Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Single-Factor Privileged Sign-In via VPN/Remote Access

Zawoo Initial Access Sentinel
MITRE ATT&CK
Valid Accounts
Data Source
SigninLogs
Date Added
2026-09-18
Last Updated
2026-09-18
Source
SOCRadar, WatchGuard ransomware tracker, ransomware.live/group/ZaWoo
What This Detects
ZaWoo's confirmed initial access vector is valid VPN credentials on an already-privileged account with no MFA enforced (no exploitation or escalation observed) — 19 victims disclosed simultaneously on 2026-08-30, concentrated in German-speaking Europe.
Query
SigninLogs
| where ResultType == 0 and AuthenticationRequirement == "singleFactorAuthentication"
| where AppDisplayName has_any ("VPN","Global Secure Access","Remote Access")
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, DeviceDetail

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.