Kuwait Press Memory Latest news
alanbaGeneral News

Warning: A single password could leave your company wide open to hackers

Warning: A single password could leave your company wide open to hackers

Breach of corporate networks no longer always requires complex software; a single employee’s password may be sufficient to hand hackers the keys to the entire network. This was revealed by a specialized firm regarding an attack targeting a manufacturing company in the Middle East.

The attackers obtained the credentials of users with elevated privileges, likely through phishing, and then accessed the company’s network remotely via VPN connections, appearing to security systems as legitimate employees rather than intruders.

Once inside, the hackers exploited existing administrative tools within the organization, reached the Active Directory that controls the network, and created a malicious object named “PAYLOAD.” This allowed them to execute commands on corporate devices, disable administrator accounts, shut down computers, and change desktop backgrounds and lock screens with ransom demands.

However, the greatest danger was that the attackers did not need to encrypt files; instead, they exfiltrated sensitive data and threatened to publish it on the dark web.

The incident highlights the rising trend of “ransomware without encryption,” where stolen credentials become a weapon enabling hackers to move within the company under the privileges of its employees, before leveraging sensitive information as leverage to extort the organization.

#Passwords #Software #Hackers

Latest news Original source
Link copied ✓