200-201 · Question #213
According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt Strike that has been
The correct answer is B. ransomware attack. The attack described, which involves data exfiltration and threatening public release if payment is not made, is a clear example of a modern ransomware attack, specifically employing a 'double extortion' tactic.
Question
According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt Strike that has been installed on victim's workstations using RDP exploits Malware exfiltrates the victim's data to a command and control server. The data is used to force victims pay or lose it by publicly releasing it. Which type of attack is described?
Options
- Amalware attack
- Bransomware attack
- Cwhale-phishing
- Dinsider threat
How the community answered
(38 responses)- A3% (1)
- B82% (31)
- C11% (4)
- D5% (2)
Why each option
The attack described, which involves data exfiltration and threatening public release if payment is not made, is a clear example of a modern ransomware attack, specifically employing a 'double extortion' tactic.
While Egregor is malware, 'malware attack' is a broad category, and 'ransomware attack' is a more specific and accurate classification given the detailed attack methodology and motivation.
The description details a ransomware attack, characterized by the exfiltration of data and the threat of public release to compel victims to pay a ransom, a common tactic known as double extortion.
Whale-phishing is a social engineering attack targeting high-value individuals, which is not the primary mechanism described for Egregor's distribution via RDP exploits.
An insider threat involves malicious activity by an authorized individual within an organization, which contradicts the external RDP exploits and malware distribution described.
Concept tested: Identifying ransomware characteristics
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/intelligence/ransomware
Topics
Community Discussion
No community discussion yet for this question.