APT-level red team operations for enterprises and organizations
CASE FILE RT-0142 Financial sector

From a job posting to Domain Admin in six days

Six days from a public job posting to the core payment database of a regional bank — through a home NAS, an MFA push storm and one reused password. The objective was reached without a single custom exploit.

Objective
Access the core payment-processing database of a regional bank
Path
A developer’s home-network NAS, exposed by a forgotten port forward, yielded corporate VPN credentials saved in a browser profile. MFA was enforced — but the VPN portal allowed push-fatigue spam. Push #14 was approved on a Friday evening. From the VPN, an outdated internal CI server reused the same local-admin password across 60+ hosts; the DPAPI-protected credentials of a tier-0 operator were recoverable from a misconfigured build agent.
Detected
The MFA-fatigue burst triggered no alert; the pass-the-hash across CI hosts fired a single low-severity rule nobody owned

After: Number-matching + PIN enforced, local-admin passwords randomized, unowned alert rules reassigned — the same scenario retested clean three months later.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • Credentials outlive devices. Browser profiles, DPAPI blobs and build agents hold tier-0 secrets nobody inventories.
  • Reusable local-admin passwords turn one host into sixty. Randomize per host, or use LAPS-style rotation.
  • An MFA prompt storm is an attack, not an annoyance. If push #14 works, number-matching and PIN are not optional.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment