Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.
How does water holing attack work?
- The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
DragonForce Breaches Major UK Retailers – And Exposes a Bigger Enterprise Threat
🚨 DragonForce Just Breached M&S, Co-op & Harrods – Using Nothing But Social Engineering.
🤯 It started with a help desk call
🔓 Ended with stolen credentials + £30M in losses
👥 The human layer is now the primary attack surface
⚙️ DragonForce operates as a RaaS cartel – and they’re scaling
🧠 AUMINT’s Trident trains, simulates, and defends against exactly these attacks
📅 Don’t wait for the breach – simulate it: https://calendly.com/aumint/aumint-intro
#DragonForce #SocialEngineering #Ransomware #Cybersecurity #LLMSecurity #CISO #Trident #AUMINT
💬 LINKEDIN COMMENT
This is the new normal:
→ No exploit kits
→ No zero-days
→ Just one persuasive phone call
Social engineering has outpaced most technical defenses – especially at the help desk.
👇 How are you protecting your human endpoints today?
#CyberAwareness #HelpDeskSecurity #AUMINT #RaaS #Trident #NCSC #RetailSecurity