
A low-severity alert masked a targeted phishing campaign — Critical Start's SOC caught it and contained it in 18 minutes.
Download the full case study
Get the complete PDF version of this Tales from the SOC story.
Threat Type: Legitimate website compromised with a sophisticated phishing campaign leveraging a compromised legitimate website
Time to Containment: 18 Minutes
Attack Characteristics: This targeted attack exploited a compromised trusted domain to gain a foothold, using social engineering rather than standard phishing links. By convincing the user to execute commands directly through the Windows Run dialog, the attacker bypassed typical detection methods, relying on the inherent trust of the source.
Initial Vendor Severity: Low priority
SOC Escalation: High priority based on behavioral analysis and threat context
Escalation Rationale: Despite the low initial severity rating provided by Microsoft Defender for Endpoint, SOC analysts identified critical behavioral indicators including suspicious registry execution patterns and the use of a compromised trusted domain. The targeted nature of the campaign and industry-specific context warranted immediate priority escalation to prevent potential widespread compromise.
This escalation decision proved critical — without analyst-driven prioritization, the alert could have been overlooked, allowing the threat to propagate across the organization.
The SOC conducted a multi-layered investigation, utilizing registry forensics and full attack reproduction to validate the threat actor's tactics. This deep-dive analysis not only identified additional targeted users but also provided the definitive insights needed to engineer custom detection signatures and neutralize the threat vector.
Legitimate website was compromised and loaded with malware
Drive-by compromise triggered when a user visited the infected site and downloaded a Word doc
Malicious Word doc reached out to C2 via a PowerShell script
RunMRU registry was modified to establish persistence
Critical Start SOC identified behavioral indicators and escalated
Critical Start SOC isolated the device, blocked C2 & website, and notified the customer immediately
The incident was handled through a coordinated, cross-platform response across multiple security technologies: isolating the device in EDR, blocking C2 at the firewall and the compromised site at the proxy, and notifying the customer immediately.
In just 18 minutes, the coordinated response isolated the affected device, severed C2 communications, and blocked access to the infected website. This rapid preventive response helped contain malware designed for lateral movement, avoiding significant operational disruption.
© 2026 Critical Start. All rights reserved.
