CK Power Hit by Hunters International Ransomware Attack

Incident Date: Nov 20, 2024

Attack Overview
VICTIM
CK Power Public Manufacturing
INDUSTRY
Energy, Utilities & Waste
LOCATION
Thailand
ATTACKER
Hunters International
FIRST REPORTED
November 20, 2024

Ransomware Attack on CK Power: A Critical Infrastructure Breach

CK Power Public Company Limited (CKP), a leading energy provider in Thailand, has recently fallen victim to a ransomware attack orchestrated by the notorious group Hunters International.

CK Power: A Pillar in Thailand's Energy Sector

CK Power, established in 2011, is a prominent player in the energy sector of Thailand and the ASEAN region. The company focuses on the production and distribution of electricity from renewable sources, including hydroelectric, cogeneration, and solar power. With a total installed capacity of approximately 3,633 MW, CKP is committed to sustainability, deriving 93% of its energy from clean sources. The company reported revenues of Baht 10,941 million in 2023, reflecting its operational performance.

Attack Overview

The ransomware group Hunters International has claimed responsibility for the attack on CK Power. The attackers successfully exfiltrated sensitive data and encrypted the company's systems, raising concerns about potential data breaches and the organization's recovery capabilities.

Hunters International: A Rising Threat

Emerging in October 2023, Hunters International is a Ransomware-as-a-Service (RaaS) group that has rapidly gained notoriety. Utilizing code from the defunct Hive ransomware, the group employs double extortion tactics, combining data encryption with data theft. Their malware, developed in Rust, is highly adaptable, targeting both Windows and Linux environments. The group is known for its sophisticated techniques, including phishing campaigns and exploiting remote services to gain initial access.

Potential Vulnerabilities

CK Power's reliance on digital infrastructure for its operations makes it a prime target for ransomware groups like Hunters International. The company's extensive use of technology in managing its energy production and distribution networks could have been exploited by the attackers. The sophistication of Hunters International's tactics, including their ability to bypass advanced security measures, poses a significant challenge to organizations in the energy sector.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.