// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / ThreatDown
Breach Record

ThreatDown

DISCLOSED 2024-08-05 · RANSOMWARE · RANSOMWARE

In July 2024, Rhysida ransomware group attacked a private school using a new Oyster Backdoor variant distributed through SEO poisoning and malvertising. The backdoor captured administrative credentials, allowing attackers to bypass ThreatDown Endpoint Protection and encrypt VMDK files on VMware hypervisors. The incident highlights the risk of relying solely on endpoint...

The record

What we know

Disclosed
2024-08-05
Attack vector
Ransomware
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the ThreatDown disclosure. It updates if new public reporting emerges. All tracked breaches →

ThreatDown just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →