RansomHub Targets Cobel Darou in Major Ransomware Breach
RansomHub Ransomware Attack on Cobel Darou: A Detailed Analysis
Cobel Darou, a leading pharmaceutical company in Iran, has recently fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. This incident highlights the vulnerabilities faced by organizations in the healthcare sector, particularly those involved in critical operations such as pharmaceutical manufacturing and distribution.
About Cobel Darou
Established in 2002, Cobel Darou has become a significant player in Iran's pharmaceutical industry. The company is involved in the manufacturing, importation, registration, marketing, and distribution of a wide range of medications. Its product portfolio includes specialty drugs for cardiovascular diseases, diabetes, cancer, and more. Cobel Darou's strategic partnerships with international pharmaceutical companies have enabled it to leverage advanced technologies, contributing to Iran's pharmaceutical self-sufficiency. With approximately 450 employees, Cobel Darou is a substantial entity in the healthcare sector.
Attack Overview
The ransomware attack was discovered on November 22, when RansomHub claimed to have accessed 87 GB of Cobel Darou's data. The attackers have threatened to release this data within the next few days, putting the company's sensitive information at risk. /p>
RansomHub's Modus Operandi
RansomHub, a Ransomware-as-a-Service group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. The group is known for its aggressive affiliate model and double extortion tactics, which involve encrypting data and exfiltrating sensitive information to increase leverage in ransom demands. RansomHub's operations are characterized by speed and efficiency, with a focus on high-value targets across various industries.
Potential Vulnerabilities
Cobel Darou's involvement in the healthcare sector makes it an attractive target for ransomware groups like RansomHub. The company's reliance on digital systems for manufacturing, distribution, and data management could have provided multiple entry points for the attackers. RansomHub affiliates are known to exploit vulnerabilities in unpatched systems and use sophisticated techniques such as phishing and password spraying to gain initial access.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!