HomeSecuritySoftServe: Ransomware attack has affected our customers

SoftServe: Ransomware attack has affected our customers

The Ukrainian company SoftServe suffered a ransomware attack on September 1st that may have led to the theft of its customers' source code.

With more than 8,000 employees and 50 offices worldwide, SoftServe is one of the largest companies in Ukraine that offer software development and IT consulting services.

News about the online attack on SoftServe first began circulating on the channel «Telegram DС8044 Kyiv Info», where a forged company message was shared with its employees.

SoftServe ransomware

In a later statement on the Ukrainian news site AIN, SoftServe confirmed that it had suffered a cyberattack that forced it to “disconnect” its customers to prevent its spread.

«Yes, indeed we experienced an attack today. The most significant consequences of the attack are the temporary loss of functionality of a part of the mail system and the interruption of some of the auxiliary testing environments. As far as we can assess, this is the biggest impact of the attack and other systems or customer data were not affected.»

“To prevent the spread of the attack, we isolated certain segments of our network and limited communication with the clients' networks. We are preparing a message to inform our customers about the situation. We are still investigating the incident so we are not ready to comment on who did it,” said Adriyan Pavlikevich, vice president of SoftServe.

A report identified today by the security researcher of MalwareHunterTeam confirms that SoftServe suffered a ransomware attack.

This incident report states that the ransomware attack added the extension “* .s0fts3rve555 – *** (like s0fts3rve555-76e9b8bf)” to the encrypted file names.

It has not been confirmed, but this extension pattern matches those used by the Defray ransomware, also known as RansomEXX, which was recently used against Konika Minolta.

The report also includes a PowerShell script used to find files that were changed during the attack, indicating that the attack occurred between 2 a.m. and 9 a.m.

The customers' source code is reported to have been stolen

In a later post on the Telegram channel DC8044, links to “source code repositories” allegedly stolen during this attack were shared. These zip files are for projects that claim to be intended for companies such as Toyota, Panasonic, IBM, Cisco, ADT, and WorldPay.

Windows customization tool that exploited the attack

According to SoftService's report, the attackers exploited a DLL vulnerability that compromised the legitimate Rainmeter application to deploy their ransomware.

Rainmeter is a legitimate Windows customization tool that loads a Rainmeter.dll at startup .

During the attack, the threat actors replaced the legitimate Rainmeter.dll with a malicious version.

Source:Bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS