Insurance giant CNA Financial has been hit by a ransomware attack. The new ransomware variant that targeted the company is called Phoenix CryptoLocker and is said to be likely linked to the hacking group EvilCorp.
See also: Stratus Technologies hit by ransomware

CNA confirmed the cyberattack: “On March 21, 2021, CNA determined that it had suffered a sophisticated cyberattack. The attack caused a network outage and impacted certain CNA systems, including corporate email.”
Sources familiar with the attack told BleepingComputer that the ransomware encrypted over 15,000 devices on the company's network.
See also: Black Kingdom ransomware: Targets Microsoft Exchange servers. Greece among the victims
Also, according to BleepingComputer, the ransomware also encrypted the computers of employees working remotely who were connected to the company's VPN at the time of the attack.
When encrypting devices, Phoenix CryptoLocker ransomware added the .phoenix to encrypted CNA files and created a ransom named PHOENIX-HELP.txt.
See also: Acer: REvil ransomware gang demands $50,000,000 ransom!
It is said that the company can restore files from backups, but it is not confirmed.
Phoenix CryptoLocker ransomware attack likely linked to Evil Corp
Phoenix Locker ransomware may be linked to the hacking group Evil Corp, as it bears similarities to other malware used by hackers.
Evil Corp is known for using the WastedLocker ransomware to carry out attacks on organizations.

Since the US government imposed sanctions on the hacking group in 2019, most companies involved in ransomware negotiations have stopped facilitating ransom payments to avoid fines or other legal consequences.
According to a recent report from CrowdStrike, Evil Corp hackers have begun using a new ransomware, called Hades, to bypass US sanctions.
This ransomware has appeared in many attacks, such as the one that targeted Forward Air.
However, CrowdStrike showed that Hades is simply a version of WastedLocker ransomware, with a different name.
The new Phoenix CryptoLocker ransomware that targeted CNA Financial is believed to be another Evil Corp spinoff.
CNA Financial said there is currently no evidence to confirm the hacking group's connection to the ransomware.
The FBI is investigating.
Source: Bleeping Computer
