ArcusMedia Ransomware Attack on BHMAC: Cyber Threats to Humanitarian Efforts
ArcusMedia Ransomware Attack on BHMAC
Overview of BHMAC
The Bosnia and Herzegovina Mine Action Centre (BHMAC) is a pivotal organization dedicated to addressing the issue of landmines and unexploded ordnance (UXO) in Bosnia and Herzegovina. BHMAC employs between 101 and 250 people and generates revenue in the range of $25 million to $50 million. The organization operates from two main offices in Banja Luka and Sarajevo. BHMAC stands out for its comprehensive approach to demining, which includes surveying, mapping, and clearing mine-affected areas, as well as conducting risk education and maintaining a detailed database of mine-affected regions.
Details of the Attack
ArcusMedia, a relatively new ransomware group, has claimed responsibility for a ransomware attack on BHMAC. The attack was announced via ArcusMedia's dark web leak site. The group is known for its direct and double extortion methods, often using phishing emails to gain initial access to victim networks. Once inside, they deploy custom ransomware binaries and use obfuscation techniques to evade detection. The attack on BHMAC highlights the vulnerabilities that even well-established organizations face in the current cyber threat landscape.
About ArcusMedia
The ransomware group ArcusMedia has been active since May 2024 and operates on a Ransomware-as-a-Service (RaaS) model. The group employs a unique affiliate program where new affiliates must be referred by a trusted member. ArcusMedia has targeted a wide range of sectors, including government, healthcare, and education. Their tactics include phishing for initial access, deploying obfuscated scripts for execution, and using tools like Mimikatz for privilege escalation. The group has quickly established itself with a distinct set of tactics, techniques, and procedures (TTPs).
Potential Vulnerabilities
BHMAC's extensive use of information systems to aid in demining efforts could have been a potential vulnerability exploited by ArcusMedia. The organization's reliance on digital databases and communication networks makes it a prime target for ransomware attacks. The attack underscores the importance of robust cybersecurity measures, especially for organizations involved in critical and humanitarian missions.
Sources
- http://www.bhmac.org
- https://www.zoominfo.com/c/bhmac/15815188
- https://bhmac.tihenoci.com/?lang=en&page_id=704
- https://www.clodura.ai/directory/company/bhmac
- https://www.loc.gov/item/lcwaN0041477/
- https://commons.lib.jmu.edu/cgi/viewcontent.cgi?article=1318&context=cisr-journal
- https://themoloch.com/infosec/new-threat-actor-drop-arcus-media/
- https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/arcus-media
- https://darkfeed.io/ransomgroups/
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!