Everest Ransomware Hits CreaGen Inc in Major Cyber Attack
Everest Ransomware Group Targets CreaGen Inc. in Significant Cyber Attack
The Everest ransomware group has claimed responsibility for a cyber attack on CreaGen Inc., a contract research organization (CRO) based in Woburn, Massachusetts. This attack, which threatens to expose sensitive data, highlights the vulnerabilities faced by companies in the healthcare services sector.
About CreaGen Inc.
CreaGen Inc. is a prominent CRO specializing in medicinal chemistry and drug discovery services. Founded in 2003, the company operates from a 22,000 square-foot facility equipped with advanced technologies for drug development. With a team of approximately 19 employees, CreaGen has built a reputation for high-quality research services, collaborating with over 50 biotech and pharmaceutical companies. The company recently secured a $107 million contract from the National Institute of Allergy and Infectious Diseases (NIAID) to develop therapeutics for HIV, underscoring its critical role in federal research initiatives.
Details of the Attack
The Everest ransomware group has threatened to release CreaGen's sensitive data within 9 to 10 days. The compromised information includes research data, documents, contracts, and laboratory tests. This breach poses significant risks to CreaGen's intellectual property and operational integrity, given the sensitive nature of the data involved. Everest has already provided sample screenshots of the breached data on their dark web portal as proof of the attack.
Profile of the Everest Ransomware Group
Active since December 2020, the Everest ransomware group is known for its involvement in ransomware attacks and data exfiltration. The group targets organizations across various industries, with a focus on the healthcare sector. Everest employs sophisticated tactics, including the use of legitimate compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement. The group has been linked to other ransomware entities, such as BlackByte, and has increasingly acted as an Initial Access Broker, selling backdoors into organizations to other criminals.
Potential Vulnerabilities
CreaGen's focus on high-stakes research and its involvement in federal contracts make it an attractive target for cybercriminals. The company's reliance on advanced technologies and sensitive data further increases its vulnerability to ransomware attacks. The Everest group's ability to penetrate CreaGen's systems may have been facilitated by exploiting weaknesses in remote access protocols or through compromised user credentials.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!