HOW ELECTRICITY COMPANY WITH 12,000 EMPLOYEES GOT ITS COMPLETE NETWORK INFECTED WITH RANSOMWARE?

Ransomware attack operators continue to diversify their methods. According to a report, the Portuguese multinational energy company Energias de Portugal (EDP) has just fallen victim to an encryption malware infection; Attackers reportedly used the dangerous variant of RagnarLocker ransomware, and demanded a $10 million payment to release the encrypted information.
Reports from MalwareHunterTeam cybersecurity specialists ensure that threat actors managed to extract more than 10 TB of confidential files from the Portuguese company, and threaten to expose them if the required payment is not received within a certain timeframe.
The alleged perpetrators of the attack also posted a message on Ragnarok, a site used by hackers to post leaked information: “We downloaded more than 10 TB of private information from EDP servers. Below you can find a couple of files and screenshots of the attacked network! This is just a sample, although we could also post the information in other blogs and online magazines,” the hackers say.
After analyzing the attack, MalwareHunterTeam identified that the hackers used the RagnarLocker attack variant. Moreover, the specialized BleepingComputer platform gained access to the ransom note received by the attacked company; In addition, tor’s payment page was discovered where hackers demand ransom payment.

Comments