ctipilot.ch

Sinobi

actor · actor:sinobi-ransomware single-source

Ransomware-as-a-service operation active for roughly a year with minimal public reporting on its operators, encrypting with the .SINOBI extension. In Cisco Talos Incident Response's first engagement with the group (April 2026) the operators used a trojanized MeshAgent binary — the agent component of the open-source MeshCentral remote-management platform — installed as a SYSTEM-level auto-start service as their primary command-and-control mechanism over encrypted WebSocket, a tactic Talos states had not previously been associated with the group; they held access about three days, cracked a weak service-account password obtained from ntds.dit, moved laterally over RDP and WinRM, and deployed ransomware domain-wide through a malicious Group Policy Object logon script with rclone staging exfiltration (Cisco Talos IR, 2026-07-28).

Coverage timeline
2
first 2026-06-22 → last 2026-07-29
Peak priority
notable
2 notable
Sources cited
3
3 hosts
Sections touched
2
deep-dive, weekly-research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
20
pinned v19.1 · see below
2026-06-222 appearances2026-07-29

ATT&CK techniques

20 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1598Phishing for Information×1

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1564.008Hide Artifacts: Email Hiding Rules×1

Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the <code>New-InboxRule</code> or <code>Set-InboxRule</code> PowerShell cmdlets on Windows systems.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Credential Access TA0006

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1111Multi-Factor Authentication Interception×1

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1621Multi-Factor Authentication Request Generation×1

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1021.006Remote Services: Windows Remote Management×1

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1534Internal Spearphishing×1

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Collection TA0009

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1102Web Service×1

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Story timeline

  1. 2026-07-29Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outright
    deep-diveCisco Talos IR's quarterly report puts three named intrusion chains on record, led by Sinobi running its command-and-control through a trojanized MeshAgent
  2. 2026-06-22Threat actor: INC ransomware's Rust rewrite and BYOVD evolution
    weekly-research

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

documented in

Where this entity is cited

  • weekly-research1
  • deep-dive1

Source distribution

  • acronis.com1 (33%)
  • blog.talosintelligence.com1 (33%)
  • thehackernews.com1 (33%)

Entries about Sinobi (2)

2026-07-29 · view entry permalink →

NOTABLENATOB2

Quarterly incident-response reports are usually read for their percentages, which is the least useful thing in them. The Q2 2026 edition from Cisco Talos Incident Response is worth a deep read for a different reason: it puts three specific intrusion chains on the public record with enough sequence to hunt against, and it documents a visibility failure that stopped Talos's own responders from answering the two questions every incident turns on (Cisco Talos Incident Response, 2026-07-28).

Sinobi: the RMM agent was the C2. Talos IR responded to Sinobi ransomware for the first time in April 2026 — a ransomware-as-a-service operation active nearly a year with minimal public reporting on its operators. The chain reads as a deliberate exercise in staying inside the shape of normal administration. Rather than deploying a bespoke implant, the operators used a trojanized MeshAgent binary — the agent component of the open-source MeshCentral remote-management platform — as their primary command-and-control mechanism, a tactic Talos states had not previously been associated with the group (Cisco Talos Incident Response, 2026-07-28). Installing it as a SYSTEM-level auto-start service collapsed persistence and privilege into the same step: no separate escalation, and boot survival from the outset. The channel was encrypted WebSocket to an attacker-controlled server, which matters because genuine MeshAgent traffic is itself WebSocket-based — Talos's assessment is that this let the actor blend malicious traffic with legitimate remote-management activity and hold undetected access for approximately three days before deploying ransomware (Cisco Talos Incident Response, 2026-07-28). Lateral movement was enabled by a service account whose weak password was cracked after being obtained from the domain credential store ntds.dit, and the operators moved through the network over RDP and WinRM. The endgame is the part worth dwelling on: rather than pushing the payload host by host, the actor deployed ransomware across the entire domain using a malicious Group Policy Object logon script, encrypting with the .SINOBI extension alongside exfiltration staging via rclone.exe (Cisco Talos Incident Response, 2026-07-28). Talos reads the GPO deployment as evidence of genuine enterprise-architecture understanding, and expects the group to keep weaponising legitimate tools precisely because they bypass signature-based alerting.

