Sophos tracks Nefilim and other ransomware attacks to “Ghost” account credentials

The target hit by Nefilim had more than 100 systems impacted. Sophos responders traced the initial intrusion to an admin account with high level access that attackers had compromised more than four weeks before they released the ransomware.