APT73 Ransomware Breach Exposes Vulnerabilities at Apex Engineering Services

Incident Date:

June 12, 2024

World map

Overview

Title

APT73 Ransomware Breach Exposes Vulnerabilities at Apex Engineering Services

Victim

Apex Engineering Services

Attacker

APT73

Location

London, United Kingdom

, United Kingdom

First Reported

June 12, 2024

APT73 Ransomware Attack on Apex Engineering Services

Overview of Apex Engineering Services

Apex Engineering Services, a UK-based company, specializes in providing comprehensive engineering solutions across various industries. With a team of seasoned freelance engineers and specialist contractors, the company offers services ranging from 3D scanning and construction site engineering to monitoring and surveys. Apex Engineering Services prides itself on delivering high-quality, innovative, and cost-effective solutions, contributing to clients' ability to complete projects on time and within budget.

Details of the Attack

The ransomware group APT73 has claimed responsibility for a cyberattack on Apex Engineering Services. The attack, disclosed via APT73's dark web leak site, resulted in the exfiltration of passwords, internal files, and 26MB of data. A sample of the stolen data has been leaked, underscoring the severity of the breach. The attack highlights vulnerabilities in Apex Engineering Services' cybersecurity measures, making them a target for sophisticated threat actors.

About APT73

APT73 is an emerging ransomware group that has recently surfaced in the cyber threat landscape. The group operates a TOR-based data leak site named "ERALEIGNEWS," employing tactics similar to the LockBit ransomware variant. APT73 primarily targets organizations through phishing attacks, compromising systems to deploy ransomware. Despite some amateurish traits, such as the lack of active mirrors for their data leak site, APT73 poses a significant threat due to their sophisticated ransomware tactics.

Penetration Tactics

APT73 likely penetrated Apex Engineering Services' systems through phishing attacks, a common method for ransomware groups. By compromising user credentials and exploiting vulnerabilities in the company's cybersecurity infrastructure, APT73 was able to deploy ransomware and exfiltrate sensitive data. The attack underscores the importance of robust cybersecurity measures to protect against such sophisticated threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.