How BlackSuit Ransomware Used a Stolen VPN to Attack a Company

A manufacturing firm was hit by Ignoble Scorpius using a stolen VPN credential from voice phishing, escalating to DCSync for more access. Attackers installed AnyDesk and a RAT, exfiltrated 400 GB of data, and encrypted VMs, demanding $20 million ransom and halting operations.


Unit 42's response helped the company recover without payment, stressing network segmentation, MFA, and updated firewalls. This incident shows how one breach can lead to widespread damage, urging businesses to monitor anomalies and enforce strong authentication.


Businesses should implement robust defenses like regular audits, zero-trust models, and employee training to prevent similar ransomware escalations from evolving cyber threats.
NPAV offers a robust solution to combat cyber fraud. Protect yourself with our top-tier security product, Z Plus Security
- Other (43)
- Ransomware (175)
- Events and News (27)
- Features (45)
- Security (499)
- Tips (80)
- Google (40)
- Achievements (12)
- Products (37)
- Activation (7)
- Dealers (1)
- Bank Phishing (57)
- Malware Alerts (276)
- Cyber Attack (360)
- Data Backup (15)
- Data Breach (194)
- Phishing (183)
- Securty Tips (4)
- Browser Hijack (26)
- Adware (15)
- Email And Password (85)
- Android Security (92)
- Knoweldgebase (38)
- Botnet (20)
- Updates (6)
- Alert (72)
- Hacking (83)
- Social Media (10)
- vulnerability (120)
- Hacker (71)
- Spyware (16)
- Windows (19)
- Microsoft (38)
- Uber (1)
- YouTube (3)
- Trojan (7)
- Website hacks (14)
- Paytm (1)
- Credit card scam (4)
- Telegram (6)
- RAT (12)
- Bug (3)
- Twitter (3)
- Facebook (12)
- Banking Trojan (14)
- Mozilla (2)
- COVID-19 (5)
- Instagram (4)
- NPAV Announcement (15)
- IoT Security (3)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (4)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (4)
- Cloud malware (3)
- Cloud storage (2)
- Financial fraud (96)
- Impersonation phishing (1)
- DDoS (11)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (83)
-
Mobile Frauds
(48)
- WhatsApp (13)
- AI (29)