RansomHub Ransomware Hits Major Auto Supplier Yorozu
RansomHub Ransomware Attack on Yorozu Corporation
Yorozu Corporation, a leading Japanese manufacturer of automotive components, has become the latest victim of a ransomware attack by the notorious RansomHub group. The attack, confirmed on October 14, resulted in the encryption of files across multiple servers, with the attackers demanding a ransom by October 31.
Yorozu Corporation: A Key Player in Automotive Manufacturing
Established in 1948, Yorozu Corporation is headquartered in Yokohama, Japan, and employs approximately 5,726 people. The company specializes in the design, development, and production of automotive parts, including mechanical components, body parts, and engine components. Yorozu's significant market presence is underscored by its major clients, such as Nissan, Honda, and Toyota, with Nissan accounting for 65.7% of its sales. The company's commitment to innovation and sustainability is evident in its recent green energy initiatives.
RansomHub: A Formidable Ransomware Group
RansomHub emerged in February 2024 as a Ransomware-as-a-Service (RaaS) group, quickly gaining notoriety for its aggressive affiliate model and double extortion tactics. The group is known for its speed and efficiency, leveraging advanced data exfiltration techniques and targeting high-value sectors. RansomHub's operations are characterized by their use of intermittent encryption and Curve 25519 elliptic curve encryption, making them a formidable threat.
Details of the Attack
The RansomHub group claims to have exfiltrated 849 GB of sensitive data from Yorozu Corporation, including confidential documents and contracts with major car manufacturers, technical documentation, budget reports, and HR files. The attack has rendered critical files inaccessible, severely impacting Yorozu's operations. The attackers have set a ransom deadline, adding pressure on the company to comply with their demands.
Potential Vulnerabilities and Penetration Methods
Yorozu Corporation's extensive network and reliance on critical data make it a prime target for ransomware groups like RansomHub. The attackers likely exploited vulnerabilities in Yorozu's systems, potentially through phishing campaigns or unpatched software. RansomHub's sophisticated techniques, including lateral movement and data exfiltration, highlight the challenges faced by organizations in safeguarding their digital assets.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!