alphv attacks SYSOL

Incident Date:

May 22, 2022

World map



alphv attacks SYSOL






Wolf-Hirth-Straße, Germany

Neckar, Germany

First Reported

May 22, 2022

SYSOL GmbH Targeted by ALPHV/Blackcat Ransomware Group

The German company SYSOL GmbH, which operates in the Software sector, has been targeted by the ALPHV/Blackcat ransomware group. The attack was announced on the group's dark web leak site, and the victim's website is SYSOL GmbH. SYSOL GmbH is a Bauschlosserei, Edelstahlverarbeitung, Metallbau, and Stahlbau company based in Esslingen, Germany, with a focus on sanierung, umbau, anbau, stahlbau, haus, garten, vorgebäude, industriegebäude, and hallen.

The size of the company is not explicitly mentioned in the search results, but it is known for its expertise in the Bauschlosserei, Edelstahlverarbeitung, Metallbau, and Stahlbau sectors, with a presence in Esslingen and the Stuttgart region. The company's website showcases its commitment to providing comprehensive services and innovative solutions for its clients.

The vulnerabilities that led to the successful attack by the ALPHV/Blackcat ransomware group are not explicitly mentioned in the search results. However, it is known that the group relies on compromised user credentials to gain initial access to victim systems. The FBI has developed a decryption tool to assist victims of Blackcat ransomware, which has saved millions of dollars in ransom demands.

The ALPHV/Blackcat ransomware group is known for its sophisticated tactics, including the use of the Rust programming language for its malware code, which is allegedly more stable and integrates better with other systems. The group also employs the Double Extortion technique, where data is both encrypted and exfiltrated, and ransom demands range from $400,000 to $3 million USD.

The attack on SYSOL GmbH is part of a larger trend of ransomware attacks targeting critical infrastructure organizations, including healthcare, public health, government, and energy sectors. The FBI, CISA, and HHS have encouraged critical infrastructure organizations to implement the recommendations in the Mitigations section of their advisory to reduce the risk of ransomware attacks.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.