Qilin Ransomware Group Strikes A&A Group Construction in Cyberattack
Qilin Ransomware Group Targets A&A Group Construction
Overview of A&A Group Construction
A&A Group Construction, a certified woman-owned construction services firm based in Fairfield, NJ, specializes in a wide range of construction services, including residential, commercial, and industrial projects. The company employs between 51-200 people and has a strong record of completing projects on time and below budget. They are certified by the State of New Jersey, Port Authority of NY and NJ, and NJ Transit as a woman-owned business. Their comprehensive approach ensures high-quality, safe, and efficient project completion.
Details of the Ransomware Attack
The Qilin ransomware group, also known as Agenda, has claimed responsibility for a cyberattack on A&A Group Construction. The attack was announced on Qilin's dark web leak site. A&A Group Construction, which operates in the construction industry and generates $10M-$25M in revenue, was targeted due to its critical role in various sectors, including healthcare, education, and transportation.
About the Qilin Ransomware Group
Qilin is a prominent ransomware-as-a-service (RaaS) group that emerged in 2022. They target critical infrastructure organizations worldwide, including healthcare and education sectors. Qilin ransomware is written in Rust and Go, making it evasion-prone and hard-to-decipher. The group employs a double extortion technique, exfiltrating sensitive data and demanding payment for a decryptor while threatening to release stolen data. Qilin advertises its ransomware on the dark web and has targeted organizations in multiple countries, including the United States, Australia, and the United Kingdom.
Penetration and Vulnerabilities
Qilin ransomware attacks often begin with phishing emails containing malicious links. Once inside the victim's infrastructure, the group laterally moves across systems, searching for essential data to encrypt. A&A Group Construction's extensive involvement in public contracts and critical infrastructure projects made them a lucrative target. The company's reliance on digital systems for project management, scheduling, and budgeting may have presented vulnerabilities that Qilin exploited.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!