The DFIR Report's Avatar

The DFIR Report

@thedfirreport.bsky.social

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. https://thedfirreport.com

1,103 Followers  |  0 Following  |  100 Posts  |  Joined: 14.08.2023  |  1.3521

Latest posts by thedfirreport.bsky.social on Bluesky

Preview
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in …

🚨 Search for software, end up getting ransomware!

SEO-driven #Bumblebee malware campaigns observed throughout July led to domain compromise, data theft & #Akira ransomware. Tools included #AdaptixC2 & #Netscan.

thedfirreport.com/2025/08/05/f...

05.08.2025 12:39 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
DFIR Labs - Subscription Plans

🚨 New: DFIR Labs Pro Tier is here!

🎯 Smarter investigations with:
β€’ 🧠 AI Timeline Builder (w/ IOCs + notes)
β€’ ⏱️ More lab time + extension credits
β€’ πŸ“Š Analytics dashboard w/ tailored insights

πŸ”— Dive in: dfirlabs.thedfirreport.com/subscription...

23.07.2025 13:13 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
Preview
KongTuke FileFix Leads to New Interlock RAT Variant Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware,…

🚨 New Interlock RAT variant spotted!

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT).

πŸ”Ž thedfirreport.com/2025/07/14/k...

#DFIR #KongTuke #InterlockRAT #FileFix

14.07.2025 11:36 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
DFIR Labs - Digital Forensics Challenge - Enterprise Edition

πŸ“’DFIR Labs Enterprise Forensics ChallengeπŸ“’

πŸ”Ή When: Aug 30, 2025 (14:00-18:00 UTC)
πŸ”Ή SIEM: Azure Log Analytics, Elastic, or Splunk
πŸ”Ή Teams: 2-3 analysts
πŸ”Ή Prizes: Top team wins! πŸ†

Limited spots available.

Register Now: dfirlabs.thedfirreport.com/dfirchalleng...

25.06.2025 12:27 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Hide Your RDP: Password Spray Leads to RansomHub Deployment Key Takeaways Initial access was via a password spray attack against an exposed RDP server, targeting numerous accounts over a four-hour period. Mimikatz and Nirsoft were used to harvest credential…

🌟New report out today!🌟

Hide Your RDP: Password Spray Leads to RansomHub Deployment

Analysis and reporting completed by @tas_kmanager, @iiamaleks and UC2

πŸ”ŠAudio: Available on Spotify, Apple, YouTube and more!

thedfirreport.com/2025/06/30/h...

30.06.2025 11:17 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
The Hive Ransomware Fail - Public Case #18364 This case is based on the public report From ScreenConnect to Hive Ransomware in 61 hours. You will investigate a domain-wide compromise that progressed through multiple stages, beginning with the abu...

Buy Now: store.thedfirreport.com/products/the... (or use your subscription token πŸ˜‰)

Oh, and the dashboard?

We gave it a full UI refresh. Cleaner, faster, easier to use. Hope you enjoy it!

2/2

27.06.2025 14:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A New DFIR Lab is out: The Hive Ransomware Fail 🐝

A domain is under siege, can you trace the threat actor's steps? Sharpen your triage and lateral movement skills in this hands-on investigation.

➑️Difficulty: Easy

1/2

27.06.2025 14:37 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Microsoft Forms

πŸ”Ž We're Hiring: Senior Security Analyst

We're looking for a full-time Senior Security Analyst with a passion for dissecting intrusions and translating technical findings into actionable insights.

Check out the full job description and apply here πŸ‘‰ forms.office.com/r/87y8wAp3gA

26.06.2025 12:28 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
DFIR Labs - Digital Forensics Challenge - Enterprise Edition

πŸ“’DFIR Labs Enterprise Forensics ChallengeπŸ“’

πŸ”Ή When: Aug 30, 2025 (14:00-18:00 UTC)
πŸ”Ή SIEM: Azure Log Analytics, Elastic, or Splunk
πŸ”Ή Teams: 2-3 analysts
πŸ”Ή Prizes: Top team wins! πŸ†

Limited spots available.

Register Now: dfirlabs.thedfirreport.com/dfirchalleng...

25.06.2025 12:27 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
DFIR Labs - Subscription Plans

We built these plans to make high-quality DFIR training accessible to everyone.

Ready to dive in? Check out all the details and sign up today! πŸ‘‡

πŸ‘‰ dfirlabs.thedfirreport.com/subscription...

5/5

23.06.2025 14:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

For Teams:

Need to level up your whole crew? Our Enterprise plans are packed with features like bulk tokens, detailed usage reporting, 7-day lab access, and priority support. Everything your team needs to sharpen their skills together!

4/5

23.06.2025 14:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

You'll get 1 token monthly, 2-day lab access, quiz retries, and rollover β€” all designed for continuous growth, not just one-time learning.

3/5

23.06.2025 14:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

For Individuals:

Ready to get hands-on with real-world intrusion labs? Our Individual plan is just $14.99/month for a limited time during launch week! Lock in this amazing discounted rate for as long as you're a member.

2/5

23.06.2025 14:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

πŸŽ‰ Huge News from DFIR Labs: Subscriptions are Here! πŸŽ‰

We're thrilled to announce that subscriptions are officially LIVE and we’re proud of what this means for the DFIR community πŸ’™

1/5

23.06.2025 14:22 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1
Preview
DFIR Discussions: Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware Reports Β· Episode

πŸŽ‰New DFIR Discussions EpisodeπŸŽ‰

πŸ”ŠAvailable on Spotify, Apple, & YouTube!

πŸŽ™οΈ We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang. Check it out and let us know what you think!

open.spotify.com/episode/1SKP...

16.06.2025 12:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 1

βš”οΈRegistration for the DFIR Labs Enterprise CTF is now LIVE! βš”οΈ

Assemble your elite SOC/IR team (up to 3 members) for a 4-hour competition to prove you're the best in the industry.

Win prizes, bragging rights, and glory! πŸ†

Register now! πŸ‘‰https://form.jotform.com/251605321344245

10.06.2025 18:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware Key Takeaways The threat actor first gained entry by exploiting a known vulnerability (CVE-2023-22527) on an internet-facing Confluence server, allowing for remote code execution. Using this access…

Haven't read the report yet?
➑️ thedfirreport.com/2025/05/19/a...

10.06.2025 12:06 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

πŸŽ™οΈ New Podcast Episode Dropping Soon!

We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang.

Stay tuned for deep insights, behind-the-scenes analysis, and expert commentary from the front lines of DFIR. πŸ”

10.06.2025 12:06 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
RansomHub Leads to Domain Compromise – Private Case #33490 This case is based on a Private Threat Brief. You’ll get to investigate a domain-wide compromise involving a multi-stage intrusion that started with a password spraying attack. The threat actor establ...

If you missed the CTF or want to relive the madness:

➑️ RansomHub Leads to Domain Compromise Lab : store.thedfirreport.com/products/ran...

Same 6-day intrusion. Same host sprawl. Same telemetry.

Take your time, pivot your way through, and sharpen those investigation skills.

08.06.2025 12:34 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Huge thanks to everyone who participated, helped organize, and supported this event. We hope you had as much fun as we did β€” and we can't wait to see you at the next one!

And now… the lab that powered the whole event is live and available πŸ”₯

08.06.2025 12:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

🚨 That CTF finale was wild. Only 300 points between 1st and 3rd β€” it stayed neck-and-neck till the very last minute.

Big congrats to our winners!

πŸ₯‡ @Friffnz β€” 5100 pts
πŸ₯ˆ snail β€” 4840 pts
πŸ₯‰ forynsics β€” 4800 pts

08.06.2025 12:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

🚨 CTF is starting soon!🚨

Don't Miss the DFIR Labs CTF - Registration Still Open!

➑️When: Today, June 7th | 16:30–20:30 UTC
➑️➑️Register: dfirlabs.thedfirreport.com/ctf

07.06.2025 12:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

/1
🚨 𝐂𝐓𝐅 𝐀𝐒𝐜𝐀𝐬 𝐨𝐟𝐟 𝐒𝐧 π₯𝐞𝐬𝐬 𝐭𝐑𝐚𝐧 48𝐑 - 𝐚𝐧𝐝 𝐭𝐑𝐒𝐬 π¨π§πžβ€™π¬ 𝐛𝐒𝐠.
One of the most involved cases we’ve ever made available to the public.

You’ll be diving into an intrusion that hit 18 hosts, including:
➑️ Domain Controllers
➑️ Backup Servers
➑️ Hypervisors
➑️ RDP Servers (Guess the initial access gonna be? 😏)

05.06.2025 17:07 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
Contact Us PGP Key

➑️ The above is from a recent Private Threat Brief: "Interlock-Linked Threat Actor Gains Access via Fake Teams ClickFix Lure"

➑️➑️Interested in receiving reports like this one? Contact us for a demo or pricing - thedfirreport.com/contact/

3/3

05.06.2025 12:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The malware in this case took 15 minutes to establish a successful connection to an online endpoint at hxxp://bristol-weed-martin-know[.]trycloudflare[.]com/init1234."

2/3

05.06.2025 12:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

"The remote endpoints it attempted to contact included several TryCloudflare domains as well as direct IP addresses.

The logic would rotate through the various servers until an online host was found.

1/3

#dfir #CyberSecurity #cyberthreatintelligence #cti #interlock #ransomware

05.06.2025 12:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

🎯 THIS SATURDAY: DFIR Labs CTF 🎯

⏰ June 7 | 1630–2030 UTC
πŸ”— Register Now β†’ dfirlabs.thedfirreport.com/ctf

πŸš€ DFIR Labs CTF is back!
πŸ’₯ Only $9.99 to join
πŸ’₯ Choose Elastic or Splunk
πŸ’₯ Access a brand-new, unreleased case
πŸ’₯ Top 5 get invited to join The DFIR Report team!

04.06.2025 12:04 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1

We had a blast speaking at the Ransomware Summit! 🎀πŸ’₯
Huge thanks to everyone involved!

πŸŽ₯ Missed our keynote? No worries β€” you can catch the full session here:

πŸ‘‰ www.youtube.com/live/nhB-xkm...

02.06.2025 13:22 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ”₯ DFIR Labs is Evolving! Have You Seen What's New? πŸ”₯

Big things are happening at DFIR Labs! We've been hard at work implementing a wave of exciting changes and improvements, all designed to enhance your experience!

➑️ Check it out now! dfirlabs.thedfirreport.com

22.05.2025 18:44 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Interested in receiving private reports similar to this report? Contact us for pricing - thedfirreport.com/contact/

4/4

22.05.2025 12:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0