Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated

Incident Date: Jul 15, 2024

Attack Overview
VICTIM
MS Ultrasonic Technology Group
INDUSTRY
Manufacturing
LOCATION
Czechia
ATTACKER
Hunters International
FIRST REPORTED
July 15, 2024

Ransomware Attack on MS Ultrasonic Technology Group by Hunters International

Company Overview

MS Ultrasonic Technology Group, headquartered in Germany, is a leading provider of ultrasonic welding solutions. Founded in 1965, the company specializes in ultrasonic welding of plastics, offering a range of products including custom machines, series machines, and modular systems for various industries such as automotive, packaging, textiles, medical technology, and consumer goods. With a revenue of $257 million, MS Ultrasonic is recognized for its innovative ultrasonic processes and global presence, with locations in Germany, the USA, Brazil, and China.

Attack Overview

On October 2023, MS Ultrasonic Technology Group fell victim to a ransomware attack orchestrated by the cybercriminal group Hunters International. The attackers claim to have infiltrated the company's systems, exfiltrating 3.7 TB of sensitive data. They have threatened to publish this data within 3-4 days if their ransom demands are not met, putting the company's operations and confidential information at significant risk.

About Hunters International

Hunters International is a Ransomware-as-a-Service (RaaS) group that emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific focus on particular industries. The group has been linked to Nigeria through domain registrations and email addresses, although they use deceptive methods to conceal their true origins.

Penetration and Vulnerabilities

The exact method of penetration used by Hunters International to infiltrate MS Ultrasonic's systems remains unclear. However, given the group's technical lineage and tactics, it is likely that they employed sophisticated phishing attacks, exploiting vulnerabilities in the company's cybersecurity infrastructure. The attack underscores the importance of robust cybersecurity measures, especially for companies like MS Ultrasonic that handle large volumes of sensitive data and operate in critical manufacturing sectors.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.