{"id":33465,"date":"2026-06-11T13:13:41","date_gmt":"2026-06-11T13:13:41","guid":{"rendered":"https:\/\/www.cbleon-abogados.com\/?p=33465"},"modified":"2026-06-11T13:13:41","modified_gmt":"2026-06-11T13:13:41","slug":"discover-how-cyber-attacks-are-carried-out-in-companies","status":"publish","type":"post","link":"https:\/\/cbleon-abogados.com\/en\/ciberataques-en-las-empresas\/","title":{"rendered":"Find out how cyberattacks are carried out against companies"},"content":{"rendered":"<h2><strong>Cyberattacks on Businesses<\/strong><\/h2>\n<p>In this post, we\u2019ll show you some of the cyberattack methods used by organized groups to break into company systems to steal information\u2014among other things\u2014and then demand a ransom.<\/p>\n<p><strong>Some of these methods have been identified by the Threat Hunting team at BlackArrow, an organization that provides offensive and defensive services through Tarlogic Security.<\/strong><\/p>\n<p>This division is a leader in cybersecurity in Europe. It has offices in Santiago de Compostela and Madrid and has recruited about a hundred experts in this field.<\/p>\n<p>Hace unas semanas, un equipo de cazadores de esta divisi\u00f3n, present\u00f3 un informe recapitulando los vectores principales de intrusi\u00f3n que se han detectado en empresas durante el 2022.<\/p>\n<p>Essentially, they conducted an investigation focused on identifying potential cyberattack threats to businesses.<\/p>\n<p>BlackArrow experts identified three methods used by cybercriminals to gain access to organizations' systems and carry out cyberattacks.<br \/>\nThese techniques, once hidden, have become a trend in 2022. They infiltrate systems through ISO and LNK files and also target the supply chain. Here\u2019s how it works.<\/p>\n<h3><strong>Cyberattacks on businesses via ISO files<\/strong><\/h3>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-33473 size-full\" src=\"https:\/\/www.cbleon-abogados.com\/wp-content\/uploads\/2022\/11\/Hacker-utilizando-el-virus-informatico-para-el-ataque-cibernetico.jpg\" alt=\"Hacker utilizando el virus inform\u00e1tico para el ataque cibern\u00e9tico\" width=\"1280\" height=\"853\" \/><\/p>\n<p class=\"translation-block\">Este es uno de los m\u00e9todos observados durante la investigaci\u00f3n. Los cibercriminales env\u00edan archivos ISO a trav\u00e9s de Google Drive.<br>\r\nEstos en apariencia son leg\u00edtimos, pero en realidad son el inicio de ciberataque a una empresa.<\/p>\n<p class=\"translation-block\">Se dirige particularmente, a lograr el control de los sistemas lo que resulta cr\u00edtico, sobre todo, si el sistema tiene capas defensivas vulnerables.<br>\r\nEl ciberataque a una empresa por este m\u00e9todo se ejecuta as\u00ed:<\/p>\n<p class=\"translation-block\"><strong>Cualquier empleado recibe el archivo ISO, en su correo electr\u00f3nico, compartido desde Google Drive. Cuando el documento se ejecuta autom\u00e1ticamente se monta e inicia toda una serie de m\u00e9todos dirigidos a la ejecuci\u00f3n de c\u00f3digos maliciosos.<\/strong><br>\r\nEstos pueden pasar a otros ordenadores de la empresa a trav\u00e9s del equipo de ese empleado. Si lo logra, el ciberataque a esa empresa puede dejar da\u00f1os cr\u00edticos.<\/p>\n<h4><strong>LNK Files: Another Method of Cyberattacks on Businesses<\/strong><\/h4>\n<p class=\"translation-block\">These are shortcuts that Windows uses to point to an original executable file.<br>\nWith this method, as with the previous one, cybercriminals use LNK files that appear legitimate but execute malicious code. The goal is to advance the intrusion sequence.<\/p>\n<p class=\"translation-block\">In this case, the code is executed as follows:<br>\n<strong>An employee may receive the LNK file via email, or from a storage device or USB drive. When the employee opens the link, the malicious activity created by the cyberattacker is executed.<\/strong><\/p>\n<h3><strong>Attack via the supply chain<\/strong><\/h3>\n<p>This method of cyberattack targeting a specific company has gained popularity in 2022. It is an intrusion vector known as a supply chain attack.<\/p>\n<p class=\"translation-block\">This means that the attack\u2019s objectives include compromising suppliers and using them as a gateway to compromise customers.<br>\n<strong>In this case, the attackers\u2019 goal is to target the larger organization by weakening the smallest link in the chain. In many cases, suppliers are more vulnerable to cyberattacks, so attackers see a clear path to the systems of larger companies.<\/strong><br>\nAll of this research has led BlackArrow experts to share some critical security tips to help today\u2019s businesses prevent cyberattacks.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-33469 size-full\" src=\"https:\/\/www.cbleon-abogados.com\/wp-content\/uploads\/2022\/10\/Soldados-de-las-Fuerzas-Especiales-de-Ciberseguridad-totalmente-armados.jpg\" alt=\"Soldados de las Fuerzas Especiales de Ciberseguridad totalmente armados\" width=\"1280\" height=\"720\" \/><br \/>\nIt is not enough to address vulnerabilities; we must also address potential threats.<\/p>\n<p class=\"translation-block\">Organizations are advised to invest in threat hunting services to protect their systems from attackers.<br>\nThey also recommend strengthening cybersecurity by placing greater emphasis on how attackers operate.<\/p>","protected":false},"excerpt":{"rendered":"<p>Ciberataques en las empresas En este post te mostramos algunos de los m\u00e9todos de ciberataques en las empresas, que est\u00e1n ejecutando grupos organizados para ingresar en los sistemas de compa\u00f1\u00edas para robar informaci\u00f3n, entre otras cosas, para luego solicitar rescate. Algunos de esos m\u00e9todos han sido detectados por el equipo de Threat Hunting de BlackArrow, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33466,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-33465","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualidad"],"_links":{"self":[{"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/posts\/33465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/comments?post=33465"}],"version-history":[{"count":1,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/posts\/33465\/revisions"}],"predecessor-version":[{"id":36226,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/posts\/33465\/revisions\/36226"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/media\/33466"}],"wp:attachment":[{"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/media?parent=33465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/categories?post=33465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cbleon-abogados.com\/en\/wp-json\/wp\/v2\/tags?post=33465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}