HomeSecurityCactus Ransomware group hacks Swedish company Coop

Cactus Ransomware group hacks Swedish company Coop

The Cactus Ransomware group hit Swedish retailer and grocery provider Coop.

Cactus Ransomware

The Cactus ransomware group claims to have carried out a hacking attack on Coop, one of the largest retail and grocery chains in Sweden.

Coop is one of the largest retail and food supply chains in Sweden, with around 800 stores across the country. The stores are owned by 29 consumer communities, with a total of around 3.5 million members. Any surplus generated by the business's operations is returned to the members or reinvested in the business, creating a cycle.

The Cactus ransomware group claims to have hacked the company Coop and threatens to reveal a large amount of personal information, over 21 thousand directories.

The Cactus hacking group added the company Coop to its list of victims on the Tor website for leaks.

Cactus Ransomware

Threat actors have published identities as proof of their infiltration.

In July 2021, Swedish supermarket chain Coop was the first company to disclose the impact of the ransomware attack on its supply chain affecting Kaseya.

Supermarket chain Coop closed around 500 stores due to a supply chain ransomware attack that affected provider Kaseya.

Coop does not use Kesaya software, however, it was affected by the incident because one of its software suppliers uses it.

According to BleepingComputer, the affected provider was Swedish MSP Visma, which manages payment systems for the supermarket chain.

Visma confirmed that it was affected by the Kaseya cyberattack, which allowed the REvil ransomware to encrypt its customers' systems.

The Cactus ransomware operation has been active since March 2023, although the perpetrators use a double extortion model, their data leakage website has not yet been discovered.

Kroll researchers reported that the ransomware variant stands out for its use of encryption to protect the ransomware binary.

The Cactus ransomware uses the SoftPerfect Network Scanner (netscan) to scan for other targets on the network along with PowerShell commands to enumerate endpoints. The ransomware identifies user accounts by displaying successful logins in the Windows Event Viewer, and also uses a modified form of the open source tool PSnmap.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cactus ransomware relies on several legitimate tools (e.g. Splashtop, AnyDesk, SuperOps RMM) to achieve remote access and uses Cobalt Strike and the Chisel proxy tool in post- breach.

Once the malware gains access to a computer, the threat actors use a command package to uninstall popular antivirus solutions installed on the computer.

Cactus uses the Rclone tool to extract data and uses a PowerShell script called TotalExec, which was previously used by the perpetrators of the BlackBasta ransomware, to automate the encryption.

Information source: securityaffairs.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS