hiveleak attacks Weidmueller
Weidmueller Suffers Ransomware Attack by Hiveleak Group
Company Overview
Weidmueller, a Brazilian company, specializes in industrial connectivity solutions, offering a diverse portfolio that includes TI applications, PCB solutions, and identification systems. Detailed information about their offerings and history can be found on their official website.
Company Size and Industry Standing
While specific details regarding Weidmueller's size are not readily available, it is known that the company plays a significant role in the manufacturing sector. This industry is particularly vulnerable to ransomware attacks due to the high potential for operational disruptions and financial repercussions.
Vulnerabilities and Targeting
Ransomware groups, such as Hiveleak, frequently exploit weaknesses in enterprise security, targeting companies utilizing widely used products from vendors like Citrix or VMware. Hiveleak has demonstrated capabilities to compromise networks through single-factor RDP, VPN, and other remote access protocols. Notably, they have also managed to circumvent multi-factor authentication, exploiting vulnerabilities such as CVE-2020-12812 to infiltrate FortiOS servers.
Response and Mitigation
In response to the ransomware attack, Weidmueller has initiated a review and enhancement of their security and protection policies. Furthermore, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services (HHS), has issued a joint alert regarding the Hive ransomware group. This alert highlights the group's focus on a broad spectrum of sectors, including Government Facilities, Communications, Critical Manufacturing, Information Technology, and notably, Healthcare and Public Health.
Sources
- Cybersecurity and Infrastructure Security Agency (CISA), FBI, and HHS Joint Alert on Hive Ransomware: https://us-cert.cisa.gov/ncas/alerts/aa20-302a
- Common Vulnerabilities and Exposures (CVE) - CVE-2020-12812: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12812
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!