HomeSecurityRhysida ransomware: Chilean Army data leaked

Rhysida ransomware: Chilean Army data leaked

The gang behind a new ransomware called Rhysidaappears to have stolen data from the Chilean Army (Ejército de Chile) after an attack that took place late last month. The hackers behind this attack have uploaded documents online that they claim were stolen from the military's system.

Rhysida ransomware

The leak occurred after the Chilean Army confirmed on May 29 that its systems were affected by a security incident detected over the weekend of May 27. This is evidenced by a statement shared by Chilean cybersecurity company CronUp .

See also: A ransomware operation targets Russian Enlisted players

The network has been isolated due to a breach. Military security have begun the process of recovering the affected systems.

The military notified the Chilean Computer Security Incident Response Team (CSIRT), which belongs to the Army Joint Staff and the Ministry of National Defense .

A few days after the attack, local media reported that an army corporal had been arrested and charged with involvement in the attack .

The Rhysida ransomware gang has uploaded data 30% of the data it claims to have stolen from the Chilean Army's network to its

“ Rhysida ransomware published around 360,000 Chilean Army documents (and according to them, it’s only 30%) ,” CronUp security researcher Germán Fernández tweeted .

See also: LockBit ransomware: Gang earned $91 million through 1,700 attacks on US organizations

The Rhysida ransomware gang describes itself as a “cybersecurity group” and states that it aims to help victims protect their networks. MalwareHunterTeam reported that it detected the gang on May 17, 2023.

Ejército de Chile Chilean Army

So far, the ransomware group has added eight victims to the data leak website and has published all stolen files for five of them.

According to SentinelOne, the Rhysida ransomware gang uses phishing to compromise targets' networks and then installs payloads on compromised systems, using Cobalt Strike or similar command-and-control (C2) frameworks.

The samples analyzed so far show that the gang's malware uses the ChaCha20. It appears that the malware is still in development, as it lacks features that most ransomware today has by default.

Upon execution, it launches a cmd.exe window, starts scanning local drives, and displays ransom notes named CriticalBreachDetected.pdf, after encrypting victims' files.

See also: Illinois government agencies attacked by ransomware group CL0P

Victims are redirected to the gang's Tor leak portal, where they are asked to enter the unique identifier in the ransom notes to access payment instructions. The gang threatens victims with data leakage, as most ransomware gangs do today.

Ransomware is a major threat to computer users around the world. It is important to take steps to protect yourself, such as keeping your software up to date and regularly backing up your files. If you do fall victim to ransomware, it is important to remain calm and carefully consider your options before making any decisions. By staying informed and prepared, you can minimize the risk of falling victim to ransomware (for you or your business).

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS