VHD Ransomware
#VHD • 2020-07
ZZZ
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence found the MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. The campaign used victim-specific spreading utilities, administrative credentials, SMB brute forcing, WMI execution, VPN exploitation, Active Directory takeover, and network-wide ransomware staging, while later reporting framed VHD as part of DPRK-linked financially motivated ransomware experimentation.
-
6
Related Reports
-
1
Affected Countries
-
73
Months Since