Qilin Ransomware Strikes Bock & Associates, LLP: A Growing Cyber Threat
Qilin Ransomware Group Targets Bock & Associates, LLP
Overview of the Attack
Bock & Associates, LLP, a certified public accounting firm based in El Paso, Texas, has fallen victim to a ransomware attack orchestrated by the Qilin group. The breach was discovered on June 13, 2024, and the extent of the data leak remains unknown. The firm, known for its tax services, payroll solutions, and general accounting services, has been in operation for over 48 years.
About Bock & Associates, LLP
Bock & Associates, LLP employs between 6-10 people and generates annual revenue of $1M-$5M. The firm prides itself on professionalism, experience, and affordability, offering a broad range of services for business owners, executives, and independent professionals. Despite not being accredited by the Better Business Bureau, the firm has no customer complaints or negative reviews, highlighting its commitment to exceptional service.
Vulnerabilities and Targeting
As a small to mid-sized firm, Bock & Associates, LLP may lack the robust cybersecurity infrastructure of larger organizations, making it a prime target for ransomware groups like Qilin. The firm's extensive handling of sensitive financial data further increases its attractiveness to cybercriminals seeking valuable information for double extortion tactics.
About the Qilin Ransomware Group
The Qilin ransomware group, also known as Agenda, emerged in 2022 and has quickly become a significant threat. Specializing in ransomware-as-a-service (RaaS), Qilin targets critical infrastructure and other essential services worldwide. Their ransomware, written in Rust and Go, is known for its evasion capabilities and customization options, complicating recovery efforts for victims.
Penetration Tactics
Qilin typically infiltrates systems through phishing emails containing malicious links. Once inside, they move laterally across the network, searching for critical data to encrypt. The group employs a double extortion technique, exfiltrating sensitive data and demanding payment for both decryption and non-disclosure. Their high payout rates to affiliates make them a formidable and attractive option for cybercriminals.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!