{"id":11314,"date":"2026-03-26T16:20:08","date_gmt":"2026-03-26T22:20:08","guid":{"rendered":"https:\/\/beaconlab.us\/?p=11314"},"modified":"2026-03-27T08:36:29","modified_gmt":"2026-03-27T14:36:29","slug":"a-case-of-operational-continuity-despite-network-disruptions","status":"publish","type":"post","link":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/","title":{"rendered":"A Case of Operational Continuity Despite Network Disruptions"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"553\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15-1024x553.png\" alt=\"\" class=\"wp-image-11356\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15-1024x553.png 1024w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15-300x162.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15-768x415.png 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15.png 1392w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This case study describes a ransomware intrusion affecting an organization operating a <strong>hybrid IT\/OT environment<\/strong>, where business systems were tightly coupled with operational processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker, later attributed to <strong>Lynx ransomware operations<\/strong>, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational processes remained partially functional\u2014revealing important insights about both attacker tradecraft and system design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the investigation, multiple data sources were utilized to gain visibility into the environment and attacker activity. These included comprehensive endpoint artifacts such as Windows event logs, registry hives, scheduled tasks, prefetch files, and system metadata collected from over 50 hosts spanning both IT and OT networks. While the organization had begun implementing specialized OT monitoring solutions, including Claroty CTD, its deployment was still in progress and not fully operational at the time of the incident. Therefore, the primary analysis relied on traditional endpoint and network telemetry, which proved essential for reconstructing the attack timeline and understanding the lateral movement and persistence techniques employed by the adversary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although Claroty CTD was not fully deployed, its logs were leveraged as an initial guide to help focus the investigation. These early indicators provided valuable context on suspicious activity within the OT network, enabling the team to prioritize data collection and analysis efforts effectively.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Phase 1 \u2013 Initial Access &amp; Reconnaissance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The intrusion originated through a <strong>remote access service (VPN)<\/strong> using valid credentials, indicating prior credential compromise (e.g., phishing, credential reuse, or infostealer activity).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Immediately after access, the threat actor initiated structured reconnaissance:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Active Directory enumeration<\/strong> via LDAP queries to identify domain structure, users, groups, and privileged accounts.<\/li>\n\n\n\n<li><strong>Network discovery<\/strong> using TCP port scanning and ICMP sweeps.<\/li>\n\n\n\n<li>Early focus on <strong>Domain Controllers, database servers, and critical infrastructure nodes.<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This behavior reflects a <strong>goal-oriented intrusion<\/strong>, where the attacker rapidly prioritizes assets that enable privilege escalation and domain-wide visibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">&nbsp;<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"864\" height=\"280\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-12.png\" alt=\"\" class=\"wp-image-11339\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-12.png 864w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-12-300x97.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-12-768x249.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Phase 2 \u2013 Expansion &amp; Exploitation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Following reconnaissance, the attacker transitioned into exploitation and access expansion. Observed behaviors included high-volume SMB authentication attempts characterized by password spraying and brute force patterns, the use of automated tooling to identify weak or reused credentials, and exploitation attempts consistent with SMB vulnerabilities. Notably, techniques aligned with MS17-010 (EternalBlue) were employed to target unpatched or legacy systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This phase resulted in the compromise of a <strong>Domain Controller<\/strong>, which became a critical turning point in the intrusion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once compromised, the Domain Controller was leveraged to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Perform <strong>internal reconnaissance at scale.<\/strong><\/li>\n\n\n\n<li>Enumerate additional systems and trust relationships.<\/li>\n\n\n\n<li>Act as a <strong>pivot node for internal propagation.<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This shift represents the transition from external access to <strong>full internal attack surface control<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"682\" height=\"262\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-11.png\" alt=\"\" class=\"wp-image-11337\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-11.png 682w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-11-300x115.png 300w\" sizes=\"(max-width: 682px) 100vw, 682px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Phase 3 \u2013 Credential Abuse &amp; Lateral Movement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With elevated privileges, the attacker moved into a highly automated lateral movement phase focused on <strong>credential reuse and remote execution<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key techniques observed included Pass-the-Hash (PtH) attacks using NTLM authentication, ongoing SMB brute force campaigns targeting administrative access, and distributed authentication attempts across multiple systems. Remote execution was achieved through native Windows mechanisms such as Windows Management Instrumentation (WMI) for remote process execution, WinRM\/WSMan for PowerShell-based command execution, and SMB-based service execution resembling PsExec behavior for payload deployment. This phase was characterized by high-speed propagation across the network, extensive reuse of administrative credentials across multiple systems, and minimal reliance on exploits after initial access, reflecting a shift towards \u201cliving off the land\u201d tactics.