alphv attacks Klasner & Solomon

Incident Date:

May 30, 2022

World map

Overview

Title

alphv attacks Klasner & Solomon

Victim

Klasner & Solomon

Attacker

Alphv

Location

Markham, Canada

Ontario, Canada

First Reported

May 30, 2022

Klasner & Solomon Law Firm Targeted by ALPHV Ransomware Group

The ALPHV ransomware group has claimed responsibility for an attack on Klasner & Solomon, a law firm operating in the Law Firms & Legal Services sector. The specifics regarding the company's size and the vulnerabilities exploited in the attack remain undisclosed.

About Klasner & Solomon

Klasner & Solomon is a law firm that provides legal advice and representation across various areas of law, including corporate law, litigation, and intellectual property law. The firm is recognized within the Law Firms & Legal Services sector, though the exact scale of its operations is not detailed.

Industry Standout

As a provider of specialized legal services, Klasner & Solomon plays a critical role in the legal industry, offering expertise in multiple legal domains to its clientele.

Vulnerabilities

While specific vulnerabilities that facilitated the ALPHV ransomware attack on Klasner & Solomon are not detailed, it is essential to note that ALPHV operates as a Ransomware as a Service (RaaS). This operation is known for its capability to encrypt files using AES or ChaCha20 algorithms, delete volume shadow copies, terminate processes and services, and halt virtual machines on ESXi servers, thereby maximizing the potential for data ransom.

ALPHV Ransomware Group

Identified since November 18, 2021, ALPHV, also referred to as BlackCat, is a ransomware family developed in Rust. It is compatible with Windows, Linux-based systems, and VMWare ESXi. Although marketed as ALPHV on cybercrime forums, the security community frequently refers to it as BlackCat, a nod to its leak site's iconography.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.