Mandiant reported a red team exercise at a European engineering organization that demonstrated how a financially motivated actor using FIN11-style tactics could move from a standard corporate endpoint into operational technology environments. Starting with regular employee credentials, the team was able to escalate access to domain administrator, steal critical data, and reach OT servers, illustrating how weaknesses between enterprise and OT networks can enable ransomware operators to extend an intrusion beyond traditional IT systems.
The report warns that OT environments remain exposed even though many ransomware incidents have primarily affected enterprise networks. Mandiant said financially motivated groups are increasingly using tradecraft associated with more advanced intrusions, and cited prior CLOP activity linked to FIN11 that used a process kill list containing OT-related processes. That overlap suggests ransomware operators may be capable of disrupting or encrypting critical OT functions without needing deep, specialized OT expertise.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Mandiant published a report concluding that OT environments remain at risk from financially motivated actors using ransomware tradecraft similar to advanced intrusion activity. The report also cited prior FIN11-linked CLOP activity that used a process kill list including some OT-related processes, underscoring potential disruption to critical OT functions.
Mandiant carried out a red team engagement for a European engineering organization to test whether ransomware-operator tactics could move from a standard corporate endpoint into operational technology environments. The exercise demonstrated a path from ordinary employee credentials to domain administrator access, data theft, and access to OT servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.