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"408\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-10.png\" alt=\"\" class=\"wp-image-11335\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-10.png 864w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-10-300x142.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-10-768x363.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker effectively transitioned into an <strong>automated lateral movement engine<\/strong>, compromising a large portion of the environment in a short time.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"306\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-9.png\" alt=\"\" class=\"wp-image-11333\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-9.png 864w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-9-300x106.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-9-768x272.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Phase 4 \u2013 Ransomware Deployment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The final phase involved coordinated deployment of the <strong>Lynx ransomware payload<\/strong> across compromised systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Execution characteristics included deployment via remote service creation using PsExec-like techniques, with simultaneous or near-simultaneous execution across multiple hosts. Additionally, ransom notes (README.txt) were distributed widely across systems and network shares to ensure visibility of the extortion demand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Observed <strong>Lynx-specific behaviors:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Selective encryption strategy<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Targeted: user data, databases, shared resources<\/li>\n\n\n\n<li>Excluded: system directories (e.g., Windows paths)<\/li>\n\n\n\n<li>Excluded: executable files (.exe, .dll, etc.)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Likely <strong>process and service termination<\/strong> to unlock files prior to encryption (e.g., database services, backup agents)<\/li>\n\n\n\n<li>Capability to encrypt <strong>network shares<\/strong>, increasing impact across the environment<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"294\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-8.png\" alt=\"\" class=\"wp-image-11331\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-8.png 766w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-8-300x115.png 300w\" sizes=\"(max-width: 766px) 100vw, 766px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Systems remained <strong>operational at the OS level<\/strong>, but:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Critical data was encrypted<\/li>\n\n\n\n<li>Business processes were disrupted<\/li>\n\n\n\n<li>Operational continuity was degraded rather than completely halted<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Lightweight, \u201cLegacy-Safe\u201d Evidence Collection<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The environment was operationally fragile: legacy hosts that were effectively \u201cHeld together with duct tape and baling wire,\u201d limited headroom in CPU\/RAM\/disk, and a real risk that any heavy tooling could push systems over the edge. Internal IT had already attempted restarts on some machines, and a few did not come back online. Our collection strategy had to prioritize a minimum footprint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We designed a two-stage collection approach using a tiny bootstrap script for cmd.exe. This script connected to an improvised internal FTP server to download a tuned, minimal KAPE bundle. We avoided the full 300MB+ distribution, instead pushing a lightweight package of just a few megabytes. The output was automatically zipped by hostname and uploaded back to the FTP. Within hours, we had extracted the vital signs of the entire network without a single additional system failure.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">How We Built the Tool: Architecture and Design<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Once the collection was completed, the analyst disconnected from the internal network to ensure full isolation. However, we quickly encountered a major bottleneck: the sheer volume of forensic data collected from more than 50 hosts. Manual analysis was not feasible within the required response timeframe.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To address this, we developed an <strong>Offline Persistence Scanner<\/strong>, a Python-based analysis pipeline designed to process large-scale forensic artifacts efficiently and consistently.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"228\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-6.png\" alt=\"\" class=\"wp-image-11327\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-6.png 864w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-6-300x79.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-6-768x203.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The tool focuses on extracting and correlating key persistence and execution artifacts, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Windows Registry hives<\/li>\n\n\n\n<li>Scheduled Tasks<\/li>\n\n\n\n<li>Startup folders and autoruns<\/li>\n\n\n\n<li>Prefetch files<\/li>\n\n\n\n<li>Jump Lists<\/li>\n\n\n\n<li>BAM\/DAM artifacts<\/li>\n\n\n\n<li>Windows Event Logs (EVTX)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">One of the main technical challenges was handling large EVTX files. Traditional Python-based parsers proved too slow for operational use. To overcome this, we integrated a <strong>compiled Rust-based EVTX parser (evtx_dump)<\/strong>, achieving performance improvements of approximately <strong>2,000+ times faster<\/strong> compared to standard approaches. This enabled us to process large Security logs (hundreds of MBs) in seconds instead of hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data Normalization &amp; Output Strategy<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond parsing, a key design decision was to normalize all extracted artifacts into structured, analysis-ready formats. The pipeline automatically converts parsed data into JSON for structured processing and automation, CSV for rapid filtering and bulk triage, and Excel (XLSX) for analyst-friendly exploration and data pivoting. This approach ensures that the same dataset can be efficiently consumed across different stages of the investigation, from automated processing to interactive analysis.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"408\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-14.png\" alt=\"\" class=\"wp-image-11350\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-14.png 864w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-14-300x142.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-14-768x363.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This multi-format output approach significantly enhanced investigation speed by enabling analysts to rapidly filter authentication events, process executions, and remote activity without the constraints of proprietary tools. By normalizing data into JSON, CSV, and Excel, the team was able to correlate artifacts across multiple hosts, facilitating rapid searches and real-time data pivoting. This flexibility not only accelerated the reconstruction of the attack timeline but also optimized technical collaboration, allowing for the immediate sharing of structured findings across different response teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Timeline Reconstruction<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By standardizing all artifacts into a unified schema, we were able to merge data from multiple sources and hosts into a single analytical layer. This enabled the correlation of key events such as logon activity, remote execution via WMI, WinRM, and SMB, service creation, and process execution. As a result, we generated a high-fidelity, cross-host timeline of attacker activity, providing a coherent and accurate reconstruction of the intrusion across the entire environment.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"360\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-4.png\" alt=\"\" class=\"wp-image-11323\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-4.png 766w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-4-300x141.png 300w\" sizes=\"(max-width: 766px) 100vw, 766px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This timeline became the backbone of the investigation, enabling a precise reconstruction of the entire attack lifecycle. It allowed us to identify the initial access vector, trace the sequence of lateral movement across the environment, understand the progression of privilege escalation, and ultimately determine the exact point at which ransomware deployment occurred<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Outcome<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The combination of high-speed parsing and structured output enabled:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rapid triage of large forensic datasets<\/li>\n\n\n\n<li>Accurate reconstruction of attacker behavior<\/li>\n\n\n\n<li>Clear visibility into lateral movement patterns<\/li>\n\n\n\n<li>Reduction of analysis time from hours to minutes<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Threat Actor Profile: The Lynx Group<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Lynx<\/strong> is a <strong>double-extortion ransomware operation<\/strong> (encrypt + threaten to leak) that maintains a <strong>public leak site<\/strong> where victim data is posted to increase pressure during negotiations. Public reporting shows a strong presence of victims in the <strong>United States<\/strong>, with additional victims in other regions, and recurring impact across <strong>manufacturing<\/strong>, <strong>business services<\/strong>, <strong>technology<\/strong>, and <strong>transportation\/logistics<\/strong>\u2014a pattern consistent with financially motivated targeting of organizations where downtime creates immediate leverage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Typical victim profile (what they go after)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lynx victim listings and analysis suggest a preference for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mid-to-large organizations<\/strong> with centralized AD, file servers, and business-critical applications.<\/li>\n\n\n\n<li><strong>Operationally sensitive environments<\/strong> (manufacturing, logistics\/transport) where disruption impacts revenue quickly.<\/li>\n\n\n\n<li>Networks with <strong>reachable backups and shared storage<\/strong>, enabling the operator to maximize blast radius and extortion value.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common TTPs observed in public reporting (high-confidence behaviors)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Public technical reporting on Lynx highlights a set of behaviors that align closely with a \u201cclassic enterprise ransomware runbook\u201d:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Ransom note delivery and user-facing intimidation:<\/strong> Lynx is reported to drop a ransom note commonly named README.txt, and may modify visual indicators (e.g., wallpaper) to ensure the incident is immediately visible to users and administrators.<\/li>\n\n\n\n<li><strong>Selective encryption logic (avoid bricking systems):<\/strong> Lynx has been reported to <strong>exclude<\/strong> certain <strong>system directories<\/strong> (e.g., Windows, Program Files, AppData, recycle bin) and avoid encrypting common <strong>binary extensions<\/strong> such as .exe, .dll, and .msi. In practice, this means <strong>data\/config\/scripts are often impacted<\/strong>, while core executables may remain intact\u2014an important detail when explaining scenarios where operational applications continue running even as data is encrypted.<\/li>\n\n\n\n<li><strong>Process killing and service stopping to maximize impact:<\/strong> Lynx is reported to terminate processes and stop services associated with <strong>databases, email, and backup\/recovery tooling<\/strong> (e.g., SQL\/Exchange\/Veeam-style targets). This increases encryption effectiveness by unlocking files and simultaneously degrades recovery options.<\/li>\n\n\n\n<li><strong>Network share encryption capability:<\/strong> Reporting indicates Lynx is capable of encrypting <strong>network shares<\/strong>, increasing the likelihood of multi-system and multi-site impact in environments with shared storage.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ATT&amp;CK technique mapping (for reporting and internal documentation)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following ATT&amp;CK techniques are commonly applicable when documenting Lynx-style intrusions and encryption events:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>T1486 \u2013 Data Encrypted for Impact<\/strong> (core ransomware outcome)<\/li>\n\n\n\n<li><strong>T1489 \u2013 Service Stop<\/strong> (stopping services that block encryption or enable recovery)<\/li>\n\n\n\n<li><strong>T1490 \u2013 Inhibit System Recovery<\/strong> (actions that reduce recovery options, often paired with service disruption)<\/li>\n\n\n\n<li><strong>T1059 \u2013 Command and Scripting Interpreter<\/strong> (operator automation and execution control)<\/li>\n\n\n\n<li><strong>T1083 \u2013 File and Directory Discovery<\/strong> (identifying what to encrypt)<\/li>\n\n\n\n<li><strong>T1057 \u2013 Process Discovery<\/strong> (identifying processes to terminate prior to encryption)<\/li>\n\n\n\n<li><strong>T1021.002 \u2013 SMB\/Windows Admin Shares<\/strong> (common in enterprise lateral movement patterns)<\/li>\n\n\n\n<li><strong>T1047 \u2013 Windows Management Instrumentation (WMI)<\/strong> (remote execution \/ admin activity)<\/li>\n\n\n\n<li><strong>T1021.006 \u2013 Windows Remote Management (WinRM)<\/strong> (remote execution via WSMan\/WinRM)<\/li>\n\n\n\n<li><strong>T1569.002 \u2013 Service Execution<\/strong> (e.g., PsExec-like execution patterns)<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Why Did Operations Keep Running?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most critical questions during this incident was: <em>why did the logistics operation never stop?<\/em> Warehouses kept moving, fleet management stayed online, and operational processes continued uninterrupted \u2014 even as domain controllers and database servers were being encrypted around them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our theory, supported by the forensic evidence collected, comes down to how the OT software was architected. The operational systems running the core logistics environment were built on a model common in legacy OT deployments: standalone executables and compiled binaries installed directly under C:\\ \u2014 not in user directories, not in network shares. Just flat .exe and supporting binary files sitting in fixed paths on local disk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This matters because Lynx \u2014 like most modern ransomware \u2014 targets file extensions. Their encryption routines are tuned to go after documents, databases, configuration files, scripts, and data stores (.docx, .xlsx, .mdb, .bak, .sql, .cfg, .ps1, .bat, .vbs, .py, etc.). And that last part is worth emphasizing: scripts were encrypted. Any .bat, .ps1, or automation script in the environment was hit. Compiled binaries and executables (.exe, .dll) are typically excluded from encryption to avoid rendering the host completely unbootable \u2014 a ransomware operator&#8217;s worst outcome, since a bricked machine can&#8217;t display a ransom note or reach a payment portal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result was a clear and observable split in the forensic evidence:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Survived: .exe and .dll binaries \u2014 the OT operational software kept running.<\/li>\n\n\n\n<li>Encrypted: Scripts (.bat, .ps1, .vbs), configuration files, databases, documents \u2014 anything text-based or data-oriented was hit.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This accidental resilience meant the core logistics processes never stopped \u2014 but it also meant that any automation, scheduled maintenance scripts, or operational scripting layer built on top of those binaries was wiped. The OT software ran, but it ran blind: no supporting scripts, no automated routines, no configuration management.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a security control. This is luck.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same architectural pattern that saved operations this time could just as easily have been the attack vector. Unmanaged binaries in flat directory structures, with no integrity monitoring, no allowlisting, and no EDR, are a prime target for binary replacement or DLL hijacking attacks. And next time, a more aggressive ransomware variant may simply choose to encrypt everything \u2014 including .exe files \u2014 accepting the risk of an unbootable host in exchange for maximum leverage.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"856\" height=\"554\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-13.png\" alt=\"\" class=\"wp-image-11341\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-13.png 856w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-13-300x194.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-13-768x497.png 768w\" sizes=\"(max-width: 856px) 100vw, 856px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">Takeaways<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>One weak seasonal password was the entry point. MFA on VPN is non-negotiable.<\/li>\n\n\n\n<li>Legacy OT environments without EDR are forensically blind. KAPE + offline analysis was the only option.<\/li>\n\n\n\n<li>The Pass-the-Hash campaign shows how fast credential abuse scales. NTLM should be restricted.<\/li>\n\n\n\n<li>Building the right tool for the environment matters. The Offline Persistence Scanner saved days of manual work.<\/li>\n\n\n\n<li>If your OT environment survived a ransomware event because the attacker &#8220;didn&#8217;t bother&#8221; with your executables, that&#8217;s not resilience \u2014 that&#8217;s a near miss.<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">References<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/socradar.io\/blog\/dark-web-profile-lynx-ransomware\/\"><em>https:\/\/socradar.io\/blog\/dark-web-profile-lynx-ransomware\/<\/em><\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-lynx\" title=\"\">https:\/\/www.fortinet.com\/blog\/threat-research\/ransomware-roundup-lynx<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[48],"tags":[],"class_list":["post-11314","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Raul B. Netto\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-03-26T22:20:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-03-27T14:36:29+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#blogposting\",\"name\":\"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab\",\"headline\":\"A Case of Operational Continuity Despite Network Disruptions\",\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/image-15.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#articleImage\",\"width\":1392,\"height\":752},\"datePublished\":\"2026-03-26T16:20:08-06:00\",\"dateModified\":\"2026-03-27T08:36:29-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#webpage\"},\"articleSection\":\"Uncategorized, Opcional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#listItem\",\"name\":\"A Case of Operational Continuity Despite Network Disruptions\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#listItem\",\"position\":3,\"name\":\"A Case of Operational Continuity Despite Network Disruptions\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/\",\"name\":\"Raul B. Netto\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bccecadf0d687d48d3ba43e84b46c2fe6e62eba36dd58b702fdb0feed7fdcfa5?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Raul B. Netto\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/\",\"name\":\"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab\",\"description\":\"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\\\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/a-case-of-operational-continuity-despite-network-disruptions\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"datePublished\":\"2026-03-26T16:20:08-06:00\",\"dateModified\":\"2026-03-27T08:36:29-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab","description":"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational","canonical_url":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#blogposting","name":"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab","headline":"A Case of Operational Continuity Despite Network Disruptions","author":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/03\/image-15.png","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#articleImage","width":1392,"height":752},"datePublished":"2026-03-26T16:20:08-06:00","dateModified":"2026-03-27T08:36:29-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#webpage"},"isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#webpage"},"articleSection":"Uncategorized, Opcional"},{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#listItem","name":"A Case of Operational Continuity Despite Network Disruptions"},"previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#listItem","position":3,"name":"A Case of Operational Continuity Despite Network Disruptions","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"Person","@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author","url":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/","name":"Raul B. Netto","image":{"@type":"ImageObject","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/bccecadf0d687d48d3ba43e84b46c2fe6e62eba36dd58b702fdb0feed7fdcfa5?s=96&d=mm&r=g","width":96,"height":96,"caption":"Raul B. Netto"}},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#webpage","url":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/","name":"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab","description":"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/#breadcrumblist"},"author":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"creator":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"datePublished":"2026-03-26T16:20:08-06:00","dateModified":"2026-03-27T08:36:29-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab","og:description":"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational","og:url":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/","og:image":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","og:image:secure_url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","article:published_time":"2026-03-26T22:20:08+00:00","article:modified_time":"2026-03-27T14:36:29+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"A Case of Operational Continuity Despite Network Disruptions - Beacon Lab","twitter:description":"This case study describes a ransomware intrusion affecting an organization operating a hybrid IT\/OT environment, where business systems were tightly coupled with operational processes. The attacker, later attributed to Lynx ransomware operations, executed a fast-paced intrusion leveraging valid credentials, automated lateral movement, and large-scale credential abuse. Despite widespread compromise across the IT environment, critical operational","twitter:creator":"@BeaconLabMX","twitter:image":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png"},"aioseo_meta_data":{"post_id":"11314","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"ot incident,","score":37,"analysis":{"keyphraseInTitle":{"score":3,"maxScore":9,"error":1},"keyphraseInDescription":{"score":3,"maxScore":9,"error":1},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":2},"keyphraseInURL":{"score":1,"maxScore":5,"error":1},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":3,"maxScore":9,"error":1},"keywordDensity":{"score":0,"type":"low","maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-03-26 22:20:09","updated":"2026-03-27 14:43:51","seo_analyzer_scan_date":null,"focus_keyword":"ot incident,","additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tA Case of Operational Continuity Despite Network Disruptions\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Uncategorized","link":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/"},{"label":"A Case of Operational Continuity Despite Network Disruptions","link":"https:\/\/beaconlab.us\/en\/a-case-of-operational-continuity-despite-network-disruptions\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/11314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/comments?post=11314"}],"version-history":[{"count":5,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/11314\/revisions"}],"predecessor-version":[{"id":11359,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/11314\/revisions\/11359"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/categories?post=11314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/tags?post=11314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}