Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

How today’s threat actors break into companies | Kaspersky official blog

0
Medium
Vulnerability
Published: 06/29/2026 (06/29/2026, 11:31:33 UTC)
Source: Kaspersky Security Blog

Description

Three real-world case studies detailing how modern threat actors breach corporate environments, along with actionable takeaways to keep your organization out of the headlines.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/29/2026, 11:42:04 UTC

Technical Analysis

The Kaspersky blog post presents three detailed case studies of corporate cyberattacks investigated by their Global Emergency Response Team. The first case involved attackers gaining access through stolen local administrator credentials, escalating privileges using tools like Mimikatz and Invoke-TheHash, and deploying ransomware across the network. The second case describes a ransomware attack leveraging a monitoring server (PRTG) with excessive privileges to pivot into the network and encrypt virtual infrastructure. The third case involved exploitation of a known SAP NetWeaver vulnerability, which had a patch available for years but was not applied, allowing attackers to deploy wiper malware that irreversibly destroyed data. These incidents highlight that attackers often rely on credential theft, privilege abuse, and unpatched vulnerabilities rather than sophisticated zero-day exploits. The report stresses the importance of patch management, least privilege access, and continuous monitoring, recommending managed detection and response (MDR) and incident response services to detect and contain such attacks early.

Potential Impact

The impact includes enterprise-wide ransomware infections leading to data hostage situations, encryption of critical virtual environments, and permanent data destruction via wiper malware. These attacks can cause significant operational disruption, data loss, and financial damage. The exploitation of unpatched vulnerabilities and abuse of legitimate credentials enables attackers to move laterally and escalate privileges within corporate networks, increasing the scope and severity of breaches.

Mitigation Recommendations

The vendor recommends deploying comprehensive cybersecurity strategies combining specialized software and managed services. Key mitigations include: 1) Implementing round-the-clock monitoring via managed detection and response (MDR) services to detect early-stage threats; 2) Engaging incident response teams for rapid containment and recovery; 3) Prioritizing patch management with routine vulnerability scanning and patch deployment, especially for critical public-facing applications like SAP NetWeaver, Microsoft Exchange, SharePoint, and Active Directory; 4) Conducting security audits and hardening access controls to prevent excessive privileges, particularly on infrastructure monitoring servers; 5) Leveraging compromise assessments to detect exploitation of legacy vulnerabilities. No official patch status is applicable as this is a report of multiple incidents rather than a single vulnerability. The vendor advisory does not indicate that no action is required; rather, it emphasizes proactive defense and remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/gert-three-cases-report/56030/","fetched":true,"fetchedAt":"2026-06-29T11:41:55.040Z","wordCount":1678}

Threat ID: 6a425a0327e9c79719c7e1e6

Added to database: 06/29/2026, 11:41:55 UTC

Last enriched: 06/29/2026, 11:42:04 UTC

Last updated: 06/30/2026, 01:53:14 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses