ArcusMedia Ransomware Strikes Botselo Mills Ltd.

Incident Date:

June 4, 2024

World map

Overview

Title

ArcusMedia Ransomware Strikes Botselo Mills Ltd.

Victim

Botselo Mills Ltd

Attacker

Arcus Media

Location

Delareyville, South Africa

, South Africa

First Reported

June 4, 2024

ArcusMedia Ransomware Attack on Botselo Mills Ltd.

Overview of Botselo Mills Ltd.

Botselo Mills Ltd., a family-operated maize milling company based in Delareyville, North West Province, South Africa, has been targeted by the ArcusMedia ransomware group. The company, a subsidiary of KLK Landbou, employs 356 people and operates on 7.5 hectares of industrial property. Botselo Mills specializes in producing a range of quality white and yellow maize products, including maize meal, grits, and beer powder. Their vertical integration, from farming to milling, ensures stringent quality control and product consistency.

Attack Overview

Recently, the ArcusMedia ransomware group claimed responsibility for the attack on Botselo Mills via their dark web leak site. The attack disrupted the operations of Botselo Mills, a key player in the agricultural sector, known for its commitment to quality, sustainability, and community development. The ransomware group likely penetrated the company's systems through phishing emails, deploying custom ransomware binaries and obfuscated scripts to evade detection.

About ArcusMedia Ransomware Group

Since May 2024, ArcusMedia has been active, employing direct and double extortion methods. They use phishing emails for initial access, followed by deploying custom ransomware payloads. The group operates on a Ransomware-as-a-Service (RaaS) model, allowing other threat actors to use their malware. ArcusMedia's unique affiliate program requires new affiliates to be referred and vetted, distinguishing them from other ransomware groups.

Penetration and Impact

Notably, ArcusMedia's tactics include creating scheduled tasks and modifying registries to maintain persistence and evade detection. They use credential dumping tools like Mimikatz for privilege escalation. The attack on Botselo Mills highlights the vulnerabilities in the agricultural sector, particularly for companies with extensive digital operations and supply chains. The disruption caused by the ransomware attack underscores the importance of robust cybersecurity measures in protecting critical infrastructure.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.