Attackers behind a Midas ransomware intrusion spent at least two months inside an unnamed technology vendor before launching encryption, using a combination of internal RDP, PowerShell, DISM, AnyDesk, TeamViewer, and Process Hacker (now known as System Informer) to move laterally and prepare the environment. Investigators found evidence that the intruders gained administrator-level access to a domain controller, harvested credentials with Mimikatz, exfiltrated data, and repeatedly created malicious Windows services to maintain access and stage the attack.
The operation culminated in the deployment of a malicious DismCore.dll through DLL sideloading and the start of ransomware activity on a limited number of servers. Response efforts interrupted the attack before broader encryption could occur, but the case highlighted how a flat network, unused remote-access tools, weak monitoring, and the absence of MFA increased the victim’s exposure and enabled the attackers to establish persistence, escalate privileges, and advance toward ransomware execution.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Sophos Rapid Response was engaged on December 8 and blocked further attacker activity. As a result, the ransomware impact was limited to a small number of servers.
Late on December 7, attackers began deploying ransomware binaries named for the target organization to victim machines. They also created a Windows service to run Process Hacker and used PowerShell to try to terminate dozens of processes and services before encryption.
Antivirus detected Mimikatz on one server, while investigators believed the tool had been successfully executed on another server the previous day. The finding showed active credential-harvesting during the intrusion.
After a three-week lull, the attackers became active again in the victim environment. The renewed activity preceded credential theft detections and further internal movement.
The attackers resumed activity on additional machines, again using service creation and PowerShell execution. This marked a renewed phase of lateral movement after the earlier October activity.
Investigators observed additional internal RDP connections during this period, indicating continued lateral movement inside the victim network. The activity followed the Mimikatz-related detections.
Logs showed a successful RDP login to a compromised domain controller using the Administrator account. Investigators cited this as evidence of administrator-level access during the intrusion.
Between October 13 and October 19, attackers created malicious Windows services and used PowerShell over SMB to spread backdoors across multiple servers. This activity established persistence and prepared later lateral movement.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.