RansomHub Targets Irish Industrial Supplier Manotherm in Ransomware Attack

Incident Date:

August 17, 2024

World map

Overview

Title

RansomHub Targets Irish Industrial Supplier Manotherm in Ransomware Attack

Victim

Manotherm

Attacker

Ransomhub

Location

Dublin, Ireland

, Ireland

First Reported

August 17, 2024

RansomHub Claims Ransomware Attack on Manotherm

Manotherm, a prominent supplier based in Ireland, specializing in controls, valves, instruments, and data loggers for various industrial applications, has fallen victim to a ransomware attack orchestrated by the group known as RansomHub. The attack was publicly claimed by RansomHub via their dark web leak site.

About Manotherm

Manotherm Limited is a key player in the industrial instrumentation market in Ireland, providing high-quality measurement solutions for temperature, pressure, level, and flow measurement. The company is known for its extensive product range, including pressure gauges, chemical seals, temperature monitoring instruments, and data loggers. Manotherm emphasizes customer support and technical guidance, ensuring accuracy and reliability in industrial processes.

Company Vulnerabilities

Despite its strong market presence, Manotherm's extensive digital infrastructure and reliance on data logging and control systems make it a potential target for cyber threats. The lack of publicly available detailed financial and employee data suggests that the company may not have the same level of cybersecurity resources as larger corporations, potentially making it more vulnerable to sophisticated ransomware attacks.

Attack Overview

The ransomware attack on Manotherm was claimed by RansomHub, a relatively new but aggressive ransomware group. The specifics of the attack, including the method of penetration and the extent of the data compromised, have not been fully disclosed. However, the claim on RansomHub's dark web site indicates that sensitive data may have been exfiltrated and encrypted, disrupting Manotherm's operations.

About RansomHub

RansomHub is a ransomware group believed to have roots in Russia, operating as a Ransomware-as-a-Service (RaaS) entity. Affiliates of RansomHub receive 90% of the ransom payments, with the remaining 10% going to the main group. The group has targeted various sectors across multiple countries, including healthcare institutions. RansomHub's ransomware strains are written in Golang, a trend among modern ransomware groups aiming for more effective and resilient attacks.

Penetration Methods

While the exact method of penetration in the Manotherm attack is not detailed, RansomHub typically employs phishing, exploiting vulnerabilities in outdated software, and leveraging weak security protocols. The use of Golang in their ransomware strains suggests a sophisticated approach, potentially bypassing traditional security measures and making detection and mitigation more challenging.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.