24/7 INCIDENT RESPONSE
(877) 259-0509

INSIGHTS & ANALYSIS

Cybersecurity Investigations,
Digital Forensics & Response.

Analysis and practical guidance from Cyber Centaurs on digital forensics, incident response, cyber investigations, threat activity, security testing, and the technical issues that shape consequential decisions.

LATEST INSIGHTS

Recent Analysis.

A denser index of recent Cyber Centaurs analysis, field notes, and practical guidance for security, legal, and executive teams.

Cyber Centaurs ClickFix loader obfuscation and stealth persistence article artwork

Threat Hunting · February 11, 2026

Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence

Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.

Read Article →
Cyber Centaurs ClickFix malvertising infection chain article artwork

Threat Hunting · February 9, 2026

Unmasking the ClickFix Malvertising Infection Chain part1

Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.

Read Article →
when Ransomware Makes Mistakes

Threat Actor Analysis · January 22, 2026

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read Article →
infiltration into the inc ransomware groups infrastructure

Threat Actor Analysis · November 10, 2025

Infiltration into the INC Ransomware Group’s Infrastructure

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read Article →
RedNovember

Threat Actor Analysis · October 4, 2025

RedNovember’s Tactics and Tradecraft

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read Article →
The 2025 Spike in Veeam Exploitation Explained

Threat Actor Analysis · September 11, 2025

Threat Actors’ Obsession with Veeam Backups

Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…

Read Article →
Supply Chain Attacks in Healthcare

Penetration Testing · May 23, 2025

Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read Article →
Guarding Against Midnight Blizzards New RDP Tactics

Threat Actor Analysis · November 26, 2024

Guarding Against Midnight Blizzard’s New RDP Tactics

As cyber threat actors continually refine their techniques, state-sponsored groups are pushing boundaries to infiltrate even the most secure networks. Among these groups, Midnight Blizzard—also known as APT29 or Cozy…

Read Article →
Digital forensics concept artwork about deleted data and modern technology

Digital Forensics · November 12, 2024

The Truth About Deleted Data and Modern Technology

Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.

Read Article →
Unmasking North Korean IT Infiltration

Threat Actor Analysis · October 26, 2024

Unmasking North Korean IT Infiltration

The evolution of remote work has created new avenues for business growth but also introduced significant cyber risks. As of 2024, around 22.8% of U.S. employees work remotely at least…

Read Article →
Metadata

Digital Forensics · October 18, 2024

Mastering Metadata for Legal Professionals

In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…

Read Article →
Defense Strategies for LOTL Attacks

Threat Hunting · October 15, 2024

Defense Strategies for Living Off the Land (LOTL) Attacks

With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…

Read Article →

INCIDENT RESPONSE

Incident Response

Analysis and guidance on ransomware, business email compromise, cloud compromise, data breaches, response strategy, and cyber incident investigations.

incident response frameworks min

Incident Response · June 25, 2024

Essential Metrics for Effective Incident Response Strategies

In today’s complex digital landscape, cybersecurity is a critical concern for corporate IT leaders, including Chief Information Security Officers (CISOs), Chief Information Officers (CIOs), and IT Directors. With the frequency…

Read →
Data Breach Disclosure

Incident Response · May 28, 2024

Navigating Data Breach Disclosures

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
Cyber Threat intelligence

Incident Response · May 11, 2024

Understanding Cyber Threat Intelligence

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
USB Trojan min

Incident Response · April 1, 2024

The Resurgence of USB-based Cyberattacks

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
View All Incident Response →

DIGITAL FORENSICS

Digital Forensics

Articles on computer and mobile forensics, digital evidence, forensic methodology, insider investigations, data movement, and investigative analysis.

Digital forensics concept artwork about deleted data and modern technology

Digital Forensics · November 12, 2024

The Truth About Deleted Data and Modern Technology

Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.

Read →
Metadata

Digital Forensics · October 18, 2024

Mastering Metadata for Legal Professionals

In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…

Read →
Video Forensics

Digital Forensics · August 27, 2024

Video Forensics in Criminal Defense

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
Legal Frameworks and Compliance

Digital Forensics · August 26, 2024

Legal Frameworks and Compliance – A Guide for Legal Practitioners

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
View All Digital Forensics →

THREAT HUNTING

Threat Hunting

Research and practical guidance on suspicious activity, attacker behavior, detection logic, persistence, credential misuse, and proactive threat investigation.

Detecting ClickFix Malvertising in Enterprise Environments

Threat Hunting · March 13, 2026

Detecting ClickFix Malvertising in Enterprise Environments

Detection strategies and threat-hunting guidance for identifying ClickFix malvertising activity, including PowerShell execution, persistence, credential access, certificate manipulation, and suspicious behaviors.

Read →
Cyber Centaurs ClickFix loader obfuscation and stealth persistence article artwork

Threat Hunting · February 11, 2026

Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence

Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.

Read →
Cyber Centaurs ClickFix malvertising infection chain article artwork

Threat Hunting · February 9, 2026

Unmasking the ClickFix Malvertising Infection Chain part1

Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.

Read →
Defense Strategies for LOTL Attacks

Threat Hunting · October 15, 2024

Defense Strategies for Living Off the Land (LOTL) Attacks

With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…

Read →
View All Threat Hunting →

PENETRATION TESTING

Penetration Testing

Technical guidance on penetration testing, attack paths, Active Directory, network security, offensive-security methodology, and remediation validation.

Supply Chain Attacks in Healthcare

Penetration Testing · May 23, 2025

Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
BlackBasta min

Penetration Testing · May 14, 2024

BlackBasta Ransomware – Threat Analysis and Indicators of Compromise

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
RAT Remote Access Trojan

Penetration Testing · January 2, 2024

Understanding Remote Access Trojans (RATs)

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
Hacker Ransomware scaled

Penetration Testing · March 5, 2020

Using Penetration Testing to Stop a New Stealth Breed of Ransomware Attacks

Ransomware is arguably one of the most insidious and damaging forms of malware. Cybercriminals are continually exploiting newer methods to circumvent strategies by enterprises to thwart ransomware attacks. A recent…

Read →
View All Penetration Testing →

THREAT ACTOR ANALYSIS

Threat Actor Analysis

Research on threat groups, campaigns, tactics, techniques, procedures, malware, infrastructure, and observed adversary behavior.

when Ransomware Makes Mistakes

Threat Actor Analysis · January 22, 2026

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
infiltration into the inc ransomware groups infrastructure

Threat Actor Analysis · November 10, 2025

Infiltration into the INC Ransomware Group’s Infrastructure

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
RedNovember

Threat Actor Analysis · October 4, 2025

RedNovember’s Tactics and Tradecraft

[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&

Read →
The 2025 Spike in Veeam Exploitation Explained

Threat Actor Analysis · September 11, 2025

Threat Actors’ Obsession with Veeam Backups

Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…

Read →
View All Threat Actor Analysis →

NEED ASSISTANCE?

Start With a
Confidential Conversation.

If an article relates to an active incident, forensic matter, or security concern affecting your organization, contact Cyber Centaurs to discuss the circumstances directly.

CONTACT CYBER CENTAURS →