Ransomware Attack on Groupe CARCAJOU by LockBit 3.0
Ransomware Attack on Groupe CARCAJOU by LockBit 3.0
Victim Overview
Groupe CARCAJOU, an engineering and industrial equipment designer based in Annecy-le-Vieux, Auvergne-Rhone-Alpes, France, was the target of a significant cyberattack by the LockBit 3.0 ransomware group. The company operates in the Mechanical or Industrial Engineering industry and employs 1-5 people with revenue ranging from $1M-$5M. Groupe CARCAJOU specializes in designing and producing industrial equipment, with a focus on serving clients such as Toyota Motor Europe, Siemens, and other major companies in the sector.
Attack Overview
The attackers behind LockBit 3.0 infiltrated Groupe CARCAJOU's systems and stole 270 gigabytes of sensitive data. This data included photos and videos of produced equipment, purchase and partner information, insurance details for group companies ETREM, ALTAIIRE, and SERIMECA, employee certificates, and import/export records. Additionally, financial statements, audit documents, project plans, and NDA agreements with major companies were compromised. A sample of this data was leaked on the dark web leak site associated with the LockBit 3.0 ransomware group.
Ransomware Group Profile
LockBit 3.0, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) group that has evolved from previous versions of LockBit. This ransomware group is known for its advanced capabilities, including file encryption, desktop wallpaper modification, and dropping ransom notes on victims' desktops. LockBit 3.0 is highly obfuscated and difficult to analyze, making it a potent threat in the cybersecurity landscape. The group operates under a RaaS model, allowing other cybercriminals to utilize their malware for attacks.
Attack Vector
LockBit 3.0 distinguishes itself by its ability to move laterally through a network via group policy updates and delete traces of itself to cover its tracks. The ransomware group has targeted a wide range of organizations globally, including major companies in various sectors. Its modular and evasive nature makes it challenging to detect and defend against, posing a significant risk to businesses like Groupe CARCAJOU.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!