View the latest
DFIR Report
  • Public Reports
  • Products
      • Products Overview
      • Threat Intel
        • Threat Feed
        • Private DFIR Reports
        • All Intel
        • Active Defense
      • DFIR Labs
      • Case Artifacts
      • -
      • Detection Pack
      • AI Training Ground
      • -
        bruteratel
        From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
        Read More
      • -
        dragonforce
        Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
        Read More
  • Services
      • Services Overview
      • Training
        • Threat Hunting
      • -
      • Professional Services
        • Integration
        • CTI Program Advisory
        • Incident Response Playbook
  • Company
      • About us
      • Contact Us
      • Collaboration
      • Careers
  • Analysts
  • Access DFIR Labs
  • Get in Touch
  • Public Reports
  • Products
    • Products Overview
    • Threat Intel
      • Threat intel Overview
      • Threat Feed
      • Private DFIR Reports
      • All Intel
      • Active Defense
    • DFIR Labs
    • Case Artifacts
    • Detection Pack
    • AI Training Ground
  • Services
    • Service Overview
    • Training
      • Threat Hunting
    • Professional Services
      • Integration
      • CTI Program Advisory
      • Incident Response Playbook
  • Company
    • Company Overview
    • About us
    • Contact Us
    • Careers
  • Analyst
  • SQL Brute Force Leads to BlueSky Ransomware
  • From OneNote to RansomNote: An Ice Cold Intrusion

UC2

Back to Analysts
UC2

Reports by UC2

ransomhub ransomware rdp
Hide Your RDP: Password Spray Leads to RansomHub Deployment
June 30, 2025
Read More
alphv cobaltstrike icedid
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
June 10, 2024
Read More
Hive cobaltstrike ransomware
From ScreenConnect to Hive Ransomware in 61 hours
September 25, 2023
Read More
Access DFIR Labs Book a Demo

The DFIR Report provides in-depth, real-world intelligence based on observed intrusions, enabling security analysts and teams 
to strengthen defenses, enhance detection, 
and accelerate response.

  • Linkedin
  • X
  • Products
    • Threat Intel
    • DFIR Labs
    • Case Artifacts
    • Threat Feed
    • Detection Pack
    • Active Defense
  • Services
    • Training
    • Professional Services
  • Public Reports
  • Company
    • About us
    • Analysts
    • Careers
    • Contact Us

© 2025 The DFIR Report. All Rights Reserved. | Privacy Policy