ElDorado Ransomware Strikes UCC Retrievals Inc.

Incident Date:

June 6, 2024

World map

Overview

Title

ElDorado Ransomware Strikes UCC Retrievals Inc.

Victim

UCC Retrievals Inc.

Attacker

ElDorado

Location

Mechanicsville, USA

Virginia, USA

First Reported

June 6, 2024

ElDorado Ransomware Attack on UCC Retrievals Inc.

Overview of UCC Retrievals Inc.

UCC Retrievals Inc., headquartered in Mechanicsville, Virginia, is a family-owned public record services company founded in 1989. Specializing in Uniform Commercial Code (UCC) filings and searches, the company assists businesses, legal professionals, and financial institutions in managing and retrieving UCC-related documents. Their services include conducting UCC searches, preparing and filing UCC documents, and monitoring the status of UCC filings. UCC Retrievals is a member of the National Public Records Research Association and the Public Record Retriever Network, underscoring their reputable standing in the industry.

Details of the Ransomware Attack

The ransomware group ElDorado has claimed responsibility for a recent attack on UCC Retrievals Inc. The group announced on their dark web leak site that data from UCC Retrievals is now up for sale. ElDorado employs a double-extortion tactic, encrypting files and exfiltrating sensitive data, which they threaten to release if ransom demands are not met. The attack has significantly impacted UCC Retrievals, potentially compromising sensitive UCC filings and client information.

About ElDorado Ransomware Group

ElDorado emerged in 2024 and quickly gained notoriety through a series of high-profile attacks. Known for their meticulous targeting and sophisticated techniques, they conduct thorough reconnaissance to identify valuable data before exfiltrating and encrypting it. Their ransom notes, typically named HOW_RETURN_YOUR_DATA.TXT, threaten to leak or sell stolen data if victims do not comply within seven days. ElDorado uses phishing attacks, exploits unpatched vulnerabilities, and leverages weaknesses in Remote Desktop Protocol (RDP) configurations to infiltrate systems.

Potential Vulnerabilities and Penetration Methods

UCC Retrievals Inc., like many small and medium-sized businesses, may have been targeted due to potentially less robust cybersecurity defenses. ElDorado likely exploited vulnerabilities in software or RDP configurations, or used phishing attacks to gain initial access. Once inside, they used legitimate system administration tools to blend in with normal operations, making detection difficult. The exfiltration of sensitive UCC filings and client data adds another layer of pressure on UCC Retrievals to meet ransom demands.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.