INSIGHTS & RESEARCH
Cyber Centaurs Insights.
Analysis, research, and practical guidance from Cyber Centaurs on digital forensics, incident response, cyber investigations, and the technical issues that shape consequential decisions.

LATEST ARTICLE
Detecting ClickFix Malvertising in Enterprise Environments
Detection strategies and threat-hunting guidance for identifying ClickFix malvertising activity, including PowerShell execution, persistence, credential access, certificate manipulation, and suspicious behaviors.
Read Article →LATEST INSIGHTS
Recent Analysis.
A denser index of recent Cyber Centaurs analysis, field notes, and practical guidance for security, legal, and executive teams.

Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence
Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.
Read Article →
Unmasking the ClickFix Malvertising Infection Chain part1
Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.
Read Article →
When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure
This article documents how Cyber Centaurs identified, validated, and safely accessed attacker-controlled data repositories operated by the INC Ransomware Group, resulting in the recovery of stolen data belonging to twelve unrelated U.S. corporations. What made this possible was not a vulnerability or a takedown, but forensic discipline applied to attacker tooling. Specifically, artifacts left behind…
Read Article →
Infiltration into the INC Ransomware Group’s Infrastructure
In a world where technology news are dominated by stories of ransomware attacks and data breaches, Cyber Centaurs is proud to share a rare story of success. While many organizations continue to struggle against a rising tide of cyber extortion, this case demonstrates that determined investigation and skilled response can lead to positive outcomes ,…
Read Article →
RedNovember’s Tactics and Tradecraft
Over the past year, a Chinese-linked threat actor known as RedNovember has emerged as a significant player in the global cyber-espionage landscape. Their operations have targeted governments, defense contractors, law firms, and critical infrastructure providers across multiple regions. What sets RedNovember apart is its pragmatic playbook: exploiting unpatched internet-facing devices to gain entry, deploying lightweight…
Read Article →
Threat Actors’ Obsession with Veeam Backups
Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…
Read Article →
Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat
Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat As supply Chain Attacks are continuing to affect Hospitals and healthcare organizations across the U.S. Cyber Centaurs is uniquely positioned to share a perspective as we have responded to a multitude of data breaches with incident response investigations for hospitals and healthcare organizations. In many…
Read Article →
Guarding Against Midnight Blizzard’s New RDP Tactics
As cyber threat actors continually refine their techniques, state-sponsored groups are pushing boundaries to infiltrate even the most secure networks. Among these groups, Midnight Blizzard—also known as APT29 or Cozy…
Read Article →
The Truth About Deleted Data and Modern Technology
Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.
Read Article →
Unmasking North Korean IT Infiltration
The evolution of remote work has created new avenues for business growth but also introduced significant cyber risks. As of 2024, around 22.8% of U.S. employees work remotely at least…
Read Article →
Mastering Metadata for Legal Professionals
In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…
Read Article →
Defense Strategies for Living Off the Land (LOTL) Attacks
With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…
Read Article →INCIDENT RESPONSE
Incident Response
Analysis and guidance on ransomware, business email compromise, cloud compromise, data breaches, response strategy, and cyber incident investigations.

Essential Metrics for Effective Incident Response Strategies
In today’s complex digital landscape, cybersecurity is a critical concern for corporate IT leaders, including Chief Information Security Officers (CISOs), Chief Information Officers (CIOs), and IT Directors. With the frequency…
Read →
Navigating Data Breach Disclosures
Understanding the intricate legal landscape surrounding data breaches and data breach notifications is crucial for any attorney representing clients who have experienced a data breach. Data breaches can lead to significant financial losses, reputational damage, and severe legal penalties. For lawyers, it is essential to provide reliable counsel on how to proceed once a data…
Read →
Understanding Cyber Threat Intelligence
What is Cyber Threat Intelligence? Cyber Threat Intelligence (CTI) is an advanced and strategic framework that organizations use to gather, analyze, and apply information about potential and current threats that could compromise their digital and informational assets. This multifaceted discipline not only focuses on identifying and mitigating cyber threats but also enhances an organization's preparedness…
Read →
The Resurgence of USB-based Cyberattacks
The resurgence of USB-based cyberattacks orchestrated by major Advanced Persistent Threat (APT) groups emanating from nation-states such as Russia and China has reignited concerns within the cybersecurity community. This peculiar trend underscores a significant shift in the landscape of digital threats, signaling an era where traditional cybersecurity measures may no longer suffice. APT groups, known…
Read →DIGITAL FORENSICS
Digital Forensics
Articles on computer and mobile forensics, digital evidence, forensic methodology, insider investigations, data movement, and investigative analysis.

