Ransomware Attack on Agrani Bank PLC

Incident Date:

May 16, 2024

World map

Overview

Title

Ransomware Attack on Agrani Bank PLC

Victim

Agrani Bank Limited

Attacker

Killsec

Location

Dhaka, Bangladesh

, Bangladesh

First Reported

May 16, 2024

Ransomware Attack on Agrani Bank PLC

Victim Overview

Agrani Bank PLC, a leading commercial bank in Bangladesh, was targeted by a ransomware attack orchestrated by the cybercriminal group Kill Security. The bank offers a range of banking services including deposits, loans, remittances, and other financial products. Agrani Bank stands out in the industry due to its strategic locations, agent banking services, and technological advancements.

Attack Details

The ransomware attack on Agrani Bank PLC involved the cybercriminals demanding a payment of $5,000. The attackers pilfered data from the bank's email server, totaling over 12,000 files containing confidential information. A sample of the compromised data was leaked, and a ransom deadline of May 26, 2024, was set.

Ransomware Group: Kill Security

Kill Security is a relatively new ransomware group that primarily conducts ransomware attacks targeting various industries, including banking and finance. The group distinguishes itself by demanding ransom payments ranging from 1,500 EUR to 10,000 EUR. Kill Security uses various communication channels such as Telegram and Session Messenger for interaction with victims.

Attack Vector

It is likely that Kill Security penetrated Agrani Bank PLC's systems through phishing emails, exploiting vulnerabilities in the bank's network, or through compromised credentials. As of the current information, there is no known decryptor available for the ransomware attacks conducted by Kill Security, posing a significant challenge for the victims.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.