During a recent incident response engagement for an external organization, the BHIS ActiveSOC team investigated activity attributed to the Aur0ra ransomware group. In this incident, initial access was gained through vishing following aggressive email bombing. This foothold was followed up by the deployment of a unique C2 mechanism with noisy lateral movement & ransomware attempts.