Emefarma Group Hit by APT73 Ransomware Attack in Brazil

Incident Date: Nov 09, 2024

Attack Overview
VICTIM
Emefarma Group
INDUSTRY
Healthcare Services
LOCATION
Brazil
ATTACKER
APT73
FIRST REPORTED
November 9, 2024

Ransomware Attack on Emefarma Group by APT73

The Emefarma Group, a key player in Brazil's pharmaceutical distribution sector, has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group APT73. This incident has disrupted Emefarma's operations, highlighting vulnerabilities within the healthcare sector.

About Emefarma Group

Founded in 2021, Emefarma Group builds on the legacy of its predecessor, Emefarma, which has been operational for over 35 years. The company operates primarily in Rio de Janeiro and Espírito Santo, serving over 16,000 customers with a catalog of more than 6,000 SKUs. Emefarma is recognized for its technological integration, offering an online sales platform that enhances customer service. The company employs between 250 to 499 individuals and generates revenue estimated between $25 million to $50 million, underscoring its significant market presence.

Details of the Attack

The attack on Emefarma involved the deployment of BASHE Ransomware, known for its sophisticated encryption capabilities. Initial investigations suggest that APT73 gained access through a phishing campaign, exploiting vulnerabilities in Emefarma's email system. Once inside, the ransomware encrypted critical data, demanding a ransom in cryptocurrency for decryption keys. This has severely impacted Emefarma's supply chain and distribution networks, prompting the company to engage cybersecurity experts and law enforcement to address the breach.

APT73: A New Threat

APT73 is a newly emerged ransomware group that surfaced in late April. It mimics the operational model of the notorious LockBit group but shows signs of amateurism, such as lacking active mirrors on their data leak site. APT73 has claimed responsibility for attacks on at least 12 victims across various sectors, including healthcare. Their aggressive approach and ability to target multiple victims quickly make them a significant threat in the current cybersecurity landscape.

Vulnerabilities and Implications

The attack on Emefarma underscores the vulnerabilities within the healthcare sector, particularly in organizations with extensive digital operations. The reliance on email systems and online platforms can expose companies to phishing attacks, a common entry point for ransomware. This incident highlights the need for enhanced cybersecurity measures to protect sensitive data and maintain operational integrity in the pharmaceutical industry.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.