ISSUE #002

An attack at 2:14 AM

At 2:14 AM on a regular school day, a dormant account on a US school district’s network woke up after years of inactivity. The attacker thought nobody would be watching. They were wrong.

Analytics

United States

Education

Fileless malware

Contained

In the early morning at 2:14 AM on a regular school day, one of our MDR analysts noticed an anomaly on a computer belonging to a mid-sized US school district: a heavily obfuscated PowerShell command originating from an account that had been inactive for years.

A dormant account comes to life

While a less specialized review might have dismissed the activity as a system quirk, the analyst identified the hallmark signs of fileless malware. Working at a time when they thought nobody would be watching, an attacker had injected malicious code directly into the system memory of a computer to bypass traditional file-based defenses, leaving no traces for standard antivirus software to catch.

The attacker frozen in place

Our analyst acted immediately to contain the attacker. They:

  • Validated the dormant account and turned the suspicious alert into a confirmed IOC.
  • Deobfuscated the PowerShell, identifying a downloader talking to the attacker’s server.
  • Discovered that we had already blocked the domain used for secondary tooling.
  • Isolated the affected host, leaving only the MDR team’s secure link in place.

Quick isolation effectively froze the attacker in place and blocked any attempts at lateral movement toward the district’s sensitive student databases or administrative servers.

With the threat contained, our MDR team performed a forensic sweep of the process tree. They identified the parent process that launched the PowerShell script and terminated it to clear the malicious code from the system memory. They also scanned the registry and searched scheduled tasks for any backdoors left by the attacker.

Finally, our MDR team performed a final, comprehensive scan to verify the environment was clean before lifting the host isolation.

A dozen schools saved

Further analysis of the attack revealed a startling detail. The attacker had been sitting dormant, waiting for the right moment to escalate, and had compromised the school two weeks before it joined our MDR service.

Waiting for the right moment to strike, co-opting stolen identities, using admin tools like PowerShell, and employing fileless malware are all techniques designed to reduce an attacker’s footprint. However, attackers know that even the stealthiest techniques are likely to trigger EDR alerts for suspicious activity, so they routinely attack at night when they think IT staff are unlikely to be watching.

The threat of attackers operating when his team was offline was exactly what led the school district’s IT Manager to deploy our MDR service. The partnership ensured the district had the around-the-clock protection it needed to secure its infrastructure, and the decision paid off sooner than anyone expected.

Our analysts’ overnight vigilance caught the threat as soon as it emerged, and before it could deploy secondary payloads or encrypt files, preventing a widespread breach that could have derailed operations across 12 schools supporting 5,000 students.

If we hadn’t brought in ThreatDown MDR, this threat would have stayed hidden until it was too late. Having a team that understands our environment and acts before a crisis starts has changed everything for us.

IT Manager, US school district


Reconstruction

From first signal to full handover

Signal

A dormant account

A dormant account sparks to life after years of inactivity, running a heavily obfuscated PowerShell command.

Hunch

Stealth tactics

To avoid detection the attacker is working at night, using a legitimate account, and running fileless malware.

Confirmation

Access denied

Deobfuscation reveals a downloader attempting to talk to a server that we had already blocked.

Containment

Isolated and swept

The host is isolated, malicious code is cleared from memory, the registry and scheduled tasks are searched for backdoors.

Handover

Verified clean

A comprehensive scan confirms the environment is clean before the host isolation is lifted. Student databases and administrative servers are untouched, and no secondary payload hit the network.

No business fights alone.

Discover how our MDR heroes can help you.