lockbit3 attacks POLYCUBE
Lockbit3 Ransomware Attack on POLYCUBE
Company Overview
POLYCUBE is a company limited that provides DCC services for cardholder's home currency at the time of purchase/withdrawal transactions. The company is located at 3 Promphan 3 Building, 9th Floor Soi Ladprow 3, Ladprow Road, Jomphol, Jatujak, Bangkok 10900 Thailand.
Industry and Vulnerabilities
The Manufacturing sector has been identified as a prime target for ransomware attacks in Thailand, with construction being the most impacted industry. The growth in leak site posts can be attributed to zero-day exploits targeting vulnerabilities such as MOVEit Transfer SQL Injection and GoAnywhere MFT.
Ransomware Group
Lockbit3 is the most active ransomware group in Thailand, with 19 counts of victims in 2023. The group is known for its multi-extortion tactics, where it threatens to leak stolen data unless a ransom is paid.
Impact and Response
The attack on POLYCUBE is part of a larger trend of ransomware attacks on the Manufacturing sector in Thailand, which has seen a 49% year-over-year (YoY) increase in multi-extortion ransomware attacks globally. The incident highlights the need for robust cybersecurity measures to protect against such attacks, particularly in industries with a large attack surface and less robust security.
Sources
- POLYCUBE Company Limited. (n.d.). About Us. Retrieved April 10, 2024, from http://polycube.co.th
- Ransomware Posts - GitHub Pages. (n.d.). Retrieved April 10, 2024, from https://www.ransomposts.com/
- Palo Alto Networks. (2024). Unit 42 2024 Incident Response Report: Speed of Exfiltration + Vulnerabilities Driving Activity. Retrieved April 10, 2024, from https://www.paloaltonetworks.com/
- RansomLook. (n.d.). lockbit3 details. Retrieved April 10, 2024, from https://www.ransomlook.io/group/lockbit3
- Ransomfeed. (n.d.). Retrieved April 10, 2024, from https://ransomfeed.it/
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!