WRAITH threat report blog post

WRAITH Threat Report | Enterprise Edition | July 2026

Key Takeaways

  • Attackers no longer rely on one point of access. They build in backup ways in before you notice the first.
  • Closing the entry point you found isn’t enough. A second, hidden one may already exist.
  • Identity-based backups are just as durable as malware. A new MFA device or access pass is just as hard to spot.
  • State-sponsored actors plan backup access by design. Some backdoors exist purely to be the backup.
  • Point-in-time testing checks whether you can close one way in. It rarely checks whether you’d catch the rest.

Built to Return: How Modern Attackers Engineer their way Back in Before They’re Ever Discovered

Your team found the entry point. You closed it, reset the credentials, rebuilt the box. Incident closed. Or so you thought.

In every case this month, closing the attacker’s initial access point didn’t remove them from the environment.

Not because the remediation was ineffective, but because that was never their only way in.

Attackers are increasingly building redundancy into their access from the start. Before the initial compromise is ever discovered, they often establish a second, quieter access path. As a result, remediation may only remove the access defenders have identified, while the attacker retains another way back in.

This month, three cases show exactly how that plays out, across three very different kinds of attacker.

Case 1: Bumblebee, AdaptixC2 & Akira Ransomware

Source: The DFIR Report, June 2026

  • A user searching for “ManageEngine OpManager” (a legitimate network monitoring tool) was lured to a lookalike domain via SEO poisoning. The site delivered a trojanised installer that side-loaded  a malware loader known as Bumblebee
  • Within five hours, the attacker deployed an AdaptixC2 beacon. They then created two backup domain admin accounts, and installed RustDesk as a persistent Windows service across multiple servers
  • Domain credentials were harvested giving the attacker full administrator access. Roughly 77GB of data was exfiltrated via FileZilla
  • Akira ransomware was deployed across the root domain approximately 44 hours after initial access
  • Two days later, the attacker returned. This time they did not use the original vulnerability,  they used the RustDesk service installed days earlier, and encrypted a second, child domain controller

Implication: The ransomware event was not the end of the intrusion. It was a checkpoint. The attacker had already built a second way back in before deploying the first payload and used it once the incident looked resolved.

Case 2: Scattered Spider 

Source: Multiple 2026 Incident Reports (Computer Weekly, Rapid7, CISA)

  • Initial access was gained through help-desk social engineering, using compromised service account credentials
  • Once inside, the group enrolled a new MFA device and registered a Temporary Access Pass. This created a way to log in without the original password or MFA
  • Multiple legitimate remote monitoring, management tools and reverse proxies were downloaded from official vendor sites. Each was capable of restoring access
  • The group has been observed sitting inside a victim’s own incident response Slack and Teams channels. From there they are able to monitor the remediation effort and adjust their approach in real time

Implication: Resetting a password or revoking one device does not remove the others. And when attackers can see the remediation plan as it’s being written, they adapt faster than the plan can execute.

Case 3: Volt Typhoon & SockDetour

Source: Unit 42 Threat Brief, CISA/Microsoft advisories

  • Volt Typhoon gains initial access through unpatched, internet-facing edge devices, firewalls, routers, VPN gateways, favouring living-off-the-land techniques over custom malware
  • The group uses a custom backdoor called SockDetour as a fallback. It’s designed for a single purpose: to provide backup access if the group’s primary method of access is detected and removed
  • In some cases, the group has maintained access to US critical infrastructure for years, even after law enforcement disrupted the botnets used to support its operations
  • The group’s goal is to establish long-term access for potential future disruption rather than carrying out attacks immediately. As a result, this backup access can remain dormant for extended periods without any visible activity

Implication: For Volt Typhoon, the backup isn’t opportunistic. It’s engineered from the outset, on the assumption that the primary access will eventually be found.

Key Patterns Across This Month’s Attacks

Three cases. Three different threat actors; a ransomware crew, a financially motivated identity specialist, and a state-sponsored APT. The same underlying discipline running through all of them.

  • No single point of access. Every case involved at least two independent ways back in, established before the first was ever detected.
  • Backups don’t look like backups. RustDesk, a new MFA device, a Temporary Access Pass, each is legitimate, expected, and easy to miss precisely because it doesn’t look like a backdoor.
  • Eviction tests confidence, not completeness. Removing the access point you found feels like resolution. It only proves you found one.
  • Some backups are built to wait. State-sponsored actors design dormant secondary access with no timeline pressure and no need to use it immediately.
  • Attackers plan for your response before you write it. In at least one case, the threat actor tracked the incident response process directly.

Attackers don’t rely on being caught out. They rely on you only finding the first way in.

Why This Matters for Enterprise Security Leaders

Most enterprise organisations validate their defences through point-in-time engagements such as:

These have real value. But by design, they are built to answer one question: can an attacker get in, and how far can they get, within a defined window?

They are not built to answer a more important second question: if you found and closed the way in, would you also find every other way back?

A scheduled red team engagement is objective-based and time-boxed.  The goal is to prove initial access, escalate privilege, demonstrate impact, write the report. It ends once those objectives are met, almost always before the client has begun remediating what was found. There is no structural reason, inside a fixed window, for an engagement to still be running once the “front door” is closed.

Consider what that means against the cases above:

  • A point-in-time test would very likely find the trojanized installer and the initial C2 foothold. It’s far less likely to still be engaged when a RustDesk service, installed almost as an afterthought days earlier, becomes the only thing keeping the attacker inside.
  • A test can flag a compromised account. It is not designed to check whether your team would catch a newly enrolled MFA device or a Temporary Access Pass registered on that same account three weeks after the original credentials were reset.
  • Nothing about a scheduled engagement can replicate an adversary prepared to leave a secondary access point dormant for months, waiting for the moment to use it.

The result is a blind spot  in point in time testing.  A red team exercise or pen test validates whether you can close the door you found. It says very little about whether you’d notice others .

How WRAITH Addresses This

The answer isn’t a longer red team. It’s a different model entirely.

WRAITH operators run continuously, not against a fixed clock; and that distinction matters more here than almost anywhere else. When our operators gain a foothold, they behave like the threat actors above.

  • They don’t stop at the first access point.
  • They establish redundancy the way a real adversary would,
  • They then wait and watch what happens when your team finds and closes the initial access point.

Because the engagement doesn’t end after two weeks, WRAITH can test the part point-in-time engagements can’t: what happens after remediation.

If your SOC closes the RDP session, resets the account, and kills the suspicious service, does the operator’s backup access still work? Would your team notice a new MFA device registered on an account they had just secured? Would they catch a foothold that was deliberately left dormant for a month?

This is the discipline modern adversaries  follow: never rely on one way in, and never assume the target found everything. WRAITH tests your organisation against ongoing adversarial pressure that mirrors how  groups like Scattered Spider and Volt Typhoon actually operate.

A scheduled test can tell you whether your team found the front door. WRAITH tells you whether you found all of them.

Picture of Jennifer Goulbourne

Jennifer Goulbourne

Jennifer is a Digital Marketing Executive at OmniCyber Security, where she's responsible for engaging the company's existing customer base across digital channels and creating helpful resources on threat intelligence and security operations for cybersecurity professionals and business leaders.

Contact us..

Related Articles