CyberSecurityNews

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network


A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging his employer’s Windows network and demanding a cryptocurrency ransom.

Daniel Rhyne, 59, of Kansas City, Missouri, received the sentence on September 28, 2026, in federal court in Trenton. Rhyne previously pleaded guilty to extortion involving threats to damage a protected computer and intentional damage to a protected computer.

U.S. District Judge Michael A. Shipp imposed the sentence after Rhyne admitted attacking an unnamed industrial company headquartered in New Jersey.

Rhyne worked as a core infrastructure engineer and served as the company’s specialist for hosting virtual machines. According to the criminal complaint, investigators traced the malicious activity to an unauthorized virtual machine created inside the company’s network on November 9, 2023.

The hidden machine became a stepping stone to the company’s domain controller, which managed network authentication. Investigators found that it repeatedly accessed a legitimate domain administrator account through remote desktop sessions between November 10 and November 25, 2023.

Former Infrastructure Engineer Sentenced

On November 25, starting around 8:12 a.m., the administrator account created approximately 16 unauthorized scheduled tasks. Six were configured to execute that afternoon, deleting 13 domain administrator accounts and changing passwords for 301 domain user accounts.

The remaining tasks were configured to shut down dozens of servers beginning December 3. The attack used Windows administration tools rather than a described file-encrypting payload.

The “net user” utility handled domain account changes, while Microsoft’s Sysinternals PsPasswd tool changed local administrator passwords. Those local credential changes targeted accounts affecting 254 servers and 3,284 workstations.

At approximately 4:00 p.m. on November 25, administrators began receiving password reset notifications. They subsequently discovered that other domain administrator accounts had been deleted, denying them administrative access to the network.

Around 44 minutes later, employees received an external email titled “Your Network Has Been Penetrated.” It demanded 20 bitcoin, worth approximately $750,000 at the time, with a payment deadline of December 2, 2023.

The message threatened to shut down 40 random servers daily for 10 days unless the company paid. It also claimed it had deleted backups.

However, the complaint describes backup deletion as an assertion in the ransom email, not a separately verified forensic finding.

Investigators connected the hidden virtual machine to Rhyne’s assigned laptop and user account. Physical access records and security footage placed him at company headquarters shortly before corresponding laptop logins and subsequent virtual machine access.

Remote connections also originated from an IP address assigned to his residence. On the attack morning, investigators reconstructed a sequence linking his laptop login, home network connection, hidden virtual machine access, and remote desktop session to the domain controller.

Another link was password reuse. The hidden virtual machine, altered domain accounts, and extortion email account shared “TheFr0zenCrew!” Investigators also found related searches about password changes, account deletion, remote shutdowns, and clearing Windows logs

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC



Source link