Cyber Threat Report: 'From OneNote to RansomNote: An Ice Cold Intrusion'

Report Author The DFIR Report
Publication Date 2024-04-01
Original Reporting Source
Related Intrusion Sets Nokoyawa Ransomware Group

This case report from The DFIR Report describes an intrusion which started with a malicious OneNote attachment. Opening the OneNote file led to the download of an IcedID DLL from a remote server. Following discovery activities, on day 33 of the intrusion IcedID was used to launch multiple CobaltStrike beacons. The threat actor installed AnyDesk for additional remote access and then utilised FileZilla to exfiltrate data. Finally the actor deployed a variant of the Nokoyawa ransomware to encrypt data.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques