HomeSecurityEnel Group: Attacked by SNAKE Ransomware

Enel Group: Attacked by SNAKE Ransomware

The giant European energy company Enel Group was attacked by SNAKE ransomware a few days ago, which affected its internal network.

Detected on June 7, the incident is the work of the operators of the EKANS (SNAKE) ransomware, the group that attacked Honda earlier this week.

snake ransomware Enel Group

Enel recovered quickly

Enel Group confirmed that its internal IT network was disrupted on Sunday afternoon following a ransomware attack that was detected by their antivirus before the malware could spread.

Addressing the incident required isolating the corporate network for a limited period of time, “to carry out all interventions aimed at eliminating any residual risks.” All connectivity was safely restored early Monday morning, the company says.

When SNAKE is deployed in a targeted attack, it performs checks on internal domains and IP addresses to confirm whether it is running on the correct network.

If these checks fail, the ransomware will not perform encryption.

Enel did not mention the name of the ransomware used in the attack, but security researcher Milkream found a SNAKE/EKANS sample submitted to VirusTotal on June 7 that shows it checks for the domain “enelint.global.”.

This domain is currently owned by Enel and redirected to the company's international page when it was live.

The same domain is linked to Enel addresses in the U.S. and Italy and later leads to websites that change based on the countries where the company operates.

Analysis by Milkream shows the string “enelint.global” in the malware sample as well as a check for an internal IP address.

There are no details on how the attackers managed to gain access to the network, but a common entry point is exposed remote desktop (RDP) connections, typically used for remote support/maintenance.

This makes sense for both Enel and Honda, as security researcher Germán Fernández from CronUp found that both companies had RDP connections exposed to the internet.

Moreover, the exposed connections involved machines at “enelint.global” and “mds.honda.com,” the same domains that were checked by EKANS ransomware samples uploaded to VirusTotal:

Enel Group: Attacked by SNAKE Ransomware

According to statements from both companies, the Snake ransomware attack was unsuccessful.

However, it is unknown when the attackers entered the network and whether they had time to steal data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS