Qilin Ransomware Strikes LBCO Contracting in Alberta

Incident Date: Nov 22, 2024

Attack Overview
VICTIM
LBCO Contracting LTD
INDUSTRY
Construction
LOCATION
Canada
ATTACKER
Qilin
FIRST REPORTED
November 22, 2024

Ransomware Attack on LBCO Contracting by Qilin: A Cybersecurity Analysis

On November 22, 2024, LBCO Contracting, a prominent heavy civil construction company based in Southern Alberta, became the target of a ransomware attack orchestrated by the threat actor Qilin. LBCO Contracting specializes in underground construction, site grading, paving, rail projects, and environmental initiatives, offering high-quality and cost-efficient construction solutions in the region.

Company Profile

LBCO Contracting Ltd. is a Calgary-based specialty contractor that was incorporated in 2014. Initially focused on underground contracting, the company has expanded its services over the years, establishing a reputation for reliability and quality in project management and execution. While the exact size of the company is not publicly disclosed, LBCO Contracting is classified as a small to medium-sized enterprise within the construction industry.

Industry Standing

LBCO Contracting stands out in the construction landscape of Southern Alberta due to its specialization in deep utility contracting and its commitment to high standards of work. The company's systematic approach to construction projects, coupled with a team of seasoned professionals, enables them to tackle complex projects effectively and deliver exceptional results.

Attack Overview

The ransomware attack by Qilin on LBCO Contracting compromised the security of the company's systems, leading to a data breach. The exact size of the data leak resulting from the attack remains unknown, posing a significant threat to the confidentiality and integrity of LBCO's operations and sensitive information.

Ransomware Group: Qilin

Qilin, also known as Agenda, is a Ransomware-as-a-Service (RaaS) group that emerged in July 2022. The group operates by providing affiliates with sophisticated ransomware tools and infrastructure, utilizing double extortion tactics to pressure victims into paying ransom. Qilin's ransomware is highly customizable, targeting Windows, Linux, and VMware ESXi environments, with a focus on large enterprises across various sectors.

Penetration and Vulnerabilities

Qilin likely penetrated LBCO Contracting's systems through spear phishing emails containing malicious links or attachments, exploiting vulnerabilities in Citrix ADC, RDP, and VMware ESXi. The ransomware group's advanced encryption algorithms and customization capabilities make it a formidable threat, allowing for data exfiltration and encryption to extort victims effectively.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.