Niko Resources Hit by Hunters Ransomware Exposing 1.5TB Data
Niko Resources Ltd. Falls Victim to Hunters Ransomware Attack
Niko Resources Ltd., a Canadian-based oil and gas exploration company, has recently been targeted by the ransomware group known as Hunters International. The attack resulted in the exfiltration of 1.5 terabytes of sensitive data, raising significant concerns about the company's cybersecurity measures.
Company Overview
Headquartered in Calgary, Alberta, Niko Resources Ltd. is a prominent player in the energy sector, focusing on the exploration and production of oil and natural gas. The company operates internationally, with significant activities in India, Bangladesh, Indonesia, and Kurdistan. Niko Resources is known for its strategic partnerships with major industry players like Reliance Industries and Gujarat State Petroleum Corporation, enhancing its operational capabilities. Despite its international presence, the company employs a relatively small team, which may contribute to its vulnerabilities in cybersecurity.
Attack Overview
The ransomware attack on Niko Resources was orchestrated by Hunters International, a group that emerged in October 2023. Utilizing a sophisticated Ransomware-as-a-Service model, Hunters International has rapidly gained notoriety for its double extortion tactics, which involve both data encryption and theft. The group claims to have acquired the code from the defunct Hive ransomware operation, allowing them to execute over 130 attacks globally by 2024.
Hunters International's Distinctive Approach
Hunters International distinguishes itself through its use of Rust-based ransomware, which provides cross-platform flexibility, targeting both Windows and Linux environments. The group employs advanced encryption algorithms, making decryption nearly impossible without the private key. Their modus operandi involves multi-stage operations, beginning with network reconnaissance and lateral movement before data exfiltration and encryption. The group is known for bypassing advanced security measures, as demonstrated in previous attacks.
Potential Vulnerabilities
Niko Resources' relatively small workforce and specialized operational focus may have contributed to its vulnerability to such sophisticated cyber threats. The company's international operations and partnerships, while beneficial for business, also increase its exposure to global cyber threats. The attack underscores the need for enhanced cybersecurity measures, particularly for companies in critical infrastructure sectors like energy.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!