216.73.216.6

From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion

· Published 29/09/2025 16:37 · Modified 30/09/2025 08:46

Export JSON

Essential information

Published
29/09/2025 16:37
Modified
30/09/2025 08:46
Tags
2025-09-29 backconnect brute ratel c4 cobalt strike credential harvesting data exfiltration javascript lateral movement latrodectus
Related entities
1 intrusion sets (apt), 25 techniques (mitre), 4 malware

Description

A user executed a malicious file linked to Lunar Spider, initiating a two-month intrusion. The file downloaded a Brute Ratel DLL, which then injected malware. The threat actor used various tools including , , and a custom .NET backdoor for persistence and . They harvested credentials from multiple sources and exfiltrated data using Rclone. The intrusion lasted nearly two months with intermittent C2 connections, discovery, , and data theft. Despite comprehensive access to critical infrastructure, no ransomware deployment was observed.