[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxQ5A6If7T3DEa3f7LQn5kY0eqbxAqk6AzX0-wPUWRFs":3},{"article":4,"iocs":37,"watch_terms":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"61f633de-8931-461f-be81-90984eceb320","RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup &amp; Replication c...","rdp-bitmap-cache-artifacts-revealed-the-threat-actor-opening-the-veeam-backup-am","RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup &amp; Replication console, reviewing backup jobs, tape &amp; storage infrastructure — and removing backups from the configuration database.\n\nFull report 👇\nhttps:\u002F\u002Ft.co\u002FIOlOAj2ClY https:\u002F\u002Ft.co\u002Fyps3RVYYlo","Forensic analysis of RDP bitmap cache artifacts revealed a threat actor's interactive session accessing the Veeam Backup & Replication console, reviewing backup jobs, tape and storage infrastructure, and removing backups from the configuration database. This forensic evidence provides detailed insight into attacker tactics for disabling backup defenses post-compromise, a critical technique in ransomware attacks.","RDP bitmap cache artifacts exposed threat actor accessing Veeam Backup & Replication console and deleting backups.",null,"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2038673364122849528","2026-03-30T17:43:01+00:00","2026-03-30T18:00:10.484657+00:00",8,[],"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73",{"id":17,"icon":11,"name":19,"slug":20},"Incident Response","incident-response",[22,27,32],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38],{"type":39,"value":40,"context":41},"malware","Veeam Backup & Replication console compromise","Threat actor interactive access to backup management console for backup deletion",[]]