Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated
Ransomware Attack on MS Ultrasonic Technology Group by Hunters International
Company Overview
MS Ultrasonic Technology Group, headquartered in Germany, is a leading provider of ultrasonic welding solutions. Founded in 1965, the company specializes in ultrasonic welding of plastics, offering a range of products including custom machines, series machines, and modular systems for various industries such as automotive, packaging, textiles, medical technology, and consumer goods. With a revenue of $257 million, MS Ultrasonic is recognized for its innovative ultrasonic processes and global presence, with locations in Germany, the USA, Brazil, and China.
Attack Overview
On October 2023, MS Ultrasonic Technology Group fell victim to a ransomware attack orchestrated by the cybercriminal group Hunters International. The attackers claim to have infiltrated the company's systems, exfiltrating 3.7 TB of sensitive data. They have threatened to publish this data within 3-4 days if their ransom demands are not met, putting the company's operations and confidential information at significant risk.
About Hunters International
Hunters International is a Ransomware-as-a-Service (RaaS) group that emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific focus on particular industries. The group has been linked to Nigeria through domain registrations and email addresses, although they use deceptive methods to conceal their true origins.
Penetration and Vulnerabilities
The exact method of penetration used by Hunters International to infiltrate MS Ultrasonic's systems remains unclear. However, given the group's technical lineage and tactics, it is likely that they employed sophisticated phishing attacks, exploiting vulnerabilities in the company's cybersecurity infrastructure. The attack underscores the importance of robust cybersecurity measures, especially for companies like MS Ultrasonic that handle large volumes of sensitive data and operate in critical manufacturing sectors.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!