PULSE NAME
Ransomware attack on a small company via a large contractor
WHITE Ngc8211 PetrP.73 2026-04-26 Modified: 2026-05-26
7
IOCs
LOW VOLUME
A recent ransomware attack compromised the entire infrastructure of a small sports organization, exploiting vulnerabilities in a major software integrator contractor's systems. The attackers utilized a leaked exploit connected to the .NET Framework, which masqueraded as legitimate software installed on 1C systems. Notably, twelve hours before the ransomware encryption occurred, there were unauthorized login attempts from an atypical address by a service account with domain privileges, likely facilitated by a weak password. Following this infiltration, attackers leveraged Remote Desktop Protocol (RDP) to gain access to the systems, disabled antivirus tools, and executed the malicious payload known as Hardbit v4.2, which is categorized as Backdoor malware.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Mogwai
Indicators of Compromise (7)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1952f6477626d797f671f2a1d5d77bb0 2026-04-26
FileHash-MD5 8f412e708f2df13f6e85fc3f06816cc7 2026-04-26
FileHash-SHA1 5845f9046ba1e9822c89896154031491ffbf27d9 2026-04-26
FileHash-SHA1 8aa46d77c5491b1e407df9cdaf520937aa3a880b 2026-04-26
FileHash-SHA256 127bb4d31ac0bd83fa004971f745837cbcc1d5b524e2726b84448f9079a9d12e 2026-04-26
FileHash-SHA256 24995b545dc6844e7ddb378ccf3f73c97fb3a563d6722ff7ed18bf31258f5c8f 2026-04-26
domain shavezy.com 2026-04-26