RansomHub Ransomware Hits Leading Islamic Finance Firm TID
RansomHub Ransomware Attack on The Investment Dar
The Investment Dar Company (TID), a leading Islamic finance organization in the MENA region, has been targeted by the ransomware group RansomHub. The attack, discovered on August 9, has raised significant concerns due to TID's prominent position in the financial sector.
About The Investment Dar
Established in 1994 in Kuwait, The Investment Dar Company (TID) is a major player in the Islamic finance sector. Founded by a consortium of Kuwaiti businessmen, TID addresses the need for consumer Islamic finance options. The company offers a wide range of Sharia-compliant financial services, including consumer finance, real estate finance, commercial finance, investment funds, Islamic sukuk, consultancy, and portfolio management. TID has expanded its operations to various markets, including Saudi Arabia, and has assets valued at approximately KD 971 million (around USD 3.2 billion) as of 2009.
Attack Overview
The ransomware attack on TID was orchestrated by RansomHub, a relatively new but aggressive ransomware group. The attack targeted TID's website, inv-dar.com, and resulted in a data leak of unknown size. Given TID's extensive operations and significant financial assets, the attack underscores the growing threat of cyberattacks on major financial institutions in the region.
RansomHub: The Threat Actor
RansomHub is a ransomware group believed to have roots in Russia, operating as a Ransomware-as-a-Service (RaaS) entity. Affiliates of RansomHub receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, with a notable focus on healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a relatively new trend in the ransomware world, which may indicate future trends in ransomware development.
Potential Vulnerabilities
While the exact method of penetration remains unclear, TID's extensive digital infrastructure and significant financial assets make it an attractive target for ransomware groups like RansomHub. The use of Golang in RansomHub's ransomware strains suggests a sophisticated approach to cyberattacks, potentially exploiting vulnerabilities in TID's cybersecurity defenses.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!