How the RSM Defense Threat Hunting Team uncovered a sophisticated fileless RAT using one of their 300+ in-house custom detections. . Published by the RSM Defense Threat Hunting Team Author: Justin Dolgos, Threat Hunting Supervisor The Short Version Every organization generates noise. Millions of events, thousands of alerts, and endless telemetry pour into a security ... READ MORE
Defense
The Threat That Slipped Past the Machines, and Ran Into a Human
How proactive threat hunting caught an attack engineered to evade the industry's leading endpoint platforms. By Justin Dolgos, Senior Threat Hunter at RSM Defense Most malware tries to avoid your security tools. This one knew them by name. Modern attackers have learned that the fastest way past a hardened security stack is not to break it. It is to convince a trusted ... READ MORE
When Your Browser Becomes the Attacker: Detecting Drive-By Script Execution in the Wild
Published by The RSM Defense Threat Hunting Team Author: Justin Dolgos - Sr. Threat Hunter MITRE ATT&CK: T1204.002 · T1059 · T1218 · T1219 · T1222 ⚠ TLDR Executive Summary Our threat hunters built a custom detection that fires the moment a browser or Windows Explorer spawns a script or suspicious executable from a user-writable directory. In a recent ... READ MORE
Fake Captcha Chains – Portable Behaviors, Practical Detections, And Field Notes
Executive Summary RSM Defense’s Threat Hunting Team performed a focused investigation after reviewing recent intelligence on the “Fake CAPTCHA” campaign. Our hypothesis was: “If the actor is in the environment, we may observe escaped or obfuscated PowerShell commands (for example h^t^t^p) used to download and stage payloads.” The hunt confirmed activity that occurred over a ... READ MORE
Threat Hunting Win: Uncovering Multi-Stage Malware from RMM Abuse
At RSM Defense, we embrace a proactive approach to cybersecurity. Instead of waiting for alerts to trigger a response, our Threat Hunting team regularly conducts hypothesis-driven investigations. These investigations are designed to uncover subtle threats hiding within behavior that might seem legitimate. In late May 2025, our proactive approach paid off when we uncovered an ... READ MORE
Microsoft and HPE targeted by Cozy Bear in seemingly unrelated attacks
Over the past week, Microsoft and Hewlett Packard Enterprise (HPE) disclosed successful campaigns targeting the organizations by Russian-based threat actor Cozy Bear (aka Midnight Blizzard, aka APT29). Both campaigns conducted successfully obtained access to emails for both companies, including emails for senior leadership and cybersecurity positions. Neither Microsoft nor HPE ... READ MORE
Intel Insights – Phishing with QR Codes
A large phishing campaign using QR codes has been detected targeting various industries, with the aim to acquire Microsoft credentials. Researchers from the security firm, Cofense, observed the attacks against “a major Energy company based in the US.” The reported phishing campaign also targeted organizations in other industries, including finance, insurance, manufacturing, and ... READ MORE
Rhysida Ransomware Attack on PMH and Connections to Vice Society Ransomware
On August 4th, 2023, the parent company of Eastern Connecticut Health Network and Waterbury Health, Prospect Medical Holdings(PMH), announced that all of its facilities were facing IT complications. Prospect Medical Holdings is a parent company to over 16 hospitals, 165 outpatient clinics, in over 4 states ( California, Connecticut, Pennsylvania, Rhode Island) It was later ... READ MORE
STORM-0558 Utilizes Acquired MSA Keys to Forge Authentication Tokens Then Attack Outlook Exchange
On July 12, 2023, The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory (CSA)(aa23-193a) detailing an attack on an Federal Civilian Executive Branch (FCEB) agency in June 2023. The attack had been observed due to observing anomalous activity within the Microsoft 365 (M365) audit logs. ... READ MORE
AI Used in Scams: Faked Kidnapping
A mother of a 15-year-old girl, Jennifer DeStefano, received a disturbing phone call on January 20th, 2023, while taking her younger daughter, Aubrey, 13, to a dance rehearsal in Scottsdale Arizona. The call's caller ID showed an “Unknown number”, yet a familiar voice was heard on the other end of the telephone call. The voice belonged to her other teenager, Brianna ... READ MORE





