Beyond the breach: inside a cargo theft actor's post-compromise playbook
Reported 16 Apr 2026 by otx · Severity: medium
A cargo theft threat actor maintained access to a decoy environment for over a month, providing extensive visibility into post-compromise operations. The attacker established redundant persistence using multiple remote access tools, including four ScreenConnect instances, Pulsewa