HomeSecurityBrazilian Supreme Court: Fell victim of RansomExx ransomware

Brazil's Supreme Court: It fell victim to RansomExx ransomware

The Brazilian Supreme Court fell victim to a ransomware attack (RansomExx) during a court session via video conference.

RansomExx ransomware

“The Supreme Court (STJ) announces that its technological network was subjected to a hacking attack on Tuesday afternoon, during sessions,” said the President of the STJ, Humberto Martins, on the Supreme Federal Court website.

The government is working to restore systems and restore all judicial services as soon as possible.

Brazilian journalist Mateus Nunes told BleepingComputer that other Brazilian government agency sites are also offline. However, we don't know if the same criminals attacked these sites separately or if they are somehow connected to the systems that host the site .

Systems are offline

The Superior Tribunal de Justiça (also known as STJ) systems were shut down to stop the spread of ransomware throughout the court's network , but many court documents and backups had already been encrypted.

The Supreme Court's website and systems are still offline, three days after the ransomware attack. It is said that they will start operating again when all systems are fully restored.

“A Domain Admin account was abused, which allowed the attacker to access our servers, enter virtual environment management groups, and finally encrypt a portion of our virtual machines,” said one of the IT technicians.

Supreme Court of Brazil

According to the Brazilian Supreme Court, all trials, virtual and/or via videoconference will be suspended or canceled until court security is restored

In addition, the court's IT department suggested to all users, including judges, interns and external collaborators, not to use their computers, even personal ones, if they are still connected to the court's network.

The RansomExx ransomware gang behind the attack

The Brazilian Supreme Court did not name the ransomware gang responsible for this attack, but one of the ransom notes found on an encrypted computer points to the hackers behind the RansomExx ransomware.

According to an anonymous source from Bleeping Computer, the systems of the State Court of Pernambuco (Tribunal de Justiça do Estado de Pernambuco – TJPE) were also affected by the RansomExx ransomware on October 27. The encrypted files had the extension .tjpe911.

RansomExx (a variant of Defray777 ransomware) was used in multiple attacks in June 2020 targeting large organizations.

The Texas Department of Transportation (TxDOT), Konica Minolta, IPG Photonics, and Tyler Technologies are also victims of the RansomExx ransomware.

During their attacks, RansomExx operators breach victims' networks and steal unencrypted sensitive documents. They then spread to other systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS