NoEscape attacks Enware Australia

Incident Date:

November 21, 2023

World map

Overview

Title

NoEscape attacks Enware Australia

Victim

Enware Australia

Attacker

Noescape

Location

Caringbah, Australia

Australia, Australia

First Reported

November 21, 2023

Enware Australia Targeted by NoEscape Ransomware Group

Enware Australia has been added to the NoEscape ransomware group's data leak site. The group claims to have obtained 20 GB of data, including banking details, certificates of compliance, orders, customer service information, HR and HR software data, SQL data, and many other company documents. Enware supplies specialist plumbing and safety equipment to a wide variety of commercial industries.

NoEscape: A New Threat on the Rise

NoEscape – assessed to be a spinoff of the disbanded Avaddon gang -- emerged in May of 2023 and operates as a Ransomware-as-a-Service (RaaS) and emerged with variants for targeting both Windows, Linux and VMware ESXi systems. NoEscape provides affiliates with 24/7 technical support, communications, and negotiation assistance, as well as an automated RaaS platform update feature. Having just recently emerged, NoEscape has rapidly become one of the more prolific attack groups, with attack volume escalating significantly in the second quarter of 2023.

Ransom Demands and Profit Sharing

IT is unclear how high the typical NoEscape ransom demands tend to be, but it has been observed that profit sharing with affiliates is on par or even more attractive than other groups with ransoms over $3 million netting 90/10 split with affiliates taking the lion’s share.

Technical Aspects of NoEscape Ransomware

NoEscape is written in C++ and is relatively unique in the space in that the developers opted to build the RaaS platform from scratch rather than rely on code reuse from other ransomware variants. NoEscape ransomware payloads support multiple encryption options ranging from extra fast to extra strong encryption and leverages RSA and ChaCHA20 encryption algorithms with a single key for all impacted files for faster decryption of a ransom is paid. NoEscape can operate in safe mode to bypass security tools, terminate processes, erase VSS shadow copies and system back-ups to thwart recovery efforts, and abuse Windows Restart Manager to circumvent processes not terminated.

Target Industries and Operations

NoEscape operations target a wide array of industry verticals with a focus on Professional Services, Manufacturing, Information Technology and Healthcare. NoEscape offers its RaaS platform to affiliate attackers and operations typically include data exfiltration or other actions to be leveraged in double extortion schemes such as a denial-of-service option for a hefty additional fee to the affiliate. NoEscape maintains a TOR-based leaks site to name-and-shame victims.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.