Corvus
Threat Playbook · Red & Blue · Paired Analysis

Adversary Vectors & Defensive Controls

Surfaced exposures evaluated as adversary opportunities (left) and the defensive controls that close them (right). Vectors and controls are paired where one directly addresses the other. Baseline controls apply across multiple vectors.

7
Red Vectors
10
Blue Controls
7
Paired
3
Baseline

Red · Adversary Vectors

7 vectors · ranked by severity
R-01 Severe High Confidence

Citrix RAS credential-reuse from active infostealer corpus

Surface: ua.intranet.db.com/Citrix/RASweb (81 occurrences), sg-kch5.dbrasweb.db.com (51), sg-dsj5.dbrasweb.db.com (47), sg-kch4.dbrasweb.db.com (36) per ent_149. An adversary purchasing a fresh stealer-log subscription that intersects DB's user-set would very likely obtain immediately-usable corporate credentials. Severity SEVERE because Citrix RAS is by design a remote-access gateway with VPN-equivalent reach; HIGH confidence because the telemetry is dated to 2025-2026 capture windows and the host enumeration pattern (kch4 → kch5) suggests active provisioning rather than decommissioned infrastructure.

R-02 Severe High Confidence

Executive credential-reuse from cracked LinkedIn + 5 corpora

christian.sewing@db.com ∈ Abrigo + CFGI + BureauvanDijk + Verifications. james.vonmoltke@db.com ∈ Abrigo + DemandScience. stefan.hoops@db.comLinkedIn 2012/2016 + Verifications + Adapt + DemandScience — LinkedIn unsalted-SHA1 plaintext circulates publicly. reiner.schaefer@db.com ∈ Verifications (~2019). dns.admin@db.com ∈ Epik 2021 (the high-profile Anonymous dump). Severity SEVERE because the targets include the CEO, CFO, and a CEO-successor candidate; HIGH confidence in the exposure (XposedOrNot is direct), MODERATE in current exploitability (depends on rotation hygiene which Corvus cannot verify passively).

R-03 Severe Moderate Confidence

3rd-party-vendor impersonation as DMARC-bypass route

With DB's @db.com perimeter very likely mature, the highest-yield phishing route shifts to (a) compromise a SaaS vendor in DB's trust web (Markit/Frontify/Salesforce per ent_052/ent_094/ent_095) and pivot through legitimate outbound channels, or (b) register look-alike domains (e.g., autobahn-db.com, db-research.com). Severity SEVERE because successful supplier-impersonation phishing can land payloads in trusted contexts; MODERATE confidence because the exploitability depends on the specific vendor's controls.

R-04 Moderate High Confidence

Internal codenames + UAT hosts leaking via CT — hygiene risk

An adversary who lands on a DB endpoint (e.g., via the R-01 / R-02 routes) can use the CT-mined internal-host dictionary to enumerate dev/test/integration environments faster than starting from zero. Severity MODERATE — this is a force-multiplier, not a primary vector. HIGH confidence in the exposure (the CT records are public primary data).

R-05 Moderate Moderate Confidence

Adversary sanctions-typology probing post-OFSI £165k

Severity MODERATE — the impact is regulatory + reputational rather than data-loss. MODERATE confidence — the probing pattern is hypothesis-supported by historical typology but Corvus cannot observe specific transaction flows.

R-06 Moderate Moderate Confidence

Insider-leak risk during 2026 succession + AGM + private-credit window

Severity MODERATE — exfiltration of internal succession-related communications, AGM-related auditor memos, or private-credit counterparty lists would produce material press but not catastrophic operational compromise. MODERATE confidence — based on inferred incentive structure rather than direct evidence of staging.

R-07 Low Moderate Confidence

Targeted pretexting against Chair Wynaendts (UAE nexus)

Severity LOW because successful exploitation requires multi-stage pretexting with limited direct data-loss surface. MODERATE confidence — the vector is plausible given the public UAE engagement footprint but Corvus surfaces no specific indicator of staging.

Blue · Defensive Controls

10 controls · paired and baseline
B-01 Paired

Mandatory MFA + password rotation on all Citrix RAS endpoints with infostealer hits

Force rotation of every credential observed in the HudsonRock corpus for ua.intranet.db.com, sg-kch4/5.dbrasweb.db.com, sg-dsj5.dbrasweb.db.com and any related Singapore/Ukraine RAS hosts. Enforce phishing-resistant MFA (FIDO2 / certificate-based) at the Citrix gateway, not just at the downstream application. Audit whether the Singapore endpoint cohort is BYOD/contractor — if so, fold those endpoints into managed-MDM scope or block their access to corporate credentials.

