Ransomware Attack Hits SESAM Informatics in Senegal
Ransomware Attack on SESAM Informatics by Hunters International
SESAM Informatics, a prominent IT integrator based in Dakar, Senegal, has fallen victim to a ransomware attack orchestrated by the notorious group Hunters International. The attackers have exfiltrated 3.6GB of sensitive data and are threatening to release it unless a ransom is paid.
About SESAM Informatics
Founded in 2006 by a Cisco-certified engineer, SESAM Informatics specializes in IT integration, consulting, project management, and training. The company offers comprehensive services in network, computer, security, and data center solutions. With a workforce of 11-50 employees and an annual revenue of approximately $6 million, SESAM Informatics is a key player in the Senegalese IT sector. Their expertise in digital transformation and cloud computing sets them apart in the industry.
Attack Overview
The ransomware group Hunters International claimed responsibility for the attack via their dark web leak site. The group is known for its sophisticated operations, focusing on both encrypting victim data and exfiltrating sensitive information. In this case, they managed to infiltrate SESAM Informatics' systems and exfiltrate 3.6GB of data, leveraging it to demand a ransom.
About Hunters International
Hunters International emerged in late 2023, following the dismantling of the Hive ransomware group. Approximately 60% of their code overlaps with Hive, although they assert their independence. The group prioritizes data theft over encryption, using a combination of AES and RSA encryption methods. Their ransomware is written in Rust, enhancing its performance and security. They employ tactics such as phishing, exploiting vulnerabilities, and social engineering to infiltrate organizations.
Vulnerabilities and Penetration
SESAM Informatics' focus on digital transformation and cloud computing, while innovative, may have exposed them to vulnerabilities that Hunters International exploited. The group's sophisticated tactics, including phishing and exploiting public-facing application vulnerabilities, likely played a role in penetrating SESAM Informatics' defenses. The attack underscores the importance of stringent cybersecurity measures, even for companies with advanced IT capabilities.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!