Monti attacks Apex

Incident Date:

February 23, 2024

World map

Overview

Title

Monti attacks Apex

Victim

Apex

Attacker

Monti

Location

Glinde, Germany

, Germany

First Reported

February 23, 2024

Ransomware Group Monti Targets German Logistics Company APEX

Ransomware group Monti has attacked the German company APEX. APEX is a logistics company that handles transport logistics, warehouse logistics, and ocean freight. It tailors service-based logistics solutions according to its customers’ unique situations and needs.

Monti ransomware was discovered by researchers in June 2022. The group drew attention by operating like the now out-of-business Conti ransomware group. In September of the same year, Blackberry's Incident Response team investigated a security incident linked to Monti. The attackers had exploited the notorious Log4Shell vulnerability on a client's internet-facing VMware Horizon virtualization system.

Once the threat actors gained entry to the victim's VMware Horizon Connection Broker server through the Log4Shell exploit, they proceeded to install Google Chrome and used it to download attack tools onto the server.

Monti's Return with a New Variant

After taking a short break, Monti returned in August 2023 with a new Linux-based Monti variant (Ransom.Linux.MONTI.THGOCBC). Trend Micro researchers pointed out that there are significant differences from previous Linux-based versions. One is the use of the "--type=soft" parameter to shut down virtual machines on the system instead of the previous "--type=hard" option. Researchers speculate this was done to help the group evade detection.

Monti's code enhancements indicate its desire to enhance its evasion detection techniques and make it harder for security practitioners to detect and mitigate their actions.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.