Niko Resources Hit by Hunters Ransomware Exposing 1.5TB Data

Incident Date: Oct 25, 2024

Attack Overview
VICTIM
Niko Resources Ltd.
INDUSTRY
Energy, Utilities & Waste
LOCATION
Canada
ATTACKER
Hunters International
FIRST REPORTED
October 25, 2024

Niko Resources Ltd. Falls Victim to Hunters Ransomware Attack

Niko Resources Ltd., a Canadian-based oil and gas exploration company, has recently been targeted by the ransomware group known as Hunters International. The attack resulted in the exfiltration of 1.5 terabytes of sensitive data, raising significant concerns about the company's cybersecurity measures.

Company Overview

Headquartered in Calgary, Alberta, Niko Resources Ltd. is a prominent player in the energy sector, focusing on the exploration and production of oil and natural gas. The company operates internationally, with significant activities in India, Bangladesh, Indonesia, and Kurdistan. Niko Resources is known for its strategic partnerships with major industry players like Reliance Industries and Gujarat State Petroleum Corporation, enhancing its operational capabilities. Despite its international presence, the company employs a relatively small team, which may contribute to its vulnerabilities in cybersecurity.

Attack Overview

The ransomware attack on Niko Resources was orchestrated by Hunters International, a group that emerged in October 2023. Utilizing a sophisticated Ransomware-as-a-Service model, Hunters International has rapidly gained notoriety for its double extortion tactics, which involve both data encryption and theft. The group claims to have acquired the code from the defunct Hive ransomware operation, allowing them to execute over 130 attacks globally by 2024.

Hunters International's Distinctive Approach

Hunters International distinguishes itself through its use of Rust-based ransomware, which provides cross-platform flexibility, targeting both Windows and Linux environments. The group employs advanced encryption algorithms, making decryption nearly impossible without the private key. Their modus operandi involves multi-stage operations, beginning with network reconnaissance and lateral movement before data exfiltration and encryption. The group is known for bypassing advanced security measures, as demonstrated in previous attacks.

Potential Vulnerabilities

Niko Resources' relatively small workforce and specialized operational focus may have contributed to its vulnerability to such sophisticated cyber threats. The company's international operations and partnerships, while beneficial for business, also increase its exposure to global cyber threats. The attack underscores the need for enhanced cybersecurity measures, particularly for companies in critical infrastructure sectors like energy.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.