Ransomware Hits Structural & Steel Products by Hunters International

Incident Date: Oct 10, 2024

Attack Overview
VICTIM
Structural and Steel Products
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Hunters International
FIRST REPORTED
October 10, 2024

Ransomware Attack on Structural & Steel Products Inc. by Hunters International

Structural & Steel Products Inc. (SSP), a prominent manufacturer based in Fort Worth, Texas, has fallen victim to a ransomware attack orchestrated by the notorious group Hunters International. SSP specializes in producing essential infrastructure components such as overhead sign structures, guardrails, crash cushions, lighting poles, and bridge decking, primarily for the highway construction sector. The company is known for its commitment to quality and compliance, conducting rigorous inspections to ensure all products meet customer specifications and industry standards.

Company Profile and Vulnerabilities

With a workforce of 201 to 500 employees, SSP plays a significant role in regional infrastructure development. The company's emphasis on quality assurance and engineering capabilities positions it as a reliable partner in the steel industry. However, its focus on critical infrastructure makes it an attractive target for ransomware groups like Hunters International. The attack highlights potential vulnerabilities in SSP's cybersecurity measures, which may have been exploited by the attackers to gain access to sensitive data.

Attack Overview

Hunters International claims to have compromised 558.8 GB of data, encompassing 510,337 files from SSP's systems. The group has threatened to release the stolen data within 1 to 2 days, putting the company's sensitive information at risk of public exposure. This attack underscores the critical threat level posed by Hunters International, which employs double extortion tactics to maximize leverage over its victims.

Hunters International: A Sophisticated Threat

Emerging in October 2023, Hunters International is a Ransomware-as-a-Service (RaaS) group that utilizes code from the defunct Hive ransomware operation. The group distinguishes itself through its adaptability, targeting both Windows and Linux environments, and employing advanced encryption techniques. Hunters International's modus operandi involves multi-stage operations, beginning with network reconnaissance and lateral movement before data exfiltration and encryption. The group likely penetrated SSP's systems through phishing campaigns or exploiting remote services, common tactics used to gain initial access.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.