PULSE NAME
Ransomware attack on a small company via a large contractor
WHITE Ngc8211 PetrP.73 2026-04-26 Modified: 2026-05-26
7
IOCs
LOW VOLUME
A recent ransomware attack compromised the entire infrastructure of a small sports organization, exploiting vulnerabilities in a major software integrator contractor's systems. The attackers utilized a leaked exploit connected to the .NET Framework, which masqueraded as legitimate software installed on 1C systems. Notably, twelve hours before the ransomware encryption occurred, there were unauthorized login attempts from an atypical address by a service account with domain privileges, likely facilitated by a weak password. Following this infiltration, attackers leveraged Remote Desktop Protocol (RDP) to gain access to the systems, disabled antivirus tools, and executed the malicious payload known as Hardbit v4.2, which is categorized as Backdoor malware.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Mogwai
Indicators of Compromise (2 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1952f6477626d797f671f2a1d5d77bb0 2026-04-26
FileHash-MD5 8f412e708f2df13f6e85fc3f06816cc7 2026-04-26