Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

Security Breach Exposes Italian Red Cross Network: Allegedly Threat Actor Shares Details of the Incident and Offers Backdoor Access

April 30, 2024
Reading Time: 1 min read
Security Breach Exposes Italian Red Cross Network: Allegedly Threat Actor Shares Details of the Incident and Offers Backdoor Access

Recently, there was claims a breach into the Italian Red Cross network, where the threat actor managed to infiltrate despite the presence of EDR/XDR technology, particularly Trend Micro Apex One, which proved ineffective in detecting or blocking the breach. With just a simple PHP shell, the threat actor gained access to the network and easily became the administrator of the company’s Active Directory.

Surprisingly, the breach did not involve sophisticated techniques like kerberoast or s4u, and the machines accessed from outside were vulnerable to various known exploits, facilitating Local Privilege Escalation (LPE). The threat actor discovered that the ‘master’ password, ‘Sviluppo.1864′ or ‘Sviluppo.1864!’, was widely used across local and network accounts.

Taking advantage of the company’s nighttime activity, as the EDR system sent alerts/events to the internal JIRA system, the breach was executed without much difficulty. The only hiccup occurred when the threat acto rstumbled upon 13TB of internal and non-internal videos, which were excluded from the data dump to avoid causing disruptions.

The breach yielded access to internal source codes, databases, backups, and more, but ransomware was deliberately avoided as the threat actor considered it unnecessary and amateurish. As a parting note, the threat actor encouraged others to mirror the data, citing issues with DMCA and Gofile’s policies. Additionally, a hidden backdoor for future access was hinted at, available upon request via private message.

 

Tags: EDRItalyRed CrossTrendMicroXDR
ShareTweet

Related Posts

Uganda Ministry of Agriculture MAAIF Suffers Data Breach
Data Breaches

Uganda Ministry of Agriculture MAAIF Suffers Data Breach

April 27, 2026
Abu Dhabi Department of Finance Super Admin Access Sale
Unauthorized Accesses

Abu Dhabi Department of Finance Super Admin Access Sale

April 27, 2026
Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach
Data Breaches

Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach

April 27, 2026
BlackSexFinder Adult Platform Suffers Massive Data Breach
Data Breaches

BlackSexFinder Adult Platform Suffers Massive Data Breach

April 27, 2026
Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info
Data Breaches

Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info

April 27, 2026
FFWPU and Tongil Group Face Extensive Data Breach
Data Breaches

FFWPU and Tongil Group Face Extensive Data Breach

April 27, 2026
Next Post
Data Breach KISTI SMART K2C: Allegedly 7.79 Million Users’ Information Exposed

Data Breach KISTI SMART K2C: Allegedly 7.79 Million Users' Information Exposed

SiegedSec Allegedly Hacks Westboro Baptist Church, Leaks Data and Source Code

SiegedSec Allegedly Hacks Westboro Baptist Church, Leaks Data and Source Code

Recommended Stories

Turkish Medical Association Allegedly Breached – Sensitive Data of Doctors Exposed

Turkish Medical Association Allegedly Breached – Sensitive Data of Doctors Exposed

August 21, 2025
Threat Actor Claims to Sell Full Access to Internal Network of Major Polish Company

Threat Actor Claims to Sell Full Access to Internal Network of Major Polish Company

July 15, 2024
Infinox Allegedly Targeted in Ransomware Attack by Arkana Group

Infinox Allegedly Targeted in Ransomware Attack by Arkana Group

May 29, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?