ArcusMedia Ransomware Attack on BHMAC: Cyber Threats to Humanitarian Efforts

Incident Date:

June 4, 2024

World map

Overview

Title

ArcusMedia Ransomware Attack on BHMAC: Cyber Threats to Humanitarian Efforts

Victim

BHMAC

Attacker

Arcus Media

Location

Kasindolska, Bosnia and Herzegovina

, Bosnia and Herzegovina

First Reported

June 4, 2024

ArcusMedia Ransomware Attack on BHMAC

Overview of BHMAC

The Bosnia and Herzegovina Mine Action Centre (BHMAC) is a pivotal organization dedicated to addressing the issue of landmines and unexploded ordnance (UXO) in Bosnia and Herzegovina. BHMAC employs between 101 and 250 people and generates revenue in the range of $25 million to $50 million. The organization operates from two main offices in Banja Luka and Sarajevo. BHMAC stands out for its comprehensive approach to demining, which includes surveying, mapping, and clearing mine-affected areas, as well as conducting risk education and maintaining a detailed database of mine-affected regions.

Details of the Attack

ArcusMedia, a relatively new ransomware group, has claimed responsibility for a ransomware attack on BHMAC. The attack was announced via ArcusMedia's dark web leak site. The group is known for its direct and double extortion methods, often using phishing emails to gain initial access to victim networks. Once inside, they deploy custom ransomware binaries and use obfuscation techniques to evade detection. The attack on BHMAC highlights the vulnerabilities that even well-established organizations face in the current cyber threat landscape.

About ArcusMedia

The ransomware group ArcusMedia has been active since May 2024 and operates on a Ransomware-as-a-Service (RaaS) model. The group employs a unique affiliate program where new affiliates must be referred by a trusted member. ArcusMedia has targeted a wide range of sectors, including government, healthcare, and education. Their tactics include phishing for initial access, deploying obfuscated scripts for execution, and using tools like Mimikatz for privilege escalation. The group has quickly established itself with a distinct set of tactics, techniques, and procedures (TTPs).

Potential Vulnerabilities

BHMAC's extensive use of information systems to aid in demining efforts could have been a potential vulnerability exploited by ArcusMedia. The organization's reliance on digital databases and communication networks makes it a prime target for ransomware attacks. The attack underscores the importance of robust cybersecurity measures, especially for organizations involved in critical and humanitarian missions.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.