Marketron , a business software provider serving more than 6,000 clients in the multimedia industry, fell victim to the BlackMatter ransomware gang over the weekend .

Marketron provides revenue and traffic management tools for organizations in the media sector.
See also: Ransomware: Are you worried? Three key steps to protect yourself
BlackMatter ransomware hits Marketron
Marketron customers learned of the incident through an email sent Sunday night by the company's CEO, Jim Howard . In the email, the CEO said that the "Russian criminal organization BlackMatter " was responsible for the ransomware attack
This is the second ransomware attack by the BlackMatter group this weekend. The gang also breached US farmers' cooperative, NEW Cooperative, and demanded $5.9 million.
Howard says in the email that he does not know how the hackers managed to breach the network, as the company had recently made significant investments in cybersecurity (new security tools, implementation of a zero-trust approach, etc.).
Howard also said that Marketron has contacted the hackers as well as the FBI and stressed that efforts are being made to restore the systems.
See also: Grief ransomware: We will destroy the decryption key if a negotiator is hired

Offline services
On Monday, Marketron announced the incident, saying it was a “cyber event” that disrupted some business operations and affected all of its customers.
“Currently, all Marketron services are offline,” the company announced, adding that the attack affected Marketron Traffic, Visual Traffic Cloud, Exchange, and Advertiser Portal services.
RadioTraffic and RepPak were still operational, but the company took them offline as a precaution. The only platforms that remained online were Pitch, Email Marketing, and Mobile Messaging.
See also: Windows MSHTML bug: Ransomware groups exploit the flaw
A Marketron executive revealed that the company has hired researchers “to understand the nature and scope of the attack, determine the root cause, and ensure the integrity and security of our systems and data.”
"We are unable to confirm the root cause of the incident at this time and this investigation is ongoing," the executive said.
BlackMatter ransomware is believed to be a rebrand of the DarkSide ransomware operation, which was shut down after the Colonial Pipeline attack in May.
The gang has been particularly active, targeting more than a dozen organizations this month alone. Some of the victims include:
- a wine and spirits company
- a banking service provider in the US
- Japanese technology giant Olympus
- a US-based construction company
- a communications company in the United Kingdom
Source: Bleeping Computer
