Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
CymuLab Live: Coming to a city near you!
Register Now
New Gartner® Report: Strategic Roadmap for CTEM
Learn More
Threat Exposure Validation Impact Report 2025
Learn More

Emotet Leads To Quantum Ransomware Infection

November 30, 2022

Threat actors were observed using Emotet to gain access to the victim's network and deploy Quantum ransomware to devices on the domain. Various tools were used for lateral movement, data exfiltration, and remote access including Cobalt Strike, Rclone, Tactical RMM, and AnyDesk. Legitimate Windows tools such as systeminfo, ping, net, nltest, and whoami were used for local and remote discovery.