Southern Acids Faces Ransomware Breach by Hunters International

Incident Date: Dec 12, 2024

Attack Overview
VICTIM
Southern Acids
INDUSTRY
Manufacturing
LOCATION
Malaysia
ATTACKER
Hunters International
FIRST REPORTED
December 12, 2024

Ransomware Attack on Southern Acids: A Closer Look at the Hunters International Breach

Southern Acids Industries Sdn. Bhd., a prominent player in the oleochemical manufacturing sector, has recently fallen victim to a ransomware attack orchestrated by the notorious group, Hunters International. This incident underscores the persistent vulnerabilities faced by companies in the chemical manufacturing industry.

Company Profile: Southern Acids Industries

Southern Acids Industries, a subsidiary of Southern Acids (M) Berhad, is based in Klang, Selangor, Malaysia. The company is renowned for its production of oleochemical products, primarily fatty acids and glycerine derived from palm oil. With a workforce of approximately 1,830 employees, Southern Acids has established a significant presence in both local and international markets, exporting to regions such as North America, Europe, and Asia. The company's commitment to sustainability and adherence to the Roundtable on Sustainable Palm Oil (RSPO) standards since 2014 distinguishes it in the industry.

Attack Overview

The ransomware attack was discovered on December 13, 2024, with Hunters International claiming responsibility. The cybercriminals assert that they have exfiltrated 409.8 GB of data from Southern Acids' systems. Notably, while the data has been exfiltrated, it has not been encrypted, indicating a strategic move by the attackers to leverage the stolen information for extortion. Southern Acids has yet to publicly comment on the breach.

Hunters International: A Formidable Threat

Emerging in October 2023, Hunters International is a Ransomware-as-a-Service (RaaS) group that has quickly gained notoriety. The group distinguishes itself through its use of Hive ransomware code and its sophisticated double extortion tactics, which involve both data encryption and theft. Their malware, developed in Rust, allows for cross-platform targeting, making it highly adaptable and effective against enterprise environments.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.