Qilin Ransomware Group Strikes A&A Group Construction in Cyberattack

Incident Date:

June 11, 2024

World map

Overview

Title

Qilin Ransomware Group Strikes A&A Group Construction in Cyberattack

Victim

A&A Group Construction

Attacker

Qilin

Location

Haywards Heath, United Kingdom

, United Kingdom

First Reported

June 11, 2024

Qilin Ransomware Group Targets A&A Group Construction

Overview of A&A Group Construction

A&A Group Construction, a certified woman-owned construction services firm based in Fairfield, NJ, specializes in a wide range of construction services, including residential, commercial, and industrial projects. The company employs between 51-200 people and has a strong record of completing projects on time and below budget. They are certified by the State of New Jersey, Port Authority of NY and NJ, and NJ Transit as a woman-owned business. Their comprehensive approach ensures high-quality, safe, and efficient project completion.

Details of the Ransomware Attack

The Qilin ransomware group, also known as Agenda, has claimed responsibility for a cyberattack on A&A Group Construction. The attack was announced on Qilin's dark web leak site. A&A Group Construction, which operates in the construction industry and generates $10M-$25M in revenue, was targeted due to its critical role in various sectors, including healthcare, education, and transportation.

About the Qilin Ransomware Group

Qilin is a prominent ransomware-as-a-service (RaaS) group that emerged in 2022. They target critical infrastructure organizations worldwide, including healthcare and education sectors. Qilin ransomware is written in Rust and Go, making it evasion-prone and hard-to-decipher. The group employs a double extortion technique, exfiltrating sensitive data and demanding payment for a decryptor while threatening to release stolen data. Qilin advertises its ransomware on the dark web and has targeted organizations in multiple countries, including the United States, Australia, and the United Kingdom.

Penetration and Vulnerabilities

Qilin ransomware attacks often begin with phishing emails containing malicious links. Once inside the victim's infrastructure, the group laterally moves across systems, searching for essential data to encrypt. A&A Group Construction's extensive involvement in public contracts and critical infrastructure projects made them a lucrative target. The company's reliance on digital systems for project management, scheduling, and budgeting may have presented vulnerabilities that Qilin exploited.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.