securelist · Crawled Aug 3, 2026
An analysis of incidents at Brazilian educational institutions
7 IoCs 1 Actors
Read original article ↗
AI Summary
SecureList analyzed cyber incidents at Brazilian educational institutions from 2025 to 2026, identifying ransomware attacks and insider threats. Two major ransomware families observed were LockBit 3 and DragonForce, with attackers using leaked LockBit builders and valid credentials for initial access. In one case, LockBit was deployed via PsExec after disabling defenses using a batch script; in another, DragonForce was delivered via AnyDesk. An insider used a custom Python keylogger to capture credentials on shared machines, storing logs in hidden files later retrieved via USB.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 7 extracted
MITRE ATT&CK TTPs 47 techniques
T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1052.001 Exfiltration over USB · Exfiltration T1053 Scheduled Task/Job · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1219 Remote Access Software · Command And Control T1222 File and Directory Permissions Modification · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1569.002 Service Execution · Execution T1573 Encrypted Channel · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access