LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Infrastructure Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
PGA of America Partnership
Secure What's Next
LevelBlue Security Operations Platforms
Security Colony
Partners
SentinelOne
Advancing integrated, intelligence‑driven security operations
Microsoft
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Partner Portal

22 Minute Watch Sean Shirley,
Cyber Threat Intelligence Analyst

When a suspicious VBS file was blocked in a customer environment, LevelBlue’s Managed Detection and Response team launched an investigation.

What appeared contained wasn’t.

That single alert led to the discovery of a broader malware campaign built on reusable infrastructure and multiple delivery paths; designed to persist beyond detection.

Deeper analysis from the LevelBlue SpiderLabs team revealed how attackers reused the same infrastructure to distribute different malware families, rotating delivery methods to evade controls. Block one path, and another remains active; supported by open directories, staged payloads, and a modular execution flow.

In this technical threat briefing, our experts walk through the investigation from initial detection to full infrastructure mapping. Using real MDR findings, you’ll see how one alert exposed a larger campaign; and how to identify similar patterns earlier in your own environment.

Watch the Webinar

Related Resources

Current: resourceswebinarstracing-a-multi-vector-malware-campaign-from-vbs-to-open-infrastructure
Resource: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Webinar

Epic Fury Decoded: Iran's Cyber Escalation Playbook

Current: resourceswebinarstracing-a-multi-vector-malware-campaign-from-vbs-to-open-infrastructure
Resource: resourceswebinarsa-cisos-guide-ai-threats-supply-chain-risk-and-security-leadership
Webinar

A CISO's Guide: AI Threats, Supply Chain Risk, and Security Leadership

Current: resourceswebinarstracing-a-multi-vector-malware-campaign-from-vbs-to-open-infrastructure
Resource: resourceswebinarsttp-briefing-in-focus-latest-threats-and-trends-from-the-frontlines
Webinar

TTP Briefing in Focus: Latest Threats and Trends from the Frontlines