Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated

Incident Date:

July 15, 2024

World map

Overview

Title

Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated

Victim

MS Ultrasonic Technology Group

Attacker

Hunters International

Location

Křimice, Czechia

, Czechia

First Reported

July 15, 2024

Ransomware Attack on MS Ultrasonic Technology Group by Hunters International

Company Overview

MS Ultrasonic Technology Group, headquartered in Germany, is a leading provider of ultrasonic welding solutions. Founded in 1965, the company specializes in ultrasonic welding of plastics, offering a range of products including custom machines, series machines, and modular systems for various industries such as automotive, packaging, textiles, medical technology, and consumer goods. With a revenue of $257 million, MS Ultrasonic is recognized for its innovative ultrasonic processes and global presence, with locations in Germany, the USA, Brazil, and China.

Attack Overview

On October 2023, MS Ultrasonic Technology Group fell victim to a ransomware attack orchestrated by the cybercriminal group Hunters International. The attackers claim to have infiltrated the company's systems, exfiltrating 3.7 TB of sensitive data. They have threatened to publish this data within 3-4 days if their ransom demands are not met, putting the company's operations and confidential information at significant risk.

About Hunters International

Hunters International is a Ransomware-as-a-Service (RaaS) group that emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific focus on particular industries. The group has been linked to Nigeria through domain registrations and email addresses, although they use deceptive methods to conceal their true origins.

Penetration and Vulnerabilities

The exact method of penetration used by Hunters International to infiltrate MS Ultrasonic's systems remains unclear. However, given the group's technical lineage and tactics, it is likely that they employed sophisticated phishing attacks, exploiting vulnerabilities in the company's cybersecurity infrastructure. The attack underscores the importance of robust cybersecurity measures, especially for companies like MS Ultrasonic that handle large volumes of sensitive data and operate in critical manufacturing sectors.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.