Login
From:
The DFIR Report
(Uncensored)
subscribe
From OneNote to RansomNote: An Ice Cold Intrusion – The DFIR Report
https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/
links
backlinks
Tagged with:
ransomware
icedid
adfind
exfiltrate data
nokoyawa
Roast topics
Find topics
Find it!
Key Takeaways In late February 2023, threat actors rode a wave of initial access using Microsoft OneNote files. In this case, we observed a threat actor deliver IcedID using this method. After load…