Attack Overview
VICTIM
37sur
INDUSTRY
Telecommunications
LOCATION
Argentina
ATTACKER
Icefire
FIRST REPORTED
August 20, 2022

IceFire Ransomware Attack on 37sur

Company Overview

37sur is a telecommunications company that aims to provide a secure and agile internet service, focusing on customer satisfaction. They have a strong commitment to teamwork and expanding their services to new locations while adapting to new technologies.

Vulnerabilities and Targeting

IceFire ransomware is known to exploit vulnerabilities in IBM Aspera Faspex, a file-sharing software, to gain access to systems. The attackers exfiltrate all enticing data prior to encrypting devices, and victims are then extorted into paying the ransom to prevent leakage and decrypt their data.

Impact and Response

In many cases, even after payment of the IceFire ransom, the decryption key is not sent by the criminals, and in these cases, there is no higher authority to turn to. Digital Recovery, a company specializing in ransomware decryption, offers solutions to recover data encrypted by IceFire ransomware on the majority of storage devices.

The IceFire ransomware attack on 37sur underscores the critical need for robust cybersecurity measures, especially in the telecommunications sector, where the potential for significant damage is high. Companies should regularly review and remove unnecessary access, monitor network traffic, and have an incident response plan in place to respond quickly and effectively to ransomware attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.