lockbit2 attacks genesis

Incident Date:

March 18, 2022

World map

Overview

Title

lockbit2 attacks genesis

Victim

genesis

Attacker

Lockbit2

Location

Elgin Court, Cayman Islands

Elgin Court, Cayman Islands

First Reported

March 18, 2022

Genesis, a Business Services Company Targeted by Lockbit2 Ransomware

Overview of the Attack

Lockbit2, a well-known ransomware group, has recently taken responsibility for an attack on Genesis, a prominent player in the Business Services sector. Genesis is notably involved with the Genesis Market, an online platform infamous for its role in facilitating cyberattacks against U.S. companies and government entities. This marketplace is a hub for stolen credentials, cookies, device fingerprints, and website vulnerabilities, attracting a significant hacker clientele.

The Nature of Genesis Ransomware

The Genesis ransomware, identified as part of the MedusaLocker family, specifically targets corporate entities rather than individual users. It employs RSA and AES cryptographic algorithms to encrypt files on the victim's network. The ransom note that follows encryption demands payment for file decryption while cautioning against any attempts to rename or modify the encrypted files. Failure to comply with the payment demand may result in the attackers selling or leaking the stolen data.

Disruption of the Genesis Market

An international cyber operation has recently disrupted the Genesis Market, leading to the seizure of over 1.5 million compromised computers and the exposure of over 80 million account credentials. The FBI has contributed to these efforts by providing victim credentials to the Have I Been Pwned website, enabling individuals to check if their access credentials have been compromised.

Despite the takedown attempt, the Genesis Market remains operational on the Tor network and has announced plans to establish new domains. However, the operation has resulted in a significant number of arrests, potentially impacting the market's profitability and long-term viability.

Implications of the Lockbit2 Ransomware Attack on Genesis

The targeting of Genesis by the Lockbit2 ransomware group underscores the persistent threat posed by cybercriminals to companies within the Business Services sector. This incident not only highlights the vulnerabilities of companies involved in or associated with illicit online marketplaces but also raises questions about the effectiveness of international cyber operations against such entities. Despite the disruption efforts, the resilience of platforms like the Genesis Market on alternative networks like Tor poses ongoing challenges to cybersecurity efforts.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.