Attackers used Windows services, stolen or abused administrative access, and legitimate remote-management tools to prepare and launch a Midas ransomware intrusion against an unnamed technology vendor. The operation reportedly lasted at least two months before ransomware was deployed, with the attackers moving laterally through the environment using PowerShell, DISM, RDP, AnyDesk, TeamViewer, and Process Hacker, while also harvesting credentials and exfiltrating data. Investigators found evidence of Mimikatz use on at least one server, abuse of administrator-level access on a domain controller, and the creation of services to execute obfuscated scripts and malicious DismCore.dll backdoors.
The victim’s environment reportedly enabled the intrusion through a flat network, broad VPN access, weak segmentation, and unused remote-access tools left installed on servers. Ransomware deployment began in early December, but the impact was limited to a small number of servers after incident responders intervened and blocked further attacker activity. The case highlights the operational risk posed by unmanaged remote-control software and insufficient monitoring of service creation, lateral movement, privileged access, and remote administration pathways, alongside the need for MFA and stronger segmentation or ZTNA-style controls.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Sophos Rapid Response was engaged and blocked further attacker activity, limiting the ransomware impact to a small number of servers.
The attackers began deploying Midas ransomware across the victim environment, transitioning from stealthy intrusion activity to overt impact.
Investigators observed another pause in attacker activity after November 29, shortly before the ransomware stage began.
The attackers made further internal RDP connections during this period, indicating continued lateral movement before ransomware deployment.
Logs showed a file named Passwords.txt containing harvested credentials was written under C:\Compaq\!logs\ on a compromised domain controller, and some machines detected and blocked Mimikatz the same day.
Investigators believe the attackers successfully executed Mimikatz on at least one server the day before detections occurred elsewhere, as part of credential harvesting activity.
The attackers resumed activity by installing services and executing PowerShell scripts on additional machines, expanding their foothold in the victim environment.
The intrusion entered another pause after November 2 before later resuming, reflecting repeated stop-start attacker behavior during the dwell period.
Investigators found evidence that AnyDesk had been used 13 times on one compromised server, showing the attackers were leveraging commercial remote access software for movement or exfiltration.
Investigators observed a lull in attacker activity after October 19, suggesting the intrusion proceeded in intermittent stages rather than continuously.
The earliest logged indicator of compromise occurred when two different internal machines used RDP to log into a compromised domain controller as Administrator, indicating the attackers had obtained or abused high-level access.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.