Exploitation of public-facing applications (e.g., Cisco ASA/FTD vulnerabilities)
Brute-force attacks on RDP and VPN credentials
Credential Access via stolen/leaked accounts
Living off the Land (LotL) using legitimate tools
Data exfiltration using Rclone
Deployment of custom ransomware binaries
Use of remote management tools (AnyDesk, ScreenConnect)
Double Extortion (encryption and data leak threats)