Warlock and the unattended agent. In a separate engagement, Talos observed Warlock operators — also tracked as Storm-2603 — deploying an installer for the Zoho Assist Unattended Agent, a capability designed to allow administrative remote control of an endpoint with no user logged in, and states it had not previously seen this tool attributed to Warlock (Cisco Talos Incident Response, 2026-07-28). That engagement did not reach encryption, but Talos notes the activity was consistent with a Warlock attack it observed in May 2026 that did. The pattern across both ransomware cases is the same substitution: where a defender's model expects a malicious binary, there is a legitimate, signed, commercially supported remote-administration product instead — which is why Talos's own recommendation shifts from signature detection to behavioural monitoring and application allowlisting that prevents unauthorised binaries from running as services.

UAT-11764: phishing that grows its own target list. From April 2026 and still ongoing in late June, Talos tracked a QR-code phishing campaign against primarily Australian organisations, attributing it to a newly designated actor. Delivery is auto-generated, victim-tailored PDF documents carrying embedded QR codes — a shape chosen to sit outside what email-gateway text and link scanning inspects. The codes lead to Microsoft 365 credential-harvesting pages; on success the operator accesses the mailbox, creates inbox rules to hide incoming mail and reduce the victim's visibility of the compromise, stages follow-on malicious documents on SharePoint, and then sends further internal and external phishing using that mailbox's own contact list (Cisco Talos Incident Response, 2026-07-28). Talos assesses with high confidence that the actor will almost certainly continue, using each newly compromised mailbox's contacts to expand reach and sustain momentum (Cisco Talos Incident Response, 2026-07-28). The tradecraft insight Talos draws is that the operation leans on trusted infrastructure — SharePoint and Microsoft 365 — rather than attacker-registered domains, so reputation-based controls have nothing to fire on. The same report profiles ARToken, the phishing-as-a-service panel this pipeline already tracks, noting it exposes over 80 API endpoints covering device-code phishing, primary-refresh-token persistence, mailbox access and SharePoint exfiltration, and bypasses multi-factor authentication through the OAuth device-authorisation flow rather than by stealing a password.

The two cross-cutting findings. Authentication abuse was the most prevalent weakness Talos recorded, in 65% of its engagements against 35% the previous quarter — and the composition is more useful than the share: adversaries defeated or bypassed multi-factor authentication using adversary-in-the-middle proxies and session-token theft, MFA-fatigue attacks, registration of attacker-controlled devices for authentication, and legacy authentication protocols that circumvent MFA altogether (Cisco Talos Incident Response, 2026-07-28). Three of those four defeat a correctly configured push-based MFA deployment, which is the deployment most organisations have. The second finding is the one to take to a budget conversation. Insufficient logging and visibility appeared in 42% of engagements against 18% the previous quarter, and Talos enumerates what that meant in practice: domain-controller security logs retained for only a few hours, host event logs truncated or overwritten before capture, absent NetFlow preventing reconstruction of external authentication and exfiltration, on-device-only logs that adversaries deleted, and cloud telemetry whose retention did not reach back to the true initial-access date. Talos states plainly that in several engagements these gaps prevented definitive determination of the initial access vector or the scope of data exfiltration (Cisco Talos Incident Response, 2026-07-28). That is not a hygiene observation — it is a statement that the questions a board, a regulator and a data-protection authority all ask first were unanswerable. Talos's remediation names 90 days of centralised retention as a minimum, logs forwarded off-device so they survive tampering and rebuilds, and process-creation, command-line and cloud-API auditing enabled.

