Central Securities Corporation Hit by Major Underground Ransomware Attack

Incident Date:

June 11, 2024

World map

Overview

Title

Central Securities Corporation Hit by Major Underground Ransomware Attack

Victim

Central Securities Corporation

Attacker

Underground Team

Location

London, United Kingdom

, United Kingdom

First Reported

June 11, 2024

Central Securities Corporation Falls Victim to Underground Ransomware Attack

Overview of Central Securities Corporation

Central Securities Corporation, a closed-end investment company based in New York City, has been a significant player in the finance sector since its inception on October 1, 1929. The company focuses on investing in a diversified portfolio of securities, including stocks, bonds, and other financial instruments, aiming for long-term capital growth and income for its shareholders. With a revenue of $230 million, Central Securities Corporation stands out for its professional management and transparent reporting to shareholders.

Details of the Ransomware Attack

Central Securities Corporation's website was recently attacked by the ransomware group Underground. The attack resulted in a data leak compromising 42.8 GB of sensitive information. The breach highlights the vulnerabilities that even well-established financial institutions face in the evolving cyber threat landscape.

About the Underground Ransomware Group

Underground ransomware is a sophisticated 64-bit GUI-based application known for its ability to delete backups, modify registry settings, and stop critical services like MSSQLSERVER. The ransomware identifies system volumes using API functions and leaves ransom notes in multiple system folders. It selectively encrypts files and directories, excluding specific file names, extensions, and folders.

Possible Infection Vectors

The distribution vector for Underground ransomware likely involves social engineering tactics, such as phishing emails with malicious attachments or links to compromised websites. These emails are often designed to appear legitimate, persuading users to open attachments or click links, leading to the execution of the malicious binary. Additionally, attackers may use malicious file downloads disguised as software updates or legitimate applications.

Implications and Industry Impact

This attack on Central Securities Corporation underscores the persistent threat that ransomware poses to the financial sector. Despite robust security measures, the sophistication of groups like Underground continues to challenge even the most prepared organizations. The breach not only compromises sensitive data but also threatens the trust and financial stability of the affected institution.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.