B-02 Paired

Targeted credential reset + MFA-enforcement audit for the 5 surfaced executive emails

Confirm Sewing / von Moltke / Hoops / Schaefer / dns.admin role-mailbox have rotated credentials post-breach exposure and that MFA is mandatory on every IdP they authenticate against (M365, SSO, GitHub, AWS, CIM, board-portal SaaS). Treat Hoops's LinkedIn 2012/2016 exposure as worst-case and audit any 13-year-old password-recovery patterns. Subscribe DB's IAM team to HIBP API for continuous credential-leak monitoring on the full @db.com namespace.

B-03 Paired

Trust-boundary hardening for SaaS vendors in DB's outbound channel (Markit / Frontify / Salesforce)

Audit DKIM / DMARC alignment on subdomains delegated to third-party SaaS (research.ctc.db.markitondemand.com, brand.db.com on Frontify, Salesforce CRM domains). Implement BIMI + verified-mark certificates on @db.com to reduce look-alike-domain phishing success rate. Run typosquat monitoring (e.g., DNSTwist or Group-IB Threat Intelligence) for db.com, autobahn.db.com, flow.db.com, and the executive surname family.

B-04 Paired

Cert-issuance hygiene: avoid internal codenames + UAT hostnames in publicly-trusted CT-logged certs

Audit DB's PKI policy so that internal codenames (Phoenix, TRXM) and UAT/SIT environment hostnames issue from a private CA rather than a publicly-trusted CA that emits to CT logs. Migrate FIS BaNCS UAT (uatbancs.us.db.com) and the trxm.{int,dev} family to internal-only certificates. Where externally-trusted certs are required, prefer generic anchor names that don't encode the internal codename.

B-05 Paired

Post-OFSI controls remediation review at DBLB

Independent third-party review of DBLB sanctions-screening controls covering the period post-Russia-2022 sanctions through 2026-04-30, with explicit scoping to entities controlled by Russian streaming, telecoms, and finance-adjacent verticals (Okko, Sber, VTB, Tinkoff, Yandex subsidiaries). Publish remediation milestones to the FCA + OFSI on a quarterly cadence.

B-06 Paired

Insider-threat playbook scoped to 2026 succession + AGM + private-credit windows

Activate insider-threat monitoring with elevated thresholds during three specific windows: (a) the management-board succession decision window (likely 2026-Q3-Q4 per FT 2026-03-19 reporting); (b) the AGM 2026-05-28 + auditor-counter-motion window; (c) private-credit-disclosure quarterly windows. Constrain attribute-based access for sensitive succession communications and Apollo-related receivables-financing data.

B-07 Paired

Executive-protection extensions for Chair Wynaendts UAE engagement footprint

Apply executive-protection protocols to Wynaendts's external engagements (calendar opacity, dedicated burner devices for sensitive travel, out-of-band confirmation for any financial-instruction request purportedly from him). Ensure Sheikh Maktoum-related correspondence routes through hardened channels.

B-08 Baseline

Enforce DMARC p=reject across every .db.com subdomain

Extend the @db.com p=reject policy to every subdomain that issues outbound mail (incl. invoicing, M365 sub-tenants, marketing automation). Audit any subdomain currently in p=quarantine or p=none and migrate to p=reject within 90 days. Already-in-place for the apex per ev_005 — extend to the full tree.

B-09 Baseline

Continuous secret-scanning + commit-hygiene across DB GitHub and internal repos

Adopt pre-commit secret scanning (gitleaks, truffleHog) across all DB-administered repositories; integrate alerts into the SOC pipeline; rotate any credential surfaced in scan, paste-site, or external aggregator output (HudsonRock, XposedOrNot, hudsonrock_email) within 24h of detection.

B-10 Baseline

Sanctions-controls compliance dashboard with cross-jurisdiction view (UK OFSI + EU + US OFAC + DE BaFin)

Maintain a single compliance dashboard reconciling sanctions designations across UK OFSI, EU consolidated list, US OFAC, and DE BaFin enforcement actions, with automated reconciliation against transaction monitoring rules. Build in evidence-of-tuning provenance so that any future post-incident review (e.g., a successor to ent_153) can demonstrate forward-looking calibration rather than reactive only.