Also recorded: exposed or unpatched internet-facing infrastructure was the third-ranked weakness at 31%, with ToolShell, an older Telerik UI deserialization flaw and SD-WAN/VPN appliance CVEs among the named examples; and unlimited outbound email thresholds enabled propagation in almost 15% of engagements, illustrated by a single compromised mailbox that sent over 6,600 phishing and spam messages before containment — a concrete number worth borrowing as an alerting threshold, since Talos rightly calls outbound rate-limiting low-effort and high-impact. On targeting, healthcare led for the second consecutive quarter at 17% of engagements, with public administration and manufacturing at 14% each; Talos's read is that the three share a critical lack of downtime tolerance, and it notes that almost all targeted public-administration organisations were local governments and that targeted manufacturers were high-value industrial-supply-chain entities where disruption cascades downstream. For a constituency built around cantonal and communal administration and critical-infrastructure operators, that is the sentence in the report with the most direct read-across — the segment being hit is not central government but the municipal tier, and the reason given is operational intolerance of downtime rather than data value.

Triage: every mechanism in the ransomware chains is normal administration, and Talos's explicit position is that this is why they were chosen — so no single event discriminates and the correlation has to carry it. For remote-management agents the discriminator is provenance against inventory: a genuine MeshAgent or Zoho Assist deployment is provisioned by your own management server onto an asset of record and appears as an expected service, whereas the malicious instance is an agent-named SYSTEM service on a host with no deployment of record. For the lateral movement, the discriminator is the identity rather than the protocol: RDP and WinRM between servers is routine, but a service account interactively authenticating across hosts is not what service accounts are for, and that is the question an access review can settle in advance. For the GPO step, the discriminator is change provenance — a logon-script modification is a discrete, auditable act with an expected author and change window, so an unattributed edit to a domain-wide policy object is high-fidelity on its own.

Notably, we observed the threat actors use a trojanized MeshAgent binary as their primary C2 mechanism during this engagement, a tactic that has not been previously associated with the group in public reporting.

The actor ultimately deployed the ransomware across the entire domain using a malicious Group Policy Object (GPO) logon script. The incident resulted in the encryption of systems with the .SINOBI file extension, alongside observed data exfiltration staging activity conducted via rclone.exe.

In one engagement, we observed Warlock ransomware operators (also known as Storm-2603) deploying an installer for the RMM tool Zoho Assist Unattended Agent, which is designed to allow administrative remote control of an endpoint without a user logged in.

We assess with high confidence that the threat actor, who we have dubbed UAT-11764, will almost certainly continue leveraging this QR code phishing operation, using each newly compromised mailbox's contact lists to expand its reach and sustain the campaign's momentum.

In several engagements these gaps prevented definitive determination of the initial access vector or the scope of data exfiltration.

Cisco Talos Incident Response 2026-07-28
annual-report29 Jul 05:55Zsingle-sourceOpen finding ↗

2026-06-22 · view entry permalink →

NOTABLE

Threat actor: INC ransomware's Rust rewrite and BYOVD evolution

Acronis and The Hacker News documented the evolution of INC ransomware into a top-tier RaaS — 830+ victims since 2023, fourth in Q1 2026 — with a Rust rewrite of its Windows and Linux/ESXi encryptors, BYOVD EDR-termination using the drivers filwfp.sys / filnk.sys / fildds.sys (the same set seen in earlier Vanilla Tempest campaigns), a Veeam credential dumper for backup infrastructure, and two source-code-leak-derived variants (Lynx, Sinobi) (Acronis TRU, 2026-06-18; The Hacker News, 2026-06-19). The geography is incidental for a CH/EU SOC — the cited reporting puts the majority of INC's victims in the US — but the tradecraft is not: the three BYOVD drivers (shared with earlier Vanilla Tempest campaigns), the Veeam backup-credential dumper, and the cross-platform Rust encryptor are detection content that generalises to any victim. Detect the three BYOVD drivers via driver-load events with a hash blocklist, alert on Veeam process-memory access from unexpected parents, and keep backup systems MFA-protected and network-isolated.

research22 Jun 00:15Zmulti-sourceOpen finding ↗