HomeSecurityOlympus: Japanese giant victim of BlackMatter ransomware?

Olympus: Japanese giant victim of BlackMatter ransomware?

Japanese company Olympus, which primarily manufactures equipment for medical and research purposes, is said to have fallen victim to the BlackMatter ransomware.

Olympus BlackMatter ransomware?
Olympus: Japanese giant victim of BlackMatter ransomware?

Olympus issued a brief statement on Sunday, saying it was investigating a possible cybersecurity incident affecting its computer network in Europe, the Middle East and Africa.

See also: Ransomware: Are you worried? Three key steps to protect yourself

“ Upon identifying the suspicious activity, we immediately mobilized a dedicated response team, including specialist investigators, and are currently working to resolve this issue. As part of the investigation, we have suspended data transfer to the affected systems and notified relevant external partners ,” the company said in a statement

TechCrunch reports that a person familiar with the incident said that Olympus faced a ransomware attack that began in the early hours of September 8. In fact, this person appears to have provided some details about the attack before Olympus announced the incident.

According to this person, the attackers left a ransom note on the infected computers, which claims to come from the BlackMatter ransomware. “Your network is encrypted and is currently not working,” it says. “If you pay, we will give you the programs for decryption.” The ransom note also included an address to a website accessible only through the Tor browser, which is known to be used by the BlackMatter ransomware gang to communicate with victims.

Brett Callow, a ransomware expert and threat analyst at Emsisoft, told TechCrunch that the site in the Olympus ransom note is indeed associated with the BlackMatter group.

BlackMatter is a ransomware-as-a-service, created as a successor to several ransomware, including DarkSide and Revil, which had recently disappeared after major attacks that attracted the attention of US authorities.

Ransomware groups like BlackMatter rent out access to their infrastructure , which is then used by other criminals to carry out attacks. In return, the BlackMatter group takes a cut of the ransom money. Emsisoft has also found common code and technical elements between Darkside and BlackMatter ransomware.

See also: Ransomware attack forces Howard University to cancel classes

Olympus: Japanese giant victim of BlackMatter ransomware?

Since the group emerged in June, Emsisoft has recorded more than 40 ransomware attacks attributed to the BlackMatter gang and its affiliates, but the number of victims may be higher.

See also: REvil ransomware servers mysteriously “return”

Ransomware groups, such as BlackMatter, steal data from a company's network before encrypting it and later threaten to publish the files online if victims do not pay the ransom.

The Japanese company Olympus is known for manufacturing technology and equipment for the medical and life sciences industries. Until recently, the company manufactured digital cameras and other electronics, until it exited this sector by selling the corresponding division of the company.

Olympus said it is working to determine the extent of the issue and will continue to provide updates as new information becomes available.

Source: TechCrunch

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS