{"id":163,"date":"2026-03-24T13:57:11","date_gmt":"2026-03-24T17:57:11","guid":{"rendered":"http:\/\/localhost\/?p=163"},"modified":"2026-03-24T13:57:11","modified_gmt":"2026-03-24T17:57:11","slug":"peer-organized-operation-disrupts-bluecrab-operations","status":"publish","type":"post","link":"https:\/\/securityblog.denison.edu\/index.php\/2026\/03\/24\/peer-organized-operation-disrupts-bluecrab-operations\/","title":{"rendered":"Peer-organized operation disrupts BLUECRAB operations"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Denison ITS, in cooperation with a number of peer institutions, identified at least ten breached accounts across these institutions which were being used to maintain persistence in computing environments, especially in email tenants and file sharing applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Disrupting these applications was an important step in disrupting BLUECRAB&#8217;s operations. In short, we disrupted their data source by removing their access to accounts they should not have had access to. These accounts were generally not used to send phishing or spear phishing attack messages. Instead, these were used to host forms and data sheets on potential victims.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Denison ITS, in cooperation with a number of peer institutions, identified at least ten breached accounts across these institutions which were being used to maintain persistence in computing environments, especially in email tenants and file sharing applications. Disrupting these applications was an important step in disrupting BLUECRAB&#8217;s operations. In short, we disrupted their data source by removing their access to accounts they should not have had access to. These accounts&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-163","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/comments?post=163"}],"version-history":[{"count":0,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/163\/revisions"}],"wp:attachment":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/media?parent=163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/categories?post=163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/tags?post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}