The Truth About Deleted Data and Modern Technology
Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.
Read →
Mastering Metadata for Legal Professionals
In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…
Read →
Video Forensics in Criminal Defense
Video evidence has become a cornerstone in criminal defense cases, playing a critical role in determining a defendant's fate. With surveillance cameras, body cams, smartphones, and dash cams seemingly everywhere, countless moments are recorded that could be pivotal in proving guilt or innocence. However, video footage isn't always as straightforward or reliable as it might…
Read →
Legal Frameworks and Compliance – A Guide for Legal Practitioners
In an era where technology intersects with nearly every aspect of life, the legal profession is increasingly challenged to navigate the complex terrain of digital evidence and compliance. The growing reliance on digital data in litigation and investigations necessitates a deep understanding of the legal frameworks that govern the acquisition, handling, and admissibility of this…
Read →THREAT HUNTING
Threat Hunting
Research and practical guidance on suspicious activity, attacker behavior, detection logic, persistence, credential misuse, and proactive threat investigation.

Detecting ClickFix Malvertising in Enterprise Environments
Detection strategies and threat-hunting guidance for identifying ClickFix malvertising activity, including PowerShell execution, persistence, credential access, certificate manipulation, and suspicious behaviors.
Read →
Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence
Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.
Read →
Unmasking the ClickFix Malvertising Infection Chain part1
Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.
Read →
Defense Strategies for Living Off the Land (LOTL) Attacks
With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…
Read →PENETRATION TESTING
Penetration Testing
Technical guidance on penetration testing, attack paths, Active Directory, network security, offensive-security methodology, and remediation validation.

Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat
Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat As supply Chain Attacks are continuing to affect Hospitals and healthcare organizations across the U.S. Cyber Centaurs is uniquely positioned to share a perspective as we have responded to a multitude of data breaches with incident response investigations for hospitals and healthcare organizations. In many…
Read →
BlackBasta Ransomware – Threat Analysis and Indicators of Compromise
The Black Basta ransomware has rapidly become a prominent cybersecurity threat, impacting over 500 organizations worldwide across various sectors. This ransomware is particularly notable for its broad targeting strategy and sophisticated execution. It penetrates systems through phishing and exploits, after which it encrypts data and demands a ransom. This detailed article delves into the operational…
Read →
Understanding Remote Access Trojans (RATs)
Understanding RATs In the dynamic landscape of cybersecurity, the Remote Access Trojan (RAT) emerges as an enduring and sophisticated menace. Functioning as a specialized form of malware, RATs excel in providing unauthorized remote access to a victim's computer system. However, their objective surpasses mere infiltration; instead, they prioritize establishing covert control to facilitate a spectrum…
Read →
Using Penetration Testing to Stop a New Stealth Breed of Ransomware Attacks
Ransomware is arguably one of the most insidious and damaging forms of malware. Cybercriminals are continually exploiting newer methods to circumvent strategies by enterprises to thwart ransomware attacks. A recent…
Read →THREAT ACTOR ANALYSIS
Threat Actor Analysis
Research on threat groups, campaigns, tactics, techniques, procedures, malware, infrastructure, and observed adversary behavior.

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure
This article documents how Cyber Centaurs identified, validated, and safely accessed attacker-controlled data repositories operated by the INC Ransomware Group, resulting in the recovery of stolen data belonging to twelve unrelated U.S. corporations. What made this possible was not a vulnerability or a takedown, but forensic discipline applied to attacker tooling. Specifically, artifacts left behind…
Read →
Infiltration into the INC Ransomware Group’s Infrastructure
In a world where technology news are dominated by stories of ransomware attacks and data breaches, Cyber Centaurs is proud to share a rare story of success. While many organizations continue to struggle against a rising tide of cyber extortion, this case demonstrates that determined investigation and skilled response can lead to positive outcomes ,…
Read →
RedNovember’s Tactics and Tradecraft
Over the past year, a Chinese-linked threat actor known as RedNovember has emerged as a significant player in the global cyber-espionage landscape. Their operations have targeted governments, defense contractors, law firms, and critical infrastructure providers across multiple regions. What sets RedNovember apart is its pragmatic playbook: exploiting unpatched internet-facing devices to gain entry, deploying lightweight…
Read →
Threat Actors’ Obsession with Veeam Backups
Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…
Read →NEED ASSISTANCE?
Start With a
Confidential Conversation.
If an article relates to an active incident, forensic matter, or security concern affecting your organization, contact Cyber Centaurs to discuss the circumstances directly.
CONTACT CYBER CENTAURS →