At least 31 U.S.-based large corporations have been attacked by a relatively new brand of targeted ransomware to force the victims to meet the unknown cyber gangs’ demand for millions in ransom.
Related Update, July 2020: Smartwatch maker Garmin suffers WastedLocker ransomware attack.
The ransomware is known as WastedLocker and is thought to be attributed to the Evil Corp cyber crew involved in the BitPaymer operation that netted its backers millions. Two Russian operatives, already under open indictments in the U.S., are said to be involved in the WastedLocker subterfuge.
All the known WastedLocker attacks were launched against Symantec’s customers, the security provider said in a new report. The cyber assailants were in the process of staging the ransomware attacks when Symantec, which discovered the infiltration while examining unusual behavior on some of its customers’ networks, interrupted the potential score. U.K.-based security and risk consultant NCC Group first documented the malware just ahead of Symantec’s outreach to its customers.
Symantec declined to name the affected organizations but allowed that all but one are located in the U.S. and most are major, recognizable corporations. Included are 11 listed companies, eight of which are Fortune 500 businesses. The one non-U.S. owned company is a subsidiary of a multinational conglomerate headquartered overseas. The mugged organizations engaged in manufacturing, information technology and media and communications.
Had Symantec not intervened, “successful attacks could have led to millions in damages, downtime, and a possible domino effect on supply chains,” Symantec said. The security specialist has alerted all of its customers struck by the malware.
Here’s how the attacks work: (via Symantec)
“The attackers behind this threat appear to be skilled and experienced, capable of penetrating some of the most well protected corporations, stealing credentials, and moving with ease across their networks,” the researchers said. “As such, WastedLocker is a highly dangerous piece of ransomware. A successful attack could cripple the victim’s network, leading to significant disruption to their operations and a costly clean-up operation.”