Introduction

This lab simulates a real-world ransomware intrusion originating from a software supply-chain compromise within a trusted Python AI/ML dependency. The investigation places the analyst in the role of reconstructing a multi-stage attack using Splunk telemetry and host-based artifacts to determine the full scope and impact of the incident.

The intrusion begins with the execution of a poisoned version of a widely used library, which is commonly trusted by AI/ML developers. The compromised dependency introduces malicious code execution during routine model training, enabling initial access without direct user interaction beyond legitimate development activity.

Following successful execution, the threat actor establishes persistence and initiates lateral movement across the domain. Native Windows utilities and Remote Desktop Protocol (RDP) are leveraged to expand access, escalate privileges, and enumerate domain resources.

Before deploying ransomware, the attacker conducts pre-encryption operations to maximize operational impact, including deleting backup artifacts, removing Volume Shadow Copies, and terminating critical services.

  • Initial access via supply-chain compromise
  • Execution and command-and-control establishment
  • Credential harvesting and privilege escalation
  • Domain enumeration and lateral movement
  • Pre-encryption impact preparation and ransomware deployment

Mapping Infrastructure

Before we begin, we need to map our infrastructure. We have two endpoints (PC01 and PC02), one File Share Server (FILE-SERVER-01), and one Backup Server (BACKUP-SERVER-01), all joined to the unucorb.local domain controlled by DC01. Sysmon is running on all machines as a log source.

Unlock Your Full Learning Experience with BlueYard Labs

Sign up to track your progress, unlock exclusive labs, and showcase
your achievements—begin your journey now!
Join for Free