Cyberattack News

Ransomhub Attacking Industrial Control Systems To Encrypt And Exfiltrate Data

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) across various industries. 

Since 2022, numerous cyberattacks have exploited vulnerabilities in ICS, causing significant disruptions to operations and infrastructure. This highlights the need for robust security measures to safeguard ICS environments. 

Ransomhub posts on their DLS

The Ransomhub ransomware group claimed unauthorized access to Gijón’s Bio-Energy Plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control. 

ANYRUN malware sandbox’s 8th Birthday Special Offer: Grab 6 Months of Free Service

The group provided screenshots as evidence, showcasing their ability to manipulate the plant’s Digester and Heating system controls.

While the exact size of the data breach remains unclear (varying between 15 GB and 400 GB), the compromised SCADA system poses a significant risk to the plant’s operations. 

SCADA system allegedly controlling the Heating Systems of Digestor Tank

Ransomhub, a RaaS operation first advertised in February 2024, utilizes Golang and C++ for its locker component and leverages asymmetric cryptography (x25519) and a combination of symmetric algorithms (aes256, chacha20, and xchacha20) to encrypt victim data while achieving faster encryption speeds. 

Notably, Ransomhub restricts attacks on CIS countries, Cuba, North Korea, and China, possibly reflecting pro-Russian leanings.

Since its emergence, they have claimed responsibility for 68 attacks, primarily targeting the IT & ITES sector and organizations within the United States. 

TA koley’s RaaS advertisement thread on the RAMP forum

According to CRIL, they have been actively trying to expand their reach, as they attempted to recruit affiliates left behind by ALPHV/BlackCat’s exit scam by listing their targets on their DLS. 

However, the affiliates’ lack of interest led them to remove the targets.

To gain notoriety, Ransomhub has tried to capitalize on high-profile incidents like the Change Healthcare ransomware attack and is now making unsubstantiated claims of attacking SCADA systems. 

Ransomhub’s claims of possessing Change Healthcare data in a post that was deleted later

They are targeting SCADA systems using stolen credentials that they bought on Russian forums from Initial Access Brokers, which shows that ransomware groups are becoming more interested in Industrial Control Systems (ICS) environments, especially those with connected Virtual Network Computing (VNC) devices. 

Security researchers warn that such setups significantly amplify the risk of similar attacks and urge a critical reassessment of cybersecurity strategies to protect these critical infrastructures.

The anticipation is that ransomware groups will increasingly target OT environments and their components in the future. 

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago