Ransomware Attack on Groupe CARCAJOU by LockBit 3.0

Incident Date:

May 23, 2024

World map

Overview

Title

Ransomware Attack on Groupe CARCAJOU by LockBit 3.0

Victim

Carcajou Group

Attacker

Lockbit3

Location

Annecy-le-Vieux, France

, France

First Reported

May 23, 2024

Ransomware Attack on Groupe CARCAJOU by LockBit 3.0

Victim Overview

Groupe CARCAJOU, an engineering and industrial equipment designer based in Annecy-le-Vieux, Auvergne-Rhone-Alpes, France, was the target of a significant cyberattack by the LockBit 3.0 ransomware group. The company operates in the Mechanical or Industrial Engineering industry and employs 1-5 people with revenue ranging from $1M-$5M. Groupe CARCAJOU specializes in designing and producing industrial equipment, with a focus on serving clients such as Toyota Motor Europe, Siemens, and other major companies in the sector.

Attack Overview

The attackers behind LockBit 3.0 infiltrated Groupe CARCAJOU's systems and stole 270 gigabytes of sensitive data. This data included photos and videos of produced equipment, purchase and partner information, insurance details for group companies ETREM, ALTAIIRE, and SERIMECA, employee certificates, and import/export records. Additionally, financial statements, audit documents, project plans, and NDA agreements with major companies were compromised. A sample of this data was leaked on the dark web leak site associated with the LockBit 3.0 ransomware group.

Ransomware Group Profile

LockBit 3.0, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) group that has evolved from previous versions of LockBit. This ransomware group is known for its advanced capabilities, including file encryption, desktop wallpaper modification, and dropping ransom notes on victims' desktops. LockBit 3.0 is highly obfuscated and difficult to analyze, making it a potent threat in the cybersecurity landscape. The group operates under a RaaS model, allowing other cybercriminals to utilize their malware for attacks.

Attack Vector

LockBit 3.0 distinguishes itself by its ability to move laterally through a network via group policy updates and delete traces of itself to cover its tracks. The ransomware group has targeted a wide range of organizations globally, including major companies in various sectors. Its modular and evasive nature makes it challenging to detect and defend against, posing a significant risk to businesses like Groupe CARCAJOU.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.