Tag

Living Off the Land Attacks

posts

Defense Evasion

When Attackers Removed Legitimate Software to Own You

They Didn't Just Bypass Your Security — They Removed Legitimate Tools Entirely In early 2024, a ransomware gang hit a mid-sized healthcare network and encrypted 11,000 endpoints in under four hours. The forensic report revealed something chilling: before deploying a single payload, the attackers methodically removed legitimate security

Carl B. Johnson Aug 10, 2026 5 min read
Living Off the Land Attacks

When Attackers Removed Legitimate Software to Hide

In February 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory about threat actors linked to Volt Typhoon — a Chinese state-sponsored group that had been living inside U.S. critical infrastructure networks for years. One of their signature moves? They removed legitimate security tools and logging mechanisms from

Carl B. Johnson Aug 19, 2024 7 min read