Qualysec

Cybersecurity News | 2024 May 4th week

Table of Contents
Greetings from Qualysec! We are excited to share with you our weekly roundup of the latest cyber security news.

1. Ransomhub Attacking Industrial Control Systems To Encrypt And Exfiltrate Data

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) across various industries.

Since 2022, numerous cyberattacks have exploited vulnerabilities in ICS, causing significant disruptions to operations and infrastructure. This highlights the need for robust security measures to safeguard ICS environments.

The Ransomhub ransomware group claimed unauthorized access to Gijón’s BioEnergy Plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control.

The group provided screenshots as evidence, showcasing their ability to manipulate the plant’s Digester and Heating system controls.

While the exact size of the data breach remains unclear (varying between 15 GB and 400 GB), the compromised SCADA system poses a significant risk to the plant’s operations.

Ransomhub, a RaaS operation first advertised in February 2024, utilizes Golang and C++ for its locker component and leverages asymmetric cryptography(x25519) and a combination of symmetric algorithms (aes256, chacha20, and xchacha20) to encrypt victim data while achieving faster encryption speeds.

Swagat Kumar Dash

Business Development Manager

“Connect with Swagat – your Security Advisor ! Feel free to share your security challenges with him and he'll guide you to the most effective solutions.”

2. Chinese Hackers Using ORB Proxy Networks For Stealthy Cyber Attacks

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) across various industries.

 

Since 2022, numerous cyberattacks have exploited vulnerabilities in ICS, causing significant disruptions to operations and infrastructure. This highlights the need for robust security measures to safeguard ICS environments.

 

The Ransomhub ransomware group claimed unauthorized access to Gijón’s BioEnergy Plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control.

 

The group provided screenshots as evidence, showcasing their ability tomanipulate the plant’s Digester and Heating system controls. While the exact size of the data breach remains unclear (varying between 15 GB and 400 GB), the compromised SCADA system poses a significant risk to the plant’s operations.

 

Ransomhub, a RaaS operation first advertised in February 2024, utilizes Golang and C++ for its locker component and leverages asymmetric cryptography(x25519) and a combination of symmetric algorithms (aes256, chacha20, and xchacha20) to encrypt victim data while achieving faster encryption speeds.

3. Sharp Dragon Hackers Attacking Government Entities Using Cobalt Strike & Custom Backdoors

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) across various

industries.

 

Since 2022, numerous cyberattacks have exploited vulnerabilities in ICS, causing significant disruptions to operations and infrastructure. This highlights the need for robust security measures to safeguard ICS environments.

 

The Ransomhub ransomware group claimed unauthorized access to Gijón’s BioEnergy Plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control.

 

The group provided screenshots as evidence, showcasing their ability to manipulate the plant’s Digester and Heating system controls.

 

While the exact size of the data breach remains unclear (varying between 15 GB and 400 GB), the compromised SCADA system poses a significant risk to the plant’s operations.

 

Ransomhub, a RaaS operation first advertised in February 2024, utilizes Golang and C++ for its locker component and leverages asymmetric cryptography(x25519) and a combination of symmetric algorithms (aes256, chacha20, and xchacha20) to encrypt victim data while achieving faster encryption speeds.

4. GenAI Bots Can Be Tricked by Anyone To Leak Company Secrets

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) across various

industries.

 

Since 2022, numerous cyberattacks have exploited vulnerabilities in ICS, causing significant disruptions to operations and infrastructure. This highlights the need for robust security measures to safeguard ICS environments.

 

The Ransomhub ransomware group claimed unauthorized access to Gijón’s BioEnergy Plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control.

 

The group provided screenshots as evidence, showcasing their ability to manipulate the plant’s Digester and Heating system controls.

 

While the exact size of the data breach remains unclear (varying between 15 GB and 400 GB), the compromised SCADA system poses a significant risk to the plant’s operations.

 

Ransomhub, a RaaS operation first advertised in February 2024, utilizes Golang and C++ for its locker component and leverages asymmetric cryptography(x25519) and a combination of symmetric algorithms (aes256, chacha20, and xchacha20) to encrypt victim data while achieving faster encryption speeds.

Contact us

Let's work together to secure your business!

Please fill out the form to let us know about your cybersecurity needs and our professionals will reach out shortly to discuss your unique needs.

Total No. Vulnerabilities
12629

4+

Years in Business

600+

Assessment Completed

150+

Trusted Clients

21+

Countries Served

    Subscribe to Newsletter

    Scroll to Top
    Pabitra Kumar Sahoo

    Pabitra Kumar Sahoo

    COO & Cybersecurity Expert

    “By filling out this form, you can take the first step towards securing your business, During the call, we will discuss your specific security needs and whether our services are a good fit for your business”

    Get a quote

    For Free Consultation

    Pabitra Kumar Sahoo

    COO & Cybersecurity Expert