Ransomware Attack on Italian Consortium Consorzio Innova by AlphaLocker

Incident Date: Aug 06, 2024

Attack Overview
VICTIM
Consorzio Innova
INDUSTRY
Construction
LOCATION
Italy
ATTACKER
AlphaLocker
FIRST REPORTED
August 6, 2024

Ransomware Attack on Consorzio Innova by AlphaLocker

On March 11, Consorzio Innova, an Italian consortium specializing in construction, plant engineering, and services for public entities, industry, and the tertiary sector, became the latest victim of a ransomware attack. The attack, attributed to the AlphaLocker ransomware group, resulted in a significant data breach, compromising approximately 225GB of sensitive information.

About Consorzio Innova

Consorzio Innova operates as a cooperative consortium of various companies based in Italy. The organization focuses on civil engineering, infrastructure development, and the provision of technical services. By leveraging the collective expertise and resources of its member companies, Consorzio Innova aims to enhance its capacity to undertake complex projects and meet diverse client needs. The consortium is also committed to sustainable practices and technological advancements, ensuring compliance with environmental standards and regulations.

Attack Overview

The ransomware attack on Consorzio Innova was orchestrated by the AlphaLocker group, a relatively new player in the ransomware landscape. The attack led to the encryption of critical data, with the threat actors demanding a ransom for decryption. The compromised data included sensitive information, highlighting the growing threat of ransomware attacks on critical infrastructure and service providers.

AlphaLocker Ransomware Group

AlphaLocker is a ransomware-as-a-service (RaaS) operation that emerged in mid-2023. The group sells its malware to cybercriminals at a low cost, providing buyers with an administrative panel, the ransomware executable, and the decryption binary. AlphaLocker primarily spreads through phishing emails containing infected attachments. Once executed, the ransomware encrypts files using an asymmetric encryption algorithm, making it impossible for victims to decrypt their files without paying the ransom.

Penetration and Vulnerabilities

The attack on Consorzio Innova likely involved phishing emails with infected attachments, a common tactic used by AlphaLocker. The consortium's focus on collaboration and the integration of multiple companies may have introduced vulnerabilities, making it an attractive target for threat actors. The use of tools like Taskkill, PsExec, Net.exe, and Reg.exe by AlphaLocker further facilitated the evasion of detection during the infection process.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.