Chip maker Advantech hit by a Conti ransomware attack

Chip maker Advantech hit by a Conti ransomware attack

Hackers behind the Conti ransomware operation infected systems of industrial automation and Industrial IoT (IIoT) chip manufacturer Advantech and are now demanding a 750 BTC (approx. $14M) ransom for a decryptor to restore encrypted systems and to stop stolen data leakage.

According to a chat log and a ransomware note seen by Bleeping Computer, on November 26 the Conti gang posted on their leak site a 3.03GB archive (2% of the stolen Advantech's data) and a text file containing a list of files included in the ZIP archive. The Conti operators also said that if the ransom is paid they will remove any backdoors deployed on the company's network and delete the stolen data.

The Conti ransomware was first spotted in the wild in December 2019, and has become increasingly common in recent months, targeting corporate and government networks. The malware spreads through networks laterally using a range of techniques, such as the Windows Restart Manager to ensure that all files can be encrypted.

In August this year, the group launched their own leak site, where they publish data stolen from victims, following the steps of other ransomware groups who operate such sites, including CLOP, Darkside, DoppelPaymer, Maze, Mespinoza (Pysa), Nefilim, NetWalker, RagnarLocker, REvil (Sodinokibi), and Sekhmet.

Back to the list

Latest Posts

Cyber Security Week in Review: March 14, 2025

Cyber Security Week in Review: March 14, 2025

In brief: Microsoft, Apple fix zero-days, LockBit ransomware dev extradited to the US, and more.
14 March 2025
New North Korea-linked Android spyware KoSpy targets Korean and English-speaking users

New North Korea-linked Android spyware KoSpy targets Korean and English-speaking users

KoSpy is distributed through fake utility applications, which masquerade as helpful tools.
13 March 2025
Chinese hackers Volt Typhoon lurked for nearly a year in systems of US utility company

Chinese hackers Volt Typhoon lurked for nearly a year in systems of US utility company

The breach is believed to be part of a broader cyberespionage effort by China’s government targeting US critical infrastructure.
13 March 2025