HomeSecurityLarge German company is out of business due to ransomware

Large German company out of business due to ransomware

ransomwareThe German company Pilz, one of the largest manufacturers in the world, announced that it had fallen victim to a ransomware attack, resulting in its operations being disrupted for more than a week.

The company announced the incident on its website: “As of Sunday, October 13, 2019, all servers and PC workstations have been affected.”

"As a precautionary measure, the company removed all systems from the network and blocked access to the corporate network."

Pilz has factories in 76 countries. According to the company, all of them were affected by the attack and disconnected from the main network. As a result, they were unable to send orders or check anything related to customers .

It took three days to restore access to email and another three to restore access to factories in all countries. Even worse, access to orders and the product delivery system was restored yesterday.

Pilz stated that the production process was not affected by the ransomware but there was no possibility of checking orders, resulting in it not being able to function properly.

Large German company out of business due to ransomware

BITPAYMER

Maarten van Dantzig, an analyst at FoxIT, discovered that the ransomware that infected the German company's systems is BitPaymer, which has targeted a large number of companies.

The analyst found and examined a sample of BitPaymer on VirusTotal. The ransom note contained information related to Pilz.

BitPaymer ransomware first appeared in the summer of 2017 and has been used in numerous attacks on hospitals in Scotland, two cities in Alaska (Matanuska-Susitna and Valdez), the company Arizona Beverages, etc.

The creators of BitPaymer always choose "high value" targets with the aim of earning large sums of money.

BitPaymer has, until now, been distributed exclusively through the botnet . ESET claimed in 2018 that the creators of Dridex also designed the ransomware.

According to many experts, the hackers behind Dridex first attack with the trojan and then infect the systems of large companies with BitPaymer.

Van Dantzig said that this ransomware has provided a lot of profit to the attackers, demanding over $1 million for the decryption of victims' files

The botnet-ransomware combination is very popular these days. The Emotet and TrickBot botnets have also been combined with the Ryuk ransomware.

Unlike other ransomware, which is encountered in attacks every day, BitPaymer attacks occasionally. This is because specific targets and not just any company. The target is high-profile companies.

Analyst Van Dantzig said that to restore a company's networks infected with BitPaymer, system administrators must also remove the Dridex trojan. If they do not, they will become infected again.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS