{"id":1313,"date":"2025-04-12T19:36:17","date_gmt":"2025-04-12T19:36:17","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=1313"},"modified":"2025-04-12T19:36:17","modified_gmt":"2025-04-12T19:36:17","slug":"ransomware-hackers-goal-lively-listing-area-controllers","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=1313","title":{"rendered":"Ransomware Hackers Goal Lively Listing Area Controllers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"generic-article\">\n<p class=\"text-muted\">\n                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/active-directory-c-809\" id=\"asset_topic_1_1\">Lively Listing<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/fraud-management-cybercrime-c-409\" id=\"asset_topic_1_2\">Fraud Administration &amp; Cybercrime<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/ransomware-c-399\" id=\"asset_topic_1_3\">Ransomware<\/a>\n                                                                                                <\/p>\n<p>                    <span class=\"article-sub-title\">Area Controllers Commandeered to Distribute Malware, Warns Microsoft<\/span><br \/>\n                <span class=\"article-byline\"><br \/>\n                                                <a rel=\"nofollow\" target=\"_blank\" class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/akshaya-asokan-i-2924\">Akshaya Asokan<\/a> (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.twitter.com\/asokan_akshaya\"><i class=\"fa fa-twitter\"\/>asokan_akshaya<\/a>)                                                    \u2022<br \/>\n                        <span class=\"text-nowrap\">April 11, 2025<\/span> \u00a0 \u00a0 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/ransomware-hackers-target-active-directory-domain-controllers-a-27981#disqus_thread\"\/><\/span><\/p>\n<figure>\n                <img decoding=\"async\" src=\"https:\/\/130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com\/ransomware-hackers-target-active-directory-domain-controllers-showcase_image-1-a-27981.jpeg\" alt=\"Ransomware Hackers Target Active Directory Domain Controllers\" class=\"img-responsive \"\/><figcaption>(Picture: Shutterstock)<\/figcaption><\/figure>\n<p> Ransomware hackers are hitting up Lively Listing area controllers to spice up privileges inside compromised networks, warns Microsoft.<\/p>\n<p><b>See Additionally:<\/b> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/top-10-technical-predictions-for-2025-a-27521?rf=RAM_SeeAlso\">High 10 Technical Predictions for 2025<\/a><\/p>\n<p>&#13;<\/p>\n<p>Almost eight out of each 10 human-operated cyberattacks entails a breached area controller, the computing big <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/04\/09\/how-cyberattackers-exploit-domain-controllers-using-ransomware\/\" target=\"_blank\">mentioned<\/a> in a Wednesday weblog publish. In additional than three out of 10 hacks, the system answerable for distributing crypto-locking software program throughout a company is a site controller.<\/p>\n<p>&#13;<\/p>\n<p>A compromise of area controllers permits hackers to extract password hashes for each consumer account, which they&#8217;ll use to establish high-privilege accounts, akin to these of the IT admins. By manipulating these accounts, the attackers can escalate privileges.<\/p>\n<p>&#13;<\/p>\n<p>&#8220;This stage of entry permits them to deploy ransomware on a scale, maximizing the impression of their assault,&#8221; Microsoft mentioned.&#13;\n<\/p>\n<p>In a single case noticed by Microsoft, a hacking group it tracked as Storm-0300 tried to hold out a ransomware assault after gaining preliminary entry by means of the goal&#8217;s digital non-public community.<\/p>\n<p>&#13;<\/p>\n<p>The hacker gained admin credentials and tried to hook up with the area controller utilizing distant desktop protocol. The hackers proceeded to conduct reconnaissance, safety evasion, as effectively privilege escalation.<\/p>\n<p>&#13;<\/p>\n<p>Microsoft provides that regardless of growing assaults focusing on area controllers, securing the servers is a problem resulting from their central function in community safety.<\/p>\n<p>&#13;<\/p>\n<p>The servers have to authenticate customers and to handle assets, so the problem for community defenders usually is &#8220;placing the fitting steadiness between safety and operational performance.&#8221;<\/p>\n<p>&#13;<\/p>\n<p>Constructing capabilities that may permit area controllers to tell apart between malicious and benign conduct is a possible step to keep away from the server compromise, Microsoft mentioned.<\/p>\n<p> &#13;<\/p>\n<p>Whereas Microsoft offers &#8220;strong defenses,&#8221; their effectiveness depends on prospects repeatedly patching and enabling multifactor authentication, mentioned Jason Soroko, a senior fellow at safety agency Sectigo.<\/p>\n<p>&#13;<\/p>\n<p>&#8220;Finally, even essentially the most superior protection mechanisms might falter if misconfigured or if legacy programs create vulnerabilities. Therefore, vigilant customer-side safety practices is essential to fortifying these programs in opposition to trendy cyber threats,&#8221; Sectigo mentioned.<\/p>\n<\/p><\/div>\n<p><template id="oUZif3s4R5PvBGdqWTKE"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lively Listing , Fraud Administration &amp; Cybercrime , Ransomware Area Controllers Commandeered to Distribute Malware, Warns Microsoft Akshaya Asokan (asokan_akshaya) \u2022 April 11, 2025 \u00a0 \u00a0 (Picture: Shutterstock) Ransomware hackers are hitting up Lively Listing area controllers to spice up privileges inside compromised networks, warns Microsoft. See Additionally: High 10 Technical Predictions for 2025 &#13; [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1315,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[768,1188,1155,1187,554,500,70],"class_list":["post-1313","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-active","tag-controllers","tag-directory","tag-domain","tag-hackers","tag-ransomware","tag-target"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1313"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1313\/revisions"}],"predecessor-version":[{"id":1314,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1313\/revisions\/1314"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/1315"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:44:29 UTC -->