Legitimate Website Compromise Averted

Tales from the SOC

Legitimate Website Compromise Averted

A low-severity alert masked a targeted phishing campaign — Critical Start's SOC caught it and contained it in 18 minutes.


PDF

Download the full case study

Get the complete PDF version of this Tales from the SOC story.

Download PDF

Incident Overview

Threat Type: Legitimate website compromised with a sophisticated phishing campaign leveraging a compromised legitimate website

Time to Containment: 18 Minutes

Attack Characteristics: This targeted attack exploited a compromised trusted domain to gain a foothold, using social engineering rather than standard phishing links. By convincing the user to execute commands directly through the Windows Run dialog, the attacker bypassed typical detection methods, relying on the inherent trust of the source.

Alert Escalation: Low to High Priority

Initial Vendor Severity: Low priority

SOC Escalation: High priority based on behavioral analysis and threat context

Escalation Rationale: Despite the low initial severity rating provided by Microsoft Defender for Endpoint, SOC analysts identified critical behavioral indicators including suspicious registry execution patterns and the use of a compromised trusted domain. The targeted nature of the campaign and industry-specific context warranted immediate priority escalation to prevent potential widespread compromise.

This escalation decision proved critical — without analyst-driven prioritization, the alert could have been overlooked, allowing the threat to propagate across the organization.

Depth of Investigation

The SOC conducted a multi-layered investigation, utilizing registry forensics and full attack reproduction to validate the threat actor's tactics. This deep-dive analysis not only identified additional targeted users but also provided the definitive insights needed to engineer custom detection signatures and neutralize the threat vector.

Weaponization

Legitimate website was compromised and loaded with malware

Initial Access

Drive-by compromise triggered when a user visited the infected site and downloaded a Word doc

Execution

Malicious Word doc reached out to C2 via a PowerShell script

Persistence

RunMRU registry was modified to establish persistence

Alert

Critical Start SOC identified behavioral indicators and escalated

Website & C2 Blocked / Device Isolated

Critical Start SOC isolated the device, blocked C2 & website, and notified the customer immediately

18 Minute Response

Coordinated Cross-Platform Response

The incident was handled through a coordinated, cross-platform response across multiple security technologies: isolating the device in EDR, blocking C2 at the firewall and the compromised site at the proxy, and notifying the customer immediately.

Outcome

18 Min
Time to Containment

In just 18 minutes, the coordinated response isolated the affected device, severed C2 communications, and blocked access to the infected website. This rapid preventive response helped contain malware designed for lateral movement, avoiding significant operational disruption.