RansomHub Ransomware Hits Leading Islamic Finance Firm TID

Incident Date:

August 8, 2024

World map

Overview

Title

RansomHub Ransomware Hits Leading Islamic Finance Firm TID

Victim

The Investment Dar

Attacker

Ransomhub

Location

Kuwait City, Kuwait

, Kuwait

First Reported

August 8, 2024

RansomHub Ransomware Attack on The Investment Dar

The Investment Dar Company (TID), a leading Islamic finance organization in the MENA region, has been targeted by the ransomware group RansomHub. The attack, discovered on August 9, has raised significant concerns due to TID's prominent position in the financial sector.

About The Investment Dar

Established in 1994 in Kuwait, The Investment Dar Company (TID) is a major player in the Islamic finance sector. Founded by a consortium of Kuwaiti businessmen, TID addresses the need for consumer Islamic finance options. The company offers a wide range of Sharia-compliant financial services, including consumer finance, real estate finance, commercial finance, investment funds, Islamic sukuk, consultancy, and portfolio management. TID has expanded its operations to various markets, including Saudi Arabia, and has assets valued at approximately KD 971 million (around USD 3.2 billion) as of 2009.

Attack Overview

The ransomware attack on TID was orchestrated by RansomHub, a relatively new but aggressive ransomware group. The attack targeted TID's website, inv-dar.com, and resulted in a data leak of unknown size. Given TID's extensive operations and significant financial assets, the attack underscores the growing threat of cyberattacks on major financial institutions in the region.

RansomHub: The Threat Actor

RansomHub is a ransomware group believed to have roots in Russia, operating as a Ransomware-as-a-Service (RaaS) entity. Affiliates of RansomHub receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, with a notable focus on healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a relatively new trend in the ransomware world, which may indicate future trends in ransomware development.

Potential Vulnerabilities

While the exact method of penetration remains unclear, TID's extensive digital infrastructure and significant financial assets make it an attractive target for ransomware groups like RansomHub. The use of Golang in RansomHub's ransomware strains suggests a sophisticated approach to cyberattacks, potentially exploiting vulnerabilities in TID's cybersecurity defenses.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.