Peeling chain | — | A laundering pattern that shaves small amounts off a balance across many hops. One traced payment used this instead of the usual consolidation hubs. |
Firmographic estimates in the Victims tab are drawn from public company sources and business directories, not from the incident reports. Indicators of compromise are published in the Gambit and CloudSEK reports and are not reproduced here.