RansomHub Targets Cobel Darou in Major Ransomware Breach

Incident Date: Nov 21, 2024

Attack Overview
VICTIM
Cobel Darou
INDUSTRY
Healthcare Services
LOCATION
Iran
ATTACKER
Ransomhub
FIRST REPORTED
November 21, 2024

RansomHub Ransomware Attack on Cobel Darou: A Detailed Analysis

Cobel Darou, a leading pharmaceutical company in Iran, has recently fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. This incident highlights the vulnerabilities faced by organizations in the healthcare sector, particularly those involved in critical operations such as pharmaceutical manufacturing and distribution.

About Cobel Darou

Established in 2002, Cobel Darou has become a significant player in Iran's pharmaceutical industry. The company is involved in the manufacturing, importation, registration, marketing, and distribution of a wide range of medications. Its product portfolio includes specialty drugs for cardiovascular diseases, diabetes, cancer, and more. Cobel Darou's strategic partnerships with international pharmaceutical companies have enabled it to leverage advanced technologies, contributing to Iran's pharmaceutical self-sufficiency. With approximately 450 employees, Cobel Darou is a substantial entity in the healthcare sector.

Attack Overview

The ransomware attack was discovered on November 22, when RansomHub claimed to have accessed 87 GB of Cobel Darou's data. The attackers have threatened to release this data within the next few days, putting the company's sensitive information at risk. /p>

RansomHub's Modus Operandi

RansomHub, a Ransomware-as-a-Service group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. The group is known for its aggressive affiliate model and double extortion tactics, which involve encrypting data and exfiltrating sensitive information to increase leverage in ransom demands. RansomHub's operations are characterized by speed and efficiency, with a focus on high-value targets across various industries.

Potential Vulnerabilities

Cobel Darou's involvement in the healthcare sector makes it an attractive target for ransomware groups like RansomHub. The company's reliance on digital systems for manufacturing, distribution, and data management could have provided multiple entry points for the attackers. RansomHub affiliates are known to exploit vulnerabilities in unpatched systems and use sophisticated techniques such as phishing and password spraying to gain initial access.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.