THREAT OPS › Threat News › An analysis of incidents at Brazilian educational institutions
An analysis of incidents at Brazilian educational institutions
<p><img alt="" class="attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image" height="400" src="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/07/24112055/SL-incidents-at-Brazilian-educational-institutions-featured-scaled-1-990x400.jpg" width="990" /></p><h2 id="introduction">Introduction</h2> <p>Because of the amount of data that can be obtained and the
MITRE ATT&CK techniques
- KeyloggingT1056.001
- VulnerabilitiesT1588.006
- DLLT1574.001
- Email AccountsT1586.002
- Remote Access ToolsT1219
- Remote ServicesT1021
- Email AccountsT1585.002
- Compromise AccountsT1586
- Exfiltration over USBT1052.001
- Hijack Execution FlowT1574
- Valid AccountsT1078
- Exploitation for Privilege EscalationT1068
- Multi-Factor AuthenticationT1556.006
- Data Encrypted for ImpactT1486
- Input CaptureT1056
- CredentialsT1589.001
- ImpersonationT1684.001
- System ServicesT1569
- Exfiltration Over Physical MediumT1052
- Remote Desktop ProtocolT1021.001
- Service ExecutionT1569.002
- Valid AccountsAML.T0012
- ImpersonationAML.T0073
Indicators of compromise
- https://jlajara.gitlab.io/Potatoes_Windows_Privescurl
- media.kasperskycontenthub.comdomain