
Threat Hunting Case Study: FileFix
FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

Ransomware attacks have sharply increased in 2023, and payments to ransomware gangs and affiliates are nearing all-time highs. With law enforcement and governments sharply focused on disrupting and imposing costs on ransomware groups, why is ransomware stubbornly sticking around?
In this edition of Studio 471, Jacqueline Burns Koven of Chainalysis discusses how ransomware is evolving and what challenges it poses for defenders.
Participants:
Jacqueline Burns Koven, Head of Cyber Threat Intelligence, Chainalysis
Jeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471

FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

Gentlemen ransomware uses credential abuse, defense evasion, and double extortion tactics to compromise enterprise environments and increase pressure on victims.

TeamPCP is exploiting trusted npm and PyPI packages to compromise developer environments, steal credentials, and extend attacks across software supply chains.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.