HomeSecurityArcus Media ransomware: Did it target the National Audit Office of Kiribati?

Arcus Media ransomware: Did it target the National Audit Office of Kiribati?

The Arcus Media ransomware gang claims to have stolen 120GB of data from the National Audit Office of Kiribati.

The Kiribati Audit Office (KAO) is an independent government agency responsible for auditing Kiribati's public accounts. Hackers have added the service to their dark web extortion site and are threatening to leak various government and business data.

See also: Fourlis Group – IKEA: Losses from ransomware attack reached €20 million.

The data breach was reportedly discovered on March 19.

Arcus Media ransomware Kiribati

Arcus Media ransomware: How does the group usually operate?

Arcus Media ransomware appeared almost a year ago, but the group quickly adapted its tactics and managed to become a significant threat.

According to expert analysis, Arcus Media uses a highly targeted approach that causes maximum disruption before it begins encrypting systems. It uses various techniques, such as process termination, selective encryption, and data recovery interruption , leaving companies with little to no options for restoring their systems. This increases the chances of paying the ransom. Let’s take a closer look at how the Arcus Media ransomware group typically operates :

Targeting and terminating processes

Arcus Media identifies and terminates critical processes. The team focuses primarily on SQL servers to disrupt database access, email clients to block communications, and tools backup to thwart data recovery attempts.

See also: Sensata Technologies hit by ransomware

Arcus Media ransomware: Did it target the National Audit Office of Kiribati?

Using Windows APIs, such as CreateToolhelp32Snapshot, the Arcus Media ransomware enumerates running processes and then executes TerminateProcess to stop them. This approach ensures that targeted applications cannot be restarted, thus maximizing overall damage before encryption begins.

Selective file encryption

Instead of encrypting entire drives, Arcus Media ransomware uses selective encryption to optimize speed and efficiency. Large files are only partially encrypted to maintain speed, but render them unusable, while smaller files are subjected to full encryption to ensure complete data loss.

This method reduces the risk of detection and increases the overall impact.

Disruption of data recovery processes

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

To prevent recovery attempts, Arcus Media ransomware deletes recovery options using built-in Windows tools. It deletes shadow backups, disables system restore, and deletes event logs. If victims cannot access their data, they are more likely to pay a ransom.

See also: RansomEXX ransomware group used Windows CLFS zero-day

Arcus Media’s sophisticated tactics pose a significant challenge to companies and organizations, including the Kiribati Audit Office. The hackers’ strategies are now forcing organizations to rethink traditional ransomware defenses and adopt new approaches to cybersecurity.

Proactive protection against ransomware is critical. Some helpful practices include:

  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to the network
  • Encryption of sensitive data
  • Updating devices and systems with the latest security patches
  • Conducting regular security audits and penetration testing
  • Using strong, unique passwords 
  • Limiting user access to only necessary systems and information
  • Use solutions email security for additional protection against phishing attacks
  • Recovery plan for rapid restoration of systems in the event of an attack
  • Regular data backups

Source: securitybuzz.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS