Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.
How does water holing attack work?
- The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
🔒 9 Free Encryption Tools CISOs Trust with Sensitive Data 🔒
Protecting sensitive data is a top priority for CISOs – but strong encryption doesn’t have to come with a big price tag. Here are 9 trusted free encryption tools that help secure files, communications, and endpoints:
1️⃣ VeraCrypt – Open-source disk encryption for full volume and container protection.
🔗 https://www.veracrypt.fr/en/Home.html
2️⃣ GnuPG (GPG) – Encrypt emails, files, and communications with open-source public-key cryptography.
🔗 https://gnupg.org/
3️⃣ OpenSSL – Toolkit for SSL/TLS encryption, certificate generation, and secure communications.
🔗 https://www.openssl.org/
4️⃣ AxCrypt – Free file encryption with secure password management for individuals and small teams.
🔗 https://www.axcrypt.net/
5️⃣ BitLocker (Windows Free Edition) – Full-disk encryption built into Windows Pro editions.
🔗 https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/
6️⃣ Cryptomator – Open-source encryption for cloud storage files and folders.
🔗 https://cryptomator.org/
7️⃣ KeePassXC – Open-source password manager with strong encryption for credentials.
🔗 https://keepassxc.org/
8️⃣ OpenSSH – Secure shell and encrypted file transfer for remote systems.
🔗 https://www.openssh.com/
9️⃣ 7-Zip – File archiver with AES-256 encryption for secure storage and transfer.
🔗 https://www.7-zip.org/
⚡ These tools help CISOs secure endpoints, emails, cloud data, and communication channels without licensing overhead.
At AUMINT.io, we complement these technical defenses by simulating human-targeted attacks, ensuring your employees understand encryption importance and don’t create accidental leaks.
🔗 Want to see where your human layer could undermine your encryption strategy? Book a free demo
#CISO #Encryption #CyberSecurity #DataProtection #AUMINT