ADVERTISEMENT

We knew about V-Silicon attack before it was claimed: This is how hackers exposed themselves

Attackers were preparing to target the industrial controls of semiconductor factories.

v silicon chip
Paulina Okunytė
Paulina Okunytė Senior Journalist
July 29, 2026 4 min read
Key takeaways:
China Active direcory devices and users   exported 06 16
Shanghai site Active Directory devices and users, exported June 16th. Screenshot by Cybernews
download_vmware_archyvepy contents
VMware archive download script. Screenshot by Cybernews

Attackers were getting ready to target industrial controls

grab_critical py contents
Sensitive file scan script. Screenshot by Cybernews
nas_locker py contents

The attack may have started weeks earlier

oceanstor brute force
OceanStor password brute-force script. Screenshot by Cybernews
processed ntds hashes
Processed NTDS hashes. Screenshot by Cybernews

Third-party may also have been compromised

ADVERTISEMENT
ransomware binary hashes
Ransomware binary hashes. Screenshot by Cybernews
search_ehv contents
Email search script. Screenshot by Cybernews

AI-generated scripts

vdecrypt ps1 contents
Backup decryption script. Screenshot by Cybernews
virustotal submission creation time
VirusTotal build date and upload date. Screenshot by Cybernews

What is known about INC Ransomware?

exfiltrated ftp credentials
UnitedDS FTP server exported credentials. Screenshot by Cybernews
virustotal behaviour analysis
VirusTotal behavior analysis. Screenshot by Cybernews

Attackers keep exposing their infrastructure

How to mitigate the risks?

Investigation timeline

Paulina Okunytė
Senior Journalist
ADVERTISEMENT