
A ransomware gang has infected the internal network of Telecom Argentina, one of the country's largest Internet service providers (ISPs), and is demanding $7.3 million to unlock encrypted files.
The attack took place on Saturday, July 18 and is considered one of the largest hacks in Argentina.
Sources within the ISP said that the ransomware gang caused extensive damage to the company's network after gaining control of an internal domain admin. From there, it installed and spread the ransomware payload to more than 18,000 workstations.
The attack did not cause Internet connection problems for ISP customers, nor did it affect landline or television services. However, many of Telecom Argentina's official websites have been down since Saturday.
Many ISP employees are using social media to share details about the incident and how Telecom Argentina is handling the crisis.
According to images posted online, the ISP immediately detected the intrusion and began warning employees by sending internal notifications to limit their interaction with the corporate network. It also advised them not to connect to the internal VPN and not to open emails containing files.
The attackers are said to be the ransomware group REvil . A tweet (now deleted) appeared on Twitter showing the dark web portal, the page where victims are directed to pay the ransom.
This page displayed a demand for payment of 109345.35 Monero coins (~$7.53 million), an amount that will double today, making it one of the largest amounts demanded in a ransomware attack this year.

Telecom Argentina has not commented on the incident.
Local media also reported that the ISP believes the hackers was a malicious email received by one of its employees. But this technique does not generally fit with the usual modus operandi of the REvil ransomware gang.
According to a report by security firm Advanced Intel (for the previous year), the REvil gang has specialized in attacks on corporate networks, exploiting unpatched systems , etc.
Security firm Bad Packets said that Telecom Argentina had Citrix VPN servers that were vulnerable to the CVE-2019-19781 vulnerability, despite the fact that a patch has been released for several months.
The REvil ransomware gang also has a site where it exposes data from its victims. So far, no Telecom Argentina files have been leaked.
