A mid-sized media company was hit by a REvil ransomware intrusion in which attackers compromised accounts, deployed Cobalt Strike, and installed ScreenConnect on roughly 130 endpoints to maintain persistence and remote access. During the attack, the intruders stole domain administrator credentials and created their own domain admin account, escalating control across the environment before launching ransomware and demanding $2.5 million.
The incident was contained during a live response effort involving the company’s IT team and Sophos Rapid Response, preventing a full operational shutdown, but the attackers still encrypted data on unprotected devices, deleted online backups, and destroyed a previously air-gapped domain after it had been connected to the internet. The case underscored how uneven endpoint protection, exposed or newly connected systems, and limited visibility into unmanaged assets can allow ransomware operators to expand quickly inside a network.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
By the second day of the incident, only intermittent inbound attacks were still being detected and the main attack attempt had ended. The attack failed to fully cripple the company, and the ransom was not paid.
Despite containment efforts, the attackers encrypted data on unprotected devices, deleted the company’s online backups, and destroyed an online undefended domain that had previously been air-gapped. The damage was mainly limited to unprotected devices and domains.
The company’s IT team and Sophos Rapid Response engaged the attackers in a live response effort lasting about four hours during the main attack phase. Sophos CryptoGuard blocked some remote encryption attempts, but attackers repeatedly relaunched encryption from different compromised unprotected devices.
A few hours after the initial Cobalt Strike detection, at about 4 a.m. local time, the attackers deployed REvil ransomware. The ransom note demanded $2.5 million.
During the intrusion, the attackers installed ScreenConnect on 130 endpoints for persistence, stole domain administrator credentials, and created their own domain admin account. They also moved laterally through unprotected computers and maintained access across the environment.
In early June 2021, a mid-sized media company detected Cobalt Strike activity on its network, marking the start of the incident described in the source. Attackers had already compromised multiple accounts by this stage, including an IT staff account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.