Everest Ransomware Hits Country Inn & Suites by Radisson
Everest Ransomware Group Targets Country Inn & Suites by Radisson
The Everest ransomware group has recently claimed responsibility for a cyberattack on Country Inn & Suites by Radisson, a prominent hotel brand under the Radisson Hotel Group. This attack underscores the vulnerabilities within the hospitality sector, particularly concerning data security and protection against sophisticated cyber threats.
About Country Inn & Suites by Radisson
Country Inn & Suites by Radisson is a well-established hotel brand known for its welcoming atmosphere and family-friendly services. Operating over 530 locations globally, the brand is part of the Radisson Hotel Group, which boasts a network of over 1,380 hotels across more than 95 countries. The brand emphasizes comfort and convenience, offering amenities such as complimentary hot breakfasts, free Wi-Fi, and business facilities. This focus on guest experience makes it a preferred choice for both leisure and business travelers.
Details of the Ransomware Attack
The Everest ransomware group has reportedly exfiltrated thousands of records from Country Inn & Suites, including personal information, credit card details, and internal communications. The breach was publicized on Everest's dark web site on October 19, with a ransom deadline set for October 31. Screenshots released by the group reveal sensitive data, such as reward account numbers and guest tax IDs, highlighting significant security lapses in the hotel's data protection measures.
Profile of the Everest Ransomware Group
Active since December 2020, the Everest ransomware group is notorious for its involvement in ransomware attacks and data exfiltration. The group has evolved from a data exfiltration outfit to a full-fledged ransomware operator, with links to the EverBe 2.0 family and BlackByte ransomware. Everest distinguishes itself by acting as an Initial Access Broker, selling access to compromised systems to other cybercriminals. This strategy allows them to maintain a low profile while monetizing their activities.
Potential Vulnerabilities and Attack Vectors
The attack on Country Inn & Suites highlights potential vulnerabilities in the hospitality sector, such as inadequate password protection and insufficient data encryption. Everest likely exploited these weaknesses, possibly using compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement within the network. The group's criticism of the hotel's security measures further emphasizes the need for enhanced cybersecurity practices in the industry.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!