Solomon Agency Corp Hit by CL0P Ransomware Attack: Key Details
Ransomware Attack on Solomon Agency Corp by CL0P
Overview of Solomon Agency Corp
Solomon Agency Corp, operating under the domain solomonus.com, is a prominent insurance agency based in New York. The company specializes in providing a wide array of insurance products and services tailored to meet the needs of various sectors, including business, education, healthcare, and more. They offer comprehensive business insurance solutions, including property and casualty insurance, employee benefits, workers' compensation, and cyber liability coverage. Their client-centric approach and industry-specific expertise make them a leader in the insurance sector.
Details of the Ransomware Attack
On July 25, 2024, Solomon Agency Corp fell victim to a ransomware attack orchestrated by the notorious CL0P ransomware group. The attack targeted the company's website, solomonus.com. While the exact size of the data leak remains unknown, the incident underscores the persistent threat ransomware poses to critical sectors. Solomon Agency Corp is currently assessing the full impact of the breach and working to mitigate any potential damage.
About the CL0P Ransomware Group
The CL0P ransomware group is a highly sophisticated and financially motivated cybercriminal group that has been active since early 2019. Associated with the larger TA505 threat group, CL0P operates as a ransomware-as-a-service (RaaS) model. The group typically targets large enterprises, particularly in the financial, healthcare, manufacturing, and media sectors. CL0P spreads through malicious email attachments, websites, and links, as well as by exploiting known vulnerabilities like those in Accellion FTA and "ZeroLogon". In late 2020, CL0P began operating a data leak site called "CL0P^_-LEAKS" on the Tor network to publicly release stolen data from victims who do not pay the ransom.
Potential Vulnerabilities and Penetration Methods
Solomon Agency Corp, like many organizations in the insurance sector, handles sensitive client data, making it an attractive target for ransomware groups like CL0P. The group employs advanced techniques such as digital signatures to evade security controls and has been observed using tools like Cobalt Strike, web shells, and remote access trojans. The exact method of penetration in this case is not yet confirmed, but it could involve phishing attacks, exploitation of software vulnerabilities, or compromised credentials.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!