BlackSuit Ransomware Breaches Corporate Network Using Single Compromised VPN Credential
A major manufacturing company recently experienced a significant ransomware attack following the unauthorized use of stolen VPN credentials. The attack was executed by the cybercrime group Ignoble Scorpius, resulting in the encryption of virtual machines…
A major manufacturing company recently experienced a significant ransomware attack following the unauthorized use of stolen VPN credentials. The attack was executed by the cybercrime group Ignoble Scorpius, resulting in the encryption of virtual machines and the disruption of critical operations.
The security breach commenced when an employee was deceived through a voice phishing call, leading to the disclosure of VPN login information on a counterfeit website. Utilizing these credentials, attackers infiltrated the network undetected and swiftly escalated their user privileges.
Subsequently, a DCSync attack was executed on a domain controller, allowing the retrieval of additional high-level credentials. Armed with administrative credentials, the attackers navigated the network using Remote Desktop and SMB protocols. They employed tools like Advanced IP Scanner to map the network and identify key servers.
To ensure ongoing network access, AnyDesk and a custom remote access Trojan were installed on a domain controller, configured as a scheduled task to persist through reboots. A second domain controller was compromised, exposing the NTDS.dit database of password hashes.
Over 400 GB of sensitive data was extracted using a renamed rclone utility. Prior to deploying the ransomware, forensic logs were erased using CCleaner.
A major manufacturing company recently experienced a significant ransomware attack following the unauthorized use of stolen VPN credentials.
The attack culminated in the deployment of BlackSuit ransomware across hundreds of virtual machines on approximately 60 VMware ESXi hosts, orchestrated through Ansible. This caused the production lines to halt, incurring significant financial and operational losses.
In response, the manufacturer enlisted Unit 42 for immediate assistance. Recommendations included replacing outdated Cisco ASA firewalls with next-generation alternatives, enforcing network segmentation, and restricting management access to critical servers.
Multi-factor authentication was mandated for all remote logins, and service accounts were secured to prevent exploitation. The $20 million ransom demand was subsequently rejected with no payment made.
This incident illustrates the potential consequences of compromised VPN credentials, leading to exploitation, data theft, and encryption. Organizations are urged to implement layered defenses, combining robust authentication, comprehensive endpoint visibility, automated containment, and expert guidance to intercept attacks before escalation.
Investments in proactive security measures are significantly more cost-effective compared to the expenses associated with a full-scale ransomware crisis.
Based on reporting by GBHackers.
