Detecting Modern Ransomware Attacks in the Financial Sector

Detecting Modern Ransomware Attacks in the Financial Sector

Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 22:45

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

RW Kaya details how ransomware groups compromise financial sector infrastructure via high-privileged cloud identities, outlining initial access vectors, post-exploitation tactics, and specific detection methodologies for Azure and AWS environments 2:15.

Key Takeaways:
• Initial access is primarily achieved through phishing (vishing, fake portals, malicious app registration), stolen tokens from underground markets, or exploiting public-facing applications 0:48.
• Post-compromise tactics include exfiltrating data via SharePoint/AWS S3 and abusing cloud-native tools like Azure Run Command for lateral movement and ransomware deployment 1:01.
• Detection requires leveraging identity risk anomalies, Azure Activity Logs, and AWS CloudTrail to identify suspicious API calls and impossible travel events 0:58.
• Prevention strategies involve disabling illicit consent grants, using Security Keys for token binding, and monitoring for abuse of IT operational functionalities 0:22.
• The presentation provides actionable intelligence for Fortune 500 and government entities to shift from passive prevention to active monitoring of the full attack lifecycle 0:30.

Organizations must implement robust identity monitoring and leverage cloud-native logging to distinguish between legitimate administrative actions and offensive reconnaissance by ransomware affiliates.

Sources:

  • 0:01 Introduction: Identity admin compromise and ransomware detection in financial sectors.
  • 0:22 Audience context: Actionable intelligence for Fortune 500 and government bodies.
  • [0:48](htt

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So today I will be speaking about from identity admins to cloud compromise and detecting modern ransomware attacks in the financial sector. Uh my name is RW Kaya. I am a senior cyber intelligence analyst at eclectic IQ. I am delivering actionable intelligence in eclectic IQ to Fortune 500 companies and governmental bodies. and I have a background in uh model analysis and incident response. I am also quite active in social media. So feel free to follow me. So today's agenda we are first going to talk about um how does ransomware groups are gaining initial access uh from cloud uh services uh by using highprivileged user accounts. Then I will be focusing on the post compromising tactics and then I will be giving you the detection methodologies for each of them. Then we will be finalizing this…