30 November 2020

Chip maker Advantech hit by a Conti ransomware attack


Chip maker Advantech hit by a Conti ransomware attack

Hackers behind the Conti ransomware operation infected systems of industrial automation and Industrial IoT (IIoT) chip manufacturer Advantech and are now demanding a 750 BTC (approx. $14M) ransom for a decryptor to restore encrypted systems and to stop stolen data leakage.

According to a chat log and a ransomware note seen by Bleeping Computer, on November 26 the Conti gang posted on their leak site a 3.03GB archive (2% of the stolen Advantech's data) and a text file containing a list of files included in the ZIP archive. The Conti operators also said that if the ransom is paid they will remove any backdoors deployed on the company's network and delete the stolen data.

The Conti ransomware was first spotted in the wild in December 2019, and has become increasingly common in recent months, targeting corporate and government networks. The malware spreads through networks laterally using a range of techniques, such as the Windows Restart Manager to ensure that all files can be encrypted.

In August this year, the group launched their own leak site, where they publish data stolen from victims, following the steps of other ransomware groups who operate such sites, including CLOP, Darkside, DoppelPaymer, Maze, Mespinoza (Pysa), Nefilim, NetWalker, RagnarLocker, REvil (Sodinokibi), and Sekhmet.

Back to the list

Latest Posts

Cyber Security Week in Review: July 26, 2024

Cyber Security Week in Review: July 26, 2024

In brief: A North Korean hacker indicted for ransomware attacks, French police dismantle the PlugX botnet, and more.
26 July 2024
Stargazer Goblin launch malware distribution-as-a-service via GitHub

Stargazer Goblin launch malware distribution-as-a-service via GitHub

The operation is using over 3,000 fake GitHub accounts.
25 July 2024
North Korean APT45 expanding into financially-motivated operations

North Korean APT45 expanding into financially-motivated operations

The threat actor has been observed targeting critical infrastructure more frequently than other North Korean hackers.
25 July 2024