RansomHub Ransomware Hits French Municipality Mairie de Mauguio
RansomHub Ransomware Attack on Mairie de Mauguio-Carnon
The Mairie de Mauguio-Carnon, a municipal government in southern France, has fallen victim to a ransomware attack orchestrated by the RansomHub group. This attack has resulted in the exfiltration of 75 GB of sensitive data, with the attackers threatening to release the information if their demands are not met by October 28.
Victim Profile: Mairie de Mauguio-Carnon
The Mairie de Mauguio-Carnon serves as the local government for the commune of Mauguio and its coastal area, Carnon. It plays a vital role in managing community life, including administration, public services, cultural activities, and tourism promotion. The Mairie is notable for its commitment to community engagement and tourism, organizing various cultural and sporting events. As a public institution, it is funded through local taxes and state grants, rather than generating revenue like a private company. The Mairie employs staff across several departments, although specific numbers are not publicly disclosed.
Attack Overview
The ransomware attack has severely disrupted the Mairie's operations, rendering its official website and several online services inaccessible. Municipal services are also unreachable by telephone. The attackers have issued a warning about the critical nature of the files they have obtained, emphasizing the urgency of their ransom demands. The municipality has acknowledged the incident, describing it as a technical issue related to ransomware.
RansomHub: A Formidable Threat
RansomHub, a Ransomware-as-a-Service group, emerged in February 2024 and quickly established itself in the cybercrime landscape. Known for its aggressive affiliate model, RansomHub employs double extortion tactics, encrypting data and exfiltrating sensitive information to increase pressure on victims. The group is affiliated with former Knight ransomware actors and ALPHV/BlackCat, leveraging their expertise to enhance its operations.
Penetration and Distinctive Techniques
RansomHub is renowned for its speed and efficiency, targeting vulnerabilities in systems such as Citrix ADC and FortiOS. The group uses phishing campaigns, vulnerability exploitation, and password spraying to gain initial access. Its ransomware is optimized for cross-platform systems, employing Curve 25519 elliptic curve encryption for security. RansomHub's modular architecture allows affiliates to update strains quickly, avoiding detection and maintaining operational complexity.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!