
Qilin: Veeam credential abuse to ESXi hypervisor encryption
A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Find the way in
50A manufacturing network with an internet-facing SSL-VPN edge saw a run of malformed remote-access requests this morning, immediately before an outsider established a session. Work the perimeter records and identify the external address that exploited the edge device.
Identify the looted server
55Once inside, the operator went straight for a server that stores credentials it could reuse. Determine which host had its stored credentials read out of a product configuration database.
Pin the operator's address
55The hands-on operator worked through the VPN to reach that server over RDP. Identify the external address the operator used so it can be blocked and hunted across the estate.
Catch the reach to the hypervisor
60From the looted server the operator self-propagated and reached the virtualization management plane. Identify the management host the propagation routine deliberately targeted.
Follow the data out
55Before the hypervisor was touched, engineering data was copied out of the network. Identify the external host the stolen data was transferred to.
Confirm the hypervisor impact
60Late in the day the virtualization layer was encrypted. Determine the file extension that was appended to the encrypted virtual-machine disk files on the datastores.
Classify the recovery sabotage
50Just before encryption, the operator made sure the victim could not simply restart the affected workloads. Map that anti-recovery activity at the hypervisor to the MITRE ATT&CK technique it represents.
7 tasks · 385 points total
Training Tools
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allMedusa RaaS: VPN access to enterprise encryption
A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.
Play (Playcrypt): FortiOS + Exchange to Double Extortion
Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.
BianLian: Exfiltration-Based Extortion
A threat actor with a valid domain account and no MFA to stop them lands on an internet-facing RDP jump host, spends the morning living off the land, dumps credentials from LSASS, and spends the afternoon moving approximately 47 GB of engineering documents out of the network through a cloud-sync utility pointed at storage they control. No files are encrypted; the leverage is the stolen data itself. Reconstruct the full chain from initial RDP spray to log wipe.