lockbit2 attacks genesis
Genesis, a Business Services Company Targeted by Lockbit2 Ransomware
Overview of the Attack
Lockbit2, a well-known ransomware group, has recently taken responsibility for an attack on Genesis, a prominent player in the Business Services sector. Genesis is notably involved with the Genesis Market, an online platform infamous for its role in facilitating cyberattacks against U.S. companies and government entities. This marketplace is a hub for stolen credentials, cookies, device fingerprints, and website vulnerabilities, attracting a significant hacker clientele.
The Nature of Genesis Ransomware
The Genesis ransomware, identified as part of the MedusaLocker family, specifically targets corporate entities rather than individual users. It employs RSA and AES cryptographic algorithms to encrypt files on the victim's network. The ransom note that follows encryption demands payment for file decryption while cautioning against any attempts to rename or modify the encrypted files. Failure to comply with the payment demand may result in the attackers selling or leaking the stolen data.
Disruption of the Genesis Market
An international cyber operation has recently disrupted the Genesis Market, leading to the seizure of over 1.5 million compromised computers and the exposure of over 80 million account credentials. The FBI has contributed to these efforts by providing victim credentials to the Have I Been Pwned website, enabling individuals to check if their access credentials have been compromised.
Despite the takedown attempt, the Genesis Market remains operational on the Tor network and has announced plans to establish new domains. However, the operation has resulted in a significant number of arrests, potentially impacting the market's profitability and long-term viability.
Implications of the Lockbit2 Ransomware Attack on Genesis
The targeting of Genesis by the Lockbit2 ransomware group underscores the persistent threat posed by cybercriminals to companies within the Business Services sector. This incident not only highlights the vulnerabilities of companies involved in or associated with illicit online marketplaces but also raises questions about the effectiveness of international cyber operations against such entities. Despite the disruption efforts, the resilience of platforms like the Genesis Market on alternative networks like Tor poses ongoing challenges to cybersecurity efforts.
Sources
- FBI – https://www.fbi.gov/
- Have I Been Pwned – https://haveibeenpwned.com/
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!