Daily Dark Web
  • Home
  • Cyber Attacks
  • DarkWeb News
  • Data Breaches
  • Vulnerability
  • Ransomware News
  • Unauthorized Accesses
  • Contact
No Result
View All Result
  • Home
  • Cyber Attacks
  • DarkWeb News
  • Data Breaches
  • Vulnerability
  • Ransomware News
  • Unauthorized Accesses
  • Contact
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

Security Breach Exposes Italian Red Cross Network: Allegedly Threat Actor Shares Details of the Incident and Offers Backdoor Access

April 30, 2024
Reading Time: 1 min read
Security Breach Exposes Italian Red Cross Network: Allegedly Threat Actor Shares Details of the Incident and Offers Backdoor Access

Recently, there was claims a breach into the Italian Red Cross network, where the threat actor managed to infiltrate despite the presence of EDR/XDR technology, particularly Trend Micro Apex One, which proved ineffective in detecting or blocking the breach. With just a simple PHP shell, the threat actor gained access to the network and easily became the administrator of the company’s Active Directory.

Surprisingly, the breach did not involve sophisticated techniques like kerberoast or s4u, and the machines accessed from outside were vulnerable to various known exploits, facilitating Local Privilege Escalation (LPE). The threat actor discovered that the ‘master’ password, ‘Sviluppo.1864′ or ‘Sviluppo.1864!’, was widely used across local and network accounts.

Taking advantage of the company’s nighttime activity, as the EDR system sent alerts/events to the internal JIRA system, the breach was executed without much difficulty. The only hiccup occurred when the threat acto rstumbled upon 13TB of internal and non-internal videos, which were excluded from the data dump to avoid causing disruptions.

The breach yielded access to internal source codes, databases, backups, and more, but ransomware was deliberately avoided as the threat actor considered it unnecessary and amateurish. As a parting note, the threat actor encouraged others to mirror the data, citing issues with DMCA and Gofile’s policies. Additionally, a hidden backdoor for future access was hinted at, available upon request via private message.

 

Tags: EDRItalyRed CrossTrendMicroXDR
ShareTweet

Related Posts

Alleged Breach of Everest Bank Customer Database
Data Breaches

Alleged Breach of Everest Bank Customer Database

May 13, 2025
Allegedly Stolen Data from Brazilian Nuclear Company Nuclep Offered for Sale
Data Breaches

Allegedly Stolen Data from Brazilian Nuclear Company Nuclep Offered for Sale

May 12, 2025
Alleged Data Breach Claims Surface Against Boulanger on Dark Web Forum
Data Breaches

Alleged Data Breach Claims Surface Against Boulanger on Dark Web Forum

April 7, 2025
Alleged Data Breach Targets Yucatán Government Website
Data Breaches

Alleged Data Breach Targets Yucatán Government Website

April 7, 2025
Threat Actor Claims to Leak 600K Records from Spanish Robinson Database
Data Breaches

Threat Actor Claims to Leak 600K Records from Spanish Robinson Database

April 7, 2025
Alleged Data Leak Targets Indonesian Ministry of Transportation
Data Breaches

Alleged Data Leak Targets Indonesian Ministry of Transportation

April 3, 2025
Next Post
Data Breach KISTI SMART K2C: Allegedly 7.79 Million Users’ Information Exposed

Data Breach KISTI SMART K2C: Allegedly 7.79 Million Users' Information Exposed

SiegedSec Allegedly Hacks Westboro Baptist Church, Leaks Data and Source Code

SiegedSec Allegedly Hacks Westboro Baptist Church, Leaks Data and Source Code

Recommended Stories

Data Breach Exposes Sensitive Information from Major Egyptian Clubs, Banks, and Real Estate Firms

Data Breach Exposes Sensitive Information from Major Egyptian Clubs, Banks, and Real Estate Firms

October 26, 2024
Global Data Breach Exposes 1.27TB of Sensitive Information

Global Data Breach Exposes 1.27TB of Sensitive Information

January 15, 2025
IntelBroker Claims to Sell Access to American Aerospace & Defense Company with Revenue of $75 Billion

IntelBroker Claims to Sell Access to American Aerospace & Defense Company with Revenue of $75 Billion

May 15, 2024

Popular Stories

  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims to Have Leaked Database Containing Personal Information of 5 Million Salvadoran Citizens

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of State Grid Corporation of China (SGCC) Data, World’s Largest Utility Company

    0 shares
    Share 0 Tweet 0
  • New ATM Malware Threatens European Banking Security

    0 shares
    Share 0 Tweet 0
  • CyberNiggers Group Allegedly Breaches HSBC and Barclays Banks, Compromising Extensive Databases and Source Code

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Daily Dark Web© 2024

No Result
View All Result
  • Contact
  • Home
  • Newsletter
  • Privacy Policy

Daily Dark Web© 2024

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?