Ransomware Attack on Italian Consortium Consorzio Innova by AlphaLocker

Incident Date:

August 6, 2024

World map

Overview

Title

Ransomware Attack on Italian Consortium Consorzio Innova by AlphaLocker

Victim

Consorzio Innova

Attacker

AlphaLocker

Location

Bologna, Italy

, Italy

First Reported

August 6, 2024

Ransomware Attack on Consorzio Innova by AlphaLocker

On March 11, Consorzio Innova, an Italian consortium specializing in construction, plant engineering, and services for public entities, industry, and the tertiary sector, became the latest victim of a ransomware attack. The attack, attributed to the AlphaLocker ransomware group, resulted in a significant data breach, compromising approximately 225GB of sensitive information.

About Consorzio Innova

Consorzio Innova operates as a cooperative consortium of various companies based in Italy. The organization focuses on civil engineering, infrastructure development, and the provision of technical services. By leveraging the collective expertise and resources of its member companies, Consorzio Innova aims to enhance its capacity to undertake complex projects and meet diverse client needs. The consortium is also committed to sustainable practices and technological advancements, ensuring compliance with environmental standards and regulations.

Attack Overview

The ransomware attack on Consorzio Innova was orchestrated by the AlphaLocker group, a relatively new player in the ransomware landscape. The attack led to the encryption of critical data, with the threat actors demanding a ransom for decryption. The compromised data included sensitive information, highlighting the growing threat of ransomware attacks on critical infrastructure and service providers.

AlphaLocker Ransomware Group

AlphaLocker is a ransomware-as-a-service (RaaS) operation that emerged in mid-2023. The group sells its malware to cybercriminals at a low cost, providing buyers with an administrative panel, the ransomware executable, and the decryption binary. AlphaLocker primarily spreads through phishing emails containing infected attachments. Once executed, the ransomware encrypts files using an asymmetric encryption algorithm, making it impossible for victims to decrypt their files without paying the ransom.

Penetration and Vulnerabilities

The attack on Consorzio Innova likely involved phishing emails with infected attachments, a common tactic used by AlphaLocker. The consortium's focus on collaboration and the integration of multiple companies may have introduced vulnerabilities, making it an attractive target for threat actors. The use of tools like Taskkill, PsExec, Net.exe, and Reg.exe by AlphaLocker further facilitated the evasion of detection during the infection process.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.