Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
π§ CISOs: Best Free Resources to Understand Ransomware Trends π§
Ransomware isnβt slowing down β itβs evolving.
To stay ahead, CISOs need more than just protection tools. You need intelligence: real-time insights, attacker TTPs, and evolving trends β without paying for expensive threat feeds.
Here are the top free resources to track ransomware evolution, tactics, and sector-specific risks:
1οΈβ£ CISA Ransomware Resources Hub β Government-grade alerts, advisories, and toolkits.
https://www.cisa.gov/stopransomware
2οΈβ£ ID Ransomware β Upload samples or notes to identify the ransomware variant attacking your org.
https://id-ransomware.malwarehunterteam.com/
3οΈβ£ The DFIR Report β Ransomware Editions β Deep-dive incident reports from real-world infections.
https://thedfirreport.com/
4οΈβ£ Ransomware.live β Live tracking of known ransomware groups and active leaks.
https://ransomware.live/
5οΈβ£ Unit42 Ransomware Threat Intelligence β Palo Altoβs research arm offers constant updates on group behaviors.
https://unit42.paloaltonetworks.com/category/ransomware/
6οΈβ£ No More Ransom Project β Joint initiative offering decryptors and prevention tools.
https://www.nomoreransom.org/
7οΈβ£ MITRE ATT&CK Ransomware Map β Understand tactics and techniques behind ransomware campaigns.
https://attack.mitre.org
8οΈβ£ RedSense (by Recorded Future) β Updated dashboards with ransomware actor profiles and IOCs.
https://www.recordedfuture.com/resources
Want to combine intelligence with simulation? π§ AUMINT.io empowers CISOs with recurring, targeted social engineering attack simulations that test human readiness against ransomware vectors.
Book a free intro call today: Schedule here
πΎ Save this post β and bookmark these resources to keep your SOC informed, alert, and one step ahead.
#CISO #Ransomware #ThreatIntel #CyberSecurity #InfoSec #AUMINT