Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
The Hidden Insider Threat Youβre Probably Ignoring β Ex-Employee Password Access
π Ex-Employees Still Have Your Passwords β And Theyβre Using Them
π¨ Many workers admit theyβve logged in to former employersβ accounts after leaving β and sometimes months later.
π₯ Itβs a silent insider threat that bypasses firewalls and phishing filters entirely.
π΅οΈ The real danger? Credentials that stay active long after offboarding, often with access to sensitive systems, customer data, or financial platforms.
β οΈ In some cases, ex-staff under strained exits can exploit this for sabotage or even sell access on the dark web.
π Even βfriendlyβ departures can lead to accidental leaks if accounts arenβt properly closed.
π The fix? Immediate credential deactivation, MFA, and ongoing account audits to spot dormant access before itβs abused.
π’ Your next security breach could come from someone who already knows your systems. Book your AUMINT.io consultation today.
#CyberSecurity #InsiderThreats #AccessControl #FraudPrevention #RiskManagement #CISOs #ITSecurity #DataProtection