RansomExx Ransomware Hits LITEON Technology: Major Data Breach

Incident Date:

July 26, 2024

World map

Overview

Title

RansomExx Ransomware Hits LITEON Technology: Major Data Breach

Victim

LITEON Technology

Attacker

Ransomexx

Location

New Taipei City, Taiwan

, Taiwan

First Reported

July 26, 2024

RansomExx Ransomware Attack on LITEON Technology

Overview of LITEON Technology

LITEON Technology, established in 1975, is a prominent global provider of optoelectronic semiconductor components and power management solutions. Headquartered in Taiwan, LITEON was the first electronics company listed on the Taiwan Stock Exchange. The company operates in various sectors, including automotive electronics, communications, industrial automation, smart homes, and medical devices. LITEON employs over 20,000 people and reported a consolidated revenue of NT$11 billion (approximately USD 365 million) for May 2024.

Details of the Ransomware Attack

On July 26th, 2024, LITEON Technology Corporation fell victim to a ransomware attack orchestrated by the RansomExx gang. The attackers posted a dataset on their DarkNet leak site, asserting that the data belonged to LITEON Technology. The compromised dataset is reported to be 142.7GB in size, indicating a significant breach of sensitive information. This incident underscores the persistent threat posed by ransomware groups and highlights the critical need for robust cybersecurity measures.

About RansomExx

RansomExx, active since 2018 and initially known as "Defray," is a dangerous ransomware variant operated by the group Sprite Spider. RansomExx targets both Windows and Linux environments, encrypting files and demanding a large cryptocurrency ransom for their decryption. The group employs a tactic known as "double extortion," where failure to pay the ransom results in the stolen data being published on their dark web leak site. RansomExx has been involved in attacks on major corporations and government agencies worldwide, including the Texas Department of Transportation, Gigabyte, Hellman Worldwide Logistics, and Ferrari.

Potential Vulnerabilities and Penetration Methods

LITEON Technology's extensive operations and significant global presence make it a lucrative target for ransomware groups like RansomExx. The group employs sophisticated techniques to infiltrate and spread within target networks, including compromised remote desktop protocol, phishing campaigns, exploiting vulnerabilities, and leveraging tools like Pyxie, Cobalt Strike, and Vatet for post-compromise activities. The attack on LITEON highlights the importance of maintaining strong cybersecurity measures to protect against such threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.