Post #4042609
2026-07-23 17:56 UTC
@neurovagrant@masto.deoan.org They analyzed 6 year old TrickBot samples. The anchor_dns campaign was studied and reported on to great length back in 2019/2020. I can recommend reading CISA's AA20-302A report from October 2020 for more details.
https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf
Replies (1)
-
@netresec@infosec.exchange 2026-07-23 17:57
@neurovagrant@masto.deoan.org The C2 commands were also documented back in 2020. https://www.netscout.com/blog/asert/dropping-anchor